Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Security

How to Prevent High Risk Authentication Coercion Vulnerabilities

Most of us already know the basic principle of authentication, which, in its simplest form, helps us to identify and verify a user, process, or account. In an Active Directory environment, this is commonly done through the use of an NTLM hash. When a user wants to access a network resource, such as a file share, their password is hashed and sent over a cryptographically secure channel to the resource.

HIPAA Compliance Checklist 2022

The Health Insurance Portability and Accountability Act (HIPAA) is a data privacy and security regulation for the healthcare industry. It is a comprehensive regulation that ensures your organization complies with the requirements of HIPAA. Organizations looking to achieve HIPAA Compliance must meet the requirements outlined by the regulation. Further, failure to comply with HIPAA regulations may result in substantial fines, especially in case of an incident data breach.

Cloud Data Management Capabilities (CDMC) framework: the challenges & best practices

Cloud adoption has gained solid momentum over the past few years. The technology has been helping organizations revolutionize their businesses and optimize their processes for increased productivity, reduced cost, and better scalability. But as organizations pour their entire focus on improving their businesses, they tend to lose control of governance. One of the many reasons that data governance tends to get more out of control is when organizations increasingly adopt a hybrid or multi-cloud model.

What is eKYC Verification? How does Aadhaar eKYC work?

Given that most KYC is registered online and the documents required are also assembled online, verification procedures should be fully digital as well, given the entire digitization of financial instruments and services. The onboarding procedure can now be completed entirely online thanks to changes made by authoritative entities. The eKYC Verification, which speeds processing for a variety of financial services, enables this.

What I wish I knew about security when I started programming

It’s critical for developers to understand basic security concepts and best practices to build secure applications. Software developers are creative problem solvers. Their job is to build functioning applications, and they deal with rapid changes—in technologies, tools, and programming languages—as the landscape evolves and the development velocity accelerates. A key part of the development process is ensuring that the products delivered meet user needs and the goals of the business.

LastPass attackers steal source code, no evidence users' passwords compromised

LastPass, the popular password manager used by millions of people around the world, has announced that it suffered a security breach two weeks ago that saw attackers break into its systems and steal information. But don’t panic just yet – that doesn’t mean that all of your passwords are now in the hands of internet criminals.

UpGuard Reporting Improvements Demo // Chris Schubert, Senior Product Manager

Hear from UpGuard's Senior Product Manager, Chris Schubert, as he introduces you to UpGuard's new Reporting Improvements Our new reports library which centralizes a variety of frequently used reports for you to explore and generate. Some updates we’ve made to both BreachSight and Vendor Risk reports; making it easier for you to generate either executive level summary reports or detailed reporting.

UpGuard Vendor Risk Matrix Demo // Annie Luu, Product Marketing Manager

Hear from UpGuard's Product Marketing Manager, Annie Luu, as she introduces you to UpGuard's new Vendor Risk Matrix. The new vendor risk matrix, that measures vendor security ratings by business impact, has been added to the Vendor Risk Executive Summary. This feature will help drive action where it matters most, highlighting your vendors of most concern in the top right of the matrix.It’s now easier to quickly focus on the most impactful areas of your third party risk management program, by visualizing your vendor portfolio risk by Security Rating and Tier.