Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: CCleaner

    The Target: The popular optimization app CCleaner

    The Take: The hackers took names, contact information and information about the products that were purchased.

    The Vector: The hackers exploited a vulnerability in the widely used MOVEit file transfer tool, which is used by thousands of organizations, including CCleaner, to move large sets of sensitive data over the internet.

    This breach is a stark reminder of how authentication controls are in an overall robust cybersecurity posture, and more critically, ensuring these controls are in place on all third-party vendors which have access to a firm’s data.

    Read more...

    Saudi Aramco VC Fund Backs AI-Powered Cybersecurity Startup

    2023-11-01

    BNN Bloomberg: Saudi Aramco’s venture capital arm has invested in SpiderSilk, a United Arab Emirates-based startup that offers AI-powered cybersecurity services.

    Read more...

    Is The Changing Cybersecurity Landscape An Opportunity For PE Investors?

    2023-11-01

    Mondaq: The cybersecurity sector is projected to experience 10% CAGR over the next 3 years, fueled by the increasing volume and complexity of cyber threats.

    Read more...

    Mastering The Art Of Building A Top-Tier Cybersecurity Team

    2023-11-01

    Forbes: The security landscape integrates various models, ideologies and best solutions for team development. Corporations and multiple institutions face challenges when attempting to structure and design functional cybersecurity teams.

    Read more...

    SEC Sues SolarWinds Over Massive Cyberattack, Alleging Fraud And Weak Controls

    2023-10-31

    CNBC: Information Technology firm SolarWinds, which was targeted by a Russian-backed hacking group in one of the worst cyber-espionage incidents in U.S. history in 2019, committed fraud and failed to maintain adequate internal controls for years prior to the hack, the Securities and Exchange Commission alleged in a lawsuit.

    Read more...

    What The White House Executive Order On AI Means For Cybersecurity Leaders

    2023-10-31

    CSO: Artificial intelligence continues to snare the technological limelight and, rightly so as we move well into the final quarter of 2023, there is wide international interest in harnessing the power of AI.

    Read more...

    US-Led Cybersecurity Coalition Vows To Not Pay Hackers’ Ransom Demands

    2023-10-31

    TechCrunch: The U.S. government and dozens of foreign allies have pledged never to pay ransom demands in a bid to discourage financially motivated hackers and ransomware gangs profiteering from cyberattacks.

    Read more...

    FTC Orders Non-Bank Financial Firms to Report Breaches in 30 Days

    2023-10-30

    Bleeping Computer: The U.S. Federal Trade Commission (FTC) has amended the Safeguards Rules, mandating that all non-banking financial institutions report data breach incidents within 30 days.

    Read more...

    Know Your Breach: Casio

    The Target: Japanese electronics manufacturer Casio.

    The Take: The exposed data includes customer names, email addresses, countries of residence, service usage details, and purchase information such as payment methods, license codes, and order specifics.

    The Vector: Casio detected the incident on Wednesday, October 11, 2023, following the failure of a ClassPad database within the company's development environment. Evidence suggests that the attacker accessed customers' personal information a day later, on October 12, 2023.

    This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

    Read more...

    How Much Cybersecurity Expertise Does A Board Need?

    2023-10-25

    CSO: Whether a specific requirement or not, companies must either educate their board of directors in cybersecurity and risk management or look to recruit directors with specific cybersecurity experience to improve organizations response and decision-making.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates