Back To Resource Center

Published: August 25, 2023

Security 3-2-1 Week of 8/25/23

By Annie articles

3 Interesting Articles

US tech firms offer data protections for Europeans to comply with EU big tech rules
CyberScoop: Starting today, the European Union’s Digital Services Act (DSA) will be in effect for large online platforms with over 45 million users. This legislation mandates transparency in platform algorithms and introduces liability for illegal content, including hate speech. It also bans ad targeting based on sensitive data and specifically prohibits targeting children with ads. In response, TikTok has allowed European users to turn off personalized results, and Meta will offer results based on keyword searches instead of user activity. Despite companies like Meta dedicating vast resources to compliance, there remains ambiguity about the DSA’s specific requirements, with experts watching closely to see if its influence extends globally, much like the GDPR.

Tesla Data Breach Investigation Reveals Inside Job
Dark Reading: Tesla admitted in a filing with Maine’s attorney general that over 75,000 individuals were affected by a data breach resulting from “insider wrongdoing.” German media outlet Handelsbatt received 100GB of data from a Tesla informant, comprising 23,000 internal files from 2015-2022, highlighting around 3,900 reports of vehicular issues and safety concerns related to Tesla’s driver assistance system. The investigation revealed two former Tesla employees had shared this information with Handelsbatt. Tesla has since informed affected individuals, taken legal action against the former employees, and is offering credit monitoring services to those impacted.

Google Workspace will require two admins to sign off on critical changes
Bleeping Computer: Google has announced enhanced cybersecurity measures for Workspace to better defend against social engineering and phishing attacks. Notable features include multi-party approval for certain sensitive actions, requiring two admins to confirm critical changes. Furthermore, select administrative accounts will soon be mandated to implement 2-Step Verification. Google is also amplifying Gmail’s AI-powered defenses for heightened email security and is offering faster log exports to Google’s Chronicle Security Operations Suite, ensuring quicker threat response times. These changes come in light of growing concerns over data breaches and threats.

2 Stats You Should Know

71% of organizations rated their SaaS cybersecurity maturity as mid to high, yet 79% suffered a SaaS cybersecurity incident in the past 12 months. (source)

Introduction of the GDPR in the EU led to over 160,000 reported data breaches in its first two years. (source)

1 More Thing

Discover 30 fun cybersecurity search engines, brought to you by Daniel Kelley, an infamous reformed Black Hat Hacker.. Plus, a bonus tool for you: Dive into a comprehensive search platform that spans various data breaches, letting you verify if your email address has been compromised 🔍😱

Our large and diverse network of experts is here to help...

Charles M.

Principal

Charlies is a 14 year cyber security expert. He started his career in the U.S. armed forces and then transitioned into commercial roles. A security engineer by training, he's well-versed in tool deployment and administration.

Ellen K.

GRC Expert

Ellen bring a decade of GRC expertise to the TalPoint community. She's knowledgeable on a variety of frameworks and employs a methodical approach to compliance. She's available for needs assessments, gap assessments, internal audits, and for certain frameworks running independent 3rd party audits.

Zachary C.

Founder and CRO

Zachary bring a 20+ year career in risk management to the TalPoint community. He's worked across healthcare, finance, and supply chain manufacturing. His broad experience offers both a holistic view of risk as well as a common sense approach to risk management.