
Supply chain attacks: Would you back yourself to spot one?
All the cybersecurity experts and vendors in the world failed to stop the SolarWinds attack. It’s often the fluency and completeness of how you respond to the news that really matters…

All the cybersecurity experts and vendors in the world failed to stop the SolarWinds attack. It’s often the fluency and completeness of how you respond to the news that really matters…

The manufacturing sector has suffered the highest percentage of cyberattacks of any sector for three years in a row, according to IBM’s latest X-Force Threat Intelligence Report. Of the top 10 attacked sectors, manufacturing suffered 25.7% of all attacks, followed by finance and insurance at 18.2%. The highest “action on objective”—meaning “the cyber attacker’s end goal”—was malware. Ransomware represented 17% of actions on objective. The same report reveals that 85% of attacks on critical infrastructure could have been prevented with […]

The financial services industry has historically been one of the most targeted industries for cyberattacks, and it’s not difficult to imagine why. Roughly 95% of attacks are financially motivated, and hackers are going directly to the source by targeting the financial services sector. Not only do these financial institutions have direct access to cash, they also tend to be high-revenue businesses that can’t afford to be disrupted or take a reputational hit, so they’re more likely to pay a ransom. […]

Here’s a gentle, objective, and not-too-technical retrospective. Are you sitting comfortably?

The average cost of a data breach in 2023 was $4.45 million — a 15% increase over three years, marking yet another year in which the average cost has risen significantly. Yet, costs can balloon even higher. Just recently, Change Healthcare had to shell out billions after its breach earlier this year. With the devastatingly high costs of cyberattacks, acting only after you’ve been compromised is a good way to incur some heavy payments or, in some cases, even go […]

As the famous saying goes, “Those who cannot remember the past are condemned to repeat it.”

Employees are a major attack vector for threat actors targeting organizations. Recent research by Stanford University confirms this, revealing that 88% of all data breaches are caused by human error. These human errors might be as simple as sending an email to an incorrect address or leaving a database publicly viewable; but they can also be more involved, as when employees become victims of targeted phishing campaigns. Let’s detail how employees might be increasing risk for organizations and what organizations […]

When you come across a threat that seems mundane at first glance, is it OK to let AI try to mop it up on its own?

Banks with safe deposit vaults don’t set them up so that every box gets the same key. But when it comes to online accounts, we’re not always so careful…

HTTPS needed at least two decades to take hold, for a bunch of curious and sometimes contradictory reasons. Join Paul Ducklin for Part 2 of this peculiar but educational tale…

HTTPS needed at least two decades to take hold, for a bunch of curious and sometimes contradictory reasons. Join Paul Ducklin for Part 1 of this peculiar but educational tale…

Dire cybersecurity warnings about QR codes are commonplace, but is the risk really as bad as some vendors are saying?

What do you do when malware you’re chasing hasn’t left a copy of itself behind on disk? Or if it’s lying about where to find it, so you grab the wrong thing?

Sometimes, measurements and observations that seem obvious and intuitive turn out to be way off base.
These ‘bad guesses’ can lead to all sorts of risky conclusions, especially in cybersecurity.

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.






