Showing posts with label information security. Show all posts
Showing posts with label information security. Show all posts

Wednesday, December 3, 2014

Top 3 Enterprise Software and Security Trends for 2015


It's the time for prognostications for 2015. Cirius is first out of the gate. Here's what it foresees as significant trends developing in enterprise software and security. 

1. Data jurisdiction and data sovereignty will impact the growth of Office 365 and Azure. 
Satisfy local, grow global: Enhanced national privacy legislation introduced in Australia, Singapore, Germany, Malaysia, as well as the EU Data Protection Directive, is the sign of what is to come. In many cases opinion trumps facts and products like Office 365 and Azure need to demonstrate aggressively that they understand the privacy and security  concerns of partners and resellers. Addressing domestic privacy and data jurisdiction concerns will help facilitate global growth

2."Cloud" will no longer be perceived as a security threat compared to on premise solutions.
The future of security is in the cloud: Cloud solution providers have had to deal with the perception the cloud was "unsecure" from day one. As a result cloud solution providers historically had to over deliver to be a viable alternative to on premise solutions. The reality is that security and compliance are not the core competency of most I.T. departments  and they lack the internal resources to meet compliance requirements and evolving security threats. 
3. Data Loss Prevention will become a hot issue for business leaders.
Who saw what when: Businesses need to know where their business critical information is at all times. Flagging content and communication before it leaves the office is a good start but it is not enough. Machine learning, pattern recognition, and "post-send" message controls are the next wave of DLP functionality that will protect employees, clients and increasingly the brand.

Wednesday, August 21, 2013

Is there anything really new happening?

I just received a flyer for another information security conference. Is there anything really new happening? I'm seeing sessions on the same old stuff, mostly at a introductory level. Sure, there are new threats and vulnerabilities popping up every day, but how different are they really? Even cloud, mobile, and big data are getting old, and we'll never solve the user problem. I mean, who doesn't know about this 

I've been trying for a long time to get someone to write books on DLP, SEIM, APT, GRC, ..., but am beginning to believe that these topics have jumped the shark. Aside from, maybe, identity and access management, what's going to drive people's need for information and, one can hope, books sales?

BTW, if anyone wants to accept the challenge of writing a book identity and access management, let me know. It's a sure way to immortality (or at least as long as the Library of Congress exists).

Friday, November 16, 2012

Battle for information security 'is being won'

... according to  The Global State of Information Security Survey 2013 published by PwC in conjunction with CIO and CSO magazines.

Cautious optimism or delusional optimism?

Tuesday, April 24, 2012

Tech groups push for cyberthreat information-sharing bill. Great idea. It's worked real well with Federal agencies.

So, now industry wants Congress to legislate what it won't do volunarily. So far, there's as much trust between companies as there is between government agencies. They're all willing for a one-way exchange. This isn't going to change in government, and it won't in industry. Which reminds me. Didn't Congress legislate sharing between agencies? That's working real well, isn't it.

Monday, April 23, 2012

Mac trojan fallout: Apple security glory days gone?

There are cults in IT. UNIX is one; Macs is another. These cultists fervently believe their OS is superior to others, and, by extension, they're superior to everyone else.

When it comes to vulnerability to attacks, though, UNIX was always an easy target. Macs are so safe and secure. Of course, until recently there weren't many of them, and they weren't in the enterprise, and so they were not as attractive a target as, say, Windows. Now that there are more Macs, making them an attactive target, the myth is staring to explode. Still, zealots being zealots, all's right in their world. Koolaid anyone?

Friday, April 20, 2012

"You can't patch stupid." House committees approve 2 cybersecurity bills

One of the best phrases I've heard lately is, "You can't patch stupid." This speaks to the ongoing threats to security posed by users. Now it appears that Congress again is trying to legislate what can't be fixed by legislation. I think "You can't patch stupid" is more easily applied to Congress.

Thursday, April 19, 2012

PWC Survey: "... majority of executives ... are confident in the effectiveness of their organization’s information security practices."

According to the results of the 2012 Global State of Information Security Survey®, the majority of executives across industries and markets worldwide are confident in the effectiveness of their organization’s information security practices.

Doesn't this fly in the face of fact? With reported breaches on the rise, and fears of fraud, APTs, and supply chain security, among other threats, increasing, why are these executives so confident?

Wednesday, November 23, 2011

From The Moscow Times, Recent trends in legal regulation of information security

The article claims Russia has strict regulations on privacy and security, but acknowledges problems. The problem with news from Russian media is that it's rank with propaganda, most of it not too subtle. The Cold War lives on. Is it heating up?

Monday, September 19, 2011

Another day, another hack

So, another big name site's been hacked, and names and PII allegedly taken. This time it's the Intelligence and National Security Alliance (INSA). This is news, but it's becoming old news.

Wednesday, September 14, 2011

SIEM Is Dead

So, a new survery reveals that 65% of security professionals say SIEM is dead. Evidently, relying on log file analysis isn't sufficient to keep on top of who's doing what. I'm sure it has nothing to do with the time, effort, and cost of set up and management. Still, if anyone's interested in writing a book on SIEM, let me know.

Thursday, September 1, 2011

So, how insightful is this?

CSO magainze has a little piece on a minor hacker who opines that "good liars undermine information security." Okay, so don't liars undermine just about everything?

Thursday, August 18, 2011

... the More Things Stay the Same

Earlier this year I surveyed some authors about what they considered their top 5 information security issues. While there were some surprises, such as supply chains, there was more consensus. Among the top issues are cloud security, malware and advance persistent threats, smart phones and other mobile devises, social media in the workplace, data loss, and critical infrastructure protection and cyberwarfare. As I said, no surprises.

Lately, though, we’ve been reading and hearing in the consumer press about malware, cyberwarfare, tons of data loss, and security and privacy problems with social media as well as more invasive and insidious tracking. So, there’s increasing awareness of these threats by the general population, or should be, and convergence between what they and people working in information security consider risky. Maybe.

There’s a lot of distance between being aware of something and doing something about it. People are still flocking to smart phones and social networking, sharing far too much data and information, and leaving themselves at risk to threats they really don’t appreciate. Ignorance is bliss until calamity strikes, and it will.

Friday, August 5, 2011

Headline: Dog Bites Man

Are you getting tired of all the reports about threats and intrusions?

InformationWeek – “Banks face ongoing cyber threats”

NetworkWorld – “Advanced persistent threats force IT to rethink security priorities

This isn’t really news to us. It’s more of the same, and it hasn’t change much, if anything.

The “Man bites dog” headlines directed at the general public are different.

Calgary Herald –“Oil industry prime target for hackers …”

ABC News – “Nation’s infrastructure still vulnerable to cyber attacks”

When these types of reports make the news, whether it’s names stolen from Sony or an intrusion at RSA, someone with the ability to act may take notice. Still, I suspect that most enterprises still consider information security as insurance; a cost to be minimized. Security training likely isn’t offered through HR along with classes on how to manage conflict or drive safely while on company business.

It’s likely, too, that despite the increased noise directed at non-techies about security-related issues, whether it’s fraud, theft, espionage, terrorism, or warfare, that the threats, the risks, and the attacks will continue to increase, and security will remain an afterthought.