Small US Cyber Agencies Are Underfunded & That’s a Problem

November 20, 2024 at 10:12AM The commentary emphasizes the underfunding of essential U.S. cybersecurity agencies, particularly NIST and the National Vulnerabilities Database (NVD). It argues that inadequate resources jeopardize the nation’s cybersecurity efforts, urging Congress to provide appropriate funding to safeguard critical infrastructure and maintain the U.S.’s status as a cyber superpower. ### Meeting Takeaways: … Read more

Kyndryl & Microsoft Unveil New Services to Advance Cyber Resilience for Customers

November 18, 2024 at 05:10PM Kyndryl, the largest IT infrastructure services provider, launched new cyber resilience services developed with Microsoft. Integrated into Kyndryl Bridge, these offerings enhance security, compliance, and operational efficiency for businesses confronting complex cyber threats. This partnership aims to empower organizations amid growing regulatory pressures and digital transformation challenges. **Meeting Takeaways:** 1. … Read more

TSA Proposes Cyber Risk Mandates for Pipelines, Transportation Systems

November 14, 2024 at 09:01PM The TSA has proposed new cybersecurity rules for pipeline, railroad, bus, and public transportation systems, enhancing existing frameworks. Affected operators must implement cyber risk management programs, report incidents, and maintain security measures. This initiative aims to boost cybersecurity resilience, with public comments accepted until February 2, 2025. ### Meeting Takeaways … Read more

OpenText Cybersecurity Unveils 2024’s Nastiest Malware

November 13, 2024 at 05:58PM OpenText has released its “Nastiest Malware of 2024” list, with ransomware LockBit topping the rankings for its persistent attacks on critical infrastructure. Cybersecurity investments are expected to rise by 14.3%, exceeding $215 billion. Other notable malware include Akira, RansomHub, Dark Angels, Redline, and Play Ransomware. ### Meeting Takeaways from OpenText … Read more

20% of Industrial Manufacturers are Using Network Security As a First Line of Defense

November 13, 2024 at 05:36PM A recent ABI Research survey found that industrial manufacturers prioritize network security for cybersecurity investments due to increasing cyber threats and regulatory pressures. With a projected $2 billion market for cybersecurity solutions in 2024, focus areas include authentication, access control, and threat detection to mitigate risks from cyber events. ### … Read more

The vCISO Academy: Transforming MSPs and MSSPs into Cybersecurity Powerhouses

November 8, 2024 at 06:45AM The rising demand for cybersecurity has led to increased interest in virtual Chief Information Security Officer (vCISO) services among small and medium-sized businesses (SMBs). The vCISO Academy was created to provide training and resources for Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs) to offer effective vCISO services. … Read more

Despite Emerging Regulations, Mobile Device, IoT Security Requires More Industry Attention

November 6, 2024 at 02:43PM Internet-connected devices are integral to daily life but pose significant cybersecurity risks. Consumers must remain vigilant against insecure devices and scams, particularly in light of recent regulatory advancements like the EU’s Cyber Resilience Act. Manufacturers need to adapt to evolving security requirements and enhance communication between product and cybersecurity teams. … Read more

The Case Against Abandoning CrowdStrike Post-Outage

October 31, 2024 at 10:01AM The July CrowdStrike outage highlighted risks in vendor security, prompting discussions on industry responses to such events. Companies should assess vendor reliability, avoid hasty changes, and maintain a balanced approach to updates. Leaders must act cautiously, avoiding panic-driven decisions while improving cybersecurity resilience and business continuity strategies. ### Meeting Takeaways … Read more

Cybersecurity Training Resources Often Limited to Developers

October 30, 2024 at 12:59PM Recent studies reveal that many cybersecurity executives prioritize software security training only for select employees, often neglecting company-wide awareness. Factors like customer satisfaction and financial costs drive their decisions, leading to ineffective training strategies. Effective, tailored training for all employees is essential to mitigate risks and enhance organizational resilience against … Read more

Why Phishing-Resistant MFA Is No Longer Optional: The Hidden Risks of Legacy MFA

October 24, 2024 at 07:38AM The article emphasizes the urgent need for organizations to adopt phishing-resistant multifactor authentication (MFA) as ransomware payments soar, with an average increase of 500%. Legacy MFA systems prove inadequate against evolving cyber threats fueled by Generative AI. Implementing advanced, biometric-based solutions is essential to combat this growing risk. ### Meeting … Read more