Tech Support For Dummies

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 25 September 2012

Be it in healthcare or infosec, the short term is for losers

Posted on 08:03 by Unknown
With all the doctor & hospital visits I've gone (and am still going) through with family members in the past few years, I've come to the conclusion that many (most?) healthcare providers - especially those smart doctors society holds on a pedestal - absolutely cannot see the big picture. They can't think past the appointment time slot in which they're currently working, much less next year and beyond.

Adding to the problem, the left hand never talks to the right so everyone is engaging in their own area of "expertise" yet nothing gets done at a higher level and the patient is the one who ends up suffering because of this approach. Here's an example of what I'm talking about...this is the hospital meal that my father received after going in for a suspected heart attack:

The Dinner of Champions

What's wrong with this picture!? Luckily, for us, it ended up being symptoms from a hiatal hernia. Whew. But still...? Come on healthcare professionals! Hey, at least our beloved Obama is going to fix this...(ha!).

The problem of not seeing the big picture is very common among business execs and even many IT professionals who just don't get what information security is all about. We see it everywhere, especially when data breaches occur...But we also see it when our own peers claim the sky is falling because of the latest Adobe Reader zero day exploit or the Web interface on someone's printer is susceptible to CSRF. Amazing....sad.

The desire for immediate gratification leads to a lot of bad choices. Ask any success/achievement expert and he or she will tell you that the lack of time perspective is one of the greatest problems in society - arguably the one thing that holds people back the most. It certainly has an impact on IT and information security.

If you want to stand out among the noise and the ignorance associated with IT and information security, think long-term in all the decisions you make. Don't expect short-term perfection in your security program. Instead, aim for incremental improvements over time.The missing link is actually making those incremental improvements over time...As Henri Frederic Amiel once said “The person who insists upon seeing with perfect clearness before he or she decides, never decides.” This is no doubt the root cause of the problems we can't seem to solve.
Read More
Posted in automated scanner oversights, careers, government intrusion, government regulations, information security quotes, personal responsibility, scary stuff, stupid security, thinking long term | No comments

Friday, 21 September 2012

Perhaps the biggest & most widespread security gaffe of all

Posted on 09:35 by Unknown

Read More
Posted in disaster recovery, incident response, personal responsibility, scary stuff, stupid security, thinking long term | No comments

Tuesday, 11 September 2012

GoDaddy: 'Malfunction' as the new scapegoat?

Posted on 12:22 by Unknown
We've been hearing about 'computer glitch' for a while. That's what the talking heads on the news always cite when something goes awry with a computer system. Perhaps 'malfunction' is the new scapegoat? That's the route GoDaddy is taking. They say it was a 'malfunction', not hacking, that took them and presumably hundreds of thousands (millions?) of other systems offline for hours yesterday.

I'm sure it had nothing to do with poor planning...or people making bad choices. That'd be too simple...and too responsible. It's easier to blame computer problems on the obscure - something that can't be understood - much less proven - by the general population, even forensics analysts.
 
Calling a network outage a 'malfunction' is similar to how legal counsel encourage executives to refer to security breaches as 'events'. In the end, a business continuity problem is a business continuity problem. It's your responsibility.

Stuff's going to happen. You just have to ask yourself what needs to be done to minimize the impact to your business. Don't wait until the you know what hits the fan to try to figure it out. Here's some material I've written that can help you get started down this path.
Read More
Posted in business continuity, hacking, incident response, personal responsibility, stupid security, thinking long term | No comments

Thursday, 16 August 2012

You can't buy security for $1, but some people will fall for it

Posted on 07:38 by Unknown
I recently deposited a check at a giant monster mega bank that's continually trying to sell me new services and the teller asked: "Would you like to buy identity theft protection for just $1 today?"

Wow, really...so you're saying my personal information will be safe and secure for a mere $1...!? Amazing...but no thanks. Sadly, many in management are like the average consumer: they just don't realize what it takes to ensure information security. No it's not just about anti-virus, or firewalls or that little lock thingy in our Web browsers. No, it's about some set of unenforceable policies sitting on a shelf that no one knows about. Nor is it those silly marketing slicks telling us our privacy "rights".

It's not that simple.

Don't you just know that, right now, this very bank has laptops, tablets, smartphones and the like chock full of sensitive information waiting to be exploited in when a loss or theft occurs. The general public doesn't get security...that's why these banks are successful in selling services that people don't need. I'm not complaining...it's good for our field.

Sadly, consumer ignorance and the unwillingness to question how personal information is handled will be overlooked while, at the same time, many of these very consumers will blame the big evil corporations for trying to make a profit. Who's the real dummy here?

Side note: identity theft protection is not a bad thing to have...Based on what I see in my information security assessment work, I wouldn't dare be without it! Just don't pay for it...Not even $1. Here's some info on how you can get it for free.

Read More
Posted in identity theft, laptop encryption, mobile security, privacy, scary stuff, stupid security, uncool products | No comments

Tuesday, 14 August 2012

Aiming for the CISSP? Check out this book.

