2022 Week 22 Security review
Summary
Not a lot of regular news, but we had both the Verizon and Sophos annual reports came out.
News
The Verizon Data Breach Investigations Report for 2022 indicated that while the education sector continues to be a favorite target, the motivator is mostly financial (somewhat confirming the Sophos report) and Medical Data is actually the least sought after. The largest sector they indicated as a target was Professional, followed closely matched Finance, Information Technology, Manufacturing, and Public Administration.
Education
The FBI issued an alert that they have become aware of cybercriminals selling usernames and passwords from university breaches. The sales are occurring on a variety of dark websites. The biggest takeaway for me was that just because you recover from an initial attack it does not mean it is over.
Healthcare
The FBI director Wray told a Boston College cybersecurity conference that his agents thwarted a planned cyberattack on a children's hospital. The attack in question was launched by a hacktivist in 2014.
Sophos released a report saying there is a 94% year-on-year increase in ransomware directed against healthcare organizations. Also of note is a 100% increase (up to 61%) in payout by said organizations. And to add more numbers, just 2% of responding organizations both paid the ransom and recovered all their data.
Legislative actions
Connecticut passed Public Act No. 22-15 which codifies consumer privacy. The law applies to any entity that conducts business in Connecticut during the preceding year. This also defined what is sensitive data which in turn triggers additional compliance obligations.
Comments
Post a Comment