It can be hard to plan for a security incident if you’ve never experienced one first hand. Incidents involve unauthorized access, denial of service, presence of malicious logic, and improper usage. As an incident responder, I’ve seen plenty of these situations play out. I was fortunate to share some of my experiences and lessons with… Read More
2018 Cyber Security Trends: Where are We Headed This Year?
We’re only a month into 2018 and we’ve already seen a flurry of security incidents. Meltdown and Spectre grabbed headlines early, bringing attention to a serious design flaw in Intel processor chips. Ransomware breaches that hit Allscriptsand Hancock Health were born from the SamSam variant, which has only gained strength as a major threat across all sectors. What else is in… Read More
[Guest Blog] Allscripts Attack Sets the Bar: First Notable Ransomware Lawsuit Puts Providers Under the Spotlight
About the Author Arnold Abraham is Principal Attorney and Founder of the CyberLaw Group (cyberlawgroup.net), a law firm focused on personal privacy and data protection. He previously served as a Senior Federal Cyber Security Executive in USCYBERCOM and the Department of Homeland Security. Companies hit by cyber attacks are increasingly finding themselves open to potential liability… Read More
Cloud Security Learning Curve Remains High: Latest Amazon S3 Misconfiguration Illustrates Need for Safety Nets
We can add yet another sensitive data breach to our lessons learned catalog. This one, involving a large volume of sensitive medical records exposed to the world, goes in the fat folder related to misconfigured storage services. A U.S.-based digital records management company stored this information in a large PDF file, which was then stored in an Amazon Web Services… Read More
Incident Response Q&A Part II: Why Incident Response Playbooks Aren’t the Answer, and Advice for New CISOs
Incident response will continue to be an important cyber security priority for many organizations in 2018. We took a moment to get some deeper insight into the incident response landscape from Delta Risk Senior Consultant Ryan Clancy. Here’s part II of our incident response discussion (you can find part I here). Dev: There have been some… Read More
Incident Response Q&A Part I: Preparing Your Staff for a Cyber Security Incident (Including How to Respond to the Media)
Incident response will continue to be an important cyber security priority for many organizations in 2018. We took a moment to get some deeper insight into the incident response landscape from Delta Risk Senior Consultant Ryan Clancy. Here’s part I of our incident response discussion. Dev: It seems like the tide is shifting and we’re… Read More