Kroll Cybersecurity Enhancement for Major Canadian Bank's OT Infrastructure
Article Content
- •Kroll delivered a comprehensive OT security program for a major Canadian bank.
- •The engagement identified critical gaps in governance and visibility within the bank's OT systems.
- •Non-disruptive assessment techniques were emphasized to ensure business continuity.
A major Canadian bank engaged Kroll to enhance its operational and cybersecurity resilience due to complex risks in its OT environment. The bank faced challenges such as limited visibility across IT/OT systems, evolving sector-specific threats, and potential exposure of critical infrastructure. Kroll implemented a multidisciplinary OT security program that included a tailored threat profile, comprehensive OT risk assessment, and incident response plan review. The assessment revealed governance and visibility gaps, emphasizing the need for improved resilience against a volatile threat landscape. Key systems involved included building automation and control systems managing power and cooling across critical facilities. The engagement required careful collaboration to maintain business continuity while addressing security needs. Kroll's approach utilized non-disruptive assessment techniques and aligned with regulatory expectations, focusing on sector-specific threats and tailored controls.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…