ISO 31000 certified TechR2 will check your organization’s systems against either the NIST or ISO standard to discover your network vulnerabilities

In this case with FirstEnergy of Ohio in the last week, it is reported that they disabled 6 million user accounts and will have all their active users reactivate them with new passwords. As perpetrators tap into easy to login accounts that do not block repeated attempts before lockout, they eventually will get access using a computerized attack. SMEs commented on businesses that do not follow industry cybersecurity rules to login to what is supposed to be customer protected information. All businesses should be using Multifactor Authentication, device recognition and geo location analysis before granting any access. In many business systems including colleges and universities, they retain inactive accounts. And these accounts that are poorly protected have lots of information for the data thieves. Again, SMEs state that companies that retain PPI and PFI are big targets. FirstEnergy should be NERC cybersecurity compliant as a utility, but maybe the NERC CIP standard is not as robust as NIST or ISO’s user account CSF requirements. Therefore, to help in Ohio and in the US, business owners and Board Members need to examine their customer online portal website today. Do you have MFA? Do you recognize the user device? Do you check for geographical location? If you can repeatedly attempt account login without lockout, this needs to be fixed immediately. In essence, many businesses need to fix their customer portals like FirstEnergy this week.
Related article: FirstEnergy hack is cyber-thieves’ latest effort to swipe personal info – cleveland.com

ISO 31000 certified TechR2 will check your organization’s systems against either the NIST or ISO standard to discover your network vulnerabilities

Tags

What do you think?

Related articles

Datacenters are a cybersecurity target

I’m a recovering intelligence officer. I’m always a recovering intelligence officer for one trauma or another. And I’ve had the benefit, the pleasure, the honor to apply a lot of those skills I use in defense of our nation in the commercial section and in the commercial world as well, rising all the way to chief operating officer of a company that I thought was pretty obscure.

Read more

Loss of data hurts everyone

Whether I’m a nation state targeting data, whether I’m a criminal enterprise targeting data, or a transnational organization targeting that, that data is valuable. And while it’s valuable to me, there is a negative externality to the people that I’m taking it from as well. It’s not a victimless crime, right?

Read more

Datacenters are the obvious target

Anybody ever watch storage wars?
You can go on the dark web and buy drives like you were buying a storage unit. “I’ll give you a thousand dollars for that storage unit”. I know there’s got to be a couple thousand bucks worth of stuff in it. Your data out there is the same way.

Read more
Contact us

Why risk it alone?
Get started today.

We’re happy to answer any questions you may have and help you determine which of our services best fit your needs.
Your benefits:
What happens next?
1

Schedule a call at your convenience

2

We do a discovery and consulting meeting 

3

We prepare a proposal 

Schedule a Free Consultation