CIO Brief: From Alert Counts to Exposure Management
The short version: Security teams are drowning in alerts and vulnerability lists. In 2024, Microsoft and other vendors pushed a different approach:...
Insights
Articles in CIO Briefings.
The short version: Security teams are drowning in alerts and vulnerability lists. In 2024, Microsoft and other vendors pushed a different approach:...
The short version: Every AWS account has a "root" login with unlimited power. Companies with many AWS accounts had many of these super-passwords to protect....
The short version: Since October 2024, Microsoft requires multi-factor authentication for anyone managing Azure through its web portals, and from 2025 also...
The short version: In September 2024, Microsoft expanded Copilot with new features — and new tools to fix the "oversharing" problem that stalled many...
The short version: In 2024, attackers scanned the internet for websites accidentally publishing their configuration files — which contained cloud passwords...
The short version: On July 19, 2024, a faulty update to CrowdStrike's security software crashed about 8.5 million Windows computers worldwide. Airlines,...
The short version: In 2024, attackers stole data from about 165 companies' accounts on Snowflake, a cloud data platform — including Ticketmaster and AT&T....
The short version: Since 2024, Microsoft lets employees use passkeys on their phones to sign in — the strongest common form of authentication, and immune to...
The short version: In April 2024, a US government review board concluded that a Chinese hack of Microsoft's email systems "should never have happened" and...
The short version: In 2024, a hidden backdoor was discovered in XZ Utils, a small but widely used piece of free software in Linux systems. Someone had spent...
The short version: In February 2024, ransomware shut down Change Healthcare, disrupting pharmacies and medical billing across the US for weeks. The...
The short version: In January 2024, Russian state hackers read email of Microsoft's senior leaders. They got in through an old test account that didn't...
The short version: In November 2023, Microsoft announced a major security push — the Secure Future Initiative — and began automatically adding security...
The short version: Microsoft 365 Copilot, available since late 2023, can find and summarize anything an employee has access to — instantly. In most...
The short version: In 2023, attackers broke into Okta's customer support system and stole login sessions from files customers had uploaded for...
The short version: In 2023, Microsoft's own AI researchers accidentally exposed 38 terabytes of internal data — including passwords and private messages —...
The short version: In 2023, a phone call to MGM's IT help desk reportedly led to a ransomware attack that shut down casinos and hotels for days and cost...
The short version: In 2023, Russian state hackers used Microsoft Teams chat — not email — to trick people into approving login requests. Companies have...
The short version: In 2023, Chinese hackers read US government email by forging digital keys in Microsoft's systems. A government agency caught it — because...
The short version: In 2023, Microsoft renamed Azure Active Directory to Microsoft Entra ID. Nothing about security changed with the name. But renames are a...
The short version: In 2023, a ransomware gang exploited a flaw in MOVEit, a file transfer product, stealing data from over 2,000 organizations — many of...
The short version: In April 2023, AWS changed the defaults so new cloud storage buckets are private and simpler to secure. That's a big improvement — but it...
The short version: In 2023, Microsoft launched Security Copilot, an AI assistant for security teams. Many vendors followed. AI can make security analysts...
The short version: Since January 2023, AWS automatically encrypts all new files stored in S3. That's good — but encryption by default doesn't stop someone...