Cyber Trust label, UK deepfake laws, Treasury attack details
Jan 8, 2025
auto_awesome
Exciting advancements in cybersecurity are on the horizon with the upcoming Cyber Trust label set for 2025. The UK is making moves to criminalize sexually explicit deepfakes, which marks a significant legislative shift. Recent discussions reveal a limited yet concerning attack on the U.S. Treasury linked to government-sponsored hackers. Moreover, there's an alarming rise in ransomware demands and connections between Tencent and the Chinese military. Tune in for insights on these urgent and complex cyber threats!
The upcoming Cybertrust label initiative aims to provide consumers with clearer information on the cybersecurity practices of connected devices, influencing federal purchasing decisions by 2027.
Washington's lawsuit against T-Mobile underscores the growing legal accountability for companies regarding their data protection measures and the expectation of robust cybersecurity practices.
Deep dives
Introduction of Cybertrust Labels
A new initiative will introduce Cybertrust labels on connected devices, similar to Energy Star certification, to inform consumers of baseline cybersecurity practices. The White House plans to enforce that federal government purchases will only include devices bearing the Cybertrust label by 2027. This program will adhere to NIST cybersecurity criteria and will provide consumers with information on the expected duration of software updates at the point of purchase. The collaboration of CISA, the FCC, and the Department of Justice will ensure oversight and enforcement of this label system.
Legal Actions Against Data Breaches
Washington's Attorney General has filed a lawsuit against T-Mobile for failing to adequately protect customer data during a 2021 breach that exposed information of 79 million individuals. The suit alleges that T-Mobile misrepresented its cybersecurity capabilities and inadequately informed affected customers about the breach. The legal action seeks to compel T-Mobile to enhance its cybersecurity practices and imposes financial penalties under the Consumer Protection Act. This case highlights the increasing scrutiny and accountability that corporations face regarding their data protection measures.
Nudge Security provides advanced security posture management for Okta, Microsoft 365, and Google Workspace. With Nudge, you’ll be alerted of identity security risks like weak or missing MFA, inactive admin accounts, and risky integrations, plus you can automate remediation tasks and on-going identity governance. Start a free 14-day trial today
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode