Close Menu
    Facebook X (Twitter) Instagram
    Facebook Instagram YouTube
    Crypto Go Lore News
    Subscribe
    Wednesday, May 27
    • Home
    • Market Analysis
    • Latest
      • Bitcoin News
      • Ethereum News
      • Altcoin News
      • Blockchain News
      • NFT News
      • Market Analysis
      • Mining News
      • Technology
      • Videos
    • Trending Cryptos
    • AI News
    • Market Cap List
    • Mining
    • Trading
    • Contact
    Crypto Go Lore News
    Home»AI News»Why data breaches have become ‘normalized’ and 6 things CISOs can do to prevent them
    AI News

    Why data breaches have become ‘normalized’ and 6 things CISOs can do to prevent them

    CryptoExpertBy CryptoExpertMay 20, 2024No Comments8 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
    Why data breaches have become ‘normalized’ and 6 things CISOs can do to prevent them
    Share
    Facebook Twitter Pinterest Email Copy Link
    Coinmama


    Join us in returning to NYC on June 5th to collaborate with executive leaders in exploring comprehensive methods for auditing AI models regarding bias, performance, and ethical compliance across diverse organizations. Find out how you can attend here.

    Every week, a new data breach threatens enterprise organizations worldwide, forcing a re-evaluation of cybersecurity strategies to protect consumers. In recent months, we’ve seen major breaches at companies like 23&Me, Okta, United Healthcare and American Express — putting incredibly sensitive consumer data at risk. Between 2022 and 2023, there was a 20% increase in data breaches. And with Microsoft, Roku and many other companies already battling data breaches in the first months of 2024, this unfortunate trend shows no sign of slowing down. 

    The Okta breach, which affected all of their customers due to an employee’s use of a personal Google profile on a company laptop, underscores the criticality of the human element in cybersecurity. According to the Verizon DBIR 2024, 74% of all breaches include the human element, with people being involved either via error, privilege misuse, use of stolen credentials or social engineering.  

    The continued role of human error in cyber breaches is a clear sign that cybersecurity training as a control approach has categorically failed the market. The Okta incident is a grave reminder of the vulnerabilities that can arise from seemingly innocuous behaviors, like signing into a personal account on a work device, which may contravene established security policies. With this in mind, it’s crucial that CISOs and their teams ensure employees are aware of these vulnerabilities, in addition to building a system that’s resilient to breaches.

    okex

    What should be on CISO priority lists (if they’re not already)

    Here are six items that CISOs should focus on in 2024 to protect their organizations from the risk of a data breach:

    VB Event

    The AI Impact Tour: The AI Audit

    Join us as we return to NYC on June 5th to engage with top executive leaders, delving into strategies for auditing AI models to ensure fairness, optimal performance, and ethical compliance across diverse organizations. Secure your attendance for this exclusive invite-only event.

    Request an invite

    Employ a remote browser isolation (RBI) system to alleviate human error: The Okta breach is a classic example of how human error can lead to significant security incidents. Even the most robust security measures can be undermined by simple mistakes. Employees must be continuously educated on the risks of mixing personal and professional digital activities. An RBI system can help to technically alleviate these issues.

    Implement a zero trust strategy: A zero trust approach assumes that breaches can happen and verifies each request as if it originates from an open network. Regardless of whether a request comes from within or outside the enterprise’s network, it must be authenticated, authorized and encrypted before granting access. This strategy mitigates damage by requiring additional verification before allowing access to sensitive customer support systems.

    Enforce and monitor IT policies: Companies must enforce policies that prevent the use of personal accounts on work devices and monitor compliance. Automated tools should be used to flag and block such activities, and anomalies and policy violations should be enforced automatically via policy controls. Policies are pointless if CISOs neglect their enforcement.

    Prepare incident responses: A swift and transparent response to breaches is crucial. Okta reported the incident and took immediate action, which is a key step in managing the aftermath of a breach. Especially with the new SEC disclosure rules, companies must be prepared to respond to breaches and report them immediately to the necessary parties.

    Strengthen privileged access management (PAM): Strengthening PAM can ensure that even if employee credentials are compromised, the access is limited and does not allow for widespread exploitation. While the goal is to avoid breaches entirely, mitigating those vulnerabilities is critical to a successful response.

    Reinforce endpoint security: Ensuring that all endpoints are secure and cannot be accessed through compromised third-party accounts is essential. Solutions that monitor for anomalous behavior could have potentially identified unusual activity resulting from the compromised credentials. Additionally, application controls and ring-fencing are valuable in addressing these issues.

    When it comes to regulations, compliance does not equal security

    It’s also worth noting that despite the introduction of significant regulations like the General Data Protection Regulation (GDPR) and the Payment Card Industry Data Security Standard (PCI DSS), as well as the potential for hefty fines for non-compliance, evidence suggests that these mechanisms have not had a dramatic impact on the security market. 

    For instance, a study investigating the impact of GDPR infringement fines on the market value of companies found that, while there was a statistically significant cumulative abnormal return of around -1% on average up to three days after a fine announcement, the negative economic impact on market value far outweighed the monetary value of the fine itself. This suggests that the fines, albeit substantial, were not sufficiently punitive to motivate significant changes in corporate behavior among large market capitalization companies Additionally, security breach announcements, which often result in fines and penalties, only led to an average market value decrease of about 1% for the affected firms, indicating a relatively minor financial impact considering the potentially vast scale of such breaches. 

