Ian Barker

Passkey vault lock

87 percent of enterprises are deploying passkeys

A new report shows that 87 percent of companies in the US and UK have, or are in the process of, rolling out passkeys with goals tied to improved user experience, enhanced security, and compliance.

The research from the FIDO Alliance, along with underwriters Axiad, HID, and Thales, finds 47 percent report rolling out a mix of device-bound passkeys on physical security keys and/or cards and passkeys synced securely across the user's devices.

By Ian Barker -
EU security NIS2

Navigating NIS 2 compliance [Q&A]

As the European Union updated the Network and Information Security (NIS 2) Directive in October last year, many companies were asking: what does it take to comply with this sweeping new regulation? Designed to tighten cybersecurity across critical industries, NIS 2 goes beyond the original directive’s framework, bringing strict rules, wider sectoral reach, and substantial penalties.

We spoke to Sam Peters, chief product officer at isms.online, to find out what businesses need to know to ensure compliance and understand the directive's impact on both operations and reputation.

By Ian Barker -
Blockchain bricks

Simplifying blockchain implementation for developers [Q&A]

Blockchain technology has often been touted as a game changer for the security of transactions in different fields.

However, many organizations still don't full appreciate its value or how to incorporate it into their applications. We spoke to Lee Jacobson, senior vice president business development Web3 at video game commerce company Xsolla to find out about how blockchain implementation can be made easier.

By Ian Barker -
Compliance rule law and regulation graphic interface for business quality policy

Changes to compliance requirements leave professionals struggling to keep up

The rise of AI and increasing global regulations have raised the stakes for businesses, as they navigate complex requirements to protect sensitive data and ensure ethical practices.

A new survey from trust management platform Drata reveals that 48 percent of governance, risk, and compliance (GRC) professionals struggle to keep pace with updates to existing compliance frameworks and identifying areas needing attention.

By Ian Barker -
Third party risk domino effect

Third-party risk is biggest cybersecurity blind spot

Third-party risk has emerged as a dominant driver of cyber insurance claims and material losses in 2024, according to new data from leading cyber risk solutions company Resilience.

Cyber insurance claims data shows that third-party risk, including ransomware and outages affecting vendors, accounted for 31 percent of all claims in 2024. Even more startling, third-party risk led to claims with incurred losses for the first time ever, making up nearly a quarter (23 percent) of incurred claims in 2024 (compared to none in 2023).

By Ian Barker -
Software architecture development

Security, privacy and AI code reliability are the biggest development challenges

The latest Reveal survey from Infragistics into development concerns shows security (51 percent), AI code reliability (45 percent), and data privacy (41 percent) among their biggest software development challenges for 2025.

AI continues to be a major focus, with 73 percent of tech leaders citing expanding the use of AI within organizations as their top priority for 2025.

By Ian Barker -
Cloud cost money cash

Enterprises set to waste billions due to lack of cloud cost awareness among developers

A disconnect between FinOps and development teams is leading to wasted spend on cloud infrastructure costs according to 52 percent of engineering leaders.

Research from software delivery platform Harness finds developers have limited insight into cloud waste. Fewer than half of respondents say they have access to real time data on idle cloud resources (43 percent), unused or orphaned resources (39 percent), and over or under-provisioned workloads (33 percent).

By Ian Barker -
The AI CPU is generating code

AI code assistants speed up development but add to risks

New research from Apiiro shows that while AI code assistants are accelerating development times they're also increasing risks.

AI code assistants have seen rapid adoption since the launch of ChatGPT in November 2022. Microsoft reports that more than 150 million developers now use GitHub Copilot, up 50 percent over the past two years.

By Ian Barker -
Ransomware key cash

2024 broke records for ransomware attacks

Ransomware attacks reached record levels throughout 2024 according to the latest State of Ransomware report from BlackFog.

LockBit, one of the most prominent ransomware gangs in recent years, remained the most active ransomware variant through 2024 affecting 603 victims. May was the busiest month, with nearly 200 attacks launched, accounting for 36 percent of all attacks that month.

By Ian Barker -
API

99 percent of organizations experience API security issues

A surge in API adoption, driven by the need for organizations to modernize infrastructures and unlock new revenue streams, is contributing to the rise in API security risk according to a new report.

The study from Salt Security finds 99 percent of respondents encountered API security issues within the past 12 months and 55 percent slowed the rollout of a new application due to API security concerns.

By Ian Barker -
DDOS attack, cyber protection. virus detect. Internet and technology concept.

Web DDoS attacks up over 500 percent

The total number of web DDoS attacks surged 550 percent last year compared to 2023, according to the latest report from Radware.

The average duration of network DDoS attacks increased 37 percent over 2023, with North America facing 66 percent of web application and API attacks.

By Ian Barker -
System patching

Addressing the challenge of non-patchable security [Q&A]

While many organizations have solutions in place to identify patchable CVEs, non-patchable security issues such as misconfigurations continue to provide threat actors with consistent access points to exploit organizations.

We spoke to Jason Mar-Tang, field CISO at Pentera, to discuss the challenge of non-patchable security issues vs. CVEs, what makes them so much more difficult to identify, the challenges of remediation, and what standards organizations should implement to tackle this challenge.

By Ian Barker -
Businesswoman in risk metering and management concept

86 percent of commercial codebases expose organizations to risk

Analysis of 965 commercial codebases across 16 industries during 2024 by Black Duck Software finds 86 percent contain open source software vulnerabilities and 81 percent high- or critical-risk vulnerabilities.

Black Duck's Open Source Security and Risk Analysis (OSSRA) report also shows that the number of open source files in an average application has tripled from around 5,300 in 2020 to more than 16,000 in 2024.

By Ian Barker -
Linux automation penguin

New solution automates fixing Linux vulnerabilities

More than ever enterprises are turning to Linux solutions. But while the open source OS has a good reputation for security that doesn't mean that it’s invulnerable and it's important to stay on top of updates and patching.

Seal Security is launching Seal OS, a holistic solution designed to automatically fix vulnerabilities in both Linux operating systems and application code.

By Ian Barker -
Vulnerability security

Record-breaking number of vulnerabilities predicted for 2025

A new report predicts a record-breaking 41,000 to 50,000 new Common Vulnerabilities and Exposures (CVEs) this year, based on data from the National Vulnerability Database (NVD).

The forecast, from the Forum of Incident Response and Security Teams (FIRST), suggests an 11 percent increase compared to 2024, and a whopping 470 percent increase compared to 2023.

By Ian Barker -

© 1998-2025 BetaNews, Inc. All Rights Reserved.