Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: PowerSchool

    The Target: PowerSchool is a cloud-based software solutions provider for K-12 schools and districts that supports over 60 million students and over 18,000 customers worldwide. The company offers a full range of services to help school districts operate, including platforms for enrollment, communication, attendance, staff management, learning systems, analytics, and finance.

    The Take: PowerSchool has confirmed that the stolen data primarily contains contact details such as names and addresses. However, for some districts, it could also include Social Security numbers, personally identifiable information, medical information, and grades.

    The Vector: After investigating the incident, it was determined that the threat actor gained access to the portal using compromised credentials and stole data using an "export data manager" customer support tool. Using this tool, the attacker exported the PowerSchool SIS 'Students' and 'Teachers' database tables to a CSV file, which was then stolen.

    This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    Investors Narrow Scope of Cyber Funding Deals in 2024

    2025-01-08

    Cybersecurity Dive: The lookback on cybersecurity funding underscored a continuing trend toward larger deals in the sector. Total funding was up year over year while the number of rounds declined.

    Read more...

    Cybersecurity Funding Reached $9.5 Billion in 2024: Report

    2025-01-08

    SecurityWeek: Funding raised by cybersecurity firms increased to $9.5 billion last year amid a decrease in funding volume, a new report from cybersecurity recruitment firm Pinpoint Search Group shows.

    Read more...

    ‘We Have To Prioritize Cybersecurity’ Within Federal Budgets, Outgoing Cyber Czar Says

    2025-01-07

    The Record: The Trump administration shouldn’t abandon an effort to get federal agencies to set cybersecurity priorities as part of their annual budget requests, the nation’s outgoing cyber czar said.

    Read more...

    US Cyber Watchdog Says No Indication Breach At Treasury Hit Other Federal Agencies

    2025-01-06

    Yahoo News: The U.S. cyber watchdog agency CISA said there was "no indication" the recently reported breach at the U.S. Treasury Department had affected any other federal agency.

    Read more...

    Know Your Breach: SRP Federal Credit Union

    The Target: SRP Federal Credit Union, one of the largest in South Carolina. SRP was founded in 1960 and said it has more than $1.6 billion in assets as of 2022.

    The Take: The potentially exposed data included names, dates of birth, addresses, phone numbers, email addresses, government-issued IDs, social security numbers, transaction activity and photographs of users.

    The Vector: After law enforcement was notified, an investigation was conducted and they realized that hackers accessed SRP Federal Credit Union systems “at times from September 5, 2024, and November 4, 2024, and potentially acquired certain files from our network during that time.”

    This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    Cybersecurity Firm Bureau Raises $30 Million to Expand Global Footprint

    2024-12-18

    Investing.com: Cybersecurity startup Bureau has raised $30 million in a funding round to expand its operations into new markets. The round was led by Sorenson Capital, the firm announced.

    Read more...

    SEC Cybersecurity Enforcement Outlook Uncertain as Trump 2.0 Looms

    2024-12-17

    CFO Dive: Much of the public company filings resulting from the Securities and Exchange Commission’s first year of implementing a rule requiring the disclosure of “material” cybersecurity breaches have been vague and confusing, producing little value for investors, legal analysts said.

    Read more...

    CISA Seeking Public Comment on Updated National Cyber Incident Response Plan

    2024-12-17

    SecurityWeek: Originally published in 2016, the NCIRP is meant as a framework on how federal, private, state, local, tribal, and territorial (SLTT), and international organizations address cyber incidents that have a higher severity, and which could cause disruptions to critical infrastructure or equipment damage.

    Read more...

    Future of Proposed US Cybersecurity Healthcare Bills in Doubt

    2024-12-16

    CSO Online: Six months after Congressional hearings that promised action on the massive Change Healthcare ransomware attack and data theft, three pieces of proposed legislation to tighten cybersecurity requirements on healthcare providers are waiting to be dealt with.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates