Intelligent CISO Issue 35 | Page 24

threat updates
1
3
4

1

CANADA
Canadian aeroplane manufacturer , Bombardier , has announced that it recently suffered a limited cybersecurity breach . An initial investigation revealed that an unauthorised party accessed and extracted data by exploiting a vulnerability affecting a thirdparty file-transfer application , which was running on purposebuilt servers isolated from the main Bombardier IT network . In accordance with established cybersecurity procedures and policies , Bombardier promptly initiated its response protocol upon detection of the data security incident . As part of its investigation , Bombardier sought the services of cybersecurity and forensic professionals who provided external confirmation that the company ’ s security controls were effective in limiting the scope and extent of the incident .

2

AUSTRALIA
Australia ’ s securities regulator has confirmed a cybersecurity breach at a server it used to transfer files including credit licence applications . The Australian Securities and Investment Commission ( ASIC ) said it became aware of the incident although it does not appear the information was downloaded . The regulator said : “ While the investigation is ongoing , it appears that there is some risk that some limited information may have been viewed by the threat actor .” Javvad Malik , Security Awareness Advocate at KnowBe4 , said : “ The breach is a good reminder that all organisations need to have good monitoring and threat detection controls in place .”
24 www . intelligentciso . com