Will the user define security policies in the future?
I think, I blogged about this event already earlier: Years ago I was meeting a customer and was talking about the future of IT. I was telling the audience (about 10 people including the Security Officer) that there is a good chance that IT will not define a set of hardware anymore but that the user will buy their own and use it for business. Additionally, different people have different ...
Get off XP or Risk your Business?
One of the highest hit rates I ever had on my blog was one I wrote right before Conficker broke out. I called it Playing Russian Roulette with your Network. The background was, that we released an out of band security update and our customers came back and asked us, whether they really shall deploy it – this situation then led to Conficker.
About 12 months from today, Windows XP will ...
Security in 2013 – the way forward?
Typically January is the month where we are asked to make predictions on the trends for the New Year. I do not like this as I am an engineer and not a fortune tellerJ. But there are things we know and things we definitely need to drive this year. I would actually put it into the context of typical hygiene of any IT environment.
Let's try to understand, where we stand ...
The Directory in the Cloud?
It seems that it is an eternity ago – and it is. Pretty much three years ago, Doug Cavit and me published a paper called the Cloud Computing Security Considerations. Even though it is three years, the paper is still worth reading as the content still applies. What we basically said was, that if you look at the Cloud, there are five areas of Considerations:
Compliance and Risk Management: Organizations shifting ...
By Roger Halbheer, on April 24th, 2012% When people look at attackers, they always think that they are extremely smart people. There are really smart people building the kits but the ones applying it? Well, you just need the right guidance:
Hacker’s Tiny Spy Computer Cracks Corporate Networks, Fits In An Altoid Tin
Fairly easy, isn’t it?
Roger
By Roger Halbheer, on April 20th, 2012% This was an interesting article on cio.com: Apple, Oracle, Google Lead Major Vendors with Software Vulnerabilities in Q1, Security Report Says – by TrendMicro. Now, these stats are always a bit a challenge: They make a really good headline but if the statistics does not include the severity of the vulnerabilities, it is hard to . . . → Read More: Q1 Software Vulnerabilities
By Roger Halbheer, on April 14th, 2011% This paper by the Geneva Centre for the Democratic Control of Armed Forces (DCAF) was just brought to my attention. A piece of work, which is definitely worth working through. It lays out the problem space and then does a deep dive into the different sections:
Governments Legislative Bodies The Armed Forces Law Enforcement Judges . . . → Read More: Cyber Security: The Road Ahead
By Roger Halbheer, on April 8th, 2011% An interesting article by ISACA: Six predictions for CIOs. Here they are:
Prediction 1: Cloud computing is here to stay and will become business as usual. Prediction 2: Virtualization will be a catalyst that drives IT modernization. Prediction 3: IT operations become service-centric and business value-focused, rather than process-driven and reactive. Prediction 4: Risk management . . . → Read More: Six predictions for CIOs
By Roger Halbheer, on March 31st, 2011% That’s really interesting:
Impressive! Kudos to MIT
Roger
By Roger Halbheer, on March 10th, 2011% FTC released their Consumer Sentinel Network Data Book for January – December 2010. The interesting and scary thing is that fraud via phone is on the raise. We get more and more complaints by customers as well, telling us that they got a call from “Microsoft” with the ask for getting access to the PC . . . → Read More: Fraud via Phone on the Raise
By Roger Halbheer, on January 28th, 2011% There are some high-level indsutry trends, which tend to be ignored by security officers. The CIO Central published an article, which I would even go further looking at the trends raised. . . . → Read More: Are You Focused On The Wrong Security Risks?
By Roger Halbheer, on January 3rd, 2011% Since quite a while, I am saying that targeted attacks are the risks, which really keep me up at night.
BBC just posted a similar article: Cyber-sabotage and espionage top 2011 security fears
I think that this is a real issue and very hard to fight!
Roger
By Roger Halbheer, on October 17th, 2010% As I am still oof, another short one: Ray Ozzie’s blog is back: http://ozzie.net/
Ray is definitely one of the driving persons behind our overall vision and architecture. So, it is worth keeping him on your RSS feed.
Roger
By Roger Halbheer, on September 19th, 2010% I was reading an interesting article: Forrester Pushes ‘Zero Trust’ Model For Security, where they mainly claim that you should not trust your internal network – something I am asking for since a long time. However, the conclusions Forrester and me are drawing are slightly different. John Kindervag – the person quoted in the article . . . → Read More: Is a “Zero-Trust” Model the Silver Bullet?
|
|
|