This site uses cookies to improve your experience. To help us insure we adhere to various privacy regulations, please select your country/region of residence. If you do not select a country, we will assume you are from the United States. Select your Cookie Settings or view our Privacy Policy and Terms of Use.
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Used for the proper function of the website
Used for monitoring website traffic and interactions
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Strictly Necessary: Used for the proper function of the website
Performance/Analytics: Used for monitoring website traffic and interactions
KrebsOnSecurity reviewed the Web sites for the global top 100 companies by market value, and found just five percent of top 100 firms listed a chief information security officer (CISO) or chief security officer (CSO). Nobody’s saying these companies don’t have CISOs and/or CSOs and CTOs in their employ.
Thoughts on Mark Rasch's essay, Conceal and Fail to Report - The Uber CSO Indictment Mark Rasch, who created the Computer Crime Unit at the United States Department of Justice, has an essay, " Conceal and Fail to Report - The Uber CSO Indictment."
Joe Sullivan, the former Chief Security Officer (CSO) of Uber, has been sentenced to three years’ imprisonment and 200 hours of community service for covering up a cyber attack on the company’s servers in 2016, which led to a databreach affecting over 50 million riders and drivers.
A review of the executives pages published by the 2022 list of Fortune 100 companies found only four — BestBuy , Cigna , Coca-Cola , and Walmart — that listed a Chief Security Officer (CSO) or Chief Information Security Officer (CISO) in their highest corporate ranks. Image: IANS Research.
Mark Rasch, who created the Computer Crime Unit at the United States Department of Justice, has an essay, “ Conceal and Fail to Report – The Uber CSO Indictment.” But I’m not sure that, as a matter of law, this constitutes “misrepresenting, concealing or falsifying” materials actually produced to the FTC.”
Department of Justice just filed federal charges against Uber's former Chief Security Offier (CSO) for allegedly covering up a company databreach and bribing hackers to stay silent about the attack. SecureWorld wrote about this case in Uber DataBreach: 3 Things Revealed in Testimony to Congress.
We also saw, for the first time, a security chief sentenced to prison for concealing a databreach. These events and many more have changed the business landscape and forced CISOs to steer a course through uncertain waters. To read this article in full, please click here
Truth, transparency and trust are the three T’s that all CISOs and CSOs should embrace as they march through their daily grind of keeping their enterprise and the data safe and secure. The case against Uber’s former CSO. Failure to adhere to the three T’s can have serious consequences.
GoDaddy WordPress databreach timeline. In a Securities and Exchange Commission (SEC) filing , Demetrius Comes, GoDaddy’s CISO, announced that the organization had discovered unauthorized access to its Managed WordPress servers. November 17, 2021: GoDaddy discovers unauthorized third-party access on Managed WordPress.
The role of a Chief Information Security Officer (CISO) is undeniably complex, yet incredibly rewarding. However, the challenges faced by CISOs are mounting, exacerbated by the evolving threat landscape and regulatory environment. RELATED: Uber CSO Found Guilty: The Sky Is Not Falling.
Databreaches can be quite a complicated issue for organizations. No matter how good, or bad, your cybersecurity is, sophisticated threat actors always seem to find a way to make life difficult for a CISO. T-Mobile databreach. The company disclosed the databreach quickly after discovering it.
This week, the former Chief Security Officer of Uber, Joseph Sullivan, was found guilty on one count of obstruction of justice and one count of misprison, the act of concealing a felony from authorities, arising out of his handling of a 2016 databreach at the company. Sullivan's actions were irregular.
A Uber breach verdict was handed down that could prove highly impactful to CISOs and CSOs in the near and distant future. The post “How will the Uber Breach Verdict Affect the CISO Role in the Future?” The post “How will the Uber Breach Verdict Affect the CISO Role in the Future?”
Nearly half of CISOs will change jobs by 2025 due to stress caused by the risk of being breached while trying to retain staff, according to the Gartner report, Predicts 2023: Cybersecurity Industry Focuses on the Human Deal. Although burnout is nothing new, it did become more visible and common during and after COVID-19.
Ransomware and databreaches pose a massive risk to organizations, resulting in loss of customer trust and shareholder value, reputation damage, hefty fines, and penalties. More than half ( 61% ) of CISOs report to a board and board members are increasingly interested in what CISOs have to say.
Multiple breaches, including the massive 2017 databreach at the credit reporting agency Equifax , have been traced back to unpatched vulnerabilities—a 2019 Tripwire study found that 27% of all breaches were caused by unpatched vulnerabilities, while a 2018 Ponemon study put the number at a jaw-dropping 60%.
Yesterday, a federal jury handed down a guilty verdict to Joe Sullivan, the former CSO on charges of “obstruction of the proceedings of the Federal Trade Commission and misprision of felony in connection with the attempted cover-up of a 2016 hack at Uber” according to a notice published by the Department of Justice (DOJ).
Chief Information Security Officers (CISO) have the luxury of being an incredibly hot commodity, so they can pretty much pick and choose where they work, as they are almost guaranteed to have a job waiting for them somewhere. Cybersecurity officials struggle in Florida. DeSantis appointed former state Rep.
In a move that has raised concerns about the company's cybersecurity posture, Amy Bogac, Clorox's CISO, has stepped down from her position. Others suggest that she may have simply felt overwhelmed by the challenges of leading the company's cybersecurity efforts in the aftermath of such a significant breach.
Paul speaks with Caleb Sima, the CSO of the online trading platform Robinhood, about his journey from teenage cybersecurity phenom and web security pioneer, to successful entrepreneur to an executive in the trenches of protecting high value financial services firms from cyberattacks. Caleb Sima is the CSO at Robinhood.
