Security Awareness Training Blog

Compliance Blog

Compliance news as it relates to cybersecurity, who it affects, and how to stay compliant.

Six Security Questions You Should Keep in Mind for Third Parties

Organizations are beginning to understand the consequences of a data breach or a phishing attack and the negative impact they can really have. But what are the security risks for third ...
Continue Reading

Confront Apprehensive Compliance Before Disaster Strikes

This blog is co-written by Aimee Laycock and Joanna Huisman When it comes to fostering a more secure environment it’s not a question of wanting to…it’s more like YOU HAVE TO. ...
Continue Reading

December Content Update: Includes New Versions of Email Exposure Check Pro and Phishing Security Test Tools

Here are a few important updates to share with you from the month of December.
Continue Reading

[LEGAL ALERT] What You May Have Overlooked in the Run Up to CCPA Compliance

LAW.COM had a very good reminder that you really need to keep in mind. Here is an extract: "With just days to go before the California Consumer Privacy Act (CCPA) compliance date, some ...
Continue Reading

99 Percent Of All Misconfigurations In The Public Cloud Go Unreported

Charlie Osborne at ZDNet wrote: "Today's data breaches often seem to be caused not just by malware infections or external threat actors, but human error, insiders with an ax to grind, and ...
Continue Reading

Financial Phishing Campaigns on the Rise

More than 1900 new potential bank phishing sites were registered in the first half of 2019, according to researchers at NormShield. Based on the increase in new suspicious domains ...
Continue Reading

British Airways Hit With Record $229 Million GDPR Fine Following 2018 Data Breach

U.K.-based airline British Airways (BA) is facing a record fine of £183 million ($229 million) after suffering a cyberattack in September last year. The U.K. Information Commissioner’s ...
Continue Reading

Nearly Half of US Orgs Not Ready for California Consumer Privacy Act Deadline

InfoSec Mag observed something a bit worrisome. "In advance of the California Consumer Privacy Act (CCPA) going into effect January 1, 2020, researchers analyzed how prepared US ...
Continue Reading

Vendors are Responsible for Almost Half of All Data Breaches

The latest data from a survey of 600 SpiceWorks IT and Security professionals shows that vendor users aren’t doing their part to keep your organization’s data safe.
Continue Reading

NY Cyber Law Hits 3rd Deadline: Toughest Yet to Come, How To Get And Stay Compliant?

Craig A. Newman, partner at Patterson Belknap wrote: "By today, financial institutions are required to meet their next deadline for compliance with New York’s cybersecurity law. The ...
Continue Reading

[Heads-up] The May 2018 GDPR Deadline May Fuel New Extortion Attempts

Trend Micro has released its annual security roundup, and it shows several interesting trends that will likely continue into 2018. There is bad news and worse news, with a little bit of ...
Continue Reading

KnowBe4 Attains SOC 2 Type I Compliance For The Hosted Phishing And Training Product Offerings

KnowBe4, Inc, the world's largest security awareness training and simulated phishing platform, this week announced it has successfully completed a Service Organization Controls (SOC) 2 ...
Continue Reading

Which EU 2018 Directive Is More Important Than GDPR?

If you have sales offices in Europe, or full subsidiaries, you need to be aware of the NIS directive. Peter Dekker at Enisa warned about the following: During 2017, the GDPR buzz reached ...
Continue Reading

Complex regulations and sophisticated cyber attacks inflate non-compliance costs

The cost of non-compliance has significantly increased over the past few years, and the issue could grow more serious. 90 percent of organizations believe that compliance with the GDPR ...
Continue Reading

URGENT - If IT and Marketing are not freaking out about GDPR compliance, you are not paying attention

I found an article about GDPR compliance written by the fine folks of HubSpot, which we use ourselves here at KnowBe4 use for marketing automation. We have customers in Europe, so our ...
Continue Reading

We're Still Not Ready for GDPR? What is Wrong With Us?

Sara Peters, Senior Editor at Darkreading wrote an excellent article about GDPR. It is both reprimanding and encouraging to get off our collective butts and do something about GDPR very ...
Continue Reading

Federal Contractor? Insider Threat Training Deadline June 1- Don't Lose Your Clearance

Insider Threat Training Requirement for US Gov't Contractors (Deadline May 31, 2017) SANS just alerted US federal contractors that wish to maintain their clearances must have completed an ...
Continue Reading

Cybersecurity Top Risk Consideration In Board Room

The Wall Street Journal polled its readers and asked them to rate the top compliance issues of 2014. The answers were very interesting!
Continue Reading

PCI Publishes Guidance On Security Awareness Training

The Payment Card Industry Council thinks Security Awareness Training is so important that they just published a 25-page guidance paper that fully explains the why, how and what of ...
Continue Reading

NISTs New Approach to Cybersecurity Standards

Applying Engineering Values to IT Security. The National Institute of Standards and Technology is developing new cybersecurity standards based on the same principles engineers use to ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews