shutterstock_490960141-1

Industry News: ESG5

    Insurer Spots Cybersecurity Weakness With Model Simulating Catastrophic Attacks

    2023-03-20

    BNN Bloomberg: Coalition Inc., a cyber-insurance provider that tries to curb digital risk, has designed technology that simulates large-scale attacks to help insurers identify potential weaknesses in their portfolios and prevent widespread losses.

    Read more...

    Know Your Breach: Latitude Financial

    The Target: Latitude Financial, an Australian-based consumer finance service company.

    The Take: Documents and records belonging to 328,000 customers including Personally Identifiable Information such as Driver’s License details which have name, addresses, and dates-of-birth.

    The Vector: An employee’s credentials were compromised, allowing the attacker pivot access to two different third-party vendors which contained the customer data.

    This breach is a stark reminder of how important authentication controls are in an overall robust cybersecurity posture. Regular social engineering, phishing awareness training, and in this case, tightly enforced password and identity management are effective strategies to mitigate these kinds of breaches to protect a firm’s customer base.

    Read more...

    Cybersecurity Market Confronts Potential Consequences of Banking Crisis

    2023-03-16

    Cybersecurity Dive: The banking crisis and nagging suspicion that hardship will spread, even to companies not directly linked to the failed banks, could have an ancillary effect on the cybersecurity market.

    Read more...

    SEC Proposes New Requirements to Address Cybersecurity Risks to the U.S. Securities Markets

    2023-03-15

    SEC: The Securities and Exchange Commission proposed requirements for broker-dealers, clearing agencies, major security-based swap participants, the Municipal Securities Rulemaking Board, national securities associations, national securities exchanges, security-based swap data repositories, security-based swap dealers, and transfer agents (collectively, “Market Entities”) to address their cybersecurity risks.

    Read more...

    Safety Net: Cybersecurity Staff Shortage Looms if Canada Fails to Develop Homegrown Talent

    2023-03-15

    Financial Post: The former chief executive of Bulletproof, a cybersecurity firm with headquarters in Fredericton, New Brunswick, points to the rash of cyberattacks against organizations around the world that have been hacked and whose IT systems have been held for ransom by online bandits, including the attack on the City of Saint John, just an hour down the road.

    Read more...

    Cybercriminals Exploit SVB Collapse to Steal Money and Data

    2023-03-14

    Bleeping Computer: The collapse of the Silicon Valley Bank (SVB) on March 10, 2023, has sent ripples of turbulence throughout the global financial system, but for hackers, scammers, and phishing campaigns, it's becoming an excellent opportunity.

    Read more...

    DeFi Lender Euler Finance Hit By $197 Million Hack, Experts Say

    2023-03-13

    BNN Bloomberg: Decentralized lending protocol Euler Finance was hit by an attack that drained $197 million in cryptocurrencies from its platform, making it the largest hack in its corner of the digital-assets market this year.

    Read more...

    SVB Meltdown: What It Means for Cybersecurity Startups' Access to Capital

    2023-03-13

    Dark Reading: The stunning collapse of Silicon Valley Bank (SVB) could put a damper on the ability of venture-backed cybersecurity startups to secure vital capital for operations and strategic investments.

    Read more...

    Know Your Breach: CHS

    The Target: Community Health Systems, a U.S based multi-state hospital chain.

    The Take: Exposure of 1 million records of Personally Identifiable Information including: full names, medical billing and insurance information, diagnoses, medication, date-of-birth, and social security numbers.

    The Vector: A zero-day exploit was used to breach a third-party vendor, Fortra, of CHS, targeting their file transfer software which let the attackers gain access to sets of files throughout the third-party vendor’s systems.

    This breach is critical reminder that zero-day exploits do happen, and furthermore that patching software in a timely, effective manner is a key component of ensuring customer data is protected. Ensuring third-party vendors are deploying patches and fixes in accordance with a firm’s cybersecurity policy is an important step in an overall robust security posture.

    Read more...

    Global Cybersecurity Market Size To Grow USD 501.6 Billion By 2030

    2023-03-08

    GlobeNewswire: The cyber security market growth includes increased number of data breaches across the globe, rising digitalization, and increased sophisticated cyber intrusions. Cyber threats are anticipated to evolve with the increase in usage of devices with intelligent and IoT technologies.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates