An audit this month from the Government Accountability Office found that while the agency has built up a variety of programs and resources to support the sector’s cybersecurity needs, it has little insight into whether they’re actually having an impact.
ESG finds that 69% of respondents say they had at least one cyberattack caused by an exploit of an unknown or unmanaged internet-facing asset, including software, cloud workloads, user accounts, and IoT devices.
As healthcare continues its digital transformation, providers must address ongoing clinical asset risks with the “borderless environment of care,” said First Health Advisory’s Carter Groome during InfoSec World.
DHS CISO Kennth Bible joined the agency "in the peak of the response actions" post SolarWinds hack. He ultimately established a four-prong strategy for supply chain risk management that pushes industry partners to take ownership of their own cybersecurity hygiene to overcome the approach of "bending metal — building something, then deciding how we wanted to address cybersecurity."
A new report says cultural and technical divides are hindering industrial organizations from developing a fully mature security program – a problem that limits visibility throughout the organization and underscores the need for a unified IT/OT security strategy.
This week, Dr. Doug talks: Elon buys my motorcycle, Lyceum, Buzz word security, PS5, Puny Code, Palo Alto, and Small biz, and the show wrap ups on the Security Weekly News Wrap Up show!
Assessing risk, earning buy-in, implementing tools to track assets, documenting processes and maintaining transparency are all important components of a strong insider threat strategy, said Code42's Todd Thorsen at this week's InfoSec World conference.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.