shutterstock_490960141-1

Industry News: ESG5

      Know Your Breach: Entrust

      Jul 27, 2022 4:14:21 PM

      The Target: Entrust, a digital cybersecurity firm focused on identity management.

      The Take: Sensitive corporate internal data from Entrust’s own IT systems.

      The Vector: The attacker used previously compromised Entrust employee credentials to access their internal systems, posing as an authenticated user. 

      This breach is a critical reminder of the importance of credential authentication and password hygiene. Enforced multi-factor authentication could have prevented the Entrust breach, and enforcing this multi-factor authentication, along with reasonably regular forced password resets, password length and complexity rules, are effective strategies to mitigate these kinds of breaches.

      Read more...

       

      Topics:Know Your Breach

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates