axio - kn

test

Posts about Cyber Risk (2):

PAM is a Process, Not Just a Tool

PAM is a Process, Not Just a Tool

In an official statement, Uber confirmed that it responded to a cybersecurity incident, the result of which is still under investigation. Based on reports from cybersecurity media, the attacker appeared to obtain a third-party contractor’s access credentials on the dark web and attempted to use them to gain access to Uber’s network and systems. On each successive attempt, the contractor was presented with a multi-factor approval request, which was ultimately accepted. The contractor’s credentials reportedly gave the hacker elevated privileges, which in some reports, included access to a network share of PowerShell scripts that contained administrative credentials with access to AWS and other key technology platforms.

S4x22 in Miami Florida: A Recap – The World’s Top ICS Professionals Back Together Again

S4x22 in Miami Florida: A Recap – The World’s Top ICS Professionals Back Together Again

I was proud to attend and participate in this year’s S4 event in Miami, Florida: The Future of OT and ICS Security. S4 is the largest gathering of ICS security talent in the world. This year’s event was held at The Fillmore, Miami Beach, from April 19-21. It was 3 days, 3 stages, and 64 speaker sessions. There were over 800 attendees from 30 countries and included a record 164 women! The conference was not only a mind meld of the industry’s best, but an ideal opportunity for me to make new friends and reconnect with many of our colleagues and partners.

Pipeline Control Systems Cybersecurity (API-1164 v3) – Highlights from our Webinar with AGA

Pipeline Control Systems Cybersecurity (API-1164 v3) – Highlights from our Webinar with AGA

In a recent webinar, Axio’s Global Co-founder and President, David White, sat down with American Gas Association’s Managing Director of Security and Operations, Kimberly Denbow, to discuss the latest release (v3) of API-1164, Pipeline Control Systems Cybersecurity, which is a NIST CSF-based community standard for cybersecurity regulation. We encourage you to check out the full webinar for all the enlightening details and discussion, which can be found on Axio’s website. Read on for some highlights…

Meet CISA: US Critical Infrastructure’s Cyber War General

Meet CISA: US Critical Infrastructure’s Cyber War General

Executive Summary 

Federal support for critical infrastructure cybersecurity is more important than ever in these heightened times of the Ukraine-Russia conflict. There is growing concern Russia will engage in cyber-attacks targeting western critical infrastructure assets as retaliation for political interference. The United States private sector relies on the Department of Homeland Security’s Cybersecurity and Infrastructure Agency (CISA) for the latest best practices, intelligence, and collaboration tools. This article serves as an introduction to CISA’s important role in supporting the nation’s critical infrastructure sectors.  

Gartner Cites Importance of Integrated Risk Management During Digital Transformations

Gartner Cites Importance of Integrated Risk Management During Digital Transformations

In a recent report, Emerging Technologies: Top Use Cases in Integrated Risk Management, Gartner included Axio in a survey of IRM technology products and service providers. IRM tools have emerged as integral pieces to a modern and successful cybersecurity program. Previously known as Governance, Risk, and Compliance (GRC) tools, IRM tools address a wider range of use cases than the legacy GRC products of the past. They provide a “vertically integrated view of risk,” using your company’s business strategy as a jumping off point. By starting here, IRM tools can be used to address the unique cybersecurity needs of your organizational operations, regardless of size or industry. Unlike GRC tools, IRM products offer a dynamic and comprehensive view of your risk environment across business units, partners, and third-party vendors.