Security: Page


  • Image attribution tooltip
    Getty
    Image attribution tooltip

    Security experts overlook attacker-favored credential stuffing

    With an endless cycle of breaches, hackers have a large pool of exposed credentials to throw at websites, increasing their probability of success. 

    By Samantha Schwartz • Sept. 30, 2020
  • UHS
    Image attribution tooltip

    UHS

    Image attribution tooltip

    UHS hit with ransomware attack, working to restore IT operations

    The for-profit owner of around 400 hospitals is struggling to contain the ripple effects of a cyberattack that locked it out of computer and phone systems.

    By Rebecca Pifer Parduhn • Sept. 29, 2020
  • How global companies factor their supply chain into data protection, privacy

    International Paper purposefully duplicates technologies to comply with international laws, from one vendor to another.

    By Samantha Schwartz • Sept. 25, 2020
  • Image attribution tooltip
    Shopify
    Image attribution tooltip

    'Rogue' employees caused Shopify's data breach. What makes an insider a threat?

    Coinciding crises are contributing to "a perfect storm for malicious insiders," Forrester's Joseph Blankenship says.

    By Samantha Schwartz • Sept. 24, 2020
  • How to negotiate software costs as IT budgets are slashed

    If vendors can't provide a degree of flexibility, abandon the deal, according to Paul McKay, senior analyst at Forrester.

    By Samantha Schwartz • Sept. 23, 2020
  • 6 types of CISO and the companies they thrive in

    Jeff Pollard, VP and principal analyst at Forrester, wants CISOs to discover the type of leader they are — transformational, tactical, steady — and run with it.

    By Samantha Schwartz • Sept. 22, 2020
  • Image attribution tooltip
    Fotolia
    Image attribution tooltip

    How cloud threat protection takes on shadow IT

    Cloud access security broker capabilities — discovery, data loss prevention, threat protection, encryption, logging — should sit between every kind of app a company houses.

    By Samantha Schwartz • Sept. 21, 2020
  • What security needs to know before diving into SaaS contracts

    If employees don't engage with security red flags, the agreement fails to address the underlying issue: an application outside of a company's risk appetite.

    By Samantha Schwartz • Sept. 18, 2020
  • Data doesn't speak for itself: 4 benefits of giving security metrics context

    When presenting security metrics and data to non-technical stakeholders, security leaders' messaging could get lost in translation.

    By Samantha Schwartz • Sept. 17, 2020
  • Security pushes DevOps to breaking point

    The future of DevOps is "going to break application security," said Dale Gardner, research director at Gartner.

    By Samantha Schwartz • Sept. 16, 2020
  • laptop, coding, code, cybersecurity
    Image attribution tooltip
    Rangel, David. [photograph]. Retrieved from https://unsplash.com/photos/4m7gmLNr3M0.
    Image attribution tooltip

    Gartner: 10 key security projects through 2021

    As companies adapt to changes in March and what's anticipated for the next 12 months, Brian Reed, senior director analyst at Gartner, wants the focus on projects, not programs.

    By Samantha Schwartz • Sept. 15, 2020
  • Image attribution tooltip
    Wikimedia Commons
    Image attribution tooltip

    How a government security framework reduces third-party risks

    The DOD says its contractor network includes upwards of 300,000 companies, and conducting an audit of all of them couldn't be done. This logjam helped create the Cybersecurity Maturity Model Certification Accreditation Body.

    By Samantha Schwartz • Sept. 14, 2020
  • Targeted cyberattacks on telehealth vendors skyrocketed along with adoption, report finds

    Telehealth vendor security alerts jumped 30% during COVID-19 compared to pre-pandemic levels, analysis from SecurityScorecard and DarkOwl found.

    By Rebecca Pifer Parduhn • Sept. 11, 2020
  • Zero trust is widely praised. What's the adoption hangup?

    The framework has a steep learning curve and requires modern technology, a Deloitte expert said.

    By Samantha Schwartz • Sept. 10, 2020
  • Image attribution tooltip
    Kendall Davis/CIO Dive
    Image attribution tooltip

    From VPNs to zero trust, coronavirus shaped security priorities

    While there are differences in security priorities pre-pandemic, a lot of hurdles were related to scale.

    By Samantha Schwartz • Sept. 9, 2020
  • Image attribution tooltip
    Getty Images
    Image attribution tooltip

    How last week's outages, DDoS attacks impacted internet infrastructure

    The outages highlight two areas of concern: cyberattacks in the age of COVID-19 and the internet's longstanding fragility.

    By Samantha Schwartz • Updated Sept. 9, 2020
  • Image attribution tooltip
    Retrieved from Pixabay.
    Image attribution tooltip

    Cloud shared responsibility models are misunderstood, report says

    Any disconnect between where a CSP's security services end and the customer's security responsibilities pick up is a recipe for disaster.

    By Samantha Schwartz • Sept. 3, 2020
  • Image attribution tooltip
    Getty Images
    Image attribution tooltip
    Sponsored by Bridgecrew

    Comprehensive DevSecOps includes securing cloud infrastructure

    Teams often overlook emerging security risks. Fortunately, new tools can help find and proactively mitigate those risks before they lead to data breaches.

    Sept. 3, 2020
  • Image attribution tooltip
    Kendall Davis/CIO Dive
    Image attribution tooltip

    Top network services companies leave exposed to the internet

    Gaps in security programs, including a lack of personnel, expertise or resources, amplify the risk of an unsafe service going undetected.

    By Samantha Schwartz • Sept. 2, 2020
  • Ransomware attacks 'raising the bar' as cities struggle to respond

    A former FBI special agent in New York walked through a typical ransomware attack with a series of redacted screenshots, as well as the report.

    By Chris Teale • Aug. 31, 2020
  • Image attribution tooltip
    CIO Dive
    Image attribution tooltip

    First half of 2020 led to nearly 800 disclosed vulnerabilities: report

    Microsoft's Patch Tuesday increased to an average of 102.7 fixes a month since January, according to a report from Trend Micro.

    By Samantha Schwartz • Aug. 28, 2020
  • Risk leaders prepare for technology challenges of reentry

    As new conditions unravel, integrating risk management will make sure the processes developed in lockdown are as sustainable as the country emerges from COVID-19.

    By Samantha Schwartz • Aug. 27, 2020
  • Understanding Carnival's ransomware attack, hitting two different data types

    Last week the cruise line disclosed a ransomware attack that impacted employee and customer data. The security divisions can get murky.

    By Samantha Schwartz • Aug. 26, 2020
  • Sink or swim: Companies adopt tech in effort to stay afloat during pandemic, recession

    While new technologies alleviate the burden of rapid adaptation to customer demand, risk is a constant factor.

    By Samantha Schwartz • Aug. 25, 2020
  • Deloitte: Companies turn to cybersecurity, cloud in pandemic response

    Executives care about agility and sustaining operations through disruption. Cloud acts as a backbone, while cybersecurity is a fence.

    By Aug. 24, 2020