Friday, 21 September 2012
Perhaps the biggest & most widespread security gaffe of all
Posted on 09:35 by Unknown
Tuesday, 11 September 2012
GoDaddy: 'Malfunction' as the new scapegoat?
Posted on 12:22 by Unknown
We've been hearing about 'computer glitch' for a while. That's what the talking heads on the news always cite when something goes awry with a computer system. Perhaps 'malfunction' is the new scapegoat? That's the route GoDaddy is taking. They say it was a 'malfunction', not hacking, that took them and presumably hundreds of thousands (millions?) of other systems offline for hours yesterday.
I'm sure it had nothing to do with poor planning...or people making bad choices. That'd be too simple...and too responsible. It's easier to blame computer problems on the obscure - something that can't be understood - much less proven - by the general population, even forensics analysts.
Calling a network outage a 'malfunction' is similar to how legal counsel encourage executives to refer to security breaches as 'events'. In the end, a business continuity problem is a business continuity problem. It's your responsibility.
Stuff's going to happen. You just have to ask yourself what needs to be done to minimize the impact to your business. Don't wait until the you know what hits the fan to try to figure it out. Here's some material I've written that can help you get started down this path.
I'm sure it had nothing to do with poor planning...or people making bad choices. That'd be too simple...and too responsible. It's easier to blame computer problems on the obscure - something that can't be understood - much less proven - by the general population, even forensics analysts.
Calling a network outage a 'malfunction' is similar to how legal counsel encourage executives to refer to security breaches as 'events'. In the end, a business continuity problem is a business continuity problem. It's your responsibility.
Stuff's going to happen. You just have to ask yourself what needs to be done to minimize the impact to your business. Don't wait until the you know what hits the fan to try to figure it out. Here's some material I've written that can help you get started down this path.
Thursday, 16 August 2012
You can't buy security for $1, but some people will fall for it
Posted on 07:38 by Unknown
I recently deposited a check at a giant monster mega bank that's continually trying to sell me new services and the teller asked: "Would you like to buy identity theft protection for just $1 today?"
Wow, really...so you're saying my personal information will be safe and secure for a mere $1...!? Amazing...but no thanks. Sadly, many in management are like the average consumer: they just don't realize what it takes to ensure information security. No it's not just about anti-virus, or firewalls or that little lock thingy in our Web browsers. No, it's about some set of unenforceable policies sitting on a shelf that no one knows about. Nor is it those silly marketing slicks telling us our privacy "rights".
It's not that simple.
Don't you just know that, right now, this very bank has laptops, tablets, smartphones and the like chock full of sensitive information waiting to be exploited in when a loss or theft occurs. The general public doesn't get security...that's why these banks are successful in selling services that people don't need. I'm not complaining...it's good for our field.
Sadly, consumer ignorance and the unwillingness to question how personal information is handled will be overlooked while, at the same time, many of these very consumers will blame the big evil corporations for trying to make a profit. Who's the real dummy here?
Side note: identity theft protection is not a bad thing to have...Based on what I see in my information security assessment work, I wouldn't dare be without it! Just don't pay for it...Not even $1. Here's some info on how you can get it for free.
Wow, really...so you're saying my personal information will be safe and secure for a mere $1...!? Amazing...but no thanks. Sadly, many in management are like the average consumer: they just don't realize what it takes to ensure information security. No it's not just about anti-virus, or firewalls or that little lock thingy in our Web browsers. No, it's about some set of unenforceable policies sitting on a shelf that no one knows about. Nor is it those silly marketing slicks telling us our privacy "rights".
It's not that simple.
Don't you just know that, right now, this very bank has laptops, tablets, smartphones and the like chock full of sensitive information waiting to be exploited in when a loss or theft occurs. The general public doesn't get security...that's why these banks are successful in selling services that people don't need. I'm not complaining...it's good for our field.
Sadly, consumer ignorance and the unwillingness to question how personal information is handled will be overlooked while, at the same time, many of these very consumers will blame the big evil corporations for trying to make a profit. Who's the real dummy here?
Side note: identity theft protection is not a bad thing to have...Based on what I see in my information security assessment work, I wouldn't dare be without it! Just don't pay for it...Not even $1. Here's some info on how you can get it for free.
Tuesday, 14 August 2012
Aiming for the CISSP? Check out this book.
Posted on 05:41 by Unknown
I recently completed the technical edits for the new book CISSP For Dummies, 4th edition. It's a great book (not because of my contribution!) that I wish I would've had when I was studying for my CISSP test back in 2001. If you're prepping for the CISSP exam or just want to brush up on the fundamental concepts of information security, this book is a must-have. Just keep in mind what I've always said, certifications are only part of the information security career equation.
Interesting side note: Years ago, around the time I first wrote Hacking For Dummies, Wiley approached me to write CISSP For Dummies. I had too much going on at the time so I declined the offer. Now that I see what this book has evolved into, I'm glad I didn't agree to write it! I believe Peter Gregory and Larry Miller did it more justice than I ever could have. Check it out.
Wednesday, 8 August 2012
Pressure washer v. university data center...guess who wins?
Posted on 16:33 by Unknown
Oops, Georgia State University forgot to check their data center for leaks. Okay, I'm not going to pick on my friends at GSU. In their defense you cannot - in any way, shape, form or fashion - predict or plan for every possible disaster recovery/business continuity scenario or outcome. But a threat exploiting a weakness that knocks phones and Internet access out for five hours, this is a great example. Add it to your list.
Tuesday, 24 July 2012
This week's webcast on common sense security
Posted on 13:29 by Unknown
Join me and Phil Owens of GFI tomorrow (Wednesday July 24, 2012) as we wax poetic about what it really takes to have a reasonable layered security defense against malware:
Defense in Depth: The Layered Approach to IT Security
Crashed systems, data theft, decreased productivity, revenue loss, reputation loss – today’s malware threats can cause critical damage to your business. IT professionals, now more than ever, need a method of in-depth protection to effectively defend their information, devices and network. They need layered security.
Watch this Ziff Davis B2B webcast to determine if your current security measures are doing enough. Phil Owens of GFI and independent information security expert Kevin Beaver of Principle Logic will provide insight into:
Crashed systems, data theft, decreased productivity, revenue loss, reputation loss – today’s malware threats can cause critical damage to your business. IT professionals, now more than ever, need a method of in-depth protection to effectively defend their information, devices and network. They need layered security.
Watch this Ziff Davis B2B webcast to determine if your current security measures are doing enough. Phil Owens of GFI and independent information security expert Kevin Beaver of Principle Logic will provide insight into:
- How malware can impact your business
- The latest malware attack vectors
- The importance of employee education
- Why you need layered security
Interesting quote on human psyche that relates to infosec
Posted on 05:52 by Unknown
I just saw the following quote from publisher Malcolm Forbes that underscores the very essence of the problems we see in information security, business and life in general:
Indeed, so many people want to control or break down (they're one in the same) others because their own lives are out of control. They simply don't believe in themselves. Like how exercise and good nutrition translate to healthy living, the problems we face are solved by simple means. It's a matter of choice.
"Too many people overvalue what they are not and undervalue what they are."
Indeed, so many people want to control or break down (they're one in the same) others because their own lives are out of control. They simply don't believe in themselves. Like how exercise and good nutrition translate to healthy living, the problems we face are solved by simple means. It's a matter of choice.
Subscribe to:
Posts (Atom)