Connect with us

Rhode Island

Budget restrictions, staff issues, and AI are threats to states’ cybersecurity • Rhode Island Current

Published

on

Budget restrictions, staff issues, and AI are threats to states’ cybersecurity • Rhode Island Current


Many state chief information and security officers say they don’t have the budget, resources, staff or expertise to feel fully confident in their ability to guard their government networks against cyber attacks, according to a new Deloitte & Touche survey of officials in all 50 states and D.C.

“The attack surface is expanding as state leaders’ reliance on information becomes increasingly central to the operation of government itself,” said Srini Subramanian, principal of Deloitte & Touche LLP and the company’s global government and public services consulting leader. “And CISOs have an increasingly challenging mission to make the technology infrastructure resilient against ever-increasing cyber threats.”

The biennial cybersecurity report, released today, outlined where new threats are coming from, and what vulnerabilities these teams have.

Hackers claim to have published data stolen from Providence Public School Department

Advertisement

Governments are relying more on servers to store information, or transmit it through the Internet of Things, or connected sensor devices. Infrastructure for systems like transit and power is also heavily reliant on technology, and all of the connected online systems create more opportunities for attack.

The emergence of AI is also creating new ways for bad actors to exploit vulnerabilities, as it makes phishing scams and audio and visual deep fakes easier.

Deloitte found encouraging data that showed the role of state chief information and security officer has been prioritized in every state’s government tech team, and that statutes and legislation have been introduced in some states which give CISOs more authority.

In recent years, CISOs have taken on the vast majority of security management and operations, strategy, governance, risk management and incident response for their state, the report said.

But despite the growing weight on these roles, some of the CISOs surveyed said they do not have the resources needed to feel confident in their team’s ability to handle old and new cybersecurity threats.

Advertisement

Nearly 40% said they don’t have enough funds for projects that comply with regulatory or legal requirements, and nearly half said they don’t know what percent of their state’s IT budget is for cybersecurity.

Talent was another issue, with about half of CISOs saying they lacked cybersecurity staffing, and 31% saying there was an “inadequate availability” of professionals to complete these jobs. The survey does show that CISOs reported better staff competencies in 2024 compared to 2020, though.

Staffing of CISOs themselves, due to burnout, has been an increasing issue since the pandemic, the report found. Since the 2022 survey, Deloitte noted that nearly half of all states have had turnover in their chief security officers, and the median tenure is now 23 months, down from 30 months in the last survey.

When it came to generative AI, CISOs seemed to see both the opportunities and risks. Respondents listed generative AI as one of the newest threats to cybersecurity, with 71% saying they believe it poses a “high” threat; 41% of respondents said they don’t have confidence in their team to be able to handle them.

While they believe AI is a threat, many teams also reported using the technology to improve their security operations. Twenty one states are already using some form of AI, and 22 states will likely begin using it in the next year. As with with state legislation around AI, it’s being looked at on a case-by-case basis.

Advertisement

One CISO said in the report their team is “in discovery phase with an executive order to study the impact of gen AI on security in our state” while another said they have “established a committee that is reviewing use cases, policies, procedures, and best practices for gen AI.”

CISOs face these budgetary and talent restrictions while they aim to take on new threats and secure aging technology systems that leave them vulnerable.

The report laid out some tactics tech departments could use to navigate these challenges, including leaning on government partners, working creatively to boost budgets, diversifying their talent pipeline, continuing the AI policy conversations and promoting the CISOs role in digital transformation of government operations.

GET THE MORNING HEADLINES.

Advertisement



Source link

Advertisement

Rhode Island

Layoffs hit WPRI Channel 12 in Rhode Island – The Boston Globe

Published

on

Layoffs hit WPRI Channel 12 in Rhode Island – The Boston Globe


PROVIDENCE — Channel 12 was hit with layoffs last week as its parent company – Texas-based Nexstar Media – moved to cut 2 percent of its workforce across the country.

The local cuts, which were in the high-single digits of employees, include at least one reporter, some sales staff, and several part-time employees. 

