SoatDev IT Consulting
SoatDev IT Consulting
  • About us
  • Expertise
  • Services
  • How it works
  • Contact Us
  • News
  • August 2, 2023
  • Rss Fetcher

A valuable report from the CISA.
Welcome to Cyber Security Today. It’s Wednesday, August 2nd, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.

I’m away for a few days, so this podcast doesn’t have the latest news. Instead I want to draw listeners’ attention to an analysis issued last week by the U.S. Cybersecurity and Infrastructure Security Agency.
(CISA) of 121 risk and vulnerability assessments it did last year. It does these for federal, state and local agencies as well as some critical infrastructure companies who have suffered cyber attacks.
IT and security leaders can learn a lot from the three main conclusions.
First, threat actors completed their most successful attacks by commonly known methods, such as phishing and exploiting unchanged default credentials in hardware and software.
In fact accessing valid accounts — including default passwords on administrator accounts or former employee accounts that weren’t deleted when the staffer left — made up 54 per cent of successful attacks studied.
Second, threat actors used constantly changing tools and techniques to successfully conduct these common attacks.
And third, many IT environments across a variety of critical infrastructure sectors had the same vulnerabilities that allowed successful attacks.
One lesson from the report: Having bulletproof identity and access control over applications is vital to stopping most attacks. This includes having phishing-resistant multifactor authentication.
Another lesson: Regular security awareness training for employees. One-third of incidents studied involved employees falling for phishing links.
Another lesson from the report: Preventing initial access by an attacker should be the main goal in protecting IT network assets and data.
There’s a lot in this 18-page report for IT and security leaders, especially those in smaller organizations with few resources or immature cybersecurity programs.
Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.The post Cyber Security Today, August 2, 2023 – A valuable report from the CISA first appeared on IT World Canada.

Previous Post
Next Post

Recent Posts

  • Marjorie Taylor Greene picked a fight with Grok
  • TechCrunch Mobility: Uber Freight’s AI bet, Tesla’s robotaxi caveat, and Nikola’s trucks hit the auction block
  • OpenAI upgrades the AI model powering its Operator agent
  • Startups Weekly: Cutting through Google I/O noise
  • Microsoft says its Aurora AI can accurately predict air quality, typhoons, and more

Categories

  • Industry News
  • Programming
  • RSS Fetched Articles
  • Uncategorized

Archives

  • May 2025
  • April 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023

Tap into the power of Microservices, MVC Architecture, Cloud, Containers, UML, and Scrum methodologies to bolster your project planning, execution, and application development processes.

Solutions

  • IT Consultation
  • Agile Transformation
  • Software Development
  • DevOps & CI/CD

Regions Covered

  • Montreal
  • New York
  • Paris
  • Mauritius
  • Abidjan
  • Dakar

Subscribe to Newsletter

Join our monthly newsletter subscribers to get the latest news and insights.

© Copyright 2023. All Rights Reserved by Soatdev IT Consulting Inc.