Policy
-
Navigating Third-Party Vendor Risks: Strategies for CISOs
With third-party vendors becoming vital to business operations, Chief Information Security Officers must assess and mitigate associated risks to safeguard sensitive data. The strategies outlined emphasize the need for comprehensive vendor evaluations and collaborative relationships.
-
New Research Unveils ChoiceJacking Threat Amid Juice Jacking Defenses
Researchers at the Graz University of Technology have uncovered a new attack method named ChoiceJacking, which exploits flaws in existing defenses against juice jacking on iOS and Android devices. This vulnerability allows malicious chargers to access sensitive data without user consent, prompting renewed warnings about the risks of public charging stations.
-
Emerging Threat: Gray Bots Reshape Digital Landscape Amid AI Surge
Gray bots, a new category of automated online programs, are significantly impacting the digital landscape by posing challenges for publishers and marketers. While these bots drive innovation for AI technologies, they also strain digital infrastructures and distort analytics, leading to increased concerns about data scraping and content theft.
-
Organizations Progress on Zero Trust Journeys, Yet Challenges Remain
A recent Gartner survey indicates that while 63% of organizations are implementing zero trust security strategies, many face significant challenges in fully realizing their potential due to cultural and operational hurdles.
-
Bridging the Gap: Addressing the Delay Between Security Detection and Remediation
As software releases accelerate, critical security measures are struggling to keep pace, with organizations taking months to resolve vulnerabilities while attackers act within days. Analysts stress the need for improved integration between security and development processes to mitigate risks effectively.
-
OECD Releases Initial Reports Under G7 Hiroshima AI Process, Enhancing Global AI Transparency
The OECD has published the first round of reports from the G7 Hiroshima AI Process Reporting Framework, enhancing global transparency into AI governance practices as organizations worldwide participate in this significant initiative.
-
Marks & Spencer Faces Payment Disruption Following Cyber Incident
Marks & Spencer is facing disruptions in contactless payments due to a cyber incident, with delays to Click & Collect orders and home deliveries. The retailer assures customers it is taking measures to resolve the situation while expressing gratitude for their understanding.
-
Rising Cyber Threats in the Energy Sector: A Closer Look
Rising cyber threats in the energy sector present significant risks to national infrastructure, as highlighted by Darktrace research. The sector confronts a combination of state-sponsored attacks, cybercriminal activity, and insider threats, with email remaining the primary attack vector. Additionally, the adoption of AI in energy poses new challenges, alongside ongoing concerns over reliance on a…
-
Shifting Data Governance Landscape as Geopolitical Turmoil Intensifies
Amid growing geopolitical tensions, the landscape of international data governance is undergoing significant changes, with the U.S. embracing data localization, and the EU pushing for revised regulations, raising concerns over the future of cross-border data transfers.
-
Marks & Spencer Demonstrates Effective Crisis Communication Amid Cyber Incident
Marks & Spencer has received significant praise for its transparent communication in response to a recent cyber incident that led to service disruptions. The retailer’s approach emphasized honesty and accountability, setting a standard for corporate crisis management.










