Attack vectors multiply as more devices connect to enterprise environments, says IANS's Chris Poulin.
As more and more organizations encourage consumers and clients to visit their websites to conduct business or shop the application security engineer is highly sought after.
Me and my job: Joel D. Rader, solution architect, Radiant Logic
Debate: Forensics staff will be replaced by robots.
Government surveillance is, however, not new, says Patrick O'Kane, barrister and compliance counsel.
A communication gap exists today between CISOs and the board of directors, says Feris Rifai, CEO, Bay Dynamics.
Even with all the hoopla, there are CISOs still having challenges, vendors that aren't meeting needs, and companies still giving security short shrift, says Illena Armstrong, VP editorial, SC Magazine.
Security is a business risk that needs to be understood and owned by your business leaders, says Jeff Brown, former technology risk officer, AIG.
IT security is finally becoming a priority - not only for IT professionals in every industry, but also for the C-suite, says Marcin Kleczynski, CEO, Malwarebytes.
Me and my job: Karthik Rangarajan security engineer, Addepar
Debate» To automate or not? You must realize the limitations of your incident response technology.
If Apple complies, the FBI would have the ability to compromise personal security when it wishes, says Ryan O'Leary, VP of Threat Research Center, WhiteHat Security. .
In cases where terrorist attacks are carried out state-side, it is vital that intelligence be obtained, says J.J. Thompson, CEO, Rook Security.
Effective detection is comprised of several parts, says Cyphort's Nick Bilogorsiy.
Talk of attack prevention is antiquated, says Illena Armstrong, VP editorial, SC Magazine.
I am recommending we develop a paradigm shift in the way that we view data breaches, says Zachery S. Mitcham, CISO, University of North Carolina Wilmington.
It's anyone's guess what the outcome of the upcoming Brexit vote will be, but it could create significant turmoil, says IBM's Jon Wilkinson.
Me and my job: Mushegh Hakhinian chief security architect, Intralinks
Threat of the Month: Executive staff/middle management
Debate: Closing the security gap is a people problem.
Having a security awareness program in place can have an innumerable ROI.
Why retrospective data analysis is critical after a security breach.
With the use of social media, HR and IT must work together to ensure that both employees and company data stay secure.
The health care industry must step up when it comes to addressing its steady stream of IT security risks, says Illena Armstrong, VP, editorial, SC Magazine.
Recently, there has been an increased intensity in scrutiny of the world's electric grids, says Edna Conway, CSO, global value chain, Cisco Systems.
Gina Chapman, senior director of security operations, Center for Internet Security
Researcher Wesley Wineberg said he's been censured due to his participation in the Facebook bug bounty program.
Threat of the month: Man-in-the-middle attack
Debate: Cybersecurity information sharing allows network defenders to stay ahead of adversaries.
Security awareness training aims not only to impart information, but also to change behavior.
Open source code might be presumed mature, but could rely on technology developed a decade earlier.
Ransomware is a complex threat, but its impact can be lessened, says Thomas Gresham.
New year commitments by the lone individual also could be adopted by the larger organization.
Many companies are establishing formal security programs for the first time or are seeking to optimize existing programs to improve the level of maturity.
A combination of machines and humans is key to risk management, Carole Fennelly says.
A combination of machines and humans is key to risk management, says Cisco CSO Edna Conway.
Many organizations still hesitate to move to the cloud. Why?
This year has been marked by the almost daily occurrence of some information security-related incident or another.
We've all received a call at one point or another from the fraud protection departments of our credit card providers, telling us they've detected some suspicious activity on our accounts and would like to verify a few recent charges.
The Internet of Things is one of the world's fastest growing technologies. Unfortunately, it is also poised to become the fastest growing source of security vulnerabilities in the enterprise - but it doesn't have to be that way.
The latest cyber attack, a breach compromising the data of up to four million of Talk-Talk's loyal customers, is yet another in a growing line of pernicious cyber attacks against corporate infrastructure.
There are legal issues and technical vulnerabilties aound the use of fingerprint scanners on mobiles, hence, Anthony Neary says, it is vital to have a mix of solutions which enable maximum possible security.
While there is a regular discussion of how to prevent successful phishing attempts, one of the most successful approaches is ongoing employee training, says Colin McKinty, VP Cyber Security Strategy at BAE Systems Applied Intelligence.
The demand for security DevOps engineers is growing.
Me and My Job: Rick Collette, devops team lead, Evident.io
many enterprises are turning to security consultants to perform assessments of their systems, says Michael R. Overly attorney, Foley & Lardner.
The one-throat-to-choke theory is a fallacy, says David Shearer, CEO, (ISC)².
As mainstream users become more expectant of massive compromises of personal information, cybercriminals show no sign of giving up on using current tactics and finding new ones to steal data whatever their endgames may be.
Lena Smart, VP / CIO of the New York Power Authority, offers a few tips for freeing yourself from mobile addiction.
Experian breach is more than just another hack as cross referencing of data sets opens up even more scope for ciminal activity says Max Vetter
Pete Shoard asks how powerful are less developed countries such as North Korea when it comes to cyber-threats, and can it be regarded as a major player in cyber-warfare anyway for the impact it has achieved?
Instead of hoping for your end-users to make the right decision or your DLP solution to make the right guess, data protection solutions need to be context-aware.
In the wake of the SYNful Knock attack on its routers, Cisco should re-engineer its devices to prevent future attacks, says Raimund Genes.
Skills in demand: Security engineer, identity management
Me and my job: Surendhar Subramani, senior information security consultant, Ernst & Young, India
Debate: What is the edge of IoT security responsibility? Will device-level security testing be enough?
Debate: What is the edge of IoT security responsibility? Will device-level security testing be enough?
Can U.S. data protection laws protect privacy and preserve tech innovation and intellectual property?
The impact of Canada's anti-spam legislation for companies big and small.
Containment solutions can help stop the spread of malware, says Bufferzone CEO Israel Levy.
Our working hours may grow longer, more demanding and more exposed as the Internet of Things (IoT) continues its fast evolution.
Many organizations are also investing heavily to hire top-notch CISOs to fill the presumed leadership gap in security.
Organizations need a solution that is built for the container pattern, says John Morello.
A leak, a hack, or a simple mistake can blow up any M&A deal carefully crafted over months or even years, says Stephen Dearing.
David F. Katz, partner, Nelson Mullins
Debate: Device manufacturers take a comprehensive approach to securing consumer products.
As mobile and cloud dominate the future of the enterprise, security and accountability are falling through the cracks.
The mobile malware threat is mostly based on hype, not facts.
Companies can benefit by using a complex security approach, says A1QA's Aleksey Abramovich.
The questions regarding a more consistent reliance on offensive capabilities are concerning.
Public and media focus on data breaches and regulatory fees have dramatically deepened the focus on information security for executive boards.
Why is there a lack of women in IT security?
While we continue to make headway toward embracing a diverse workforce in the IT security field, we're still far from fully realizing this end.
How you are securing your sensitive information should not be a guessing game
Shuabang companies in China sell installs and user ratings to app developers to help boost their profile, which is leading to new forms of malware, says Chema Alonso.
Invest in the talented women on your team, says Joyce Brocaglia.
The need for experienced incident response professionals is outstripping the available supply of talent.
Mikel Draghici, principal mobile security specialist, Usher
After 30-plus years as an official in the National Security Agency (NSA), William Binney has been speaking out about what he sees as the "very ugly path" his former employer, along with the FBI and CIA, are currently following.
Threat of the Month: Cryptolocker
Debate: The Pentagon's strategy to use cyberwarfare in conflicts with enemies is necessary.
Congress took significant action in April to address cybersecurity information-sharing efforts.
You can't hire quality information security talent the same way you hire customer service reps.
There's been quite a bit of lip service paid to the ages-old concept of information sharing, says Illena Armstrong, VP, editorial, SC Magazine..
Cisco Systems CSO Edna Conway calls for action to stop the risks of counterfeit or tainted information.
Debate: Congress should mandate that the payment card industry adopt safer technology.
Much needs to be done to convince boardrooms of the importance of information security.
It's time for a dramatic reimagining of how companies approach security.
A single solution won't stop data theft, says ADP's Roland Cloutier.
Trust directly correlates to our expectations of privacy, says Illena Armstrong, VP, editorial.
It is important for everybody to stay vigilant when online, says Lena Smart, CIO, New York Power Authority.
Vendors bundling software with open source libraries caught the IT community unprepared, says Secunia's Kasper Lindgaard.
You likely have a list of criteria to check through during the hiring process of a vendor, but if you haven't added cybersecurity standards to that list, you should.
To extend the ERM approach to information and IP, companies need to create a comprehensive inventory of sensitive data and intellectual property that are key to their competitiveness.
Today's CISO must play a strategic and forceful role in mandating the transition to a more secure enterprise infrastructure.
Target. Home Depot. Morgan Stanley. Sony. Anthem. Jennifer Lawrence. You?
IT pros, beware: The phenomenon of "data breach fatigue" isn't just an issue of consumer complacency.
In this month's "Me and my job" feature, we get to know Johannes Ullrich of the SANS Technology Institute.
Given the recent headline-grabbing breaches, in this month's debate information security professionals discuss whether or not money is safe online.
SC Magazine Articles
- PCI DSS version 3.2 release extends multifactor authentication requirement
- Over 7M Minecraft mobile credentials exposed after Lifeboat data breach
- New site on dark web offering one-stop ransom services
- Pwnedlist vulnerability exposed 866M accounts
- Turkish fascists claim responsibility for Qatar bank data breach
- DōTERRA breach exposes customer info; including SS, DOB, and addresses
- Federal court bucks trend, rules general liability insurance covers data breach
- The anatomy of a spearphishing scam, or how to steal $100M with a fake email
- Report: Ransomware feeds off poor endpoint security
- Pros examine Mossack Fonseca breach: WordPress plugin, Drupal likely suspects