Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - 3 Cyber Security Lessons to Learn from 2015
Articles

3 Cyber Security Lessons to Learn from 2015

John HarrisBy John HarrisJanuary 4, 2016Updated:July 16, 20214 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
3 Cyber Security Lessons to Learn from 2015
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

One of the best ways to improve is to learn from others’ mistakes. The good news is, with cyber security, there’s no shortage of curriculum.

Looking at the last year alone, we’ve seen devastating cyber security attacks and data breaches that affected millions of Americans. The healthcare industry, the federal government and one of the country’s largest financial service providers were targeted, illustrating that all companies that use a computer, cell phone, tablet or other digital device are at risk.

So let’s put the pages of history to use and learn something from them, shall we?

  • Healthcare

Three cyber attacks in 2015 underscored the vulnerability of the healthcare industry. Premera BlueCross BlueShield took a hit when hackers stole data from 11.2 million subscribers. Social Security numbers, bank account information and addresses were leaked, along with medical information that put victims at risk of insurance fraud.

BlueCross BlueShield was hurt again when hackers illegally accessed Carefirst information. Although names, birthdays and email addresses of over one million members were compromised, Social Security numbers and medical information were protected by password encryption.

That wasn’t the case for Anthem. The Wall Street Journal reported that 80 million unencrypted patient and employee records at Anthem were compromised in a data breach.

The lesson: Millions of victims, three large companies and one vulnerable industry can teach us at least one thing for the coming year: encryption is vital to the safety of your data and digital documents. It was a factor in Premera, the largest reported breach involving patient medical information, and Anthem could have protected sensitive information if it had implemented encryption. Carefirst showed that even simple password encryption can be an effective step to mitigate risk.

Government

When a contract employee transferred data to a non-accredited third-party data center, private information of 850,000 Army National Guard employees was exposed. Although the incident was not considered a hack because the leaked information wasn’t used unlawfully, it made information of many government officials vulnerable.

Made public in early June, the Office of Personnel Management (OPM) suffered one of the largest cyber attacks in history when hackers accessed the personal information of current and former government employees. More than 5 million fingerprints were stolen along with the social security numbers and addresses of 21.5 million people. As a direct result of the attack, OPM deployed a two-factor authentication policy that had previously been neglected because it required a full code re-write for the outdated system.

The lesson: If the federal government is at risk, we all are. Two-factor identity authentication is a proven method to mitigate the risk of a cyber security breach. Don’t be annoyed when you have to answer your mother’s maiden name or enter a code that was sent to you via SMS – steps like these can go a long way in avoiding some of the most destructive data breaches of the year. Also, an investment in current operating systems that integrate with innovative security can save time and money in the long run. Nobody wants to be the subject of a headline that says, “White House orders government IT to do what it should have done in the first place.”

Financial Services

In October, Scottrade revealed that hackers accessed the private information of 4.6 million clients. The incident could have been worse—only names and addresses were leaked—but the deeper issue was the company’s lack of awareness. The attacks occurred between 2013 and 2014, but Scottrade didn’t know its data had been compromised until federal authorities uncovered the issue this year.

The lesson: It’s impossible to fix a problem you don’t know about. With e-signatures in particular, tamper-evident technology alerts signers to any changes that are made after a document is signed, which can help detect fraud. Audit trails can also help identify foul play, because they track each time someone opens, sends or signs a document.

Using cyber security measures like data encryption, two-factor identity authentication or tamper-evident technology doesn’t mean you have full immunity to an attack, but they will always reduce your cyber risk.

With these lessons in mind, is it time for you to make a New Year’s Resolution and improve your cyber defenses?

John Harris

Chief Technology Officer at SIGNiX - and Evangelist on Mobility, E-Signatures and Leading Edge Technologies

  • John Harris
    Nothing to Fear but a Data Incident
  • John Harris
    Protect your E-Signatures and E-Signed Documents from a Data Breach

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}