Continuous Compliance…Moving Beyond a Checklist Mentality
Often, people incorrectly view governance and compliance as a static checklist set of activities, that when completed, signify that an organization has successfully guaranteed its present and future...
View ArticleAn Upbeat Mood: Impressions of the 2015 RSA Conference
The annual RSA Security Conference was held last week at the Moscone Center in downtown San Francisco. The conference was bigger than ever, with 32,000 total attendees (many come for a day just to see...
View ArticleAdvance Your Approach to Ensure Security Against Advanced Threats
5 Things You’re Doing…But Are You Doing Them Well? Security is not just a discussion of business and technology anymore. Major enterprise security and data breach incidents in recent years, and...
View ArticleNo Time to Think Differently – It’s Time to Move: Speed is Everything When It...
“The Chinese have penetrated every major corporation of any consequence in the United States and taken information,” said former NSA director Mike McConnell in a speech he delivered on March 13,...
View ArticleTime to FREAK Out?
Another day, another media-hyped vulnerability supposedly threatening the viability of the Internet. This latest one originated with attempts by the US government to control (read “weaken”) the level...
View ArticleEnd to End Security in the Cloud – Securing Your AWS Workloads
When we consider cloud security we still focus on the same tenets of defense in depth and defense in breadth as in any traditional infrastructure. What this really means is that we consider...
View ArticleBYOD: How to Achieve a Win-Win for Employee and Enterprise
As per the Wikipedia article on BYOD, Bring Your Own Device, the term BYOD began to gain prominence in 2011 when Unisys and Citrix Systems shared their perceptions of the trend. As per IDC, the...
View ArticleData Center Security – Thinking Beyond Perimeter-based Defenses
In today’s information-centric world, the heart of any enterprise undoubtedly lies in its data center. With virtualization now a mainstream technology, workloads are increasingly being migrated to and...
View Article4 Tips for Organizations to Combat Cybercrime
Earlier this year, newspapers reported that for the first time, the U.S. had filed criminal charges against five Chinese military officers. This was the first time Washington singled out a foreign...
View Article5 Key Security Considerations for SMBs in 2015
In the U.S., October marks National Cyber Security Awareness Month, and as the New Year fast approaches, small and medium-sized companies are either starting or in the middle of planning their...
View Article3 Tips for Critical Infrastructure Protection
As citizens, most of us take for granted that electricity will make our lights glow the moment we flip a switch, that fresh drinking water will be available the moment we turn a faucet handle, and that...
View ArticleThree Key Steps to Sensitive Data Protection
At the heart of every security strategy is the objective to protect sensitive information from unauthorized disclosure. Whether you’re designing a defense-in-depth approach to security, or addressing...
View ArticleCybersecurity Strategy Series — Part 3: The Roadmap Towards a Cyber-resilient...
In my previous posts — Cybersecurity Strategy Series – Part 1: Setting the Context and Cybersecurity Strategy Series – Part 2: Options for an Effective Cybersecurity Strategy — I observed how current...
View ArticleEnterprise Governance, Risk, and Compliance (eGRC) – Managing Risk in the...
Over the last 25 years that I have been managing technology, and more specifically, security technology, the one predominant battle that many of my peers have been waging, and generally losing, is the...
View ArticleCybersecurity Strategy Series – Part 2: Options for an Effective...
In your house you have various rooms that let you enjoy a high-quality life, each one offering you some cherished functionality: kitchen, dining, billiard, study, library, fitness, music, sleeping …...
View ArticleSensitive Data Protection: 3 Reasons for the Vanishing Perimeter
Protecting sensitive data has become a complex proposition for a majority of organizations. The network perimeter of the past has vanished and data can no longer be contained, let alone protected....
View ArticleCybersecurity Strategy Series – Part 1: Setting the Context
We certainly live in interesting times. One might argue we have seen better ones, but the point I wish to make is different. All throughout history, times of change have given rise to new ideas,...
View ArticleSecuring Critical Infrastructure Needs Technology with Attitude
Critical infrastructure organizations across the globe rely on supervisory control and data acquisition (SCADA) and industrial control systems (ICS) to keep operations going 100 percent of the time...
View ArticleConsumers Aren’t Worried About Internet Security? That’s Worrisome
Each year, the media coverage of cyber attacks, data breaches, computer viruses and other cybersecurity dangers becomes more dire and frightening. The past year was no different, with several high...
View ArticlePOS Security Hacks: How to Keep the Bad Guys Out, Sensitive Data In
In 2013 corporations saw an unprecedented amount of cyber-attacks from hackers and fraudsters. Hackers were able to successfully shut down websites, tamper with and steal enterprise intellectual...
View Article