IT Security & Privacy

Insights from the 2024 IBM Security Report

In an era where digital transformation is accelerating at an unprecedented pace, the cybersecurity landscape is evolving just as rapidly. The latest Cost of a Data Breach Report from IBM Security sheds light on the complex challenges organizations face in 2024, revealing both concerning trends and promising solutions.

Cybersecurity Maturity: Revisions to the NIST Cybersecurity Framework Explained

The National Institute of Standards and Technology (NIST) has unveiled its eagerly awaited version 2.0 of the Cybersecurity Framework (CSF). This update isn’t just a minor tweak—it's a significant overhaul from the previous v1.1.

Major Data Breach at HealthEquity Affects 4.3 Million Individuals: Key Lessons for Risk, Resilience, & IT Security Professionals

HealthEquity, a prominent health benefits administrator, has reported a significant data breach that may have compromised the personal information of approximately 4.3 million individuals. The company disclosed this incident in a recent notification filed with the Maine Attorney General's office.

Legal Scholar Warns of Fragility in Global Cybersecurity Infrastructure

Last Friday, a critical IT outage wreaked havoc across the globe, impacting airlines, emergency services, and retail businesses. The disruption began when cybersecurity firm CrowdStrike released a faulty software update, causing widespread system failures. Although the issue was eventually resolved, the aftermath continued to disrupt operations over the weekend, leaving passengers stranded, surgeries postponed, and retailers grappling with unexpected closures.

Massive Australian Health Data Breach: 12.9 Million Records Sold on Dark Web

In one of the largest data breaches in Australian history, cybersecurity experts confirm that highly sensitive health data of 12.9 million Australians, stolen from eScripts provider MediSecure, has been sold on the dark web and is now being offered for resale.

South Korea Issues Detailed Guidelines for Foreign Companies on Data Protection Compliance

The Personal Information Protection Commission (PIPC) of South Korea has released comprehensive guidelines titled "Guidelines on Applying the Personal Information Protection Act to Foreign Business Operators." These guidelines aim to help foreign companies navigate and comply with South Korea's Personal Information Protection Act (PIPA), particularly in light of major amendments made to the law in 2023.

Verizon Subsidiary Hit with $16M FCC Fine Over API Security Lapses

TracFone Wireless has agreed to pay $16 million to settle Federal Communications Commission (FCC) investigations into a series of data breaches that exposed customer information. The settlement, announced on July 22, 2024, highlights growing concerns over API security in the telecommunications industry.