Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Security

Customizing your controls

We know that your business is unique, and you may already have security and privacy programs in place, so we’ve made customization a focus and a pillar in our platform, making it effortless for you to craft custom controls and policies that are integral to your business. On the control details page in TrustOps, you now have the ability to edit a control and customize the control statement language, policy mappings and frequency of the control to accurately reflect your business practices.

Add Your Brand Identity to Your TrustShare

With this update, we’ve made it easy for your team to customize your TrustShare portal to reflect your brand identity. As part of the most recent update to the TrustShare Admin app, we’re excited to introduce a “Branding” section where you can select your brand’s color palette and add your logo. Your TrustShare will reflect your branding in the appropriate places as soon as you publish your selections. You also have the ability to preview changes before publishing, so you can ensure that everything looks and feels right.

TrustShare

As with everything we do at Kintent, we wanted to make it effortless for you to develop and share your information security program! Automatically Share Your Compliance Documents TrustShare is part of Kintent’s Trust Management Platform. It automatically pulls details from the platform, such as your controls, policies, security questionnaires, and subprocessors. Whenever a change is made to the underlying information, Trust Share is automatically updated, so you won’t ever have to worry about the validity of the compliance data you are sharing with your customers.

More Online Privacy Horror Stories: 7 Disturbing Hacks and Breaches That Happened In 2022

It's that time of year again when ghouls, creeps, ghosts, and goblins take to the streets and scare the living daylights out of regular, everyday folk. None of these monsters compare to something much scarier, much more heinous–hackers! Cybercriminals don't wait until October to wreak havoc on the living, they do it every day, and their cyberattacks become bolder with each passing year. It's difficult to fathom how many cyberattacks actually happen.

How Banks Around the World Can Prevent Cyber Attacks

As both consumer and commercial banking clients shift to primarily utilize online banking, they still have high expectations that their financial assets will be secure. In 2021, the banking industry reported 703 cyberattack attempts per week — a 53% increase from 2020. And the cost of cyberattacks in the industry has reached $18.3 million annually per breach.

Differences Between Cloud-Based and On-Prem Password Managers

The adoption of cloud software in organizations continues to grow. In 2020, the combined end-user spending on cloud services totaled $270 billion, according to Gartner. By 2022, projections indicate that this total will rise to a staggering $397.5 billion. In fact, according to Arcserve, there will be over 100 zettabytes of data stored in the cloud by 2025. To give you some perspective, a zettabyte is equivalent to a billion terabytes. But are cloud services superior to an on-premises solution?

Discovering the Critical OpenSSL Vulnerability with the CrowdStrike Falcon Platform

OpenSSL.org has announced that an updated version of its OpenSSL software package (version 3.0.7) will be released on November 1, 2022. This update contains a fix for a yet-to-be-disclosed security issue with a severity rating of “critical” that affects OpenSSL versions above 3.0.0 and below the patched version of 3.0.7, as well as applications with an affected OpenSSL library embedded.

How to Speak Fluent Board

You and your board have the same goal: to drive your organization in the right direction. That makes everything easy, right? Well, not always. Whereas the problem used to be an overall lack of security awareness, boards now are very much aware of the business risk less-than-robust cybersecurity poses. Today, it’s all about communicating effectively and fluently, especially when introducing cybersecurity solutions.

Upcoming Critical OpenSSL Vulnerability

OpenSSL is the most popular implementation of the TLS protocol (Transport Layer Security) which is essentially the de-facto security protocol of the internet today. The OpenSSL team announced critical security updates of versions above version 3.0 (OpenSSL 3.0 was released on September 7, 2021). The myriad of projects and software depending on OpenSSL must update and release a new version to enable end users to start patching their systems.

Why fuzzing tools should be part of your security toolkit

Fuzzing is a software security testing technique that automatically provides invalid and random input to an application to expose bugs. The goal of fuzzing is to stress the application to cause unexpected behavior, crashes, or resource leaks. It allows us, as developers, to understand the behavior and vulnerability of applications more comprehensively. We use fuzzing tools, referred to as fuzzers, to perform this kind of testing.