<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>MarcoWeb, Cybersecurity &amp; IT Governance</title><description>Cybersecurity analysis, breach case studies, and IT General Controls insights from Marco Cavani.</description><link>https://marcoweb.org/</link><language>en-au</language><item><title>Lapsus$ Bypassed MFA. Cloudflare Did Not Let Them. Here Is the Difference.</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>In 2022, the Lapsus$ group compromised Microsoft, Okta, Samsung, and Nvidia by spamming push MFA notifications until tired users approved. Cloudflare was also targeted. Their FIDO2 hardware keys made the attack irrelevant. Authentication is the control that decides which outcome you get.</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate><category>Authentication</category><category>ITGC</category><category>MFA</category><category>Lapsus$</category><category>FIDO2</category><category>Identity Security</category><category>IT Audit</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>DORA for a Fintech: Turning Operational Resilience into a Legal Duty</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>The EU&apos;s Digital Operational Resilience Act makes surviving an IT disruption a matter of law for financial firms, and fintechs are squarely in scope. Here are the five pillars, the third-party trap, and where the accountability actually sits.</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate><category>DORA</category><category>Fintech</category><category>Operational Resilience</category><category>ICT Risk</category><category>Third-Party Risk</category><category>TLPT</category><category>EU Regulation</category><category>Compliance</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Network Segmentation and VPN for Critical Infrastructure</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>In critical infrastructure a network breach is not a data problem, it is a physical one. Here is why segmentation is the control that keeps a compromised laptop away from a turbine, and why the VPN meant to protect the network is so often the way in.</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate><category>Critical Infrastructure</category><category>Network Segmentation</category><category>VPN</category><category>OT Security</category><category>IEC 62443</category><category>Zero Trust</category><category>ICS</category><category>Cybersecurity</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>SOC 1 for iGaming: Auditing the Financial Database in the Cloud</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>In an online gaming platform the financial truth lives in a database, and that database increasingly lives in the cloud on infrastructure the operator does not run. Here is how a SOC 1 gives assurance over it, and what an auditor actually tests.</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate><category>SOC 1</category><category>iGaming</category><category>Cloud</category><category>Database</category><category>ISAE 3402</category><category>SSAE 18</category><category>ITGC</category><category>Assurance</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>SOC 2 for a SaaS Provider: The Report Your Customers Ask For</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>For a SaaS company, a SOC 2 is the report a serious customer wants before they trust you with their data. Here is what the Trust Services Criteria actually mean, how SOC 2 differs from SOC 1, and how to read one properly.</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate><category>SOC 2</category><category>SaaS</category><category>Trust Services Criteria</category><category>Assurance</category><category>Cloud</category><category>Security</category><category>ITGC</category><category>Vendor Risk</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>SaaS, OS and Database: Auditing the Full Stack of an e-Gaming Platform</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>An e-gaming platform is a stack, not a single system. Audit only the application and you have checked the shop window. Here is how to scope the full three layers, application, operating system and database, in the cloud.</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate><category>e-Gaming</category><category>IT Audit</category><category>SaaS</category><category>Database</category><category>Cloud</category><category>ITGC</category><category>Full Scope</category><category>Shared Responsibility</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Samsung Engineers Sent Proprietary Source Code to ChatGPT. Three Times.</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>In April 2023, Samsung discovered that employees had pasted confidential source code, test sequences, and internal meeting notes into ChatGPT in three separate incidents. The data cannot be retrieved. AI Controls exist to prevent exactly this scenario.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate><category>AI Controls</category><category>ITGC</category><category>Generative AI</category><category>Data Security</category><category>Samsung</category><category>ChatGPT</category><category>IT Audit</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Critical Infrastructure Report: The DP World Port Shutdown and 30,000 Stranded Containers</title><link>https://marcoweb.org/reports/undefined/</link><guid isPermaLink="true">https://marcoweb.org/reports/undefined/</guid><description>In November 2023, a cyberattack forced DP World Australia to take its port operations offline for four days, stranding 30,000 containers at four major Australian ports. The incident demonstrated that a single managed logistics provider&apos;s security posture could be leveraged to disrupt 40 percent of Australia&apos;s container port capacity.