1,205 Breaches. A Record Year. And Your Sector Is a Fixture in the Top Five.

CyberSecurity Loop Newsletter - Cyooda - Sydney

The privacy regulator just published the worst annual breach numbers since mandatory reporting began — and legal services made the most-affected list again. This fortnight: a record year the OAIC would rather not be reporting, a critical ACSC alert that probably applies to your firm’s own website, hard numbers showing ransomware gangs have repriced what your files are worth, and a Patch Tuesday so large it broke records.

READ MORE >>

Your Help Desk Is the Easiest Way Into Your Firm

Scammers target your helpdesk

For a decade, firms have been hardening the network. Firewalls, endpoint detection, email filtering, MFA everywhere. That investment worked and attackers responded the way attackers always respond. They stopped attacking the hardened thing and moved to the soft thing next to it.

The soft thing is the human process for getting back into an account when you’re locked out.

READ MORE >>

The Shift: A New Era of AI Regulation

Explore how recent US export controls on frontier AI models like Anthropic’s Fable signal a new era of regulatory uncertainty. Learn how security leaders can build resilient AI strategies by treating frontier models as volatile assets rather than stable technology

READ MORE >>

AI Acceptable Use Policy for Law Firms: What It Should Say | Cyooda

Cyooda AI Use Policies

Your firm already has an AI policy. You just didn’t write it.

Right now, in the absence of anything official, every member of your staff is making their own individual decision about what to paste into ChatGPT. Some have decided client names are fine as long as they change them slightly. Some have decided a contract is fine as long as they delete the parties’ details. Some have decided nothing is fine and are quietly falling behind colleagues who’ve decided everything is.

READ MORE >>

68 days. That’s how long attackers are hiding in Australian networks before anyone notices.

CYbersecurity Loop Edition 21

Your device management tool just became a weapon. This fortnight: Iran-linked hackers wipe 200,000 devices using Microsoft’s own admin tools, an Australian healthcare software vendor hit by ransomware this week, a landmark finding on how long attackers are hiding undetected in Australian networks, and AML/CTF reforms that will reshape how law firms collect and store…

READ MORE >>

Lexis Nexis Breaches – and your data maybe in the dump

The cybersecurity loop - edition 20

Your legal research tool just became a threat vector. This fortnight: a breach that hits law firms at the supply chain, Australia’s first Federal Court cyber penalty, an elite school data breach, and a ransomware gang the ASD wants you to know about. 🔐 4 things law firm leaders should know right now: 1. LexisNexis…

READ MORE >>