The station is also putting “Dan Yorke State of Mind” – a weekly public affairs show hosted by the WPRO radio host – on hiatus after laying off the show’s producer. There’s a chance the show will return in some form next year.

Advertisement

”Our broadcasting and sales divisions are streamlining their organizations to reduce our operating expenses and accelerate collaboration across the company,” Nexstar spokesman Gary Weitman said in a statement. “While it is difficult to make these sorts of changes, they will impact less than 2 percent of our workforce and allow us to focus on areas of growth for our viewers, partners, and customers. We are committed to managing through this period of unprecedented change in the media industry so that Nexstar continues to thrive for years to come.”

What wasn’t said: What Weitman failed to mention in his statement was that Nexstar Chairman and CEO Perry Sook bragged to investors last month that Nexstar “delivered the highest third quarter net revenue in the company’s history.” 

Behind the scenes: The Channel 12 layoffs were announced last Wednesday, and the company also abruptly canceled its Christmas party that was scheduled for yesterday afternoon at the Narragansett Brewery. 

Advertisement

During an all-staff meeting on Friday, general manager Pat Wholey acknowledged the station has had a “challenging” end to the year on the revenue side, but expressed confidence that his team has put together a plan that will cause the company minimal disruption in its on-air product.The layoffs at Channel 12 are unrelated to an unionization effort at the company that appears to have fizzled in recent months.

Disclosure: Channel 12 and Globe Rhode Island recently entered into a partnership that includes several on-air appearances each week with Globe reporters. Money doesn’t change hands as part of the deal, and the partnership will continue.


This story first appeared in Rhode Map, our free newsletter about Rhode Island that also contains information about local events, links to interesting stories, and more. If you’d like to receive it via e-mail Monday through Friday, you can sign up here.


Dan McGowan can be reached at dan.mcgowan@globe.com. Follow him @danmcgowan.

Advertisement





Source link

Continue Reading

Rhode Island

California man arrested for stealing $300K from RI town

Published

on

California man arrested for stealing 0K from RI town


Crime

Prosecutors say Alec Tahir Baker allegedly stole nearly $9 million dollars from companies and individuals across the country, including the Town of Bristol.

A man from California was allegedly involved in a scam that targeted the Town of Bristol, prosecutors said on Wednesday. Matthew J Lee/Globe staff

A California man was indicted in federal court on Wednesday after he allegedly participated in multiple scams that defrauded people, establishments, and the town of Bristol, Rhode Island out of nearly $9 million dollars, prosecutors said.

The Rhode Island U.S. Attorney’s office named Alec Tahir Baker, a resident of Corona, California, as a “key participant” in an email conspiracy and money laundering scam. 

Advertisement

The indictment alleges Baker, 60, was involved in a scam where someone would send phishing emails to individuals, businesses, and Town of Bristol email addresses. If opened, prosecutors said, the email allowed the scammers to access the recipient’s computer information. Then Baker, along with unnamed co-conspirators, would allegedly direct victims’ banks to transfer money into an account owned by Baker or other conspirators, the indictment said.

According to the indictment, Baker, along with the co-conspirators, allegedly defrauded individuals and businesses of at least $8,854,243. In addition, the indictment alleges that around $7,649,876 in fraudulent proceeds were transmitted to bank accounts under Baker’s control.

Baker also allegedly targeted Bristol through the scam, allegedly stealing more than $300,000 dollars from the town.

First charged through a criminal complaint on Nov. 1, the Attorney’s office said Baker was arrested in Dallas, Texas, on Nov. 5 and detained after his first appearance in U.S. District Court. 

He faces charges of conspiracy to commit money laundering, bank fraud, and two counts of aggravated identity theft, the indictment said. Federal prosecutors said he will be transported to Rhode Island to be arraigned on those charges at a “later date.”

Advertisement

Representation for Baker did not immediately reply to a request for comment.

California resident, along with alleged scam enterprise, allegedly defrauded Town of Bristol

The indictment alleges Baker and his co-conspirators used phishing emails to gain access to the Town of Bristol’s computer network in January of 2023. 

