Topic: cyber risk management

  • Diligent Automates Cyber Risk Assessments and Reporting

    Diligent Automates Cyber Risk Assessments and Reporting

    Diligent Cyber Risk Management, launching summer 2026, uses an agentic AI solution to compress cyber risk assessments from weeks to hours by linking threats directly to business goals and board-level oversight. The platform consolidates technical and business data to enable AI-powered risk scorin...

    Read More »
  • DeVry CISO: Tackling Cybersecurity Risks in Higher Ed

    DeVry CISO: Tackling Cybersecurity Risks in Higher Ed

    Modern universities balance open collaboration with cybersecurity by architecting a clear separation between student-facing systems and secure backend infrastructure, allowing for controlled access to sensitive administrative data. A cross-functional Cyber Risk Committee evaluates threats by weig...

    Read More »
  • Infosecurity Europe: Getting Boards to Prioritize Cyber Risk Quantification

    Infosecurity Europe: Getting Boards to Prioritize Cyber Risk Quantification

    Cyber executives are gaining board-level support for cyber risk quantification by translating technical threats into business language, using financial metrics like potential revenue loss, regulatory fines, and operational downtime rather than fear-based presentations. Building trust over time th...

    Read More »
  • Secure Your Network: NIS2 Password, MFA & AD Best Practices

    Secure Your Network: NIS2 Password, MFA & AD Best Practices

    The EU's NIS2 Directive mandates stricter cybersecurity measures, including robust risk management, proactive identity and access management, and continuous monitoring for compliance across various sectors. Strengthening Active Directory is essential under NIS2, as it centralizes authentication a...

    Read More »
  • Munich Re acquires cyber-insurer At-Bay for $575M, half of 2021 value

    Munich Re acquires cyber-insurer At-Bay for $575M, half of 2021 value

    Munich Re agreed to acquire cyber-insurance startup At-Bay for $575 million, a steep drop from its $1.35 billion valuation in 2021, reflecting tougher conditions in tech and insurance sectors. At-Bay specializes in cyber insurance for small and medium businesses, using its "InsurSec" platform tha...

    Read More »
  • Patched FortiGate Firewalls Hacked, Cisco RCE Probed

    Patched FortiGate Firewalls Hacked, Cisco RCE Probed

    A critical authentication bypass flaw (CVE-2025-59718) persists in Fortinet firewalls despite patches, while Cisco urgently addressed an exploited RCE vulnerability (CVE-2026-20045), highlighting ongoing challenges in securing network infrastructure. Sophisticated phishing targets the energy sect...

    Read More »
  • UK Unveils Major Plan to Fortify Public Sector Cybersecurity

    UK Unveils Major Plan to Fortify Public Sector Cybersecurity

    The UK government is investing over £210 million in a new cybersecurity initiative, establishing a central Government Cyber Unit and mandating minimum security standards to protect essential public services. The strategy includes a public-private Software Security Ambassador Scheme and follows ne...

    Read More »
  • US Critical Infrastructure Hit by Pro-Russia Cyberattacks

    US Critical Infrastructure Hit by Pro-Russia Cyberattacks

    Pro-Russia hacktivist groups are exploiting weak security to breach U.S. critical infrastructure, causing real disruptions in sectors like water and energy, as detailed in a joint advisory from CISA, the FBI, and the NSA. These loosely organized groups, such as Cyber Army of Russia Reborn, use ba...

    Read More »
  • Hackers Evade Security Tools to Directly Target Users

    Hackers Evade Security Tools to Directly Target Users

    A new report from cybersecurity firm Bridewell warns of a rise in "fix-style attacks," where hackers bypass traditional security tools by directly targeting users through deceptive technical support scams. These attacks trick victims into voluntarily granting remote access or installing malware, ...

    Read More »
  • Aviation cyber threats grounded, but blind spots remain in the air

    Aviation cyber threats grounded, but blind spots remain in the air

    Aviation cyber threats primarily occur while planes are on the ground, not in flight, because parked aircraft fall outside the airline's network monitoring, allowing attacks like GNSS jamming to go undetected in traditional SIEM systems. A vulnerability in the open-source PX4 Autopilot platform h...

    Read More »
  • US regulators pause bank cyber exams for Wall Street to patch Mythos flaws

    US regulators pause bank cyber exams for Wall Street to patch Mythos flaws

    In response to disruptions caused by Anthropic's Mythos AI model, U.S. regulators, including the Federal Reserve, are pausing certain cyber examinations for major banks to allow them to address newly exposed vulnerabilities. The pause prioritizes patch management and system hardening over standar...

    Read More »