Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

NASDAQ Implements New Security Measures Following Cyber Attack

In a letter sent to customers on Friday, and obtained by SecurityWeek, NASDAQ outlined measures put in place to secure its Directors Desk platform, including changes made since an attack that occurred October of 2010.

In a letter sent to customers on Friday, and obtained by SecurityWeek, NASDAQ outlined measures put in place to secure its Directors Desk platform, including changes made since an attack that occurred October of 2010.

NASDAQ Directors Desk Security

“After the attack, our customers rightly questioned our security. Since then we have made substantial investments to implement additional cutting-edge security enhancements, thereby outpacing our competitors and bringing our security to an industry leading, military-grade level,” the letter explained.

“Our achievements in security are not lost on our new and existing customers. In fact, in the last 12 months, we have increased sales of Directors Desk by 52% and the number of new users increased by more than 170. This is no doubt a measure of the fact that you recognize that we are hyper-focused on providing the most secure environment for our customers.”

Included in the security overview for Directors Desk is the mention of hardened operating system, database, and network perimeter deployments. NASDAQ’s security posture has been subject of several reports suggesting that lax security controls contributed to the 2010 attack against the exchange.

Other security mentions include, AES-256 encryption for data storage, encrypted backups, customer data segregation, IDS systems, extensive integrated logging, alerting, and reporting (SEIM), a policy of least privilege, as well as vulnerability and patch reviewing processes.

The interesting part however was focused on the WebAppSec processed, which include WebApplication Firewalls, annual third-party audits, and the kicker – independent validation against the OWASP Top 10.

Advertisement. Scroll to continue reading.

“The NASDAQ OMX Information Security Department conducts ongoing security assessments of Directors Desk using multiple leading security testing firms. The independent reviews have been expanded to include the new iPad app that was recently launched,” the security overview explains.

When it comes to disclosure, the final report summaries for the independent testing are included in the Directors Desk Information Security Packet, available to all Directors Desk clients.

Written By

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Rapid7 announced that Wael Mohamed will assume the role of Chief Executive Officer, replacing current Chief Executive Officer Corey Thomas, who will become Executive Chairman of the Board.

Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter.

CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.