Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Advanced

    The Target: Advanced Computer Software Group, a provider of IT and software services to the U.K.’s National Health Service (NHS) and other healthcare organizations.

    The Take: The data breach affected 82,946 people, with sensitive information being exfiltrated, including medical records, phone numbers, and access details to the homes of 890 individuals receiving care at home.

    The Vector: The incident, which occurred in August 2022, involved a ransomware attack that accessed systems via an account lacking multi-factor authentication.

    This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    Cybersecurity Firm Wiz to Open European Headquarters in London

    2024-08-15

    The Guardian: Cybersecurity firm Wiz, which last month rejected a $23bn (£18bn) takeover bid from Google’s parent company, Alphabet, is to open a European headquarters in London – a move that is a major shot in the arm for the UK’s aspiration to be a global tech hub.

    Read more...

    Hackers May Have Stolen The Social Security Numbers of all Americans. Here's What to Know.

    2024-08-15

    CBS News: A new lawsuit is claiming hackers have gained access to the personal information of "billions of individuals," including their Social Security numbers, current and past addresses and the names of siblings and parents — personal data that could allow fraudsters to infiltrate financial accounts or take out loans in their names. 

    Read more...

    M&A Activity Can Amplify Ransomware Insurance Losses, Research Finds

    2024-08-14

    Cybersecurity Dive: Global M&A deal volume increased 36% in the first quarter of the year, according to an Ernst & Young analysis. While such growth can be seen as a sign of positive economic development, it can also create new entry points for cyber threat actors, Resilience said in its report.

    Read more...

    Kiteworks Captures $456 Million at a $1 Billion+ Valuation to Help Secure Sensitive Data

    2024-08-14

    TechCrunch: Mark up another unicorn and large funding round for the cybersecurity industry: Kiteworks, which builds tools to secure email communications, file sharing and situations where people work with sensitive data, has raised $456 million from Insight Partners and Sixth Street Growth. The investment values the company at over $1 billion.

    Read more...

    CISOs Face Uncharted Territory in Preparing For AI Security Risks

    2024-08-13

    CSO Online: Generative AI, which has the unique ability to create original content and actions, had its conceptual origins in 1906 when Russian mathematician Andrei Andreevich Markov created a stochastic model of probabilities known as the Markov chain. 

    Read more...

    Warburg Pincus-Backed Cybersecurity Firm eSentire Explores Sale, Sources Say

    2024-08-13

    Yahoo Finance: The owners of eSentire are exploring options including a potential sale that could value the cybersecurity company at about $1 billion, including debt, according to people familiar with the matter.

    Read more...

    CrowdStrike Tries to Patch Things Up With Cybersecurity Industry

    2024-08-12

    Dark Reading: A combination of factors caused the CrowdStrike Falcon endpoint detection and prevention (EDR) sensor to crash, resulting in the global outage affecting 8.5 million Windows systems in July, the company said in a root-cause analysis of the incident.

    Read more...

    Know Your Breach: HealthEquity

    The Target: HealthEquity, a Utah-based health savings account (HSA) provider.

    The Take: The stolen information included a mix of benefits sign-up information that varied by customer. That mix could include name, address, phone number, employee ID, employer, Social Security number, and dependent information.

    The Vector: The company said in a notice that a hacker managed to breach an "an unstructured data repository outside our core systems" containing customer data, making off with various kinds of personally identifiable information.

    This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

    Read more...

    Ransomware Attack Forces Hundreds of Small Indian Banks Offline, Sources Say

    2024-08-01

    MSN: A ransomware attack on a technology service provider has forced payment systems across nearly 300 small Indian local banks to shut down temporarily, two sources directly aware of the matter said.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates