Today’s columnist, Ryan Noon of Material Security, says we can expect more SolarWinds attacks until we change to an “inside-out” strategy that assumes attackers are already inside the network and security teams set defenses accordingly.
The Cuba ransomware gang launched assaults in February on a payment processor widely used by many state and municipal agencies across the United States to manage utility bills and driver’s license data.
The report comes after attempts late last year by suspected North Korean hackers to steal data from at least nine healthcare companies, such as Johnson & Johnson, Novavax and AstraZeneca.
Before implementing controls, facilities may first need to conduct a thorough risk assessment and prioritization exercise. And if they don’t start to apply some of these measures themselves, government just might step in.