Are you doing enough to address your risk? Here are a seasoned CISO’s fundamentals
Several years ago, I received an early-morning phone call at home from one of my security staff. Our security operations center had just contacted us, reporting anomalous data traffic. They believed we had several assets that were infected with malware. As I listened to the incident response team triage the event, I thought to myself, "What can I do as a CISO to better protect my organization?"
I had numerous networks and legacy assets under my purview, and even though I had a solid security program, I didn’t feel we were doing enough to address our risk. What fundamentals could I incorporate to better prepare my teams and my security organization?
FBI wants US businesses to stop using Kaspersky software
The FBI has admitted that it is actively discouraging businesses to not use security products from Kaspersky Lab.
Rob Joyce, the US government's Cyber Security Coordinator, said that the agency has been actively trying to convince companies in the private sector to no longer use products from the Russian security firm following a number of recent concerns.
Why are so many organizations struggling to patch? [Q&A]
Many recent cyber attacks like WannaCry have succeeded by exploiting vulnerabilities that, although known, have gone widely unpatched.
Why do some organizations find it so difficult to keep their systems up to date and what can they do to better protect themselves? We spoke to Wendy Nather, principal security strategist at Duo Security to find out.
Google Play apps spread malware through advertising SDK
Through the use of an advertising software development kit contained in 500 apps on the Google Play Store, cybercriminals were able to spy on users and even infect their mobile devices with malware.
That's according to security firm Lookout, which discovered that the Android apps in question all had the lgexin ad SDK built into them which gave unauthorized third parties access to user devices.
Government organizations lag behind in implementing latest security practices
Cyber attacks are becoming more complex and intense. In addition, many hackers are interested in the types of sensitive data held by government bodies. Yet a new study shows that these organizations are lagging behind in dealing with IT risks.
The study by data visibility platform Netwrix reveals that while 57 percent of government entities focus on endpoint protection, 72 percent experienced security incidents in 2016, the most common reasons being human errors and insider misuse.
Non-Windows platforms increasingly at risk from malware
Where it was once the case that damaging malware attacks were aimed solely at Windows devices, a new study shows that strategic attacks on both Mac and Android devices are rapidly rising.
The report by Malwarebytes reveals that Android ransomware was up by more than 100 percent in the second quarter of 2017. In addition, Mac malware
this year is already at the highest it has ever been.
With Android Oreo, Google is stepping up app security
App security is undeniably an issue for Android users, particularly those who choose to install apps from outside of Google Play. Even apps that are housed in the main store are not immune to security issues, but those from other sources are rather more risky.
With Android O, Google has ditched "Allow unknown sources" -- the setting that could be toggled to allow for the installation of non-Play apps. Instead, there is a new "Install unknown apps" permission, and Google thinks this offers more control and greater security.
DDoS attacks increase by 28 percent in Q2 2017
DDoS attacks are seeing a major rise as hackers seek more diverse threats, according to new research.
The latest State of the Internet/Security Report from Akamai reveals that the number of DDoS attacks increased by 28 percent in the second quarter of 2017, following three consecutive quarters of activity decline, as attacks from the PBot malware hit a new high.
Enterprises not confident security can keep up with digital transformation
Businesses are increasingly turning to digital transformation to accelerate their online presence, to enrich products, deepen customer relationships, and boost their brand.
But the bad guys have gone digital too, taking advantage of the digital ecosystem and user trust to make more sophisticated attacks. A new study sponsored by digital threat management company RiskIQ finds that for many businesses digital transformation and the changing external threat landscape are outpacing enterprise security capacity.
SaaS solution analyzes user credentials to help prevent data breaches
Data breaches arising from misuse of credentials can often be made worse by users having excessive or inappropriate entitlements.
A new solution from One Identity allows companies to analyze and compare user entitlements, and pinpoint situations where they deviate from the norm and thus pose an elevated risk.
UK businesses lack necessary security skills and awareness
British firms are putting themselves at risk of being hit by major cyber-attacks such as the WannaCry ransomware due to a lack of proper security skills and awareness, a new government report has warned.
Over two thirds (68 percent) of board members at FTSE 350 businesses have not been trained to deal with major cyber security attacks, according to the latest government cyber health check report, revealed today.
New solution aims to cut mobile app fraud
One of the ways developers can boost the popularity of their mobile apps is via pay-per-click advertising. But this leaves them open to fraud where bots can be used to generate large numbers of hits.
Mobile advertising technology firm AppLift is launching a new Fraud Buster tool, which combats app install fraud in real time to ensure users are genuine and deliver increased return on advertising spending.
Cyber-security is an investment, not a burden
CEOs across the UK are increasingly seeing cyber-security not as a burden, but rather an investment opportunity, a new study has claimed.
The KPMG CEO Outlook 2017 report, based on a poll of 150 CEOs in the UK, found that 70 percent considered investing in cyber-security an opportunity to find new streams of revenue.
Hackers can disable your car's safety systems
Hackers could disable a modern car's airbags and other safety systems, putting the driver and the passengers at grave risk, according to a new warning.
Researchers from security firm Trend Micro have revealed a flaw that could allow the controlling network of a connected car to be overloaded, allowing possible hackers to compromise key systems in the vehicle, including safety aspects.
How network segmentation can help contain cyber attacks
Cyber crime continues to be a major problem globally and companies are seeking new ways of combating it.
However, there are some older technologies that remain an effective defense. One of these is network segmentation, and network security specialist Tufin Technologies has produced an infographic explaining how segmentation works and how it can help keep organizations secure from today’s sophisticated cyber attacks.

