IT Security & Privacy

Cybersecurity Maturity: Revisions to the NIST Cybersecurity Framework Explained

The National Institute of Standards and Technology (NIST) has unveiled its eagerly awaited version 2.0 of the Cybersecurity Framework (CSF). This update isn’t just a minor tweak—it's a significant overhaul from the previous v1.1.

Major Data Breach at HealthEquity Affects 4.3 Million Individuals: Key Lessons for Risk, Resilience, & IT Security Professionals

HealthEquity, a prominent health benefits administrator, has reported a significant data breach that may have compromised the personal information of approximately 4.3 million individuals. The company disclosed this incident in a recent notification filed with the Maine Attorney General's office.

Legal Scholar Warns of Fragility in Global Cybersecurity Infrastructure

Last Friday, a critical IT outage wreaked havoc across the globe, impacting airlines, emergency services, and retail businesses. The disruption began when cybersecurity firm CrowdStrike released a faulty software update, causing widespread system failures. Although the issue was eventually resolved, the aftermath continued to disrupt operations over the weekend, leaving passengers stranded, surgeries postponed, and retailers grappling with unexpected closures.

Massive Australian Health Data Breach: 12.9 Million Records Sold on Dark Web

In one of the largest data breaches in Australian history, cybersecurity experts confirm that highly sensitive health data of 12.9 million Australians, stolen from eScripts provider MediSecure, has been sold on the dark web and is now being offered for resale.

South Korea Issues Detailed Guidelines for Foreign Companies on Data Protection Compliance

The Personal Information Protection Commission (PIPC) of South Korea has released comprehensive guidelines titled "Guidelines on Applying the Personal Information Protection Act to Foreign Business Operators." These guidelines aim to help foreign companies navigate and comply with South Korea's Personal Information Protection Act (PIPA), particularly in light of major amendments made to the law in 2023.

Verizon Subsidiary Hit with $16M FCC Fine Over API Security Lapses

TracFone Wireless has agreed to pay $16 million to settle Federal Communications Commission (FCC) investigations into a series of data breaches that exposed customer information. The settlement, announced on July 22, 2024, highlights growing concerns over API security in the telecommunications industry.

The Evolving Landscape of Cybersecurity: Challenges & Opportunities in 2024

The cybersecurity sector faces a delicate balancing act between protection, progress, and business enablement. As cyber threats grow more sophisticated and widespread, organizations are increasingly challenged to safeguard their operations while still driving innovation and efficiency. This dynamic environment demands a comprehensive approach to cybersecurity that addresses rising costs, emerging threats, and the integration of advanced technologies.