CIO Brief: Third-Party Cloud Risk — Writing Security Into Vendor Contracts
The short version: In 2017, a Verizon vendor exposed customer records — including account PINs used for phone support — in a cloud storage folder anyone...
Insights
Articles in CIO Briefings.
The short version: In 2017, a Verizon vendor exposed customer records — including account PINs used for phone support — in a cloud storage folder anyone...
The short version: Microsoft 365 E3 includes solid security basics. E5 adds advanced threat protection, risk-based identity controls and stronger compliance...
The short version: NotPetya, in 2017, entered companies through a trusted software update and then spread using administrator passwords stolen from one...
The short version: In 2017, a data company working for the Republican National Committee left personal details on 198 million voters in an unprotected cloud...
The short version: In 2017, WannaCry ransomware infected hundreds of thousands of computers worldwide using a Windows flaw that had been patched two months...
The short version: In 2017, a bug at Cloudflare, a major internet provider, leaked private data from customer websites, including login sessions. The...
The short version: In 2017, a mistyped command at Amazon took down a core storage service in one region for about four hours, and thousands of websites went...
The short version: Every AWS customer gets Shield Standard free, and it handles the most common DDoS attacks. Shield Advanced is a paid upgrade that adds...
The short version: When a big company like Yahoo loses billions of passwords, your company is also at risk. Your employees reuse passwords, and attackers...
The short version: In October 2016, an attack on one DNS company, Dyn, made major websites unreachable for hours. The websites were fine. A supplier they...