New York, NY, USA
1932
  |  By Kroll
From September 11, 2026, any manufacturer, importer or distributor of hardware and software products with digital elements made available on the EU market must comply with the Cyber Resilience Act (CRA). The harmonized standards under the CRA are still being drafted, and the first will not be finalized before manufacturers need to act.
  |  By Kroll
Despite their complexities, cyber incidents often start in a very similar manner. There is a helpdesk ticket that appears routine, a slightly unusual login attempt or a system that might just need a restart. By the time an organization formally declares an incident, the attacker has likely already been inside for hours, sometimes longer, moving quietly through cloud platforms, SaaS applications and identity systems long before anyone notices the warning signs.
  |  By Kroll
On August 18, 2026, the SEC proposed Regulation Crypto Assets1, a new regulatory framework intended to create a tailored registration exemption regime for certain crypto asset offerings while maintaining core investor protection requirements. The proposal represents a significant evolution in the SEC's approach to digital assets and could provide the clearest pathway to date for crypto issuers seeking to raise capital in the United States.
  |  By Kroll
How Kroll transformed its global Managed Detection and Response (MDR) service to Kroll Responder MDR by utilizing CrowdStrike Falcon to deliver faster onboarding, deeper expertise and proactive resilience on a global scale. In December 2025, Kroll and CrowdStrike announced a multiyear strategic partnership to elevate MDR services worldwide.
  |  By Kroll
To read more on this story and the significance of Business Email Compromise (BEC), visit The Wall Street Journal where Dave Burg was interviewed (subscription required). A few months ago, scammers hijacked a routine infrastructure project in Surfside Beach, South Carolina, costing the small town $545,000. The scheme stemmed from a single spoofed email sent from a lookalike domain, instructing the town to switch payment from check to ACH.
  |  By Kroll
Has your organization been exposed? How can you act on the exposures that matter most? What’s the best way to demonstrate measurable risk reduction?
  |  By Kroll
The organizations that thrive in 2030 will be those that treat governance as the foundational architecture for innovations in autonomy.
  |  By Kroll
Each month, our Cyber Threat Intelligence team compiles data from our engagements to determine key industry trends. We look at the initial access methods threat actors are using to gain entry into a network, types of incidents most commonly impacting organizations, which sectors are being more heavily targeted, and which threat groups are most prevalent.
  |  By Kroll
A fully managed, end-to-end CrowdStrike deployment delivered at enterprise scale by Kroll A global quick-service restaurant brand needed to establish consistent, enterprise-grade protection and centralized visibility to quickly strengthen its security posture. It had to move fast without disrupting global operations or overburdening a lean IT team.
  |  By Kroll
In a fast-moving threat landscape, finding the answers to complex security challenges can be fraught with unknowns. Asking the right questions can make all the difference, as Steven Escobar and Ben Habing know well through their work in the Assessments and Advisory practice within Cyber and Data Resilience at Kroll.
  |  By Kroll
This week’s briefing covers: Dive deeper.
  |  By Kroll
This week’s briefing covers: Dive deeper.
  |  By Kroll
This week’s briefing covers: Dive deeper.
  |  By Kroll
This week’s briefing covers: Dive deeper.
  |  By Kroll
This week’s briefing covers: Dive deeper.
  |  By Kroll
This week’s briefing covers: Dive deeper.
  |  By Kroll
This week’s briefing covers: Dive deeper.
  |  By Kroll
In this series, we chat with cybersecurity and data resilience leaders from Kroll and our partners. This week's guest is Gaurav Sheth, Global Head of Digital Identity, Data and OT Security. Future episodes will cover topics such as the Cyber Threat Landscape, AI Risk Governance and Private Equity.
  |  By Kroll
This week’s briefing covers: Dive deeper.
  |  By Kroll
This week’s briefing covers: Dive deeper.
  |  By Kroll
As per data published by the Office of the Australian Information Commissioner, the healthcare industry in Australia accounted for 22% of notifiable data breaches between January to June 2020, which was more than any other industry. Cybercriminals continue to target this industry due to the vast amounts of highly sensitive personal information (such as Medicare numbers, credit card information and medical insurance numbers) that is stored by healthcare providers.

Kroll is the world’s premier provider of services and digital products related to governance, risk and transparency. We work with clients across diverse sectors in the areas of valuation, expert services, investigations, cyber security, corporate finance, restructuring, legal and business solutions, data analytics and regulatory compliance. Our firm has nearly 5,000 professionals in 30 countries and territories around the world.

Kroll experts provide rapid response to more than 2,000 cyber incidents of all types annually. We help countless more clients with eDiscovery and litigation support (including expert witness services); managed detection and response services for both active threats and as an integral part of network security; notification solutions, including multilingual call center support; and proactive services, including general and threat-focused risk assessments, response planning, tabletop exercises and more.

Our experts are able to deliver best-in-class endpoint security through our managed detection and response solution, Kroll Responder. Responder handles every step, with 24x7 managed detection and response services fueled by threat hunting and superior incident response.