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate><category>Critical Infrastructure</category><category>DP World</category><category>Maritime</category><category>Supply Chain</category><category>Port Operations</category><category>Incident Report</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Critical Infrastructure Report: WannaCry and the NHS, When Ransomware Hit the National Health Service</title><link>https://marcoweb.org/reports/undefined/</link><guid isPermaLink="true">https://marcoweb.org/reports/undefined/</guid><description>On 12 May 2017, WannaCry ransomware encrypted devices across 80 NHS organisations in England, forcing the cancellation of at least 19,000 appointments and procedures. This report examines how a nation-state-developed exploit became a criminal weapon and what it exposed about patch management and network segmentation in public health infrastructure.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate><category>Critical Infrastructure</category><category>NHS</category><category>WannaCry</category><category>Healthcare</category><category>EternalBlue</category><category>Incident Report</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Critical Infrastructure Report: The Oldsmar Water Treatment Attack and the Sodium Hydroxide Near-Miss</title><link>https://marcoweb.org/reports/undefined/</link><guid isPermaLink="true">https://marcoweb.org/reports/undefined/</guid><description>On 5 February 2021, an attacker remotely accessed the control system of the Oldsmar, Florida water treatment plant and raised the sodium hydroxide concentration to 111 times the safe level. An alert operator noticed the cursor moving and reversed the change. This near-miss exposed the open remote access vulnerabilities common in small water utilities across the US.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate><category>Critical Infrastructure</category><category>Water Treatment</category><category>Oldsmar</category><category>OT Security</category><category>TeamViewer</category><category>Incident Report</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Critical Infrastructure Report: Shamoon and Saudi Aramco, the Largest Targeted Wiper Attack in History</title><link>https://marcoweb.org/reports/undefined/</link><guid isPermaLink="true">https://marcoweb.org/reports/undefined/</guid><description>On 15 August 2012, the Shamoon malware wiped the master boot records and overwrote data on approximately 30,000 Saudi Aramco workstations. The attack took the world&apos;s most valuable oil company offline for weeks and established the wiper attack as a nation-state weapon against energy infrastructure.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate><category>Critical Infrastructure</category><category>Saudi Aramco</category><category>Shamoon</category><category>Wiper Attack</category><category>Energy Sector</category><category>Incident Report</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Critical Infrastructure Report: The Ukraine Power Grid Attack, the First Confirmed Cyberattack to Cut Electricity</title><link>https://marcoweb.org/reports/undefined/</link><guid isPermaLink="true">https://marcoweb.org/reports/undefined/</guid><description>On 23 December 2015, a coordinated cyberattack by the Sandworm group cut power to approximately 225,000 customers in western Ukraine. It was the first confirmed cyberattack to cause an electricity outage. This report examines the attack chain, the operational technology vulnerabilities it exploited, and what it established for the security of power grid infrastructure globally.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate><category>Critical Infrastructure</category><category>Ukraine</category><category>Power Grid</category><category>Sandworm</category><category>ICS Security</category><category>Incident Report</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Education Incident Report: Why Universities Are the Most Consistently Targeted Sector for Ransomware</title><link>https://marcoweb.org/reports/undefined/</link><guid isPermaLink="true">https://marcoweb.org/reports/undefined/</guid><description>More than 60 percent of UK universities experienced a ransomware or significant cyberattack between 2019 and 2023. This report examines the structural characteristics that make universities persistent ransomware targets, the ITGC control gaps common across the sector, and the specific cases that illustrate the pattern.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate><category>Education</category><category>University</category><category>Ransomware</category><category>Open Networks</category><category>Research Data</category><category>Incident Report</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Healthcare Incident Report: The Medibank Breach and the Weaponisation of Health Data</title><link>https://marcoweb.org/reports/undefined/</link><guid isPermaLink="true">https://marcoweb.org/reports/undefined/</guid><description>In October 2022, REvil-linked actors exfiltrated the health insurance records of 9.7 million Australians from Medibank Private. When the company refused to pay the ransom, the attackers published customers&apos; most sensitive medical data online. This report examines the breach, the control failures, and what happens when health data becomes a coercion instrument.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate><category>Healthcare</category><category>Medibank</category><category>Health Data</category><category>REvil</category><category>Ransomware</category><category>Incident Report</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Financial Services Incident Report: The Latitude Financial Breach and 14 Million Records Through a Service Provider</title><link>https://marcoweb.org/reports/undefined/</link><guid isPermaLink="true">https://marcoweb.org/reports/undefined/</guid><description>In March 2023, attackers used stolen employee credentials from a service provider to access Latitude Financial&apos;s systems, ultimately stealing 14 million customer records including 7.9 million identity document numbers. This report examines the largest confirmed data theft in Australian history, the systemic third-party access failure, and the insurance and consumer finance sector&apos;s data retention exposure.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate><category>Financial Services</category><category>Latitude Financial</category><category>Third-Party Breach</category><category>Identity Documents</category><category>Incident Report</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Legal Sector Incident Report: The HWL Ebsworth Breach and the Law Firm as a Government Data Aggregator</title><link>https://marcoweb.org/reports/undefined/</link><guid isPermaLink="true">https://marcoweb.org/reports/undefined/</guid><description>In April 2023, ALPHV/BlackCat ransomware exfiltrated 4 terabytes of data from HWL Ebsworth, one of Australia&apos;s largest law firms, including data belonging to 65 federal government agency clients. This report examines how law firms function as unintended data aggregators for their clients, and why the legal sector&apos;s cybersecurity posture creates systemic risk for governments and corporations alike.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate><category>Legal</category><category>HWL Ebsworth</category><category>ALPHV BlackCat</category><category>Law Firm Security</category><category>Government Data</category><category>Incident Report</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Telecom Incident Report: The Optus Breach and the Unauthenticated API That Exposed 9.8 Million Australians</title><link>https://marcoweb.org/reports/undefined/</link><guid isPermaLink="true">https://marcoweb.org/reports/undefined/</guid><description>In September 2022, an unauthenticated API endpoint allowed an attacker to systematically enumerate and download the personal records of 9.8 million current and former Optus customers. This report examines the architectural failure, the identity document exposure it created, and what the telecommunications sector&apos;s data obligations mean for ITGC controls.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate><category>Telecommunications</category><category>Optus</category><category>API Security</category><category>Identity Theft</category><category>Data Breach</category><category>Incident Report</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Retail Incident Report: The Woolworths MyDeal Breach and the Post-Acquisition Security Gap</title><link>https://marcoweb.org/reports/undefined/</link><guid isPermaLink="true">https://marcoweb.org/reports/undefined/</guid><description>In October 2022, 2.2 million customer records were stolen from Woolworths&apos; MyDeal e-commerce subsidiary using a compromised employee credential. This report examines how post-acquisition security integration failures create breach conditions, and what the retail sector&apos;s credential-based breach pattern means for ITGC controls.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate><category>Retail</category><category>Woolworths</category><category>MyDeal</category><category>Credential Breach</category><category>M&amp;A Security</category><category>Incident Report</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>LastPass Proves That Penetration Testing Must Cover Your Cloud Environment</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>LastPass was breached twice in 2022. The second breach exploited a DevOps engineer&apos;s home computer to reach cloud backups that held encrypted vaults for 33 million users. Periodic security assessments of the cloud environment should have identified the path. They did not.</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate><category>Periodic Security Assessment</category><category>ITGC</category><category>Penetration Testing</category><category>LastPass</category><category>Cloud Security</category><category>IT Audit</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Uber Paid $100,000 to Cover Up a Breach That a SIEM Should Have Caught</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>In 2016, attackers accessed Uber&apos;s GitHub, found AWS credentials in plain text, and downloaded 57 million user records. The entire attack was detectable. The signals existed. No system was watching and correlating them. That is what a SIEM is for.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate><category>SIEM</category><category>ITGC</category><category>Security Monitoring</category><category>Uber Breach</category><category>Threat Detection</category><category>IT Audit</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Government Incident Report: The Australian Parliament House Network Breach and the Nation-State Threat to Democratic Institutions</title><link>https://marcoweb.org/reports/undefined/</link><guid isPermaLink="true">https://marcoweb.org/reports/undefined/</guid><description>In February 2019, three weeks before the Australian federal election, the Australian Signals Directorate disclosed that the Parliament House network had been breached by a sophisticated state actor. This report examines the threat context, the ITGC implications for government networks, and the broader challenge of defending democratic institutions from nation-state espionage.