“Having a risk management framework is essential, because risk can never be totally eliminated; it can only be effectively managed,” says Arvind Raman, CISO at telecommunications company Mitel Networks. To read this article in full, please click here (Insider Story)
With databreach rates rising and criminal attack methods becoming more sophisticated each day, it is essential for every organization to take security seriously. Even if a company employs a Chief Information Security Officer (CISO) or Chief Security Officer (CSO), the position may still report to the CIO.
SolarWinds this week announced that its vice president of security Tim Brown has taken on the additional title of CISO, as part of the company’s ongoing efforts to institute a secure-by-design posture. (“ SolarWinds letters” by sfoskett at is licensed under CC BY-NC-SA 2.0 ). Tim Brown, SolarWinds’ new CISO.
Seasoned CISOs/CSOs understand the importance of effectively communicating cyber risk and the need for investment in cybersecurity defense to the board of directors. To ensure cybersecurity becomes a strategic part of the corporate culture, it is crucial for CISOs to present the topic in a clear, concise, and compelling manner.
And the recent clarifications—focusing on material cybersecurity incidents—is a step in the right direction," said Glenn Kapetansky , CSO, Trexin Group. "In In the short term, however, the definition of 'material'—which depends on sector and even timing—is murky enough that CISOs are still uncertain what is material and what is not.
Equifax is sharing its Security Controls Framework to anyone who wants it as a pay-it-forward for lessons learned from its 2017 databreach in which attackers exfiltrated hundreds of millions of customer records from the credit reporting agency. "We into our security transformation. Today, we're making it available to everyone.
Verizon Business’ annual DataBreach Investigations Report (DBIR) is out and confirms what many CISOs already know: ransomware continues to plague business. Ransomware-related breach instances rose 13%, an increase larger than in the past 5 years combined. DBIR finds ransomware increased by double digits.
Circle Security boasts an impressive advisory board featuring several high-profile cybersecurity thought leaders including Bruce Schneier, Lucia Milica, global CISO of Proofpoint, and Eric Liebowitz, CISO of Thales Group. Credential-driven databreaches are the biggest threat vector for most companies.
(on-demand webinar) The Data-Factor: Why Integrating DSPM Is Key to Your CNAPP Strategy (blog) When CNAPP Met DSPM (infographic) VIDEO Integrated DSPM features - enable data protection today! Relying solely or mostly on a single cloud-services provider is risky and restrictive.
For CISOs, the sad truth is that it’s no longer a matter of if an organization will be breached, but when. Even with strong defenses in place to prevent a potential databreach, security teams should still prepare for the worst.
David Estlick, chief information security officer of Chipotle Mexican Grill joined James Christiansen, vice president and CSO of cloud security transformation at Netskope, to speak about managing corporate expectation. ” CISOs and security leaders must therefore communicate that expectations, Christiansen added.
.” “It would be possible, on detailed examination of video, to compromise elements of operational security,” agreed Mike Hamilton, co-founder and chief information security officer of CI Security and former Seattle CISO. Odds are more than one was breached here,” said Davisson. “I Look at the Mac operating system.
Expectations around how corporate America responds to and communicates around databreaches has evolved significantly over the past two decades,” said T.J. When a databreach is discovered, the heat is on the IS/IT department(s) and, in many organizations, there is a culture of blame,” said Winick. Here is a sampling.
Under the guidance of Dan Meacham, VP of Global Security and Corporate Operations and CSO/CISO, the multi-billion dollar organization transitioned from on-premises data centers to the cloud in 2012. Data protection with user and entity behavior analytics (UEBA). Unacceptable levels of risk.
In March, the company disclosed a databreach that exposed about 1.2% Here’s a look at some of those issues — including some that came up at this week’s RSA Conference in San Francisco. But OpenAI has experienced some problems with its generative AI platform that could also apply to GPT-4.
Everyone on the board is responsible and could potentially be held accountable for a breach both legally and financially. It is not only the CISO, CSO or CIO’s responsibility to care and do the right thing. Everyone is responsible and accountable. When one person doesn’t do their part, things can fall apart for a company.
Dimitri Chichlo , CSO, BforeAI Chichlo Our networks remain fragile because of interdependence and the assumption that technology always works. Dylan Owen , CISO, Nightwing Owen Now is a good time to review incident response plans and identify any weak spots, like missing backups.
Featured interview: CISO and cyber attorney Alexander Urbelis who uncovered this cyberattack. Huawei USA's CSO answers questions about trust, verification, cybersecurity, and supply chain security. Featured interview: Tim Callahan, Aflac Global CSO. Chinese Hackers and the Equifax DataBreach.
With 24% of all databreaches using ransomware, this commoditisation of cybercrime significantly broadens the field, resulting in a sharp increase in the frequency and variety of attacks. Useful resources include: The Professional Association of CISOs at [link].
Examples of this include keeping software up to date, backing up data, and maintaining good password practices. At the end of the day, lack of education and human error are two of the largest contributors to databreaches. Tyler Farrar ,CISO, Exabeam. Wes Spencer, VP, External CSO, ConnectWise.
We organize all of the trending information in your field so you don't have to. Join 28,000+ users and stay up to date on the latest articles your peers are reading.
You know about us, now we want to get to know you!
Let's personalize your content
Let's get even more personalized
We recognize your account from another site in our network, please click 'Send Email' below to continue with verifying your account and setting a password.
Let's personalize your content