Posted on 05:41 by Unknown



I recently completed the technical edits for the new book CISSP For Dummies, 4th edition. It's a great book (not because of my contribution!) that I wish I would've had when I was studying for my CISSP test back in 2001. If you're prepping for the CISSP exam or just want to brush up on the fundamental concepts of information security, this book is a must-have. Just keep in mind what I've always said, certifications are only part of the information security career equation.

Interesting side note: Years ago, around the time I first wrote Hacking For Dummies, Wiley  approached me to write CISSP For Dummies. I had too much going on at the time so I declined the offer. Now that I see what this book has evolved into, I'm glad I didn't agree to write it! I believe Peter Gregory and Larry Miller did it more justice than I ever could have. Check it out.
Read More
Posted in certifications, cissp, cool products, recommended books | No comments

Wednesday, 8 August 2012

Pressure washer v. university data center...guess who wins?

Posted on 16:33 by Unknown
Oops, Georgia State University forgot to check their data center for leaks. Okay, I'm not going to pick on my friends at GSU. In their defense you cannot - in any way, shape, form or fashion - predict or plan for every possible disaster recovery/business continuity scenario or outcome. But a threat exploiting a weakness that knocks phones and Internet access out for five hours, this is a great example. Add it to your list.
Read More
Posted in business continuity, stupid security | No comments

Tuesday, 24 July 2012

This week's webcast on common sense security

Posted on 13:29 by Unknown
Join me and Phil Owens of GFI tomorrow (Wednesday July 24, 2012) as we wax poetic about what it really takes to have a reasonable layered security defense against malware:

Defense in Depth: The Layered Approach to IT Security 
Crashed systems, data theft, decreased productivity, revenue loss, reputation loss – today’s malware threats can cause critical damage to your business. IT professionals, now more than ever, need a method of in-depth protection to effectively defend their information, devices and network. They need layered security.

Watch this Ziff Davis B2B webcast to determine if your current security measures are doing enough. Phil Owens of GFI and independent information security expert Kevin Beaver of Principle Logic will provide insight into:
  • How malware can impact your business
  • The latest malware attack vectors
  • The importance of employee education
  • Why you need layered security
I hope you'll consider joining in! You can register here.


Read More
Posted in Kevin's security content, malware, message from Kevin, webcasts | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Reaver Pro: a simple tool for cracking WPA on a LOT of wireless networks
    If wireless security testing is on your radar, you need to get Reaver Pro . As I outlined in this Hacking For Dummies, 4th edition chapter ,...
  • Low information users and the challenges they create
    Thanks to the political elite and the dumb masses they inspire, you've probably heard the term low information voter …In a nutshell, thi...
  • "Top Blogs" list & some home security considerations
    I think I may have found the first sign that my blog is growing and gaining some traction. I've made it to the Top 20 Home Security Blog...
  • Wooo...HIPAA audits are coming & the irony of KPMG's involvement
    I've always believed that compliance is a threat to business [hence why I help businesses take the pain out of compliance by addressing ...
  • Windows 8.1 changes/enhancements, BitLocker's improvements, and related Windows mobile/security tips
    In addition to my independent information security assessments through my consultancy Principle Logic , I've been writing a ton...includ...
  • What you need to know about security vulnerability assessments (that no one is willing to share)
    I'd love it if you'd join me over at SearchSecurity.com next week where I'll be talking about the rest of the story regarding ...
  • Sprechen Sie Deutsch? Hacking For Dummies now in German!
    Check out the latest foreign-language edition of my book Hacking For Dummies: Hacking For Dummies is now in 6 languages: English, Estonian, ...
  • It's hard being human
    Cavett Robert once said something about character that resonates within information security - especially regarding ongoing management and l...
  • Experiencing problems with authenticated web vulnerability scans? Try NTOSpider.
    You're performing authenticated web vulnerability scans , right? If you're not, you're missing out...big time. When performing a...
  • The compliance crutch mentality rides on
    I believe it was my colleague Kevin Bocek who once said: "Security done right will yield compliance for free. Compliance for complianc...