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><category>Government</category><category>Australia Parliament</category><category>State-Sponsored</category><category>Nation-State</category><category>Espionage</category><category>Incident Report</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>The Breach That Ran for Three Months Because Nobody Watched the Logs</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>Capital One&apos;s 2019 breach exposed 100 million customer records. AWS CloudTrail logs captured every step of the attack in real time. Nobody was watching. Event Logging is the control that turns data into detection.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate><category>Event Logging</category><category>ITGC</category><category>Log Management</category><category>Capital One Breach</category><category>Audit Trail</category><category>IT Audit</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Fintech Incident Report: The Revolut Data Breach and What It Reveals About Third-Party Risk</title><link>https://marcoweb.org/reports/undefined/</link><guid isPermaLink="true">https://marcoweb.org/reports/undefined/</guid><description>In September 2022, a social engineering attack targeting a third-party database provider exposed the personal data of 50,150 Revolut customers. This report examines the incident, the ITGC control failures that enabled it, and the systemic risk facing fintech firms that aggregate sensitive customer data at scale.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>Fintech</category><category>Revolut</category><category>Data Breach</category><category>Third-Party Risk</category><category>Social Engineering</category><category>Incident Report</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Mining Incident Report: Norsk Hydro, LockerGoga, and the Aluminium Smelter That Ran on Paper</title><link>https://marcoweb.org/reports/undefined/</link><guid isPermaLink="true">https://marcoweb.org/reports/undefined/</guid><description>In March 2019, LockerGoga ransomware encrypted Norsk Hydro&apos;s global IT systems, forcing aluminium smelters to switch to manual operations and costing the company approximately USD $71 million. This report examines how a credential compromise became a production shutdown, and what IT/OT convergence means for mining sector cybersecurity controls.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>Mining</category><category>Norsk Hydro</category><category>LockerGoga</category><category>OT Security</category><category>Ransomware</category><category>Incident Report</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Pharmaceutical Incident Report: Merck, NotPetya, and the $1.3 Billion Cost of an Uninsured Cyberwar</title><link>https://marcoweb.org/reports/undefined/</link><guid isPermaLink="true">https://marcoweb.org/reports/undefined/</guid><description>In June 2017, the NotPetya wiper destroyed 30,000 of Merck&apos;s computer systems, halted pharmaceutical manufacturing, and resulted in estimated losses of USD $1.3 billion. This report examines the incident, its specific implications for regulated pharmaceutical environments, and the ITGC control failures that amplified the damage.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>Pharmaceutical</category><category>Merck</category><category>NotPetya</category><category>Manufacturing</category><category>Disaster Recovery</category><category>Incident Report</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>The Vendor in Your Network: Why Third Party Management Is an ITGC Control</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>Attackers do not always break through your front door. Sometimes they walk in through a vendor&apos;s access. The Target breach is the textbook case, and the lessons still apply a decade later.</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate><category>Third Party Management</category><category>ITGC</category><category>Vendor Risk</category><category>Supply Chain Security</category><category>Target Breach</category><category>IT Audit</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>The Equifax Breach Was On the Risk Register: The IT Risk Management Failure Nobody Talks About</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>Equifax knew about the Apache Struts vulnerability. A patch existed. The risk was real and documented. The breach happened anyway. That is the definitive case for why IT Risk Management is an audit control, not a planning exercise.</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate><category>IT Risk Management</category><category>ITGC</category><category>Risk Register</category><category>Equifax</category><category>Vulnerability Management</category><category>IT Audit</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>How a Flat Network Let Attackers Hide in Marriott for Four Years</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>When Marriott acquired Starwood in 2016, they inherited a compromised network. Because the two environments were poorly segmented, attackers moved freely for four years. Network Architecture is the control that determines how far a breach can travel.</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate><category>Network Architecture</category><category>ITGC</category><category>Network Segmentation</category><category>Marriott Breach</category><category>Defence in Depth</category><category>IT Audit</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>SolarWinds and the Firewall Rules Nobody Reviewed</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>The SolarWinds SUNBURST attack compromised 18,000 organisations. The malware called home for months. Egress filtering and network security controls should have caught it. Here is what was missing and what auditors check.</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate><category>Network Security Controls</category><category>ITGC</category><category>Firewall</category><category>SolarWinds</category><category>Egress Filtering</category><category>IT Audit</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>WannaCry Didn&apos;t Need a Zero-Day: It Needed Unpatched Endpoints</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>In May 2017, WannaCry ransomware spread across 150 countries in hours. The NHS lost 19,000 appointments. The vulnerability it exploited had been patched two months earlier. Endpoint protection is the control that closes that gap.</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate><category>Endpoint Protection</category><category>ITGC</category><category>WannaCry</category><category>EDR</category><category>Patch Management</category><category>NHS</category><category>IT Audit</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>730,000 Client Records on a Home Server: The Morgan Stanley DLP Failure</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>A Morgan Stanley financial adviser downloaded the details of 730,000 clients to a personal device over 18 months. Data Loss Prevention controls should have caught it. When they did not, the cost was a $1 million regulatory fine and a breach affecting nearly a million people.</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate><category>Data Loss Prevention</category><category>ITGC</category><category>DLP</category><category>Insider Threat</category><category>Morgan Stanley</category><category>IT Audit</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Log4Shell: When a Logging Library Becomes the World&apos;s Biggest Attack Surface</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>In December 2021, a critical vulnerability in the Log4j logging library put hundreds of millions of devices at risk. The flaw had existed for years. Exploitation appeared within hours of disclosure. Vulnerability Management is the only control that closes that window.</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate><category>Vulnerability Management</category><category>ITGC</category><category>Log4Shell</category><category>CVE</category><category>Patch Management</category><category>IT Audit</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Why IT Governance Is the Control That Governs All Controls</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>IT Governance sets the tone from the top. When boards and executives treat cybersecurity as someone else&apos;s problem, attackers treat your organisation as their next target. The Colonial Pipeline breach proved it.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>IT Governance</category><category>ITGC</category><category>COBIT</category><category>Board Accountability</category><category>Colonial Pipeline</category><category>IT Audit</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Mastering Incident Response: Key Insights from the NIST Guide</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>A strategic deep-dive into NIST&apos;s Computer Security Incident Handling Guide, covering the full IR lifecycle, team structure, detection methods, prioritisation frameworks, and the power of post-incident learning.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate><category>Incident Response</category><category>NIST</category><category>SOC</category><category>Blue Team</category><category>Detection</category><category>Containment</category><category>Cybersecurity Framework</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Australia&apos;s New Privacy Act: A Wake-Up Call for Businesses</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>Australia&apos;s revised Privacy Act hands consumers new powers and puts businesses on the hook for data breaches. With AI lowering the bar for cybercriminals, here&apos;s what organisations must do now.</description><pubDate>Sat, 18 Jan 2025 00:00:00 GMT</pubDate><category>Privacy Act</category><category>Australia</category><category>Data Security</category><category>OAIC</category><category>Compliance</category><category>AI</category><category>CrowdStrike</category><category>Regulation</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Understanding the Cost of Data Breaches</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>Key insights from IBM&apos;s Cost of a Data Breach report: healthcare leads at $10.1M per breach, while AI platforms, DevSecOps, and incident response teams can significantly cut costs.</description><pubDate>Wed, 15 Jan 2025 00:00:00 GMT</pubDate><category>Data Breach</category><category>IBM</category><category>Cost Analysis</category><category>Healthcare</category><category>AI Security</category><category>DevSecOps</category><category>Incident Response</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>The Growing Threat of Phishing in 2024: A Gateway Crime</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>Nearly 1.9 million phishing attacks in a single year, $4.5M average breach recovery cost, and seniors losing $3.4B. The data on phishing in 2024 is staggering. Here&apos;s what organisations must do.</description><pubDate>Sat, 28 Dec 2024 00:00:00 GMT</pubDate><category>Phishing</category><category>Cybercrime</category><category>BEC</category><category>Social Engineering</category><category>Cyber Awareness</category><category>Data Breach</category><category>2024</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>The Casino Hack: How Scattered Spider Took Down MGM Resorts</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>MGM Resorts International suffered a $100M cyberattack in 2023; slot machines went dark, room keys failed, booking systems crashed. Here&apos;s exactly how Scattered Spider did it.</description><pubDate>Tue, 03 Sep 2024 00:00:00 GMT</pubDate><category>Scattered Spider</category><category>MGM Resorts</category><category>Ransomware</category><category>Social Engineering</category><category>BlackCat</category><category>Okta</category><category>Vishing</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Scattered Spider: The Casino Hacks</title><link>https://marcoweb.org/reports/undefined/</link><guid isPermaLink="true">https://marcoweb.org/reports/undefined/</guid><description>In 2023, a hacking group known as Scattered Spider or UNC3944 made headlines for its sophisticated cyberattacks on two of the largest casino companies in the United States: Caesars Entertainment and MGM Resorts International.</description><pubDate>Tue, 03 Sep 2024 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Ransomware</category><category>Social Engineering</category><category>Threat Intelligence</category><category>Casino Security</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Deepfake Awareness: The AI Threat You Can&apos;t Always See</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>How Generative Adversarial Networks are being weaponised by cybercriminals, why regulators are scrambling to catch up, and what individuals and organisations can do to protect themselves.</description><pubDate>Fri, 14 Jun 2024 00:00:00 GMT</pubDate><category>Deepfake</category><category>AI</category><category>Social Engineering</category><category>Fraud</category><category>Machine Learning</category><category>GAN</category><category>Cybercrime</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Information Security Analysis for Western Power</title><link>https://marcoweb.org/reports/undefined/</link><guid isPermaLink="true">https://marcoweb.org/reports/undefined/</guid><description>A comprehensive assessment and strategic roadmap for Western Power, addressing key challenges in cybersecurity, insider threats, and climate change resilience for one of Australia&apos;s largest electricity distributors.</description><pubDate>Tue, 20 Feb 2024 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Critical Infrastructure</category><category>Information Security</category><category>Australia</category><category>Energy Sector</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>The Crucial Role of Information Security in Critical Infrastructure</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>An in-depth analysis of why information security is vital for critical infrastructure operators, covering CIA triad principles, classification frameworks, and the real-world consequences of cyber disruptions.</description><pubDate>Thu, 05 Oct 2023 00:00:00 GMT</pubDate><category>Information Security</category><category>Critical Infrastructure</category><category>CIA Triad</category><category>NIST</category><category>PSPF</category><category>Western Power</category><category>Risk Management</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Boss of The SOC V3 Timeline</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>A chronological account of the BOTSv3 security incident on 20 August 2018, categorised by MITRE ATT&amp;CK tactics, from initial access and phishing through to exfiltration and a Memcached DDoS attack.</description><pubDate>Sun, 28 May 2023 00:00:00 GMT</pubDate><category>MITRE ATT&amp;CK</category><category>BOTSv3</category><category>Incident Response</category><category>Blue Team</category><category>SIEM</category><category>Splunk</category><category>CTF</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Exploring Zero-Day Vulnerabilities</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>A vendor-based analysis of zero-day vulnerabilities from 2006 to 2023, revealing which companies are most associated with exploitable weaknesses, and what organisations can learn from the patterns.</description><pubDate>Wed, 17 May 2023 00:00:00 GMT</pubDate><category>Zero-Day</category><category>Vulnerabilities</category><category>Microsoft</category><category>Threat Intelligence</category><category>NIST</category><category>Patch Management</category><author>marco@marcoweb.org (Marco Cavani)</author></item><item><title>Governance: A Cybersecurity Lifeline for SMEs</title><link>https://marcoweb.org/blog/undefined/</link><guid isPermaLink="true">https://marcoweb.org/blog/undefined/</guid><description>How cybersecurity governance frameworks help small and medium enterprises identify, assess, and manage risks, and why the most impacted businesses in Australia are often the ones with the least protection.</description><pubDate>Thu, 02 Mar 2023 00:00:00 GMT</pubDate><category>Governance</category><category>SME</category><category>Cybersecurity</category><category>NIST</category><category>Risk Management</category><category>ACSC</category><author>marco@marcoweb.org (Marco Cavani)</author></item></channel></rss>