shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Casio

    The Target: Japanese electronics manufacturer Casio.

    The Take: The exposed data includes customer names, email addresses, countries of residence, service usage details, and purchase information such as payment methods, license codes, and order specifics.

    The Vector: Casio detected the incident on Wednesday, October 11, 2023, following the failure of a ClassPad database within the company's development environment. Evidence suggests that the attacker accessed customers' personal information a day later, on October 12, 2023.

    This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

    Read more...

    How Much Cybersecurity Expertise Does A Board Need?

    2023-10-25

    CSO: Whether a specific requirement or not, companies must either educate their board of directors in cybersecurity and risk management or look to recruit directors with specific cybersecurity experience to improve organizations response and decision-making.

    Read more...

    Tikehau Capital Launches The New Vintage of Brienne, its Flagship Private Equity Cybersecurity Strategy

    2023-10-25

    Business Wire: The focus of this next vintage will be on seizing European opportunities and supporting companies with significant global B2B scalability potential. It aims to invest ticket sizes ranging from €10 million to €50 million, including reinvestments, thus offering the potential for substantial backing to companies poised to redefine the cybersecurity landscape.

    Read more...

    September Was a Record Month For Ransomware Attacks in 2023

    2023-10-24

    Bleeping Computer: Ransomware activity in September reached unprecedented levels following a relative lull in August that was still way above regular standards for summer months.

    Read more...

    Censys Lands New Cash to Grow its Threat-Detecting Cybersecurity Service

    2023-10-24

    TechCrunch: Investments in cybersecurity companies are beginning to turn a corner, seemingly. After a brutal summer, VC funding to security startups saw a slight (12%) uptick from Q3, according to Crunchbase — reaching nearly $1.9 billion compared to $1.7 billion in the second quarter.

    Read more...

    Microsoft to Help Australia’s Cyber Spies Amid $5 Billion Investment in Cloud Computing

    2023-10-23

    The Guardian: Microsoft says it will invest an additional $5 billion in Australia over the next two years to expand hyperscale cloud computing capacity while collaborating with the Australian Signals Directorate (ASD) to boost domestic protection from cyber threats.

    Read more...

    Okta Cybersecurity Breach Wipes Out More Than $2 Billion In Market Cap

    2023-10-23

    CNBC: Okta has shed more than $2 billion from its market valuation since the company disclosed a hack of its support systems. The high-profile incident is the latest in a string of incidents that have been tied to Okta or its products, including a spate of intrusions at casinos that crippled Las Vegas hotel rooms for days.

    Read more...

    Fighting Cyberattacks Requires Top-Down Approach

    2023-10-23

    Chief Investment Officer: Mitigating cybersecurity threats requires organizations to reassess their approach to technical vulnerability, advised an internet security expert and author at the “Cybersecurity Threats and Concerns: An Overview” session of CIO’s Cybersecurity livestream on October 12.

    Read more...

    Know Your Breach: D.C. Board of Elections

    The Target: The District of Columbia Board of Elections (DCBOE) operates as an autonomous agency within the District of Columbia Government and is entrusted with overseeing elections, managing ballot access, and handling voter registration processes.

    The Take: This dataset includes the individual's name, registration ID, voter ID, partial Social Security number, driver's license number, date of birth, phone number, email, and more.

    The Vector: DCBOE’s investigation into the claims has revealed that the attackers accessed the information through the web server of DataNet, the hosting provider for Washington D.C.'s election authority.

    This breach is a stark reminder of how authentication controls are in an overall robust cybersecurity posture, and more critically, ensuring these controls are in place on all third-party vendors which have access to a firm’s data.

    Read more...

    "Cybersecurity in the Cloud Era: Financial and Operational Impacts Decoded"

    2023-10-19

    PR Newswire: Measured Analytics and Insurance, the AI-powered cyber insurance provider to small and midsize enterprises (SMEs), introduced its latest white paper, "Cybersecurity in the Cloud Era: Financial and Operational Impacts Decoded."

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates