Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

NASDAQ Implements New Security Measures Following Cyber Attack

In a letter sent to customers on Friday, and obtained by SecurityWeek, NASDAQ outlined measures put in place to secure its Directors Desk platform, including changes made since an attack that occurred October of 2010.

In a letter sent to customers on Friday, and obtained by SecurityWeek, NASDAQ outlined measures put in place to secure its Directors Desk platform, including changes made since an attack that occurred October of 2010.

NASDAQ Directors Desk Security

“After the attack, our customers rightly questioned our security. Since then we have made substantial investments to implement additional cutting-edge security enhancements, thereby outpacing our competitors and bringing our security to an industry leading, military-grade level,” the letter explained.

“Our achievements in security are not lost on our new and existing customers. In fact, in the last 12 months, we have increased sales of Directors Desk by 52% and the number of new users increased by more than 170. This is no doubt a measure of the fact that you recognize that we are hyper-focused on providing the most secure environment for our customers.”

Included in the security overview for Directors Desk is the mention of hardened operating system, database, and network perimeter deployments. NASDAQ’s security posture has been subject of several reports suggesting that lax security controls contributed to the 2010 attack against the exchange.

Other security mentions include, AES-256 encryption for data storage, encrypted backups, customer data segregation, IDS systems, extensive integrated logging, alerting, and reporting (SEIM), a policy of least privilege, as well as vulnerability and patch reviewing processes.

The interesting part however was focused on the WebAppSec processed, which include WebApplication Firewalls, annual third-party audits, and the kicker – independent validation against the OWASP Top 10.

“The NASDAQ OMX Information Security Department conducts ongoing security assessments of Directors Desk using multiple leading security testing firms. The independent reviews have been expanded to include the new iPad app that was recently launched,” the security overview explains.

When it comes to disclosure, the final report summaries for the independent testing are included in the Directors Desk Information Security Packet, available to all Directors Desk clients.

Advertisement. Scroll to continue reading.
Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Discover strategies for vendor selection, integration to minimize redundancies, and maximizing ROI from your cybersecurity investments. Gain actionable insights to ensure your stack is ready for tomorrow’s challenges.

Register

Dive into critical topics such as incident response, threat intelligence, and attack surface management. Learn how to align cyber resilience plans with business objectives to reduce potential impacts and secure your organization in an ever-evolving threat landscape.

Register

People on the Move

Cloud security firm Mitiga has appointed Charlie Thomas as Chief Executive Officer.

Cynet announced the appointment of Jason Magee as Chief Executive Officer.

Ajay Garg has joined Saviynt as Chief Development Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.