Weekly #cybersecurity digest to your inbox

Subscribe for our weekly digest and get each Friday the most important cyber security news, list of upcoming free webinars and a summary of Cyberday development to your inbox.
Thanks! See you in your inbox on Fridays. :)
Unfortunately something went wrong. You can contact us at team@cyberdayai.

Framework recap, US security & and role management: Cyberday product and news summary 3/2025 🛡️

The March product and news update presents updates to role management and the new Trust Center, a review of the key frameworks for 2025 and US security.

article

28.3.2025

Understanding DORA compliance: Key steps to prepare your organization

Understand DORA compliance and get a clear DORA requirements summary with key compliance areas, practical steps, and essential guidelines to strengthen your organization's digital resilience.

article

18.3.2025

ISMS implementation: comparison of documents, wikis, ISMS tools and GRC

There are a few different approaches to building an ISMS. In this post, we’ll compare these different methods, helping you understand which might be the best fit for your organization’s security management needs.

article

6.3.2025

What is Statement of Applicability (SoA) in ISO 27001?

In this blog, we'll cover the main purpose and benefits of a well-working Statement of Applicability document. We'll also explain why SoA is important, and 4 key roles it can play in information security work.

article

4.3.2025

Why is ISO 27001 compliance now more important than ever?

Year after year, ISO 27001 standard has remained one of the gold standards for information security. The global standard has remained relevant, but where did ISO 27001 originate? And why is it's popularity just going up?

article

27.2.2025

10 most common non-conformities in ISO 27001 audits

Audits and non-conformities drive organizations toward continuous improvement. But before your first ISO 27001 certification, it's good to be aware of some most common non-conformities, so you can avoid these in your certification audit.

article

18.2.2025

Got an ISO 27001 audit interview request - what should I expect?

In this blog, we will talk about the importance of employee participation in the audit interview process, why auditors value employee insights, and look into possible questions asked in an ISO 27001 interview.

article

13.2.2025

ISO 27001 compliance and certification checklist

Looking to ensure you fill ISO 27001 requirements? This checklist will present clearly ordered key steps that guide your organization in building an ISMS and getting compliant with the ISO 27001 standard.

article

6.2.2025

Ransomware Costs in 2019

2019 has seen ransomware costs higher than they ever have been and are expected to increase in 2020. It needs to become an unprofitable business to stop the attacks from hackers.

Go to article at
15.5.2020
Ransomware

Banner Health agrees to $6 million settlement over 2016 breach

Jessica Kim Cohen reports an update on a 2016 breach covered on this site: Banner Health has agreed to pay up to $6 million...

Go to article at
15.5.2020
Illegal Personal Data Processing

Prison inmates’ sensitive data left exposed on leaky cloud bucket

A completely-avoidable data leak has exposed prescription records, mugshots, and other sensitive information related to an unknown number of prison inmates.

Go to article at
15.5.2020
Cloud Storage Misconfiguration

Dangerous Domain Corp.com Goes Up for Sale

As an early domain name investor, Mike O'Connor had by 1994 snatched up several choice online destinations, including bar.com, cafes.com, grill.com, place.com, pub.com and television.com. Some he sold over the years, but for the past 26 years O'Connor refused to auction perhaps the most sensitive domain in his stable -- corp.com. It is sensitive because years of testing shows whoever wields it would have access to an unending stream of passwords, email and other proprietary data belonging to hundreds of thousands of systems at major companies around the globe.

Go to article at
15.5.2020
Password Attacks

Quanta Storage adopts SecureCircle’s DASB to eliminate insider threats

SecureCircle, the world’s first Data Access Security Broker (DASB), announced an agreement to eliminate insider threats such as accidental sharing and malicious users with Quanta Storage (QSI). QSI, a worldwide leader in OEM and ODM services to the world’s leading consumer electronics brands and based in Taoyuan City, Taiwan, is adopting SecureCircle’s DASB to eliminate insider threats. SecureCircle’s data-centric access control persistently protects customer data without impacting applications, workflow, or end-user experience. “SecureCircle was selected … More → The post Quanta Storage adopts SecureCircle’s DASB to eliminate insider threats appeared first on Help Net Security.

Go to article at
15.5.2020
Insider Attacks

Uncovering the Abilities of MedusaLocker Ransomware

The MedusaLocker ransomware was first observed in the wild towards the end of September 2019.

Go to article at
15.5.2020
Ransomware

Ransomware: The average ransom payment doubled in just three months

A new report into the state of ransomware at the tail end of 2019 has revealed that things aren’t getting any better. In Q4 of 2019, according to the new study published by security firm Coveware, the average ransom payment more than doubled – reaching $84,116, up from $41,198 in Q3 of 2019. Coveware’s report […]… Read More The post Ransomware: The average ransom payment doubled in just three months appeared first on The State of Security. The post Ransomware: The average ransom payment doubled in just three months appeared first on Security Boulevard.

Go to article at
15.5.2020
Ransomware

How to Secure a Home WiFi Network for Remote Work

Take these six concrete steps to ensure that your home WiFi network and asociated hardware is secure and properly configured for remote work. The post How to Secure a Home WiFi Network for Remote Work appeared first on JumpCloud. The post How to Secure a Home WiFi Network for Remote Work appeared first on Security Boulevard.

Go to article at
15.5.2020
Employee Negligence

TrickBot Now Steals Windows Active Directory Credentials

A new module for the TrickBot trojan has been discovered that targets the Active Directory database stored on compromised Windows domain controllers. [...]

Go to article at
15.5.2020
Malware