Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Orrick, Herrington & Sutcliffe

    The Target: Orrick, Herrington & Sutcliffe, a popular San Francisco-based international law firm.

    The Take: The stolen data encompassed a vast array of information, including names, dates of birth, addresses, email addresses, and government-issued identification numbers like Social Security, passport, driver’s license, and tax identification numbers.

    The Vector: The intrusion into Orrick’s network compromised a file share, revealing personal information and sensitive health data of victims.

    This breach is a stark reminder of how authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    NZ Firm Pushes for ‘Complete Ban’ on Paying Cyber Ransoms

    2024-01-04

    The Post: A New Zealand cyber-security firm that has the ear of many media organisations around the world has called for a complete ban on paying off ransomware attackers, arguing it is the only way to get on top of the crime.

    Read more...

    Atos Shares Drop After Airbus Deal Talks Disappoint Investors

    2024-01-03

    Yahoo Finance: Atos SE shares fell after the company’s announcement that it was in early talks to sell its big data and cybersecurity business to Airbus SE for as much as €1.8 billion ($2 billion) disappointed investors.

    Read more...

    OpenAI Moves to Shrink Regulatory Risk in EU Around Data Privacy

    2024-01-02

    TechCrunch: While most of Europe was still knuckle deep in the holiday chocolate selection box late last month, ChatGPT maker OpenAI was busy firing out an email with details of an incoming update to its terms that looks intended to shrink its regulatory risk in the European Union.

    Read more...

    Google Cloud Report Spotlights 2024 Cybersecurity Challenges

    2024-01-02

    Security Boulevard: As the New Year dawns, a cybersecurity report from Google Cloud suggests that while there are many challenges ahead, it will also become simpler for cybersecurity teams to leverage artificial intelligence (AI) to better defend IT environments.

    Read more...

    Early-Stage Hard Tech Firm Countdown Capital Shutting Down

    2024-01-02

    TechCrunch: Countdown Capital, an early-stage venture capital firm focused on hard tech industrial startups, will shut down by the end of March and return uninvested capital, firm founder and solo general partner Jai Malik said in an annual letter.

    Read more...

    Four Ways Companies Can Respond And More Effectively Comply With The SEC’s New Cybersecurity Rules

    2024-01-02

    SC Media: With two major actions in the last six months of 2023, the Securities and Exchange Commission (SEC) has made it clear that it plans to get tough on cybersecurity.

    Read more...

    The Law Enforcement Operations Targeting Cybercrime In 2023

    2024-01-01

    Bleeping Computer: In 2023, we saw numerous law enforcement operations targeting cybercrime operations, including cryptocurrency scams, phishing attacks, credential theft, malware development, and ransomware attacks.

    Read more...

    Know Your Breach: Americold

    The Target: Americold is the world’s largest publicly traded real estate investment trust focused on temperature-controlled warehouses. The company controls 250 warehouses across the world — most of which are used by food producers, distributors and retailers.

    The Take: Names, addresses, Social Security numbers, driver’s license/state ID numbers, passport numbers, financial account information, and employment-related health insurance and medical information were leaked

    The Vector: Americold confirmed that hackers had breached its systems on April 26 and accessed the information of current and former Americold employees as well as their dependents. While the company did not explicitly call it a ransomware attack, it said the cybersecurity incident “involved the deployment of malware on certain systems.”

    As phishing actors continue to explore every potential abuse opportunity on legitimate service providers, novel security gaps constantly threaten to expose users to severe risks. It is essential not to rely solely on email protection solutions, and also scrutinize every email that lands on your inbox, look for inconsistencies, and double-check all claims made in those messages.

    Read more...

    Cyber Resilience Good Practice For Firms

    2023-12-19

    Financial Conduct Authority (FCA): CBEST tests the cyber resilience of firms and financial market infrastructures (FMIs) through live testing that mimics the actions of cyber attackers.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates