Latest Blog Posts
The Year of the Security Standard
May 09, 2013 Added by:Anthony M. Freed
Often in the security field we hear the question asked, “Who’s watching the watchers?” It occurred to me recently that one might make a similar rhetorical quip about other aspects of our field – in particular, the question of “Who’s standardizing the standards?”
Comments (0)
Three Reasons Why a One-Size-Fits-All Secure SDLC Solution Won’t Work
May 08, 2013 Added by:Rohit Sethi
Forcing a security process on development teams that doesn’t take into account the way they develop software is a recipe for disaster. A good goal to have for secure SDLC is to minimize the impact on the team’s existing software development practice.
Comments (0)
Bore Them With Death-by-Awareness: That’ll Teach em!
May 08, 2013 Added by:Lee Mangold
As security professionals, we have to understand that not everyone has a passion for security. In fact, most people don’t. Given that we know “they” don’t share our passion, and we know they are the most vulnerable attack vector, why do we continue to bore them with homogenous and irrelevant training?
Comments (0)
Seven “Sins” of Cyber Security
May 07, 2013 Added by:Rick Comeau
While some of the cyber attacks making news lately are the result of sophisticated methods, many are not: they often take advantage of a lack of basic security protections. Let’s take a look at seven “sins” that organizations and users are committing that are leaving them vulnerable.
Comments (0)
Resilience ‒ The way to Survive a Cyber Attack
May 07, 2013 Added by:Jarno Limnéll
In reality, a well-prepared cyber attack does not need to last for 15 minutes to succeed. After preparations it takes only seconds to conduct the attack which may hit targets next door as well as those on the other side of the world.
Comments (0)
Pentagon Ups Cyber Espionage Accusations Against China
May 07, 2013 Added by:InfosecIsland News
A new report from the Pentagon marked the most explicit statement yet from the United States that it believes China's cyber spying is focused on the US government, as well as American corporations.
Comments (0)
What Should I Know about Mobile Cybercrime?
May 06, 2013 Added by:Robert Siciliano
Mobile devices run on different operating systems and use different apps from PCs and Macs, which presents opportunities to create new device-specific attacks.
Comments (0)
What Security Risks Do Healthcare Organizations Face?
May 06, 2013 Added by:Michael Fornal
Today, hospitals and healthcare organizations face many risks that they didn’t have to deal with until few years ago. This ever growing list of risks includes social engineering, redundant applications, within a network and keeping patient files secure and confidential but yet available and escalation of privileges.
Comments (0)
SCADA and ICS Cyber Security - Facing the Facts
May 05, 2013 Added by:Eric Byres
In the past, the main reason for securing a SCADA/ICS network was to protect against inadvertent network incidents or attacks from insiders. The risk of an external malicious cyber-attack was considered minimal.
Comments (0)
Thoughts on THOTCon & Bsides Chicago
May 02, 2013 Added by:Scott Thomas
Well I've had a few days to recover from the awesomeness that is the Chicago Con Weekend including GrrCon and THOTCon.
Comments (0)
Five Questions Boards of Directors Need to Ask About Cloud Governance
May 01, 2013 Added by:InfosecIsland News
ISACA has issued new guidance outlining key questions for boards of directors to ask to ensure their enterprise’s cloud initiative is in line with business objectives and the organization’s risk tolerance.
Comments (1)
The Stand Alone Complex and Jihad
May 01, 2013 Added by:Krypt3ia
We have seen Anonymous as a form of SAC and now I think we can make a substantial case for the jihad being one too. If this idea becomes more memetic and resonates with those of a like mind then we will see more of these types of attacks as well as those out there (not only AQ) trying to entice others to action as well.
Comments (0)
Infographic: Staying Safe While Using Public Wi-Fi
May 01, 2013 Added by:InfosecIsland News
To help users avoid online fraud and malware risks, ThreatMetrix provided the following infographic which highlights several scenarios of how cybercriminals can access sensitive transactions over public networks.
Comments (2)
Why Are We Failing at Software Security?
May 01, 2013 Added by:Nish Bhalla
While there are many granular reasons for software security failures at the institutional, developer or vendor level - there are five industry-wide problems that are fueling the current state of insecurity. These are complicated problems and will not be easy to solve. But until we do, software security will remain at risk.
Comments (0)
Top 10 Encryption Benefits
April 30, 2013 Added by:Steve Pate
If deployed correctly, encryption does not need to be a headache. Instead, encryption can be an enabler to achieve the flexibility, compliance and data privacy that is required in today’s business environments. Below are top 10 benefits for those considering encryption.
Comments (0)
The Severe Effects of Syria’s Cybered Conflict
April 29, 2013 Added by:Jarno Limnéll
The conclusion to be drawn from the effects of Syria’s cybered conflict is that using of cyberspace needs to be seen as an integral part of any contemporary and future conflict.




