Weekly #cybersecurity digest to your inbox

Subscribe for our weekly digest and get each Friday the most important cyber security news, list of upcoming free webinars and a summary of Cyberday development to your inbox.
Thanks! See you in your inbox on Fridays. :)
Unfortunately something went wrong. You can contact us at team@cyberdayai.

ISO 27001 and ISO 9001: Differences, how they work together and benefits of combining

Learn about the synergy between ISO 27001 and ISO 9001. Learn how integrating these standards enhances information security, quality management, and overall operational efficiency, using case examples and actionable insights.

article

6.6.2024

NIS2 Compliance: Top 5 Reasons for the Manufacturing Sector

The article highlights the critical importance for manufacturers to comply with NIS2 regulations to safeguard their operations and infrastructure from cyber threats.

article

31.5.2024

Cannes Hospital data breach, the impact of AI and NIS2 evolution: the Cyberday product and news round-up 5/2024 🛡️

May's Product and News Update presents the new monthly ISMS reports as well as the Metrics page. Other topics include Cyberday's new framework DORA and recent news around the world.

article

17.5.2024

6 ways to assess security work effectiveness

Evaluating the effectiveness of your cybersecurity involves examining the adequacy of your existing security measures. This process helps you identify your current security status and determine the necessary actions to enhance and fortify.

article

3.5.2024

System acquisition and development in NIS2: Suggested best practices

Get tips on securely acquiring and developing systems with a focus on ISO 27001, helping meet NIS2 requirements. Post explains key aspects like secure coding, acquiring secure applications and testing or publishing changes in a controlled manner.

article

16.4.2024

Continuity management in NIS2: Benchmark measures for business continuity and backups with ISO 27001

This post offers insight on complying with NIS2's continuity and backup requirements using ISO 27001's best practices. It guides you through continuity planning, backup processes, challenges, and achieving compliance effectively.

article

12.4.2024

HR security in NIS2: Best practices for compliance

Discover how the crucial role of HR in information security not only shapes the corporate security culture, but also steers the organization towards ISO 27001 and NIS2 compliance, ensuring secure handling of information assets and much more.

article

5.4.2024

Access control & MFA in NIS2: Build a solid foundation with ISO 27001 controls

What are the requirements for access control and MFA in NIS2 and ISO 27001 and how can they be implemented successfully? Learn more about the controls, requirements, best practices and how to overcome potential challenges in this blog post.

article

4.4.2024

How cybercriminals are using Microsoft Sway to launch phishing attacks

Attackers are creating phishing sites from Sway, an effective approach as links for the domain are typically trusted, says security firm Avanan. However, even if your organization doesn't use this software, you can still be vulnerable to phishing attacks that are hosted from Sway, according to Avanan. Since the pages are hosted on Microsoft's own Sway domain, the pages and their links are automatically trusted by URL filters and can easily fool users into thinking they're valid. To convince potential victims to access a malicious Sway phishing page, cybercriminals will send emails with notifications for voicemails or faxes, hoping that unsuspecting users will click on the link or image. Microsoft itself trusts the Sway and Office domains, so this URL will sneak past Safe Link settings. This type of phishing attack can succeed because it sends users to a trusted page hosted by Microsoft rather than a compromised website that would likely be blocked by web browsers and blacklists.

Go to article at
15.5.2020
Phishing

Starbucks Devs Leave API Key in GitHub Public Repo

One misstep from developers at Starbucks left exposed an API key that could be used by an attacker to access internal systems and manipulate the list of authorized users. [...]

Go to article at
15.5.2020
Cloud Storage Misconfiguration

Why Third-Party Security is Critically Important in 2020

The new year has only just begun, and many CISOs and compliance professionals are making third-party risk management a priority. Similar to how those who never received flu shots may suddenly decide to vaccinate during a particularly bad flu season, companies that never had a formal third-party security process are now focusing attention on how to create and implement one.   The post Why Third-Party Security is Critically Important in 2020 appeared first on Security Boulevard.

Go to article at
15.5.2020
Supply Chain Attacks

CEOs quit social media to keep them secure | Avast

Cyber threats now command the corporate sector’s full attention. The post CEOs quit social media to keep them secure | Avast appeared first on Security Boulevard.

Go to article at
15.5.2020
Business-Email-Compromise,CyberNow

Visa's plan against Magecart attacks: Devalue and disrupt

Beginning last summer, Visa begun throwing considerable resources at combating Magecart -- a type of attack were cybercriminals hack into an online store to plant malware that collects payment card data as users enter personal details in checkout forms. Speaking to ZDNet in a phone interview this week, Visa Senior Director of Payment Systems Intelligence David Capezza says Visa's strategy against Magecart groups is to "devalue and distrupt." Through this approach Capezza says Visa aims to devalue the data attackers can steal from online stores, and then disrupt existing operations and prevent future attacks. Visa's plan to devalue payment card data involves the rollout of new technologies like the Visa Token Service and Click To Pay systems. The Visa Token Service is a new payment mechanic through which payment card numbers and details are replaced by a token. However, as Visa and its partners on the payments market are rolling this new checkout experience to a broader audience, Visa's security team has also been spending its time disrupting existing Magecart operations as much as possible.

Go to article at
15.5.2020
Supply Chain Attacks

Understanding The Ripple Effect: Large Enterprise Data Breaches Threaten Everyone

Go to article at
15.5.2020
CyberNow

Why the Latest Marriott Breach Should Make Us "Stop and Think" About Security Behaviors

Marriott International has experienced their second data breach

Go to article at
15.5.2020
Employee Negligence

Texas bank attacked with DoppelPaymer ransomware — attackers’ report

It’s getting uglier out there.  Both Maze Team and the DoppelPaymer ransomware teams seem to be attempting to increase...

Go to article at
15.5.2020
Ransomware

Most IT leaders believe remote workers are a security risk

57 percent of UK IT decision makers still believe that remote workers are a security risk, and that they will expose their organization to the threat of a data breach, according to a survey by Apricorn. This figure has inclined steadily from 44 percent in 2018 and 50 percent in 2019. The rise could reflect a corresponding increase in the number of remote workers, or an enhanced awareness of the risks of doing so as … More → The post Most IT leaders believe remote workers are a security risk appeared first on Help Net Security.

Go to article at
15.5.2020
Employee Negligence