“The next day, a member of the conspiracy caused $310,500 to be wired from one of the Town’s bank accounts into a business account controlled by Baker, who then withdrew or transferred funds from that account and deposited the money into other accounts he controlled,” the Attorney’s office said.

Of that $310,500, Baker allegedly withdrew $75,000 from the town’s Citibank account with the note “Q1 salary” on Jan. 20, 2023, the indictment said. Three days later, he allegedly withdrew $144,700 from the same Citibank account and deposited it into a Chase account, the indictment said. Next, on Jan. 31, the indictment said he withdrew $89,169.87 from the Citibank account and put it in a cashiers’ check payable to Al Hujen Group, a US Bank account operated by Baker.

The indictment said one of the involved scammers would allegedly pose as vendors and email employees of the targeted companies. The scammer would give the employee fraudulent bank information and direct the employee to make payments to that new account, which was controlled by Baker or co-conspirators, the indictment alleged. 

Advertisement

According to the indictment, the targeted companies and individuals were located across the country.

The Town of Bristol did not immediately reply to a request for comment.

Profile image for Eva Levin

Eva Levin is a general assignment co-op for Boston.com. She covers breaking and local news in Boston and beyond.





Source link

Continue Reading

Rhode Island

Rhode Island's RIBridges system breached in cyberattack targeting personal data – SiliconANGLE

Published

on

Rhode Island's RIBridges system breached in cyberattack targeting personal data – SiliconANGLE


An unknown threat actor has stolen data belonging to potentially hundreds of thousands of residents of Rhode Island in a cyberattack and is threatening to release the data if a payment is not made.

The cyberattack was first detected on Dec. 5 when Rhode Island state officials were informed by its technology vendor, Deloitte Touche Tohmatsu Ltd., that the RIBridges data system had been the target of a potential cyberattack. RIBridges is Rhode Island’s integrated online system for managing public assistance programs.

Forward to Dec. 10 and Deloitte then advised the state that the RIBridges system had been breached and that those behind the breach had sent a screenshot of file folders stolen to Deloitte. The following day, Deloitte confirmed that there was a high probability that the folders contained personally identifiable data from RIBridges.

On Dec. 13, Deloitte confirmed that it had found malicious code in the system. The state then directed Deloitte to shut RIBridges down to remediate the threat.

Advertisement

According to a press release from the governor of Rhode Island, the data stolen may include any individual who has received or applied for health coverage or health and human services programs or benefits. The programs and benefits managed through the RIBridges system include Medicaid, the Supplemental Nutrition Assistance Program, Temporary Assistance for Needy Families, the Child Care Assistance Program, health coverage purchased through HealthSource Rhode Island, Rhode Island Works, Long-Term Services and Supports and the General Public Assistance Program.

Data stolen may include names, addresses, dates of birth, and Social Security numbers, as well as certain banking information. Rhode Island is providing those affected with free credit monitoring and a dedicated call center for assistance.

Data theft isn’t new, but some parts are missing from this story. Ransomware has not been mentioned, nor have any files reported being encrypted. However, ransomware operators in 2024 have been known to skip encryption and simply steal data to extort victims with a promise that the data will be released unless payment is made. Whether such an attack would still count as ransomware versus simply extortion likely doesn’t matter to the victims.

Whatever the finer details, hundreds of thousands of Rhode Island residents have had their personal data stolen weeks before the New Year, a new year that promises even more such attacks as ransomware operators and similar threat groups continue to cast a wide net for victims.

Image: SiliconANGLE/Ideogram

Your vote of support is important to us and it helps us keep the content FREE.

One click below supports our mission to provide free, deep, and relevant content.  

Join our community on YouTube

Join the community that includes more than 15,000 #CubeAlumni experts, including Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger, and many more luminaries and experts.

“TheCUBE is an important partner to the industry. You guys really are a part of our events and we really appreciate you coming and I know people appreciate the content you create as well” – Andy Jassy
Advertisement

THANK YOU



Source link

Continue Reading
Advertisement

Trending