Weekly #cybersecurity digest to your inbox

Subscribe for our weekly digest and get each Friday the most important cyber security news, list of upcoming free webinars and a summary of Cyberday development to your inbox.
Thanks! See you in your inbox on Fridays. :)
Unfortunately something went wrong. You can contact us at team@cyberdayai.

Most important documents in ISO 27001 certification audit

The ISO 27001 standard does specifically define some key documents, which need to be gathered together and be easily shareable e.g. for the auditor. In this blog, we'll present these most important documents for an ISO 27001 certification audit.

article

30.1.2025

NIS2 & national implementation: which local NIS2 laws are available in Cyberday?

EU Member States are required to adopt NIS2 into national law. Key national decisions include defining local authorities, monitoring mechanisms, and tailoring regulations to meet specific needs.

article

23.1.2025

ISO 27001 certification: What happens in the certification audit?

This blog post gives an overall intro to information security auditing and a detailed go-through of the ISO 27001 certification audit process.

article

22.1.2025

What is ISO 27001? Intro to the global information security gold standard.

Whether you're new to ISO 27001 or looking to strengthen your current practices, this post will walk you through its essentials, why it matters, and how it can improve your approach to information security.

article

22.1.2025

Password Security: Avoid these 5 common mistakes

Password security is something that no one should underestimate in the face of today's threats. One sensible option for secure password management is to use software designed for this purpose.

article

16.1.2025

Framework recap, role of the CISO & and vendor assessments: Cyberday product and news round-up 12/2024 🛡️

December's product and news round-up will showcase the vendor security assessments and new enterprise-level features, an overview of the key frameworks for 2025 and the roles of the CISO and personnel in an organisation's security.

article

19.12.2024

Europe's Compliance Revolution: Evolving Cyber Sec Consulting

The evolving cyber sec landscape and growing demand for compliance in combination with a shortage of professionals calls for new ways of working. With the help of partnerships and agile tools, consultants can benefit from the current situation.

article

18.12.2024

TISAX: Understanding the Automotive framework

By embracing TISAX, automotive industry operators can improve information security, enhance compliance and strengthen their market position. Read more about TISAX, its scope, requirements and how ISO 27001 fits in.

article

3.12.2024

7 new social engineering tactics threat actors are using now

Social engineering is nothing new, but cyber criminals constantly develop new methods to watch out for, e.g.: 🌐 Typosquatting or lookalike domains 🎙️ Deepfake recordings 🔗 Malicious QR codes #cybersecurity

Go to article at
14.4.2021

This Android malware hides as a System Update app to spy on you

A new, "sophisticated" spyware disguises itself as a System Update app and has complex capabilities otherwise too. This app was luckily still on a third-party repository (not official Play Store), but good to stay aware. #cybersecurity

Go to article at
30.3.2021

FatFace sends controversial data breach email after ransomware attack

Clothing brand experienced a #ransomware attack, which resulted in the attackers being paid 2M$. A big uproar was caused by an odd breach notification message to data subjects, asking to "keep the message confidential". #cybersecurity

Go to article at
30.3.2021

Fleeceware apps earned over $400 million on Android and iOS

Fleeceware = Apps w/ free trial (and no special functionality), after which they overcharge for subscriptions - even if the app is deleted. Research found 204 apps, w/ > 1 billion downloads & $400 million in revenue. #cybersecurity

Go to article at
30.3.2021

CompuCom MSP expects over $20M in losses after ransomware attack

Costs of CompuCom #ransomware attack: Downtime for customers: -5M $ System recovery and "repair": -10M $ Cyber insurance is expected to "possibly cover a portion". #cybersecurity

Go to article at
30.3.2021

Manufacturing Firms Learn Cybersecurity the Hard Way

🏭 Manufacturing firms have become a top target of cybercriminals. 61% of smart factories have had a cybersecurity incident, 3/4 of those taking production offline. Lacking collab between IT and OT seen as problem. #cybersecurity

Go to article at
30.3.2021

Ongoing Office 365-themed phishing campaign targets executives, assistants, financial departments

MS 365 -themed phishing is constantly active. Initially an access to any email account of an employee / partner is pursued. Sensitive info in this account is then utilized to create more credible “lures” to swin upstream. #cybersecurity

Go to article at
23.3.2021

Only 14% of domains worldwide truly protected from spoofing with DMARC enforcement

DMARC is a vendor-neutral authentication protocol that allows email domain owners to protect their domain from unauthorized use, or "spoofing". Without DMARC enforcement spoofing is 4.75x more likely. #cybersecurity

Go to article at
23.3.2021

Finding the Cracks in the Wall – How Modern Scams Bypass MFA

MFA is an efficient speed bump, but not a force field. Ways to bypass MFA: ⚠️ Stealing one-time passwords ⚠️ SIM Swapping ⚠️ Bypassing MFA process (e.g. though utilizing legacy auth APIs that are still allowed) #cybersecurity

Go to article at
23.3.2021