For years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape where defenders had considerably more time to establish the facts and decide what to do next. In 2019, the average data breach took 206 days to identify and another 73 days to contain, creating a total breach lifecycle of 279 days.
As the time between initial access and attacker movement continues to contract, security teams are being asked to operate within a much narrower window. AI is accelerating reconnaissance, vulnerability discovery, and campaign execution, while defenders are responsible for growing volumes of data across cloud, identity, endpoint, SaaS, and AI environments, often without equivalent growth in analyst capacity.
Read more…
Source: Rapid7 News
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- Sustainability Business Division of Schneider Electric Responds to Cybersecurity Incident
January 29, 2024
On January 17th, 2024, a ransomware incident affected Schneider Electric Sustainability Business division. The attack has impacted Resource Advisor and other division specific systems. Schneider Electric Global Incident Response team has been immediately mobilized to respond to the attack, contain the incident, and to reinforce existing security measures. Sustainability Business division has informed impacted customers. Read more… Source: ...
- Microsoft actions following attack by nation state actor Midnight Blizzard
January 19, 2024
The Microsoft security team detected a nation-state attack on our corporate systems on January 12, 2024, and immediately activated our response process to investigate, disrupt malicious activity, mitigate the attack, and deny the threat actor further access. Microsoft has identified the threat actor as Midnight Blizzard, the Russian state-sponsored actor also known as Nobelium. Beginning in ...
- New York: Refuah Health to spend over $1M on cyber security following ransomware attack
January 8, 2024
A Hudson Valley health care provider will spend more than $1 million on cybersecurity after a ransomware attack leaked patients’ information. An investigation by the state attorney general found Refuah Healthdid not have proper precautions set up to prevent the attack. Read more… Source: Bronx News 12
- ECB to conduct mock cyber attacks at 109 banks
January 3, 2024
The European Central Bank (ECB) will stress test 109 banks over the next twelve months to see if they are adequately prepared for cyber attacks. The banks’ response and recovery capabilities will be prioritized, not the potential to prevent incidents. The 109 banks in question are all under the direct supervision of the ECB. The stress ...
- Henry Schein Sales Hurt by Cyber Attack, Macro Woes
December 27, 2023
Henry Schein (HSIC) is currently entangled in a major cyber-attack incident. Headwinds like unfavorable currency movement and global economic uncertainties continue to affect the company. The stock carries a Zacks Rank #4 (Sell). In October 2023, Henry Schein stated that a portion of its manufacturing and distribution businesses experienced a cybersecurity incident. Henry Schein took precautionary ...
- Ubisoft apparently stopped a 900GB data breach
December 24, 2023
Just days after Insomniac suffered a horrible data breach, Ubisoft may have avoided the same fate. Security collective VX-Underground shared a report on X that, on Dec. 20, an “unknown Threat Actor” got access to Ubisoft’s internal tools, sharing screenshots online. They allegedly intended to get 900GB worth of data from the French game publisher behind ...
