2022 Week 22 Security review

 Summary

Not a lot of regular news, but we had both the Verizon and Sophos annual reports came out.

News

The Verizon Data Breach Investigations Report for 2022 indicated that while the education sector continues to be a favorite target, the motivator is mostly financial (somewhat confirming the Sophos report) and Medical Data is actually the least sought after.  The largest sector they indicated as a target was Professional, followed closely matched Finance, Information Technology, Manufacturing, and Public Administration.  

Education

The FBI issued an alert that they have become aware of cybercriminals selling usernames and passwords from university breaches.  The sales are occurring on a variety of dark websites.  The biggest takeaway for me was that just because you recover from an initial attack it does not mean it is over.


Healthcare

The FBI director Wray told a Boston College cybersecurity conference that his agents thwarted a planned cyberattack on a children's hospital.  The attack in question was launched by a hacktivist in 2014.  

Sophos released a report saying there is a 94% year-on-year increase in ransomware directed against healthcare organizations.  Also of note is a 100% increase (up to 61%) in payout by said organizations. And to add more numbers, just 2% of responding organizations both paid the ransom and recovered all their data.



Legislative actions 

Connecticut passed Public Act No. 22-15 which codifies consumer privacy.  The law applies to any entity that conducts business in Connecticut during the preceding year.  This also defined what is sensitive data which in turn triggers additional compliance obligations.



Comments

Popular posts from this blog

2021 Week 11 Security Roundup

2021 Weeks 32-40 Security Roundup

2021 Week 29 Security Review