    While PCI DSS compliance aims to secure credit card data and involves penalties ranging from fines to card acceptance rights revocation, the effectiveness of these sanctions as a deterrent is questionable. The threat of negative publicity and the business risk associated with non-compliance are known, yet breaches and compliance failures continue to occur. This tells us that the potential costs of non-compliance might not be perceived as a significant business threat or that the enforcement of these penalties is not consistent enough to enforce compliance.

    To put it simply, compliance does not equal security. And to date, no significant fines or punitive measures have shown impact on the market overall. These cases underscore a broader issue within the security market: While regulations and fines aim to motivate companies towards better security practices and compliance, their actual impact, especially on major companies with substantial resources, seems limited. The lack of significant punishment for overt failures, as evidenced by minimal impacts on market valuation and the continued occurrence of data breaches, points to a need for re-evaluating the effectiveness of current compliance and penalty mechanisms.  

    Security leaders’ opportunity to educate their workforce and up their game

    While current regulations are not having their intended effect on the market, there are steps organizations can take to protect themselves, as mentioned above. In connecting with IT and cybersecurity leaders, discussions should focus on real-world implementation of zero trust principles, the balance between ease of use and security and promoting a security-first culture among all employees to reduce the risk of human error. Additionally, exploring technologies like behavior analytics, AI-driven threat detection, RBI and continuous authentication methods can provide further insights into building resilient systems. 

    As cybersecurity professionals improve their practices, so do the hackers behind data breaches. These attackers are finding new methods to break into systems at a rapid pace. However, doing the simple things to prevent human error ensures that you won’t make hacking into your system a walk in the park. The recent ConnectWise vulnerability was described as “embarrassingly easy” to exploit, and these types of mistakes are simply unacceptable in 2024. Too many organizations are rolling the dice on security, especially given the threats we face today.

    Every day that goes by without a cyber-educated workforce is another day that digital systems are at extreme risk. If CISOs can get on the same page about doing the little things, and ensure  all employees are fully aware of the threats and the resources they have to fight them, we will see data breaches start to decrease in both number and size. A proactive, informed approach to cybersecurity will be the cornerstone in defending against 2024’s evolving cyber-attacks, ensuring the security and integrity of global digital ecosystems and the consumers who use them.

    Chase Cunningham (“Dr Zero Trust”) is VP of security market research at G2.

    DataDecisionMakers

    Welcome to the VentureBeat community!

    DataDecisionMakers is where experts, including the technical people doing data work, can share data-related insights and innovation.

    If you want to read about cutting-edge ideas and up-to-date information, best practices, and the future of data and data tech, join us at DataDecisionMakers.

    You might even consider contributing an article of your own!

    Read More From DataDecisionMakers



    Source link

    coinbase
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
    CryptoExpert
    • Website

    Related Posts

    AI News

    AI Trading Bots Explained (Pocket Option Guide)

    April 9, 2026
    AI News

    How is AI reshaping opportunities for students? #news #ai #trending #opportunity #shorts

    April 3, 2026
    AI News

    Create Stunning AI Videos in Minutes! LunaBloomAI Full Tutorial for Beginners (2024)

    December 16, 2025
    AI News

    Glimmering Labs of 2050 AI Shaping Tomorrow’s Materials

    December 15, 2025
    AI News

    Sunday Funny Comic #google #AI News #War #Dogs Virals memes #stockmarket #news #crypto #shorts

    December 14, 2025
    AI News

    ✨ What I Noticed About AI Today 🤖 | Simple Tip for Beginners #shorts

    December 13, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Recommended
    Editors Picks

    Ethereum Sees 56.9% Jump in Transfers as Adoption Gains Ground

    April 12, 2026

    Polymarket Briefly Appears in Google News Before Being Removed

    April 12, 2026

    The Bitcoin miner sell-off looks close to exhaustion marking impending reversal in market pressure

    April 9, 2026

    Uniswap price outlook as Ethereum’s Vitalik Buterin offloads UNI tokens

    April 9, 2026
    Latest Posts

    We are a leading platform dedicated to delivering authoritative insights, news, and resources on cryptocurrencies and blockchain technology. At Crypto Go Lore News, our mission is to empower individuals and businesses with reliable, actionable, and up-to-date information about the cryptocurrency ecosystem. We aim to bridge the gap between complex blockchain technology and practical understanding, fostering a more informed global community.

    Latest Posts

    Ethereum Sees 56.9% Jump in Transfers as Adoption Gains Ground

    April 12, 2026

    Polymarket Briefly Appears in Google News Before Being Removed

    April 12, 2026

    The Bitcoin miner sell-off looks close to exhaustion marking impending reversal in market pressure

    April 9, 2026
    Newsletter

    Subscribe to Updates

    Get the latest Crypto news from Crypto Golore News about crypto around the world.

    Facebook Instagram YouTube
    • Contact
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    © 2026 CryptoGoLoreNews. All rights reserved by CryptoGoLoreNews.

    Type above and press Enter to search. Press Esc to cancel.

    bitcoin
    Bitcoin (BTC) $ 75,754.00
    ethereum
    Ethereum (ETH) $ 2,076.86
    tether
    Tether (USDT) $ 0.998493
    bnb
    BNB (BNB) $ 651.89
    xrp
    XRP (XRP) $ 1.33
    usd-coin
    USDC (USDC) $ 0.999617
    solana
    Solana (SOL) $ 83.93
    tron
    TRON (TRX) $ 0.372735
    figure-heloc
    Figure Heloc (FIGR_HELOC) $ 1.03
    staked-ether
    Lido Staked Ether (STETH) $ 2,265.05