Security: Page 14


  • Blue padlock made to resemble a circuit board and placed on binary computer code.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Risk of cyberattack emerges as top concern of US executives

    PwC research shows cyber risk is a top concern among entire C-suite and corporate boards as companies spend more to boost resilience.

    By David Jones • Aug. 22, 2022
  • A Mailchimp logo on a phone with a larger Mailchimp in the background.
    Image attribution tooltip

    Rafael Henrique/Zumapress/Newscom

    Image attribution tooltip

    Mailchimp breach shines new light on digital identity, supply chain risk

    Sophisticated threat actors are targeting weak links in the email marketing space to go after vulnerable financial targets.

    By David Jones • Aug. 18, 2022
  • Trendline

    IT Security

    Executives are working to improve the security posture of their businesses, a task that requires cross-function collaboration.

    By CIO Dive staff
  • CISO salaries balloon, likely spurred by demand

    Tenure matters, but not as you might suspect. Median total cash compensation fell for CISOs who have been in their roles at least five years, Heidrick & Struggles found. 

    By Naomi Eide • Aug. 18, 2022
  • cybersecurity stock photo
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Zero trust skyrockets, nearing universal adoption

    A report from Okta shows organizations fully embracing zero-trust principles, as hybrid work requires long-term changes to identity management. 

    By David Jones • Aug. 16, 2022
  • Chris Krebs, former director of the Cybersecurity and Infrastructure Security Agency, testifies on Capitol Hill, October 19, 2017 in Washington, DC.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Don’t count on government, tech vendors to fix security woes, former CISA chief Krebs says

    The state of cybersecurity is bad and it’s going to get worse, Chris Krebs said at Black Hat. But somehow things might eventually get better.

    By Matt Kapko • Aug. 11, 2022
  • Team of data center system administrators and IT specialists use laptop and tablet computers.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    AWS, Splunk lead open source effort to spot and curb cyberattacks

    A broad group of 18 tech companies is collaborating to establish a less cumbersome model for cybersecurity defense coordination.

    By Matt Kapko • Aug. 10, 2022
  • Close up of young businessman with blue eyes wearing the glasses looking on the waveform lines
    Image attribution tooltip

    Shutterstock/HQuality

    Image attribution tooltip
    Sponsored by Druva

    Delivering the promise of resiliency across all tenets of risk

    To protect data against a number of risks, organizations need comprehensive, end-to-end resiliency.

    By Stephen Manley, Chief Technology Officer, Druva • Aug. 8, 2022
  • A password field reflected on a eye.
    Image attribution tooltip
    Leon Neal via Getty Images
    Image attribution tooltip

    Slack resets passwords en masse after invite link vulnerability

    The bug, which went undetected for five years, impacts at least 60,000 users but likely more.

    By Matt Kapko • Aug. 5, 2022
  • Image depicts the implementation of cybersecurity with a lock displayed over a screen.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Ransomware defense guidance risks hang-ups under many steps

    Small and mid-sized businesses don’t typically have the resources to meet every safeguard. But every action, however small, helps.

    By Matt Kapko • Aug. 4, 2022
  • Ransomware virus has encrypted data. Attacker is offering key to unlock encrypted data for money.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Most cyberattacks come from ransomware, email compromise

    Attackers are scanning for vulnerabilities in unpatched systems within 15 minutes, stressing the pace and scale of the threat.

    By Matt Kapko • Aug. 2, 2022
  • AWS logo appears in the background of a busy conference.
    Image attribution tooltip
    Noah Berger/Getty Images via Getty Images
    Image attribution tooltip

    AWS wants to be an enterprise security strategy advisor

    The cloud giant advised customers to focus on specific needs, and rely on embedded defenses running automatically behind the scenes.

    By Matt Kapko • July 27, 2022
  • A group of co-workers surround a computer screen
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Where 5 programs are investing to close cyber skills gap

    In line with a White House push to close the cyber skills gap, technology firms, nonprofits and other organizations have launched a range of programs to develop a new generation of workers.

