shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Thomson Reuters

    The Target: Thomson Reuters, a multi-national media conglomerate.

    The Take: Exposure of sensitive company login credentials, including plain-text passwords to some third-party vendors, corporate and legal information, and logs which contain the email addresses of account holders who recently reset their passwords.

    The Vector: A misconfigured Elasticsearch server was accessible over the internet to anyone with a connection.

    This breach is critical reminder that authentication controls are an important piece in an overall robust cybersecurity posture, especially maintaining correct access configurations. The data exposed here can also lead to pivot attacks and targeted phishing. Multi-factor authentication, reasonably regular forced password resets, and password length and complexity rules are all effective strategies to mitigate these kinds of breaches to protect a firm’s data.

    Read more...

    Versa Raises $120M for Its Software-defined Networking and Security Stack

    2022-10-27

    Techcrunch: Networking and cybersecurity firm Versa announced that it raised $120 million in a mix of equity and debt led by BlackRock, with participation from Silicon Valley Bank. CEO Kelly Ahuja tells TechCrunch that the proceeds, which bring Versa’s total capital raised to $316 million, will be put toward go-to-market efforts and scaling the company. He demurred when asked what percentage of the financing was equity versus debt.

    Read more...

    Cyber Security: Recession Proof?

    2022-10-27

    Financier Worldwide: Amid ongoing economic and geopolitical challenges, the cyber security sector remains strong, according to a new report from ICON Corporate Finance.

    Read more...

    Cybersecurity Teams Are Reaching Their Breaking Point. We Should All Be Worried

    2022-10-25

    ZDNet: A global study of 1,100 cybersecurity professionals by Mimecast found that one-third are considering leaving their role in the next two years due to stress and burnout.

    Read more...

    The Global Artificial Intelligence in Cybersecurity Market Size Is Expected to Reach $57.1 Billion by 2028, Rising At a Market Growth of 24.5% CAGR During the Forecast Period

    2022-10-25

    Global Newswire: AI-powered systems can be set up to automatically respond to dangers and combat online threats more quickly. Analyzing and improving cyber risks as well as cyber-attacks is no more a task on a human scale as the business attack surface develops and changes. To accurately quantify risk, up to highly-varying signals must be handled, based on the scale of the organization.

    Read more...

    Cybersecurity M&A Bustling Again in Q4 After a Bleak Q3

    2022-10-25

    S&P Global: Global cybersecurity transaction volume dropped to 33 deals between July 1 and Sept. 30, compared to 45 deals in the second quarter and 58 in the third quarter of 2021, according to data from 451 Research.

    Read more...

    Here’s What Regulators Will Want Boards to Know About Cybersecurity

    2022-10-24

    World Economic Forum: New United States Securities and Exchange Commission (SEC) rulemaking makes cyber risk reporting and business resilience planning a key component of effective board governance. 

    Read more...

    FTC Seeks to Hold Drizly CEO Accountable for Alleged Security Failures, Even if He Moves to Another Company

    2022-10-24

    CNBC: In a new proposed settlement, the Federal Trade Commission is seeking to hold a tech CEO accountable to specific security standards, even if he moves to a new company.

    Read more...

    Know Your Breach: Microsoft

    The Target: Microsoft, one of the world’s leading computer hardware and software companies. 

    The Take: Exposure of Personally Identifiable Information belonging to over 65,000 business entities. The data included: names, email addresses, email content, company name, phone numbers, Statement of Work documents, product offers, and more. 

    The Vector: A misconfigured Microsoft server was accessible over the internet to anyone with a connection.

    This breach is a stark reminder that authentication controls are a critical piece in an overall robust cybersecurity posture, including maintaining correct access configurations. In addition, multi-factor authentication, reasonably regular forced password resets, and password length and complexity rules are all effective strategies to mitigate these kinds of breaches to protect a firm’s data.

    Read more...

    Antony Blinken’s Silicon Valley Visit Underscores US Cybersecurity Concerns

    2022-10-20

    The Guardian: The US secretary of state visited Silicon Valley this week, on a trip that experts say highlights the Biden administration’s growing concerns over cybersecurity and officials’ push to collaborate more closely with the US’s powerful tech industry.

    Read more...

    Banco Santander and Forgepoint Capital Announce Strategic Alliance to Advance Cybersecurity Investment and Innovation Globally

    2022-10-20

    Dark Reading: Banco Santander, one of the largest banks in the world with over 157 million customers, and Forgepoint Capital, one of the world’s leading venture capital firms focused on cybersecurity, announced today a strategic alliance to drive cybersecurity investment and innovation globally.

    Read more...

    Cybersecurity Workforce Gap Grows by 26% in 2022

    2022-10-20

    Infosecurity: The global cybersecurity workforce gap has increased by 26.2% compared to 2021, with 3.4 million more workers needed to secure assets effectively, according the (ISC)2 2022 Cybersecurity Workforce Study.

    Read more...

    Passwords Still Dominate, and Are Causing Headaches for Everyone

    2022-10-19

    ZDNet: While Google, Microsoft and Apple roll out passwordless passkey functionality for their platforms, most people are still dependent on passwords.

    Read more...

    Australia's No. 1 Health Insurer Says Hacker Stole Patient Details

    2022-10-19

    U.S. News: Australia's biggest health insurer said a criminal had apparently stolen customers' medical information as part of a massive breach of data, fuelling concern about a wave of high-profile cyber attacks.

    Read more...

    Ottawa’s Cybersecurity Bill Flawed and Should Be Amended, New Report Warns

    2022-10-18

    Global News: A new research report says federal cybersecurity legislation is so flawed it would allow authoritarian governments around the world to justify their own repressive laws.

    Read more...

    Gen Z, Millennial Workers Are Bigger Cybersecurity Risks Than Older Employees

    2022-10-18

    Dark Reading: A new survey shows Generation Z and millennials, younger workers who have grown up as digital natives, are surprisingly more careless about their employer's cybersecurity than their senior Gen X and baby boomer colleagues. 

    Read more...

    Know Your Breach: Optus

    The target: Optus, an Australian Telecommunications company

    The take: Personal information for up to 10 million customers, including names, email addresses, postal addresses, phone numbers, dates of birth, and some passport numbers, driver’s license numbers and Medicare numbers.

    The attack vector: Reports suggest that an application programming interface (API) was exposed to the public internet and did not enforce any kind of authentication to access customer data.

    Where sensitive data is handled, controls must be put in place to authenticate access, and verify an individual’s authorization to access that data. Failing to ensure that such access is carefully controlled is akin to leaving the window open.

    Read more...

    Supply Chain Hacks Are On the Rise. But Most Companies Aren't Prepared

    2022-10-13

    ZDNet: The UK's cybersecurity agency has told firms to do more to protect themselves from attacks on their supply chains. 

    Read more...

    Crypto Hackers Set for Record Year After Looting Over $3 Billion

    2022-10-12

    BNN Bloomberg: At least $718 million has been stolen so far in October alone, taking the gross tally for the year past $3 billion and putting 2022 on course to be a record for the total value hacked, according to blockchain specialist Chainalysis Inc.

    Read more...

    Vista Equity Partners to Acquire KnowBe4 In $4.6bn Deal

    2022-10-12

    Private Equity Wire: Vista Equity Partners (Vista) is to acquire KnowBe4, the provider of the world’s largest security awareness training and simulated phishing platforms, in an all-cash transaction valued at approximately $4.6 billion on an equity value basis.

    Read more...

    A Consumer-focused Cyber Labeling Scheme May Be Put Into Play After Years On the Drawing Board.

    2022-10-11

    FCW: In an Oct. 11 fact sheet, the White House teed up plans to host a meeting with stakeholders including companies and trade associations to discuss "a common label for products that meet U.S. government standards and are tested by vetted and approved entities."

    Read more...

    German Cybersecurity Chief Investigated Over Russia Ties

    2022-10-10

    AP News: Arne Schoenbohm, who heads the BSI agency, co-founded a cybersecurity group a decade ago that brings together experts from public institutions and the private sector. German media reported that one of its members is a company founded by a former Russian intelligence agent.

    Read more...

    Lloyd's of London Says No Evidence Found of Data Compromise From Cyberattack

    2022-10-10

    U.S. News: "The investigation has concluded that no evidence of any compromise was found and as such Lloyd's has been advised that its network services can now be restored," a company spokesperson said in an email.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates