Weekly #cybersecurity digest to your inbox

Subscribe for our weekly digest and get each Friday the most important cyber security news, list of upcoming free webinars and a summary of Cyberday development to your inbox.
Thanks! See you in your inbox on Fridays. :)
Unfortunately something went wrong. You can contact us at team@cyberdayai.

Framework recap, US security & and role management: Cyberday product and news summary 3/2025 🛡️

The March product and news update presents updates to role management and the new Trust Center, a review of the key frameworks for 2025 and US security.

article

28.3.2025

Understanding DORA compliance: Key steps to prepare your organization

Understand DORA compliance and get a clear DORA requirements summary with key compliance areas, practical steps, and essential guidelines to strengthen your organization's digital resilience.

article

18.3.2025

ISMS implementation: comparison of documents, wikis, ISMS tools and GRC

There are a few different approaches to building an ISMS. In this post, we’ll compare these different methods, helping you understand which might be the best fit for your organization’s security management needs.

article

6.3.2025

What is Statement of Applicability (SoA) in ISO 27001?

In this blog, we'll cover the main purpose and benefits of a well-working Statement of Applicability document. We'll also explain why SoA is important, and 4 key roles it can play in information security work.

article

4.3.2025

Why is ISO 27001 compliance now more important than ever?

Year after year, ISO 27001 standard has remained one of the gold standards for information security. The global standard has remained relevant, but where did ISO 27001 originate? And why is it's popularity just going up?

article

27.2.2025

10 most common non-conformities in ISO 27001 audits

Audits and non-conformities drive organizations toward continuous improvement. But before your first ISO 27001 certification, it's good to be aware of some most common non-conformities, so you can avoid these in your certification audit.

article

18.2.2025

Got an ISO 27001 audit interview request - what should I expect?

In this blog, we will talk about the importance of employee participation in the audit interview process, why auditors value employee insights, and look into possible questions asked in an ISO 27001 interview.

article

13.2.2025

ISO 27001 compliance and certification checklist

Looking to ensure you fill ISO 27001 requirements? This checklist will present clearly ordered key steps that guide your organization in building an ISMS and getting compliant with the ISO 27001 standard.

article

6.2.2025

Päivitä heti: VMware varoittaa kriittisestä haavoittuvuudesta

VMware prompts vCenter users to patch vCenter Server versions 6.5, 6.7, and 7.0 immediately. Upon gaining access to port 443, an attacker may choose to run any code of his choice on the host. #cybersecurity

Go to article at
28.5.2021

Should Paying Hacker Ransoms Be Illegal?

#Ransomware gangs make money. Colonial Pipeline just paid 4,5 M$ ransom - small part of one group's earnings. No-one wants payments for crooks, but ban has its difficulties too, especially if organisation is poorly prepared. #cybersecurity

Go to article at
21.5.2021

Cobalt Strike Becomes a Preferred Hacking Tool by Cybercrime, APT Groups

Data from Sophos shows that Cobalt Strike, a threat emulation software, is one of the top tools used in cyber attacks. Cyber criminals use it to e.g. drop malware and employ PowerShell commands to camouflage their activity. #cybersecurity

Go to article at
21.5.2021

The basics of security code review

Article gives ideas for improving code security: ✅ determine common vulnerabilities for the type of app you’re working with ✅ dedicate enough time for reviewing code / fixing bugs ✅ use automated SCA & SAST tools #cybersecurity

Go to article at
19.5.2021

Student’s Negligence Opened Door for Ryuk into Biomolecular Facility

Lots of work and week of biomolecular research data went to waste due to student's #cybersecurity negligence: 🛑 bypassing malware protection ⚠️ searching for a free software version ⚠️ using personal device on work network

Go to article at
19.5.2021

Why Password Hygiene Needs a Reboot

All it takes is one compromised credential to cause a data breach. To combat this, the revised NIST recommendations suggest that you e.g.: ✅ Adapt credential screening solutions 🛑 Don't require periodic password resets #cybersecurity

Go to article at
19.5.2021

Insurer AXA hit by ransomware after dropping support for ransom payments

Week ago insurer AXA announced, that it would be dropping reinbursement for #ransomware payment. Now they are hit by ransomware gang. Breach includes e.g. customers health data 🧪, copies of ID cards 💳 and claim forms 📃. #cybersecurity

Go to article at
19.5.2021

Colonial Pipeline Shells Out $5M in Extortion Payout, Report

Colonial Pipeline paid a ransom of 5 M$ for Eastern-European cyber criminals. This enabled the company to begin restarting the largest refined fuel line in the US, which by itself will anyway take several days. #cybersecurity

Go to article at
14.5.2021

A Closer Look at the DarkSide Ransomware Gang

FBI confirmed, that a relatively new #ransomware group DarkSide was responsible of the cyber attack causing Colonial Pipeline to shut down almost 9000 km of fuel pipe. This article provides a review to group's activity. #cybersecurity

Go to article at
12.5.2021