Intelligent CISO Issue 73 | Page 24

threat

UPDATES
1
US
2
UK
A hacking group with links to the Russian Government is now suspected of being responsible for a cyberattack that caused a tank at a Texas water facility to overflow in January . Debrup Ghosh , Senior Manager at the Synopsys Software Integrity Group , said : “ The current attacks targeting water and wastewater systems should serve as a stark reminder that our critical infrastructure comprises cyber-physical systems that can be targeted and exploited by hackers .
Flooring retailer Carpetright has been hit by a cyberattack , impacting its systems and customer base .
Dominic Trott , Director of Strategy & Alliances at Orange Cyberdefense UK , said : “ Carpetright is the latest retailer to be hit by an attack , but the firm appears to have dealt with the issue quickly and thoroughly by taking all systems offline . While this led to shortterm disruption for customers and staff it ultimately meant that no data was accessed by cybercriminals .
“ This drives home the point that organisations of all types , including public utilities , are essentially software companies – and as such , they need to take cybersecurity hygiene and software supply chain security seriously .
“ At a minimum , critical infrastructure organisations need to adopt basic software security best practices like automated security testing , periodic penetration testing , and vulnerability management to avoid becoming low-hanging fruit for attackers . More specifically , these organisations should have constant visibility into their software supply chain so they can respond quickly to vulnerabilities and threats and prevent disruptions or breaches .”
“ It indicates a mature approach towards managing enterprise risk , calculating that the short time while systems were taken offline was a lower risk than keeping those systems available but then potentially allowing threat actors to spread across the organisation and exfiltrate valuable and sensitive resources .”
A cyberattack underway at the Centre Hospitalier de Cannes – Simone Veil ( CHC-SV ) – Hôpital de Cannes Hôpital de Cannes ( ch-cannes . fr )
2
3
4
1
24
WWW . INTELLIGENTCISO . COM