Operation Don’t Cry – Part 1
Got Some Critical News to Share… The Situation Yesterday (May 14) Microsoft issued a global warning about a Monster Computer Bug. This article aims to get into some of the details about why this could...
View ArticleNearly 1 Billion User ID’s compromised!
Now that I’ve got your attention… Well, the operative number is 773 million, so, I guess my headline for this blog was only 227 million short (who’s counting…) Just two business weeks into the New...
View ArticleUser Authentication BIGGEST Cyber Risk in Healthcare
User Authentication IS THE MOST Common Cyber Risk for Hospitals and Health Systems User authentication short-comings, endpoint data leakage, and too much end-user permission are three of the most...
View ArticleSamSam – Recent Alert, Summary and Recommendations
Yesterday, December 3, The United States Department of Homeland Security (DHS), National Cybersecurity and Communications Integration Center (NCCIC), and the Federal Bureau of Investigation (FBI)...
View ArticleQuick Stats: Healthcare Ransomware Attacks
It is a fact that most ransomware attacks are taking place in the U.S. Specifically, healthcare and local governments are the apparent favorite targets amongst hackers. About 24% of them were...
View ArticleAdvanced Persistent Threat – What is It, How to Detect It
Some people refer to Advanced Persistent Threats (or APTs for short) as a form of malware or a virus. They are so wrong. Advanced Persistent Threat usually translates to a “your internal corporate...
View ArticleAre Data Breaches in Healthcare on the Rise?
The security surrounding personal health information, patient records, and personal data (in general) is obviously a very important topic throughout the world. Each year, many millions of data...
View ArticleUnified Labeling Goes Live and Scares the Heck Out of Me
We’ve all know that Microsoft’s implementation of Unified Labeling was coming. This was going to enable us to use much of the functionality of Azure Information Protection in O365 which has been long...
View ArticleGDPR, California, and You
So, what do GDPR, California, and you all have in common? Possibly a lot! Forward Since almost all of us are internet-connected creatures, the recent EU General Data Protection Regulation (or GDPR) is...
View ArticleAzure RMS Super Users
Azure RMS and Azure Information Protection offer excellent tools to protect information in your organization. Using them it is easy for end users to encrypt sensitive information so that no matter...
View ArticleGDPR: Immediate Fallout
The Y2K Event of this decade? GDPR’s hype looked a lot like the millennium cyber-clock meltdown, according to some. But here’s a key difference: GDPR has actually spurred immediate, tangible changes to...
View ArticleMayDay: questions and concerns from last-minute GDPR compliance seekers….
It’s been a very long week ushering in the infamous and inevitable May 25th GDPR enforcement go-live date. I’ve been calling this day “MayDay”. May 25th 2018 is going to feel like a Y2K moment to me,...
View ArticleSecurity tools overload? Security-as-a-Service will help
Catapult’s Spyglass security team sees this a lot, and that is, prospective clients with too few resources just trying to keep up: managing many disparate security and monitoring tools, trying to...
View ArticleGDPR – Can you handle the 72-hour breach notification requirement?
Nearly every security professional knows that the European Union has unleashed a stringent new law called the General Data Protection Regulation (GDPR). Standing out among many complex mandates within...
View ArticleFacebook’s big reveal… All 2.2 billion users’ personal data likely misused.
In my recent post about the Facebook and Cambridge Analytica debacle, I shared that 50 million Facebook users’ personal data was sold to Cambridge Analytica without the consent of the user. Well…...
View ArticleUnder Armour Hacked… MyFitnessPal No Longer My Pal
It’s getting difficult for me to determine which security incidents to blog about… First up, Facebook‘s unauthorized sharing/selling of 50 million persons’ private information, a definite FTC violation...
View ArticleJust Wow! Facebook “shares/sells” 50 million user’s PII without their...
As Facebook continues to explain their inexplicable actions in the Cambridge Analytica scandal, it is clear that the Facebook probably can’t be trusted to regulate itself. Mark Zuckerberg Facebook CEO...
View Articlememcached and massive Denial of Service attack (amplification attack), how to...
Two of the largest distributed denial-of-service attacks in the history of the “World Wide Webs” were launched this past week. This particular attack (called a reflection and amplification attack)...
View ArticleHealth Data (PHI) Breaches – The last 8 Years
Did you know that in the United States, the HITECH Act requires the Secretary of Health & Human Services to post a list of breaches of unsecured Protected Health Information affecting 500 or more...
View ArticleLost Productivity as a Result of an Outage
Much attention is given to the calculated costs associated with a security breach, where the business may experience both downtime (an outage) as well as external costs as you’ll see below. We often...
View Article