cybersecurity

Why Cyber Insurers Should Partner in Cybersecurity Support

Cyber insurers should partner in cybersecurity as threats grow. Insurers can enhance business resilience by offering proactive services like risk assessments, training, penetration testing, and incident response. This shift supports brokers as trusted advisors, strengthens policyholder security, and leads to fewer claims and improved underwriting models, emphasizing prevention over reaction.

https://www.insurancejournal.com/magazines/mag-features/2025/03/10/814547.htm

18 Cybersecurity Tools That May Cause a False Sense Of Security

18 cybersecurity tools create a false sense of security; adding more doesn't always enhance protection and can introduce complexities or vulnerabilities. Reliance on standard measures like traditional antivirus, SMS-based 2FA, and certifications can obscure real threats. Proper security requires holistic approaches, employee education, and continuous monitoring, not just tool accumulation.

https://www.forbes.com/councils/forbestechcouncil/2025/03/07/18-cybersecurity-tools-that-may-cause-a-false-sense-of-security/

NIST Releases Draft Cybersecurity White Paper on Crypto Agility, Aims to Shape Future Cybersecurity Strategies

NIST released a draft cybersecurity white paper on crypto agility, analyzing strategies and challenges for adapting cryptographic algorithms. The paper highlights the need for operational mechanisms to ensure security and interoperability during algorithm transitions, especially in light of threats from future quantum computing. NIST seeks stakeholder input to develop sector-specific strategies and emphasizes collaboration among experts to enhance cryptographic resilience.

https://industrialcyber.co/nist/nist-releases-draft-cybersecurity-white-paper-on-crypto-agility-aims-to-shape-future-cybersecurity-strategies/

ENISA’s NIS360 Report Guides NIS2 Directive Implementation, Maps Sectoral Maturity, Flags Cybersecurity Challenges 

ENISA's NIS360 report aids NIS2 Directive implementation, assessing cybersecurity maturity across sectors and highlighting challenges. It offers detailed analysis, identifies sector strengths and weaknesses, and recommends improvements to enhance resilience. The report underscores the importance of collaboration, tailored guidance, and cross-border alignment while pointing out risks in six sectors. Key sectors like electricity, telecoms, and banking display higher maturity levels, while others like public administration and health need significant improvements. Recommendations focus on upskilling, targeted guidelines, and sector-specific incident response planning. Future efforts will continue to refine strategies for improved cybersecurity compliance.

https://industrialcyber.co/reports/enisas-nis360-report-guides-nis2-directive-implementation-maps-sectoral-maturity-flags-cybersecurity-challenges/

Cyberattacks Targeting IT Vendors Intensify, Causing Bigger Losses

Cyberattacks on IT vendors are escalating, resulting in significant financial losses, according to a Resilience report. In 2024, 23% of cyber insurance claims involved third-party breaches, causing operational disruptions and high costs, exemplified by UnitedHealth's $3.1 billion ransomware attack. Ransomware is still the leading cause of cyber claims, but attackers are shifting focus to larger targets for bigger payouts.

https://www.ciodive.com/news/vendor-driven-cyberattacks-losses/741686/

Identity: The New Cybersecurity Battleground

TLDR: Identity is now the primary target for cyberattacks due to the fragmented nature of tech stacks and the rise in cloud services. Centralizing Identity can enhance visibility, automate threat response, and improve security integration across systems. Organizations must adopt an Identity-first security strategy to mitigate risks and streamline operations.

https://thehackernews.com/2025/03/identity-new-cybersecurity-battleground.html

ENISA NIS360 2024 Report: a Comprehensive Look at Cybersecurity Maturity and Criticality of NIS2 Sectors

ENISA's NIS360 2024 report assesses the cybersecurity maturity and criticality of NIS2 sectors in the EU, identifying improvement areas. Key findings highlight that electricity, telecoms, and banking are the most mature and critical, while digital infrastructures lag. Recommendations stress enhanced sector collaboration, development of specific guidance for NIS2 implementation, and cross-border cooperation. Other sectors like ICT, space, and health face unique challenges requiring tailored guidance and awareness to improve resilience. The report aims to inform national authorities and policymakers for effective strategy development.

https://www.enisa.europa.eu/news/enisa-nis360-2024-report

CISO Liability Risks Spur Policy Changes at 93% of Organizations

93% of organizations updated policies to address CISO liability risks due to regulatory shifts, including increased board involvement and enhanced legal support. Key incidents like the Uber CISO conviction prompted this change. However, a lack of clarity over accountability for cybersecurity incidents persists, with only 36% of firms clearly defining roles.

https://www.infosecurity-magazine.com/news/ciso-liability-risks-policy-changes/

Zero Trust Network Access (ZTNA)

ZTNA: Security model ensuring access control based on user identity. No trust by default; verifies each request regardless of location. Enforces least privilege, enhances endpoint security, and mitigates risks from breaches.

BlackLine CISO Jill Knesek on Building Security Teams

Jill Knesek, BlackLine's CISO, discusses her experience in cyber threat mitigation and building security teams. She emphasizes a structured cybersecurity team with governance, risk, compliance, application security, and operations units. Knesek prioritizes soft skills and cultural fit in hires, alongside technical training. Effective communication with executives using risk management language and transparency builds trust. She identifies ransomware as a top threat, advocating strong security practices and employee training. Knesek acknowledges the potential of AI in enhancing security while remaining cautious of its risks. Her key advice is to focus on fundamental security hygiene to address the majority of attack vectors.

https://www.infosecurity-magazine.com/interviews/blackline-ciso-jill-knesek/

Scroll to Top