With the threat landscape evolving rapidly, it is more important than ever for IT Managers to have confidence in their network security. As the first line of defense, your firewalls need real-time centralized management to properly enforce your security...
Bring Your Own Device (BYOD) has crossed the chasm from a bleeding edge to an early adopter technology. According to IDC, more than half the companies they recently surveyed already let employees use their own smart devices within the...
Over the years, I have found that there are three opposing forces when it comes to the procurement of new technology investment. IT, the line of business, and the sourcing/supply chain. All organizations have a vested interest in these forces...
Mobile security has become a hyper-sensitive topic in many business conversations today. A CIO magazine article headline in January proclaiming “Mobile Attacks Top the List of 2013 Security Threats” echoes this sentiment and a report by...
In my experience working with hundreds of companies pursing Payment Card Industry Data Security Standard (PCI DSS) compliance, I have recognized a few trends. Like all spectrums, two extremes exist. On one end of the spectrum...
In just the past year, businesses of all types have been under attack. Some of these attacks have been very public; others have received less notoriety. But make no mistake, every major business segment was affected in some way, from...
Data collection and its use and security are creating healthy discussions within the healthcare industry. I recently conducted a Q&A session with Janice McCallum, managing director of Content Advisors and a leading Health IT thought...
Last time I checked, the AT&T global network was reportedly carrying over 43 petabytes of data on the average business day. That’s what I call Big Data! To put 43 PB into perspective, that is the digital equivalent of transmitting the U.S. Library of Congress every 12 and 3/4 minutes. Or imagine a stack of typical CD-ROMs that would stretch over 55 miles high....
The rules governing the PCI DSS can be complex and confusing . When coupled with the 250+ requirements, and their dependencies, it can be a daunting task to understand to which systems the standard applies, and which requirements apply under what conditions. In training thousands of QSAs, merchants, and banks, I have developed a concept that helps...
It has become impossible to avoid the headlines announcing that our data is being breached, from credit card information and social security numbers to other personal information. Each day, it seems there are reports of nefarious behavior happening in our Internet / cyber world environment. Due to this, there are five questions I challenge you to consider:...
The clock is ticking down to Sept. 23, 2013, the HIPAA final omnibus rule deadline. If you’re a hospital or health system, do you have “reasonable and appropriate administrative, technical and physical safeguards” in place to help protect your...
A couple of weeks ago, a major news service’s Twitter account was hacked, and several fake tweets not only sent ripples through the media, they impacted stocks globally. While there’s a key lesson here about the importance of social media, this...
Are you in business to make money or lose it? For most people, the answer to this question is a no brainer! As a security professional, I truly believe that security can impact your bottom line. It is key to protecting your most vulnerable business asset – your data. If your business has anything worth protecting, whether it’s money, intellectual property, or a trusted...
Security and risk awareness have been part of the lives of humans from the very earliest days. At its core, security focuses on keeping things safe. In a business environment, complete safety can restrict access and availability, and is therefore impractical. Focusing solely on security, without balancing associated risk, is unrealistic, as businesses need to take certain risks to grow and be profitable. Let’s look at the history of...
I read almost daily in the news about cyber attacks on U.S. banks, infrastructure, government agencies, and businesses. In fact, government agencies saw a more than 650% increase in cyber security incidents from 2006 to 2010, according to the Government Accountability Office (GAO). The GAO reports that a main reason for the increase is the failure of agencies to fully implement their IT security programs....
Every day corporate networks are faced with increasingly complex threats to IT security. But there’s an entirely new approach that can help you minimize risks. It’s called “Orbital Security”—and it just might save your company’s data. Orbital Security allows you to create an IT security strategy based on the relationships your company has...
The cyber-threat landscape is in a constant state of evolution. Threats and attacks are increasing in frequency and complexity. Nowhere is that more evident than in the onslaught of Distributed Denial of Service (DDoS) attacks almost constantly assaulting organizations of all sizes. IT leaders looking to...
Have you ever tried to move an object by pushing a rope? How about herding cats? Tell me if this video reminds me of your workplace. Doesn’t make much sense, right?...
At Mobile World Congress, Samsung announced an end-to-end secure Android solution that provides security hardening from the hardware through to the application layer called KNOX. This announcement is another indication of the evolving world of security that is being driven by the adoption of mobility and...
For security professionals 2012 was a very exciting year. We saw some major changes in information security attack strategies, known as vectors, and an increase in their public visibility. Advanced Persistent Threats (APTs) became more common and mobile and wireless security came into the forefront of our...
These days, we use mobile devices for just about everything, from online purchases while we’re standing in line at the coffee shop to managing our bank accounts and storing confidential data. “Human factor” is often cited as one of the weakest links in...