Cyber insurance: lack of evidence puts the policy at risk
Underwriters require reliable evidence of security controls. False statements about MFA, endpoint protection or backups can jeopardise coverage.
What are you looking for?
Benedikt Langer is an editor at SecurityToday. His focus areas are cloud security, zero trust and NIS2 compliance. He shapes the thematic direction and ensures editorial quality.
Underwriters require reliable evidence of security controls. False statements about MFA, endpoint protection or backups can jeopardise coverage.
Investigators dismantled the KillSec ransomware group. Its suspected leader is 16, and initial access often came through cloud storage.
Matthias Muhlert, Chair of the ECSO CISO Community, ahead of the ECSO CISO Meetup 2026 in Berlin on board responsibility, metrics, suppliers and AI …
Nvidia shifts control of AI agents into runtime and hardware. The Sentry component for BlueField-4 remains a reference design for now.
Admin accounts, backdoors and remote access services survive the update. Attacks on Artifactory and PaperCut show what still needs to be checked after patching.
Armed with three AI agents, an attacker targeted hundreds of online shops and stole data from at least 600,000 credit cards.
A lawyer, an engineer and a computer scientist are building a compliance platform based on European law in Munich. They rank 20th in the …
Microsoft Teams for Android allows path traversal. NVD added CVE-2026-65768 on August 11, 2026. Microsoft rates it 8.8, NVD rates 9.8.
Codex Security CLI: open-source client code under Apache 2.0, scanning backend in limited beta against OpenAI infrastructure.
Zabbix Advisory with score 9.6: CERT-Bund withdrew the alert after 24 hours. What this means for tickets, CSAF status, and false alarm costs.
Risk-based Windows patch management: prioritize critical assets using CERT-Bund alerts, ring rollouts, and parallel detection.
Cyberattacks on German businesses are becoming more targeted. Cyber resilience means prioritizing: closing API attack surfaces, managing patch windows, and testing recovery - without …
AI agents handling MCP challenge classic SASE assumptions. Those filtering only domains miss the tool channel.
Shadow AI: 40% already avoided it because approvals are useless. Patricia Leppert (TeamViewer) in an interview on risks, fake AI, and CISO measures.
Bitwarden Business vs 1Password: Hosting, SSO, SCIM and Recovery decide the Vault purchase in the midmarket.
The EU Commission sues Ireland, Spain, France, and the Netherlands over incomplete NIS2 implementation. What this means for CISOs.
Record Patch Tuesday with 622 CVEs. Prioritize AD FS and SharePoint first, then exposure, then breadth—this controls the change window.
CVE-2026-50661 bypasses BitLocker with physical access. CVSS 6.1, July patch, checklist for laptops, device pools, and lost-device procedures.
Nihon Kotsu reports malware on July 11, 2026. Dispatch systems offline, AiLock ransom claim filed July 15. Case study with key lessons for control …
Cybersecurity: A manipulated npm-SDK accessed private wallet keys and spread across 17 packages. Why every build is affected.
The KRITIS roof law makes supplier reliability a mandatory duty for operators. Governance roadmap to registration.