    By David Jones • July 26, 2022
  • close up programmer man hand typing on keyboard laptop for register data system or access password at dark operation room , cyber security concept - stock photo
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Threat actors use Google Drive, Dropbox to launch cyberattacks

    By using trusted applications, threat actors gain a low-cost way to collect data and host malware, Unit 42 researchers said.

    By David Jones • July 20, 2022
  • Computer language script and coding on screen.
    Image attribution tooltip
    themotioncloud via Getty Images
    Image attribution tooltip

    Fake GitHub commits can trick developers into using malicious code

    Threat actors can easily alter the identity and timestamp associated with software updates, putting developers at serious risk, Checkmarx research shows.

    By Matt Kapko • July 18, 2022
  • Golden circuit cloud showing cloud computing technology
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    5 experts demystify post-cloud migration challenges

    Businesses must think about what comes after cloud migration and prepare for the challenges that arise once workloads are transferred.

    By July 15, 2022
  • The U.S. Capitol Building at night with lightning in the background.
    Image attribution tooltip
    Naomi Eide/CIO Dive
    Image attribution tooltip

    Log4j is far from over, cyber review board says

    Exploitation of Log4j occurred at lower levels than experts predicted, yet it remains an "endemic vulnerability," the Cyber Safety Review Board said.

    By Naomi Eide • July 14, 2022
  • A sign is posted in front of a Marriott hotel.
    Image attribution tooltip
    Justin Sullivan via Getty Images
    Image attribution tooltip

    Latest Marriott breach shows a human error pattern

    The latest incident at the hotel chain is relatively minor compared to major breaches in late 2018 and early 2020, but it signals a pattern of neglect.

    By Matt Kapko • July 7, 2022
  • A conference room equipped with laptops in a modern panoramic office.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Cybersecurity expertise creeps onto Fortune 500 boards

    Companies are trusting technology experts to advise on cybersecurity and regulatory pressures from the board’s perspective.

    By Barbara DeLollis • July 6, 2022
  • A diverse group of executives talking in meeting room.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    CISO priorities for the second half of 2022

    Security executives from Zoom, NS1 and Oomnitza shared their security priorities for the rest of 2022, with a special emphasis on mastering the basics. 

    By Sue Poremba • July 5, 2022
  • Cyberattack and internet crime, hacking and malware concepts.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Is your remote IT job candidate legit?

    Organizations are seeing a rise in deepfakes and stolen identities during the job application process, the FBI said.

    By Naomi Eide • June 29, 2022
  • Communication network concept. GUI (Graphical User Interface).
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Organizations lag on confidence and policies to manage open source security

    It's taking longer for companies to find open source vulnerabilities, and shaky policies mean only the most critical flaws are attended to. 

    By David Jones • June 24, 2022
  • Team of professionals meeting in office around computers
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Analysts nudge businesses to decentralize cybersecurity leadership

    The push is to enable employees to make informed security decisions while meeting enterprise needs with spread out security leadership. 

    By June 22, 2022
  • Software building
    Image attribution tooltip
    Getty Images
    Image attribution tooltip
    Q&A

    What enterprise leaders can divine from software bills of materials

    Cyber defense tool: Software bills of materials (SBOMs) can expose elements of risks in applications.

    By June 13, 2022
  • An aerial view on a sunny morning of several of San Francisco's most well known architectural landmarks. A backdrop of the skyscrapers and Bay Bridge behind them.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    5 takeaways from the RSA Conference

    The event tried to pick up where it left off 28 months ago. Can companies keep up with the accelerated pace and scale of cyber threats?

    By Matt Kapko • June 13, 2022
  • software, code, computer
    Image attribution tooltip

    Markus Spiske

    Image attribution tooltip

    Organizational changes required to mitigate security risks

    CIOs are implementing new strategies to lower software supply chain risk, but evaluating internal operations could prove more effective.

    By June 7, 2022