When Cybersecurity and IT Risk Converge

risk

The other week I had the good fortune to speak on a webinar about IT risk management, and specifically how compliance and security teams should take more of a risk-focused approach to cybersecurity, rather than a compliance-focused approach.  I’d like to unpack some of that today, because the challenges within a risk-focused approach are becoming…

Read More

Thoughts on IT Risk Management

risk

Another week, another report painting a mottled picture of corporations and their approach to IT risk and compliance. This time around we have interesting points to explore about the pandemic’s effect on IT risk, how companies are responding to that pressure, and who is or isn’t in charge of all this stuff. The report is…

Read More

A Hair-Raising Ransomware Story

ransomware

Anyone interested in a sobering example of cybersecurity risk management and disaster recovery planning gone wrong? Because we have a doozie, courtesy of Washington’s top cybersecurity preparedness agency. CISA, the Cybersecurity & Infrastructure Security Agency, released a bulletin last Friday warning corporate organizations about the threat of ransomware. The bulletin wasn’t much (two pages long)…

Read More

Zoom and FTC Enforcement to Come

Zoom

A few weeks ago the Federal Trade Commission took an enforcement action against Zoom Technologies for misleading statements Zoom made about the security of its videoconferencing services. The case wasn’t too exciting except for a dissenting statement from one of the Democratic FTC commissioners — which read like a foreshadowing of cybersecurity enforcement in the…

Read More

Another Cybersecurity Threat to Compliance

cybersecurity

Today we circle back to enterprise cybersecurity and its role in effective corporate compliance. Why? Because researchers recently discovered a vulnerability in SAP software that lets attackers infiltrate your IT systems to steal personal data, alter financial transactions, or otherwise cause all sorts of mischief that would saddle your business with huge compliance concerns. The…

Read More

On Internal Control and Mr. Potato Head

Mr. Potato Head

Here’s one way to convey the importance of software patch management: a bunch of Canadian Tire retail stores had to close last week because “a downloading error” caused all purchases to be scanned at the checkout register as Mr. Potato Head.  The Toronto Star dug up this story last week. Five Canadian Tire stores in…

Read More

A Security Threat That Evades Internal Control

cybersecurity

Well this is sobering stuff for internal auditors and SOX compliance professionals: a cybersecurity firm is raising alarms about flaws in the Oracle business software that countless companies use to manage their finances, which lets hackers steal or alter financial data — all undetectable by standard internal controls or GRC technology. Be warned, this is…

Read More

Fresh SEC Tips on Cybersecurity

cybersecurity

The Securities and Exchange Commission released fresh advice on Monday about cybersecurity risk, on everything from oversight of cybersecurity risk to nitty-gritty practices around access controls, vendor management, operational resiliency, and more. Compliance, security, and risk professionals will want to give this a read. The advice comes in the form of a 13-page bulletin published…

Read More

FTC Warns on Data Security Orders

risk

The Federal Trade Commission posted a reminder Monday of its “new and improved” data security orders, which compliance and risk professionals might want to read for its lessons about cybersecurity oversight and compliance generally.  The statement, published on the FTC Business Blog, reviews several changes the FTC made last year to its data security orders.…

Read More

Operational Resiliency, Part II

risk

Well this is convenient: one week after we had a post exploring the intersection of operational resiliency and compliance, two examples of the issue ripped from the headlines show just how much this obscure idea has real impact on compliance professionals’ lives. First, one of the Federal Reserve’s top regulators said last week that the…

Read More