Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Cyber Insurance Premiums Drop For First Time, Report Finds

    2025-06-24

    Cybersecurity Dive: Last year’s decrease in the premiums generated from cyber insurance represents the first such decline since the National Association of Insurance Commissioners began collecting data in 2015, according to AM Best’s report.

    Read more...

    US Braces for Cyberattacks After Bombing Iranian Nuclear Sites

    2025-06-23

    SecurityWeek: After the US bombed three key nuclear sites in Iran, the regime in Tehran vowed to retaliate. The Department of Homeland Security (DHS) issued a national terrorism advisory system bulletin, warning that the Iranian government has publicly condemned the United States’ involvement in the conflict and that retaliation could come in several forms.

    Read more...

    Citing Strategic Shift, SEC Withdraws 14 Biden-Era Proposals

    2025-06-16

    Plan Adviser: The Securities and Exchange Commission has withdrawn 14 proposed rules and amendments issued between March 2022 and November 2023, under former President Joe Biden, continuing the agency’s regulatory shift under leadership appointed by President Donald Trump. 

    Read more...

    Hackers Switch to Targeting U.S. Insurance Companies

    2025-06-16

    Bleeping Computer: Threat intelligence researchers are warning of hackers breaching multiple U.S. companies in the insurance industry using all the tactics observed with Scattered Spider activity.

    Read more...

    Know Your Breach: Sensata

    The Target: Sensata is a global industrial tech firm specializing in missioncritical sensors, controls, and electrical protection systems. It serves the automotive, aerospace, and defense industries, among others, and has an annual revenue of over $4 billion.

    The Take: The company is now notifying an undisclosed number of impacted individuals that the following data was stolen: Full name, address, Social Security Number (SSN), driver's license number, state ID card number, passport number, financial account information, payment card information, medical information, health insurance information, date of birth.

    The Vector: Subsequent investigations into the incident supported by an external expert showed that the ransomware actors breached Sensata's network on March 28, 2025.

    This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

    Read more...

    Banking Groups Ask Treasury to Limit Data Collection After Cybersecurity Incidents

    2025-06-09

    PYMNTS: Four financial industry trade associations said that federal agencies should limit their data collection to “only what is necessary” after a series of cybersecurity incidents targeted those agencies.

    Read more...

    SentinelOne Shares New Details on China-Linked Breach Attempt

    2025-06-09

    Bleeping Computer: SentinelOne has shared more details on an attempted supply chain attack by Chinese hackers through an IT services and logistics firm that manages hardware logistics for the cybersecurity firm.

    Read more...

    New Trump Cybersecurity Order Reverses Biden, Obama Priorities

    2025-06-09

    Dark Reading: A June 6 cybersecurity executive order from the Trump White House takes a couple of swipes at presidential predecessors Barack Obama and Joe Biden.

    Read more...

    Know Your Breach: Lee Enterprises

    The Target: As one of the largest newspaper groups in the United States, Lee Enterprises publishes 77 daily newspapers and 350 weekly and specialty publications across 26 states.

    The Take: The information that could have been subject to unauthorized access and/or acquisition includes first and last name, as well as Social Security number.

    The Vector: The investigation determined that information may have been accessed or acquired without authorization on February 3, 2025.

    This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    Trump’s National Cyber Director Nominee Dodges Criticism of Funding Cuts

    2025-06-05

    Cybersecurity Dive: President Donald Trump’s nominee for national cyber director spent his Senate confirmation hearing calling for bold action to repel hackers but ducking questions about the impact of the administration’s proposed cybersecurity funding cuts.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates