From The Blog

Displaying items by tag: vendor mangement

Black Hat 2023 – Las Vegas. Risk is an interesting subject and has many different meanings to many different people. For the most part Risk breaks down into a few categories, depending on who you are talking to cyber risk, financial risk, and reputational risk. Although these are certainly not the extent of risk, they are some of the most common. One of the biggest challenges with these is that they are usually built and tracked by different groups inside of an organization each with their own goals and motivations. Because of this they can be at odds with each other. This is where risk platforms come into play and can add some outside context which can be helpful in combining the risk types into a coherent message. We talked to one of these, Black Kite, while at Black Hat to see how they approach this.

Published in Security Talk

The breach of IDAM group Okta in January by the self-promoting group Lapsus$ amidst other high-profile breaches and data leaks this year was a significant concern. The concern rose because when the incident first happened, Okta passed it off as an unsuccessful attempt to breach a third-party vendor’s system that had access to Okta systems. However, in March the Lapsus$ group released screenshots of internal systems including what appeared to be Okta’s superuser system.

Published in Security Talk