Showing posts with label network security. Show all posts
Showing posts with label network security. Show all posts

Wednesday, February 21, 2018

Vendor Cyber Risk Management

Perhaps you remember Fazio Mechanical, the unfortunate HVAC contractor that was the access point to Target for its massive 2013 data breach. Using network credentials stolen from Fazio, attackers broke into the retailer’s network in November, 2013. Data containing the names, mailing addresses, phone numbers, email addresses and payment card information for up to 70 million people was compromised.

Fazzio Mechanical was far from an anomaly. Hackers often look for vulnerabilities in vendors’ security systems as a way into a target company’s network. Supplier networks are often more vulnerable than those of the target enterprise, which may have more resources devoted to security. Home Depot and Boston Medical Center are other examples of organizations that were breached as a result of compromised third parties. Recently an Indiana hospital paid hackers to unencrypt patient records that were targeted in an attack launched through an outside vendor’s account.

Network security is increasingly as a key consideration in vendor risk assessment, and companies are starting to integrate cybersecurity into their supplier qualification criteria. A number of cybersecurity software companies offer tools to assess vendor cyber hygiene, and many do a good job of identifying security flaws and summarizing exposures through scoring systems or in easy-to-understand reports.

Read more at https://www.advisenltd.com/blog/2018/02/20/vendor-cyber-risk-management/

Dave Bradford. (2018, February 20). Vendor Cyber Risk Management [Blog].

This blog post in an excerpt of the original. The content originally appeared in Advisen Blog.

Friday, November 4, 2016

New Firm Mullen Coughlin Dedicated Entirely to Data Privacy

After nearly three years as chair of Lewis Brisbois’ data privacy and network security practice, John Mullen—and his entire team of attorneys—are leaving to start a new law firm dedicated to data privacy as addressed by the insurance industry.

“We believe we are the first law firm ever with our breath of experience totally dedicated to the cyber insurance space,” Mullen told Advisen. “Cyber insurance is critical for virtually all entities. Our lawyers possess scores of years of experience within this very focused niche. They have handled thousands of breaches.”


Chad Hemenway, New firm Mullen Coughlin dedicated entirely to data privacy (October 17, 2016), available with subscription at Advisen Cyber Front Page News.

Friday, January 29, 2016

2016 Cyber Risk Insights Conference – London

February 09, 2016
08:00 - 18:00 GMT 

155 Bishopsgate
Liverpool St - 155 Bishopsgate 
London, EC2M 3YD
UK
020 3735 4400

Advisen again brings its acclaimed Cyber Risk Insights Conference series to Europe with a full-day event in London addressing the critical privacy, network security and cyber insurance issues confronting risk professionals and their organisations. An expert faculty comprised of leaders in network security, regulation, law enforcement, risk management and cyber risk insurance will offer their insights on managing risk on a rapidly evolving and increasingly dangerous threat landscape. This day of learning and networking for risk managers, CISOs, CROs, insurance brokers, underwriters, reinsurers and other risk professionals will present a global perspective on cyber threats, but also will examine how the European business and regulatory environment influence cyber risk management decisions.


2016 Cyber Risk Insights Conference – London, Advisen Events (February 09, 2016), available with registration at www.advisenltd.com.