shutterstock_490960141-1

Industry News: ESG5

    Latitude Financial Cyber-attack Worse Than First Thought with 14m Customer Records Stolen

    2023-03-27

    The Guardian: Latitude Financial has revealed that 14m customer records – including driver’s licence numbers, passport numbers and financial statements – were stolen from its system in a cyber-attack that was far worse than the company initially reported.

    Read more...

    Know Your Breach: Lionsgate Play

    The Target: Lionsgate Play, a U.S based video-streaming platform.

    The Take: Exposure of 30 Million records of User Data including: IP addresses, operating system, user search queries, and web browser information.

    The Vector: A misconfigured Elasticsearch database was left open and unsecured, meaning anyone with an internet connection could have viewed and downloaded the data. 

    This shows how important authentication controls are, and even more critically, that they be purposefully and smartly deployed with security in mind. Multi-factor authentication and password length and complexity rules on server access are effective strategies to mitigate these kinds of breaches to protect a firm’s data.

    Read more...

    Arlington Forms New Cyber Intelligence Platform

    2023-03-23

    Private Equity Wire: Arlington Capital Partners has launched Eqlipse Technologies, (Eqlipse) a new platform company formed from firms focused on full-spectrum cyber and signals intelligence engineering, digital operations and identity management, and research and development.

    Read more...

    Less Talk, More Action: 3 Steps to Diversify the Cybersecurity Workforce

    2023-03-22

    Information Week: Despite all the conversations about diversity initiatives and efforts in the past few years to get more women in STEM careers, it often seems the needle is moving slowly. Too often, these conversations are just that -- talking points that sound good but aren’t connected to action-oriented strategies.

    Read more...

    Banks, Financial Industry Hit by Rising Ransomware Attacks

    2023-03-21

    BNN Bloomberg: Ransomware gangs didn’t come out with any big new innovations last year, but “what 2022 lacked in innovation it made up for in volume,” according to a report by a financial services group.

    Read more...

    Geopolitical Tensions Enabled Increased Hacktivist Cyber Threats in 2022

    2023-03-21

    Global Newswire: FS-ISAC, the member-driven, not-for-profit organization that advances cybersecurity and resilience in the global financial system, announced the findings of its annual Global Intelligence Office report, Navigating Cyber 2023.

    Read more...

    New Cisco Study Finds Only 9% of Canadian Companies Surveyed are Ready to Defend Against Cybersecurity Threats

    2023-03-21

    Financial Post: A mere 9% of organizations in Canada have the ‘Mature’ level of readiness needed to be resilient against today’s modern cybersecurity risks, according to Cisco’s NASDAQ: CSCO first-ever Cybersecurity Readiness Index released.

    Read more...

    Cybersecurity Skills Shortage, Recession Fears Drive 'Upskilling' Training Trend

    2023-03-21

    Dark Reading: Companies continue to value cybersecurity skills, but many have moved their focus from hiring cybersecurity professionals to training up in-house staff on needed cybersecurity skills.

    Read more...

    Insurer Spots Cybersecurity Weakness With Model Simulating Catastrophic Attacks

    2023-03-20

    BNN Bloomberg: Coalition Inc., a cyber-insurance provider that tries to curb digital risk, has designed technology that simulates large-scale attacks to help insurers identify potential weaknesses in their portfolios and prevent widespread losses.

    Read more...

    Know Your Breach: Latitude Financial

    The Target: Latitude Financial, an Australian-based consumer finance service company.

    The Take: Documents and records belonging to 328,000 customers including Personally Identifiable Information such as Driver’s License details which have name, addresses, and dates-of-birth.

    The Vector: An employee’s credentials were compromised, allowing the attacker pivot access to two different third-party vendors which contained the customer data.

    This breach is a stark reminder of how important authentication controls are in an overall robust cybersecurity posture. Regular social engineering, phishing awareness training, and in this case, tightly enforced password and identity management are effective strategies to mitigate these kinds of breaches to protect a firm’s customer base.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates