Security news aggregator

Latest coverage for Compensation

Discover the latest on compensation in infosec: trends, salary insights, and how it impacts retention and talent in the cybersecurity sector.

36 headlines in this view

Refine the feed

Search across headline titles and summaries.

Tag briefing

Background for this topic.

Compensation is a term within information security that denotes the controls or measures put in place to mitigate risk when existing controls are deemed insufficient or ineffective. In the context of information security, compensation often involves adding additional safeguards to strengthen the overall security posture when primary controls cannot be implemented due to technical, operational, or business constraints.

Effective compensating controls are designed to provide similar protection as the original security measures or to counteract potential threats that may exploit the vulnerabilities left by the limitations of the primary controls. For instance, if a software application does not support two-factor authentication, a compensating control could be the implementation of stringent password policies and regular monitoring of login activities.

Overall, compensating controls are an essential aspect of risk management strategies in information security, ensuring that organizations maintain robust security layers and compliance with industry standards even when conventional security solutions fall short.

Volume over time

Weekly headline count for the current query.

Showing 20 most recent headlines of 36 Filtered view
Bank Info Security 4 months, 4 weeks ago

Breached E-Commerce Giant Details $1B 'Customer Trust' Plan

Critics of South Korea's Coupang Dismiss Offer as Marketing More Than CompensationAfter suffering a data breach that exposed personal data for two-thirds of South Korea' population, online retailer Coupang promised to distribute $1.2 billion in vouchers to "restore customer trust." But critics have accused the move of being more about marketing than true compensation.

Bank Info Security 1 year, 1 month ago

Cryptohack Roundup: KiloEX Offers Compensation

Also, Nike Sued Over Shutdown of NFT SubsidiaryThis week, KiloEX compensation after Oracle exploit, Nike sued over NFT shutdown, SEC dropped probe into PayPal PYUSD, Long Island man sentenced for crypto fraud, Americans lost billions to crypto scams, Loopscale exploiter agreed to return stolen funds and bank regulators softened stance on crypto.

Bank Info Security 1 year, 3 months ago

Australia's Anti-Scams Bill: What's in It for Victims?

Experts Say Consumers Gain Little as Implementation Challenges Loom for FrameworkAustralia's new scams framework bill sets the foundation for industry action but leaves consumers with limited protections. Experts warn that enforcement and reimbursement mechanisms are unclear, forcing victims to navigate a complex system with little guarantee of compensation.

Bank Info Security 1 year, 6 months ago

Cyberstarts Program Sparks Debate Over Ethical Boundaries

Scrutiny Over Ethics of Profit-Sharing Prompts End to Cyberstarts CISO CompensationAllegations of conflicts of interest in Cyberstarts’ Sunrise program have sparked debate in the CISO community. While the program connected CISOs with startups for advisory purposes, its profit-sharing incentives drew criticism, leading some participants to resign and the firm to halt compensation.

3 Countries Taking Different Approaches to Accountability and Victim CompensationGovernments globally are intensifying anti-scam measures, introducing new guidelines to banks, telecom providers and other key sectors to bolster security controls and mitigate fraud risks for consumers and businesses. Some new frameworks threaten to levy stiff penalties for non-compliance.

Company Plans to Link Executive Compensation to Achieving Security MilestonesThe executive vice president for Microsoft Security has announced an overhaul of the company's security practices following a series of high-profile cyberattacks that allowed foreign state-sponsored hacking groups to access its internal systems and cloud networks.

Loading more headlines...