Intelligent CISO Issue 48 | Page 25

threat updates
2
3 1

3 UK GLOBAL

The ICO has issued a fine to Tuckers Solicitors following a successful ransomware attack against the law firm . The company was fined £ 98,000 after a data breach caused by ransomware , during which hackers accessed 24,000 court bundles containing sensitive data such as medical files and witness statements – which were then released on the Dark Web . The action notice shows the firm did not have MFA in place , and had unpatched software for six months leading up to the breach . After gaining access to the network , the attackers were able to install tools , set up an account on the network , before deploying ransomware .
Gartner has identified digital supply chain risk as a new security threat and one of its top seven security and risk management trends for 2022 . Increasingly , there are products in the digital supply chain that companies rely upon that are the “ unsung core components holding up our digital operations ,” said Peter Firstbrook , Research Vice President at Gartner . “ When an underlying component of a third-party app a company uses has a critical vulnerability , they are not responsible for its maintenance , so there are underlying dependencies that are out of their control ,” Firstbrook said , referencing the SolarWinds breach and Log4j attack . That can lead to ‘ cascading failure ’. www . intelligentciso . com
25