Shifting responsibility is causing uncertainty and more security breaches

Data security is creating fear and trust issues for IT professionals, according to a new Oracle and KPMG report. The study of 750 cybersecurity and IT professionals across the globe found that a patchwork approach to data security, misconfigured servic… Continue reading Shifting responsibility is causing uncertainty and more security breaches

Paying the ransom = paying double

Paying cybercriminals to restore data encrypted during a ransomware attack is not an easy and inexpensive path to recovery, a Sophos survey reveals. In fact, the total cost of recovery almost doubles when organizations pay a ransom. The survey polled 5… Continue reading Paying the ransom = paying double

Debunking myths related to client-side security and Magecart attacks

The client-side landscape has been overrun by third-party script attacks executed by malicious attackers utilizing formjacking or other methods made famous by the Magecart attack group. Many companies assume their current security stack ensures protect… Continue reading Debunking myths related to client-side security and Magecart attacks

5 easy steps to immediately bolster cybersecurity during the pandemic

Cyber attacks have increased exponentially since the start of the pandemic, with AT&T Alien Labs Open Threat Exchange (OTX) finding 419,643 indicators of compromise (IOC) related to COVID-19 from January to March, with a 2,000% month-over-month in… Continue reading 5 easy steps to immediately bolster cybersecurity during the pandemic

Eye-opening statistics about open source security, license compliance, and code quality risk

99% of commercial codebases contain at least one open source component, with open source comprising 70% of the code overall, according to Synopsys. Open source components and security More notable is the continued widespread use of aging or abandoned o… Continue reading Eye-opening statistics about open source security, license compliance, and code quality risk

How to implement least privilege in the cloud

According to a recent survey of 241 industry experts conducted by the Cloud Security Alliance (CSA), misconfiguration of cloud resources is a leading cause of data breaches. The primary reason for this risk? Managing identities and their privileges in … Continue reading How to implement least privilege in the cloud

New third-party healthcare data rules: Increased access alongside privacy considerations

It would be an understatement to say that 2020 is a monumental year for healthcare. The COVID-19 pandemic brought many aspects of care to the forefront – from technology and its ability to connect us, to the necessity for records to be quickly dissemin… Continue reading New third-party healthcare data rules: Increased access alongside privacy considerations

(ISC)2 Professional Development Institute: Timely and continuing education opportunities

In this Help Net Security podcast, Mirtha Collin, Director of Education for (ISC)², talks about the Professional Development Institute (PDI), a valuable resource for continuing education opportunities to help keep your skills sharp and curiosity piqued… Continue reading (ISC)2 Professional Development Institute: Timely and continuing education opportunities

Leveraging automation to maximize security budgets

With the economic impact of COVID-19 increasingly looking like an imminent recession and the way we do work altered perhaps forever, CIOs and CISOs will most likely be managing reduced budgets and a vastly different threat landscape. With the average c… Continue reading Leveraging automation to maximize security budgets