Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Hg Invests in Cybersecurity Compliance Provider A-LIGN

    2025-07-08

    Investing.com: HgCapital Trust plc announced it will invest approximately £48 million in A-LIGN, a provider of cyber compliance services, as part of a larger acquisition by Hg.

    Read more...

    72% of Portfolio Companies Hit by a Cyber Attack in the Past Three Years

    2025-07-07

    Private Equity Wire: Cyber security consulting firm S-RM’s latest study, based on a survey of 100 PE professionals across the UK, Europe, and the US, reveals that 72% of respondents have experienced a serious cyber incident across their portfolios in the past three years – highlighting cyber attacks as systemic risks that span entire investment ecosystems.

    Read more...

    SEC Seeks SolarWinds Settlement in Reversal for Agency Under New Leadership

    2025-07-07

    Cybersecurity Dive: The Securities and Exchange Commission has reached a settlement with SolarWinds and the company’s chief information security officer, Timothy Brown, to resolve charges stemming from the Russian-backed cyberattack on the company’s systems.

    Read more...

    Know Your Breach: Kelly Benefits

    The Target: Kelly Benefits is a provider of benefits consulting, enrollment technology, payroll administration, HRIS, compliance support, and carrier management.

    The Take: The data breach notice sent to impacted individuals informs recipients of the specific data types impacted by the breach, which vary per person. However, the general notice published on the site says that the compromised info may contain full names, Social Security number, tax ID number, date of birth, medical information, health insurance information, and financial account information.

    The Vector: The Maryland-based health and life insurance agency has issued an update on a security incident it suffered last year between December 12-17, when unauthorized actors breached its IT systems and stole files. On April 9, 2025, the company stated that the incident impacted 32,234 individuals. The figure was revised multiple times until the final tally shared with authorities in the U.S. counted 553,660 individuals.

    This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    FBI Cyber Guidance To Lawmakers Falls Short, US Senator Says

    2025-07-02

    Cybersecurity Dive: As commercial spyware proliferates and hackers linked to U.S. adversaries step up their attempts to breach high-profile American targets, one U.S. senator says the FBI isn’t doing enough to help lawmakers protect themselves.

    Read more...

    Most Enterprises Can’t Secure AI, Accenture Says

    2025-07-01

    CIO Dive: CIOs are under pressure to move AI projects along faster and demonstrate the corresponding value, but a need for speed doesn’t always translate to sustainable momentum. 

    Read more...

    DOJ Charges 4 North Koreans in $1 Million Crypto Theft From Blockchain Startup

    2025-07-01

    Cointelegraph: Four North Korean nationals were charged in the state of Georgia with wire fraud and money laundering after posing as remote IT workers at US and Serbian blockchain companies and stealing almost $1 million in crypto, prosecutors said.

    Read more...

    Know Your Breach: McLaren Health Care

    The Target: McLaren is a nonprofit health system in the U.S. with $6.6 billion in annual revenue, operating a network that spans 14 Michigan hospitals (2,624 beds).

    The Take: The McLaren data breach notification sample submitted to U.S. authorities confirms that full names were exposed, redacting other data types that were exposed. Therefore, the full extent of the data breach remains unclear.

    The Vector: In the notice sent to impacted individuals, McLaren Health Care admits that the incident concerned a ransomware attack, though the INC ransomware gang, believed to be responsible for the attack, is still not mentioned.

    This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

    Read more...

    Judge Approves AT&T’s $177 Million Data Breach Settlement

    2025-06-25

    Cybersecurity Dive: The consolidated class action highlights a growing concern for business leaders: the steady escalation of cybersecurity threats and data breach costs.

    Read more...

    Cycurion Secures $8 Million In New Cybersecurity Contracts

    2025-06-25

    Investing.com: Cycurion, Inc., a cybersecurity firm with trailing twelve-month revenue of $17.4 million and current market capitalization of $12.5 million, has secured several new contracts totaling over $8 million with government and commercial clients, the company announced.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates