Weekly #cybersecurity digest to your inbox

Subscribe for our weekly digest and get each Friday the most important cyber security news, list of upcoming free webinars and a summary of Cyberday development to your inbox.
Thanks! See you in your inbox on Fridays. :)
Unfortunately something went wrong. You can contact us at team@cyberdayai.

Most important documents in ISO 27001 certification audit

The ISO 27001 standard does specifically define some key documents, which need to be gathered together and be easily shareable e.g. for the auditor. In this blog, we'll present these most important documents for an ISO 27001 certification audit.

article

30.1.2025

NIS2 & national implementation: which local NIS2 laws are available in Cyberday?

EU Member States are required to adopt NIS2 into national law. Key national decisions include defining local authorities, monitoring mechanisms, and tailoring regulations to meet specific needs.

article

23.1.2025

ISO 27001 certification: What happens in the certification audit?

This blog post gives an overall intro to information security auditing and a detailed go-through of the ISO 27001 certification audit process.

article

22.1.2025

What is ISO 27001? Intro to the global information security gold standard.

Whether you're new to ISO 27001 or looking to strengthen your current practices, this post will walk you through its essentials, why it matters, and how it can improve your approach to information security.

article

22.1.2025

Password Security: Avoid these 5 common mistakes

Password security is something that no one should underestimate in the face of today's threats. One sensible option for secure password management is to use software designed for this purpose.

article

16.1.2025

Framework recap, role of the CISO & and vendor assessments: Cyberday product and news round-up 12/2024 🛡️

December's product and news round-up will showcase the vendor security assessments and new enterprise-level features, an overview of the key frameworks for 2025 and the roles of the CISO and personnel in an organisation's security.

article

19.12.2024

Europe's Compliance Revolution: Evolving Cyber Sec Consulting

The evolving cyber sec landscape and growing demand for compliance in combination with a shortage of professionals calls for new ways of working. With the help of partnerships and agile tools, consultants can benefit from the current situation.

article

18.12.2024

TISAX: Understanding the Automotive framework

By embracing TISAX, automotive industry operators can improve information security, enhance compliance and strengthen their market position. Read more about TISAX, its scope, requirements and how ISO 27001 fits in.

article

3.12.2024

Security fatigue is real: Here’s how to overcome it

IT security is seen as “Department of No”. As #cybercrime economy grows fast, they want to limit the damage employees can cause. But going too far can lead to security fatigue, resulting in reckless and impulsive behavior. Read more >>

Go to article at
25.11.2022

100 people arrested in UK’s biggest fraud investigation

Over 200k victims were targeted via the iSpoof fraud website, which was taken down by Scotland Yard’s #cybercrime unit. 100 people arrested. Almost 20 people every minute were being contacted by scammers - stealing reported £50m.

Go to article at
25.11.2022

Bahamut cybermercenary group targets Android users with fake VPN apps

Active #malware campaign ongoing disquising as legitimate SecureVPN app. Main purpose of the app modifications is to extract sensitive user data and actively spy on victims’ messaging apps. Read a detailed analysis >>

Go to article at
25.11.2022

Ouch! Ransomware gang says it won’t attack AirAsia again due to the “chaotic organisation” and sloppy security of hacked airline’s network

⚠️ #Ransomware breach can also lead to gross public humiliation. Daixin gang said Air Asia, who lost data of 5M passengers and all employees, had so chaotic and poorly-secured IT infra that it refuses to repeat the attack.

Go to article at
25.11.2022

ICS cyberthreats in 2023 – what to expect

2023 #cybersecurity trends: More attacks on "real economy" - food 🌾 transport 🚢 energy ⚡ medical 💊 Rising number of political hacktivists 🦹 Ransomware towards critical infra 🏭 Rise of embedded phishing pages on legitimate sites 🎣

Go to article at
25.11.2022

Token tactics: How to prevent, detect, and respond to cloud token theft

⚠️ When we increase MFA coverage, threat actors need more sophisticated techniques to compromise resources. Recently there's been a significant increase in token theft. Read Microsoft's DART team's report on the #cybersecurity threat >>

Go to article at
18.11.2022

Google to Pay $391 Million Privacy Fine for Secretly Tracking Users' Location

391M$ fine: Google's #privacy actions deemed deceptive. ⚠️ "misled users to think they turned off location tracking, but continued to collecting data" Location is combined with behavioral data to create user profiles eg for ad targeting.

Go to article at
18.11.2022

Instagram Impersonators Target Thousands, Slipping by Microsoft's Cybersecurity

⚠️ #Phishing attack targets 22k students in the US with a "unusual login on Instagram" scam. To note: attack used a valid 41-month old domain with a good reputation, and was able to pass e.g. MS 365 and Exchange email protections.

Go to article at
18.11.2022

It’s time. Delete your Twitter DMs

Twitter is in quite a chaos. Security people are advising to e.g. delete DMs 💬 and stop using Twitter SSO 🔐. Recently quitted Twitter employees include: - CISO - Head of Trust & Safety - CPO (privacy) - CCO (compliance) #cybersecurity

Go to article at
18.11.2022