Weekly #cybersecurity digest to your inbox

Subscribe for our weekly digest and get each Friday the most important cyber security news, list of upcoming free webinars and a summary of Cyberday development to your inbox.
Thanks! See you in your inbox on Fridays. :)
Unfortunately something went wrong. You can contact us at team@cyberdayai.

Encryption, RaaS, supply chain attacks: Monthly Cyberday product and news roundup 12/2023 🛡️

In December's summary, development themes include UI updates and information security statements. On the news side talk about encryption, RaaS and supply chain attacks.

article

15.12.2023

How do you benefit from ISO 27001 certification?

Why do organizations choose to go for ISO 27001 certification? In this blog article, we will give you our top 5 reasons to get certified. Certification will certainly benefit your security directly, but there are other kind of benefits available too.

article

25.10.2023

Working towards NIS2 compliance with Cyberday

✈️ You want to lift your cyber security management to a new level & get NIS2 compliant with a smart tool like Cyberday? In this post you'll learn how your organization can achieve NIS2 compliance in a smart way by building an own agile ISMS.

article

23.8.2023

Who does NIS2 apply to? Scope and required security measures explained.

In this post you'll learn about what industries are affected by NIS2, security requirements the directive sets, and the available enforcement methods if an organization is not compliant.

article

23.8.2023

What is NIS2 directive? Know EU's new cyber security legislation

Learn what is the new EU NIS2 directive, why the original NIS was not enough and how it affects your company's compliance requirements.

article

1.8.2023

SOC 2: Working towards compliance

With the help of SOC 2, organisations can provide proof of effectively implemented controls and the use of best practices to protect the data to their customers and stakeholders, which may help to build trust.

article

31.7.2023

Personnel information security training and guidelines in Cyberday

Most data breaches start with human error. Still, investments in technical information security are often made more eagerly. We tell you why staff information security training and guidelines are important and how to implement then efficiently.

article

13.6.2023

Information security risk management in Cyberday: Identifying risks, evaluation, treatment and closure

Every cyber security framework highlights risk management in its own way. We summarize in this post, what's essential in information security risk management and what kind of an approach Cyberday offers for it.

article

13.6.2023

Consumer Confidence in Data Security Plummets

Default customer trust in good #cybersecurity is being replaced by suspicion (2000 US adults surveyed): ⚡ 78% believe it’s easy for cybercriminals to breach an organization ⚡ 73% believe most organizations lack good controls over access

Go to article at
24.8.2021

Tietosuojavaltuutetun toimisto tehostaa ETA-maiden ulkopuolelle tehtävien henkilötietojen siirtojen valvontaa

As guidance is fined down, Finnish DPA is increasing control of data transfers. ⚠️ Before transferring data outside the EEA, you must be aware of the basis for the transfer and ensure an adequate level of #dataprotection is quaranteed.

Go to article at
24.8.2021

How attackers could exploit breached T-Mobile user data

T-Mobile suffered a data breach that affected about 50 million people. Danger to victims includes: ⚠️ SMS phishing (impersonating the operator) and malware ⚠️ SIM swapping attacks Read the article for protection tips #cybersecurity

Go to article at
24.8.2021

Education giant Pearson fined $1M for downplaying data breach

2018 data breach led to the compromise of 13 000 student / admin login credentials. The breach was disclosed only after media inquiries and its effects were downplated. This resulted in now decided $1M additional fine. #cybersecurity

Go to article at
19.8.2021

XSS Bug in SEOPress WordPress Plugin Allows Full Site Takeover

Cross-site scripting (XSS) vulnerability in a popular WordPress plugin allows attackers to inject arbitrary web scripts into sites, as one API endpoint was insecurely implemented. Plugin is installed on 100,000 websites. #cybersecurity

Go to article at
19.8.2021

Phishing Costs Nearly Quadrupled Over 6 Years

“Until organizations deploy a people-centric approach to cybersecurity that includes security awareness training and integrated threat protection to stop and remediate threats, phishing attacks will continue.” #cybersecurity

Go to article at
17.8.2021

65 vendors affected by severe vulnerabilities in Realtek chips

Researchers found a vulnerability on Realtek chips, informed them and Realtek promptly provided an appropriate patch. To prevent risky devices, manufacturers need to check their hardware and provide patches to their users. #cybersecurity

Go to article at
17.8.2021

Most organizations experienced at least one ransomware attack, multiple attacks very common

Worrying #ransomware statistics: ⚠️ 37% of organisations experienced a successful attack in previous 12 months ⚠️ only 13% of attacked organisations reported NOT paying the ransom 📈 avg. ransom 250k$ #cybersecurity

Go to article at
17.8.2021

How hackers can use message mirroring apps to see all your SMS texts — and bypass 2FA security

Major vendors (e.g. Microsoft) have urged users to abandon 2FA solutions that leverage one-time codes sent via SMS. 2FA w/ SMS is open to multiple attacks, like SIM swapping, request smuggling and notification mirroring. #cybersecurity

Go to article at
17.8.2021