Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Explore compliance requirements, frameworks, and best practices that help organizations protect sensitive information and manage regulatory obligations. Learn how standards such as HIPAA, CMMC, NIST, and CIS can strengthen governance, reduce risk, and support a more secure business.

CMMC Audits Are Paused: Here's Why Your Compliance Risk Just Went Up, Not Down

cmmc-level2-certification
The Pentagon just paused third-party CMMC audits and made it permanent policy, but a $507,000 settlement from June shows that "paused" doesn't mean "off the hook," and the lesson applies well beyond defense contracting.
Continue reading
  109 Hits

It Wasn't a “Hack” It Was a Mistake Anyone Could Make: What the Manchester Airports Breach Teaches SMBs About Vendor Risk

Airport-flight-checkin
A breach that exposed the data of 8.7 million people didn't require nation-state malware or a zero-day exploit, it exploited exposed login credentials sitting in plain view in website code, tied to a third-party marketing platform. That's not a sophisticated attack. That's a mistake almost any business could make, which is exactly why every small and mid-sized business should be paying attention.
Continue reading
  181 Hits

CIRCIA Is Almost Here

SOC Security Operations Center
After more than four years of waiting, the federal government's most far-reaching cybersecurity reporting law is finally close to taking real, enforceable shape. The Cybersecurity and Infrastructure Security Agency (CISA) has told stakeholders it intends to publish the long-delayed final rule for the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) in September 2026 — and once that happens, the clock starts ticking toward mandatory reporting for hundreds of thousands of U.S. businesses.
Continue reading
  633 Hits

CMMC Level 2 Is on Hold: What Defense Contractors Need to Know

Government-Manufacturing

If you've been preparing your company for a CMMC Level 2 certification assessment, you may have heard some confusing news: the federal government has put CMMC Phase II on hold.

That part is true.

What isn't true is that CMMC has disappeared.

On July 13, 2026, the Department announced the immediate suspension of CMMC Phase II, which had been scheduled to begin November 10, 2026. At the same time, officials launched a 60-day review of the program. Phase I self-assessment requirements remain in place.

Continue reading
  245 Hits

Canada orders TikTok to shut down over national risk concerns

TikTok

The Canadian government has ordered the dissolution of TikTok Technology Canada following a multi-step review that provided information and evidence of the social media company posing a national risk. 

Continue reading
  1649 Hits

Google Cloud to Enforce Multi-Factor Authentication by 2025 for All Users

clou_20241109-185203_1

Google's cloud division has announced that it will enforce mandatory multi-factor authentication (MFA) for all users by the end of 2025 as part of its efforts to improve account security.

Continue reading
  2321 Hits

Microsoft warns it lost some customer's security logs for a month

microsoft-red-header

Microsoft is warning enterprise customers that, for almost a month, a bug caused critical logs to be partially lost, putting at risk companies that rely on this data to detect unauthorized activity.

Continue reading
  2426 Hits

Mozilla accused of tracking users in Firefox without consent

Mozilla--logo

European digital rights group NOYB (None Of Your Business) has filed a privacy complaint with the Austrian data protection watchdog (DSB) against Mozilla, alleging the company uses a Firefox privacy feature (enabled without consent) to track users' online behavior. 

Continue reading
  2249 Hits

US sanctions 12 Kaspersky Lab execs for working in Russian tech sector

Kaspersky

The Treasury Department's Office of Foreign Assets Control (OFAC) has sanctioned twelve Kaspersky Lab executives for operating in the technology sector of Russia.

Continue reading
  2602 Hits

SEC: Financial orgs have 30 days to send data breach notifications

sec-red-flar_20240519-185154_1

The Securities and Exchange Commission (SEC) has adopted amendments to Regulation S-P that require certain financial institutions to disclose data breach incidents to impacted individuals within 30 days of discovery.

Continue reading
  2604 Hits

Norway recommends replacing SSL VPN to prevent breaches

global-pew-pe_20240519-183959_1

The Norwegian National Cyber Security Centre (NCSC) recommends replacing SSLVPN/WebVPN solutions with alternatives due to the repeated exploitation of related vulnerabilities in edge network devices to breach corporate networks. 

Continue reading
  3107 Hits

Former AT&T customers get $6.3 million in data throttling refunds

AT-T

The Federal Trade Commission (FTC) is sending out $6,300,000 in partial refunds to 267,000 former AT&T Wireless customers as part of a data throttling settlement in 2019.

Continue reading
  2699 Hits

New executive order bans mass sale of personal data to China, Russia

Joe_Biden

U.S. President Joe Biden has signed an executive order that aims to ban the bulk sale and transfer of Americans' private data to "countries of concern" such as China, Russia, Iran, North Korea, Cuba, and Venezuela.

Continue reading
  2490 Hits

FTC sues H&R Block over deceptive 'free' online filing ads

H-R-Bloc_20240225-193859_1

The U.S. Federal Trade Commission (FTC) sued tax preparation giant H&R Block over the company's deceptive "free" online filing advertising and for pressuring people into overpaying for its services.

Continue reading
  2842 Hits

Microsoft says it fixed a Windows Metadata server issue that’s still broken

Windows

Microsoft claims to have fixed Windows Metadata connection issues which continue to plague customers, causing problems for users trying to manage their printers and other hardware.


Continue reading
  4283 Hits

iPhone apps abuse iOS push notifications to collect user data

iphone

Numerous iOS apps are using background processes triggered by push notifications to collect user data about devices, potentially allowing the creation of fingerprinting profiles used for tracking.


Continue reading
  3106 Hits

Google Pixel phones unusable after January 2024 system update

google-pixel-7

Google Pixel smartphone owners report problems after installing the January 2024 Google Play system update, being unable to access their devices internal storage, open the camera, take screenshots, or even open apps.


Continue reading
  2613 Hits

Steam drops support for Windows 7 and 8.1 to boost security

steam-brighter

Steam is no longer supported on Windows 7, Windows 8, and Windows 8.1 as of January 1, with the company recommending users upgrade to a newer operating system.


Continue reading
  2925 Hits

iPhone Triangulation attack abused undocumented hardware feature

apple_triangl_20240101-180232_1

 The Operation Triangulation spyware attacks targeting iPhone devices since 2019 leveraged undocumented features in Apple chips to bypass hardware-based security protections.

Continue reading
  3178 Hits

CISA urges tech manufacturers to stop using default passwords

0_CISA

Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged technology manufacturers to stop providing software and devices with default passwords. 

Continue reading
  3536 Hits

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024