CIO Brief: Governance at Scale — Why Control Tower Matters
The short version: AWS Control Tower, released in 2019, sets up your AWS cloud as a well-organized group of accounts with security rules built in. It is the...
Insights
Articles in CIO Briefings.
The short version: AWS Control Tower, released in 2019, sets up your AWS cloud as a well-organized group of accounts with security rules built in. It is the...
The short version: In 2019, Microsoft warned about BlueKeep, a flaw that could let attackers take over older Windows computers through remote desktop...
The short version: In 2019, attackers got into Microsoft's consumer email support systems by compromising a single support agent's account. Help desks are...
The short version: In 2019, Citrix — a company that sells remote access technology to enterprises — was breached, likely through attackers trying common...
The short version: In 2019, Microsoft released Sentinel, a security monitoring service that runs in the cloud. It made centralized security monitoring...
The short version: In 2018, AWS added a setting that prevents cloud storage from being made public at all. Turned on across an account, it stops the most...
The short version: AWS recommends running your cloud as many separate accounts — one per application or environment — instead of one big account. In 2018,...
The short version: In 2018, Microsoft's multi-factor authentication service had a major outage, and many organizations couldn't sign in to their email and...
The short version: When Marriott bought Starwood in 2016, it also bought a hacker who had been inside Starwood's systems since 2014. The breach wasn't...
The short version: In 2018, a Facebook bug let attackers steal the digital "keys" that keep users signed in, giving access to millions of accounts without...
The short version: In 2018, Microsoft started pushing businesses toward signing in without passwords, using phones, fingerprints and security keys instead....
The short version: In 2018, Reddit was breached even though its employees used two-factor authentication — the attacker intercepted text message codes. All...
The short version: Most password rules produce predictable passwords like "Summer2018!", which attackers try first. In 2018, Microsoft introduced a way to...
The short version: GDPR, enforceable since 2018, made organizations legally responsible for knowing where personal data lives and protecting it — with fines...
The short version: Cambridge Analytica obtained data on tens of millions of Facebook users through an app most of them never used. The same mechanism — apps...
The short version: In 2018, the US indicted Iranian hackers who stole large volumes of data by trying common passwords against thousands of accounts. It is...
The short version: In 2018, attackers broke into Tesla's cloud through an unprotected management console and used its computers to mine cryptocurrency....
The short version: In 2018, researchers found flaws in nearly every computer processor that could let one program read another's data. Cloud providers had...
The short version: Uber's 2016 breach began with cloud passwords left in a code repository. What made it infamous was the cover-up: the company paid the...
The short version: In 2017, cloud storage tied to US military programs was found open to the public. If defense organizations can make this mistake, any...
The short version: Amazon GuardDuty, launched in 2017, watches your AWS accounts for signs of attack and costs relatively little. The decision is not really...
The short version: Equifax lost data on about 147 million people in 2017 because a known software flaw went unpatched for months, and monitoring that should...
The short version: Deloitte's 2017 email breach reportedly started with one administrator account protected only by a password. Admin accounts are the keys...
The short version: In 2017, AWS released Macie, a tool that finds sensitive data like customer records hidden in cloud storage. Its premise is simple and...