Categories

  • active directory
  • application firewalls
  • APTs
  • aslr
  • atm security
  • audio programs
  • audit logging
  • automated scanner oversights
  • back to basics
  • backups
  • big brother
  • bitlocker
  • budget
  • business case for security
  • business continuity
  • BYOD
  • car hacking
  • careers
  • certifications
  • change management
  • checklist audits
  • cissp
  • clear wireless
  • cloud computing
  • communication
  • compliance
  • computer glitch
  • conferences
  • consulting
  • content filtering
  • cool products
  • cool sites
  • cross-site request forgery
  • cross-site scripting
  • csrf
  • customer no service
  • cybersecurity bill
  • data at rest
  • data breach laws
  • data breaches
  • data centers
  • data destruction
  • data leakage
  • data protection
  • data retention
  • database security
  • degrees
  • desktop management
  • disaster recovery
  • disk imaging
  • disposal
  • dns
  • document security
  • domino
  • DoS attacks
  • drive encryption
  • e-discovery
  • ediscovery
  • employee monitoring
  • encrypting data in transit
  • encryption
  • end point security
  • ethical hacking
  • exchange
  • experience
  • expert witness
  • exploits
  • facebook
  • FERPA
  • file integrity monitoring
  • firewalls
  • forensics
  • full disk encryption
  • global warming
  • goal setting
  • good blogs
  • government intrusion
  • government regulations
  • great quotes
  • hacking
  • hardware
  • hipaa
  • hitech
  • hitech act
  • home security
  • humor
  • identity access management
  • identity theft
  • IIS
  • incident response
  • information classification
  • information security quotes
  • intel
  • intellectual property
  • internal threat
  • java
  • Kevin's books
  • Kevin's interviews
  • Kevin's keynotes
  • kevin's panels
  • kevin's quotes
  • Kevin's security content
  • Kevin's seminars
  • Kevin's videos
  • laptop encryption
  • laptop security
  • legal
  • Linux
  • locking screens
  • low-hanging fruit
  • malware
  • marketing hype
  • message from Kevin
  • messaging security
  • metasploit
  • metrics
  • mobile apps
  • mobile security
  • motivation
  • multi-factor authentication
  • network analysis
  • network complexities
  • network protocols
  • network security
  • networking essentials
  • Novell
  • office
  • online backup
  • online safety
  • open source security
  • owasp
  • p2p
  • passwords
  • patch management
  • patching
  • pci 6.6
  • pci dss
  • PCNAA
  • penetration testing
  • people problems
  • personal responsibility
  • phishing
  • physical security
  • pii
  • podcasts
  • policy enforcement
  • politics
  • presentations
  • privacy
  • quality assurance
  • recommended books
  • recommended magazines
  • recycling
  • remote access security
  • ridiculous password requirements
  • risk analysis
  • risk management
  • rogue insiders
  • ROI
  • RSA 2012
  • running a business
  • saas
  • salary
  • scary stuff
  • sccm
  • sdlc
  • security assessments
  • security audits
  • security awareness
  • security committees
  • security leadership
  • security management
  • security operations
  • security policies
  • security policy
  • security scans
  • security standards
  • security statistics
  • security technologies
  • security testing tools
  • security tools
  • selling security
  • sharepoint
  • small business
  • smartphone security
  • SMBs
  • social media
  • software development
  • source code
  • source code analysis
  • special offer
  • SQL injection
  • sql server
  • ssl
  • storage security
  • student information systems
  • stupid security
  • success
  • telecommuting
  • testimonials
  • thinking long term
  • third-party applications
  • threat modeling
  • time management
  • training
  • twitter
  • uncool products
  • unstructured information
  • unstructured infromation
  • user awareness
  • vendors
  • virtual machine security
  • visibility
  • voip
  • vulnerability assessments
  • web 2.0
  • web application security
  • web browser security
  • web server security
  • webcasts
  • WebInspect
  • whitelisting
  • whitepapers
  • Windows
  • Windows 7
  • windows 8
  • windows 8.1
  • Windows Mobile
  • windows security
  • Windows Vista
  • wireless
  • wireless security
  • zero tolerance

Blog Archive

  • ▼  2013 (35)
    • ▼  November (3)
      • Reaver Pro: a simple tool for cracking WPA on a LO...
      • Low information users and the challenges they create
      • My latest security content (lots of stuff on appli...
    • ►  October (3)
    • ►  September (1)
    • ►  August (2)
    • ►  July (3)
    • ►  June (1)
    • ►  May (4)
    • ►  April (4)
    • ►  March (4)
    • ►  February (5)
    • ►  January (5)
  • ►  2012 (77)
    • ►  December (2)
    • ►  November (2)
    • ►  October (4)
    • ►  September (3)
    • ►  August (3)
    • ►  July (4)
    • ►  June (5)
    • ►  May (9)
    • ►  April (5)
    • ►  March (10)
    • ►  February (14)
    • ►  January (16)
  • ►  2011 (163)
    • ►  December (15)
    • ►  November (11)
    • ►  October (9)
    • ►  September (16)
    • ►  August (13)
    • ►  July (8)
    • ►  June (13)
    • ►  May (18)
    • ►  April (16)
    • ►  March (13)
    • ►  February (13)
    • ►  January (18)
  • ►  2010 (170)
    • ►  December (10)
    • ►  November (14)
    • ►  October (7)
    • ►  September (27)
    • ►  August (20)
    • ►  July (8)
    • ►  June (15)
    • ►  May (4)
    • ►  April (23)
    • ►  March (21)
    • ►  February (11)
    • ►  January (10)
  • ►  2009 (55)
    • ►  December (5)
    • ►  November (10)
    • ►  October (21)
    • ►  September (19)
Powered by Blogger.

About Me

Unknown
View my complete profile