Opinions Executive order, NIST initiatives may help electric providers get ahead of the threat

Executive order, NIST initiatives may help electric providers get ahead of the threat

While a major attack has yet to take place on the U.S. energy sector, now is the right time for these critical infrastructure providers to ready their defenses.

SC Canada

$20m to fund cyber strategies

Defence Minister Peter MacKay has committed $20 million to fund projects aimed at making Canada safer from cyber attacks.

SC Canada

Report due on business risks from cyber crime

Canadians are about to get their first comprehensive look at the extent of cyber crime on domestic business.

SC Canada

Canadian government gets serious about storage devices

More than 2,000 USB keys were replaced after a hard drive and key went missing.

SC Canada

Canadians savvy on privacy

Privacy concerns are driving Canadians away from smartphone apps and online services.

Opinions Follow me on this, your security team includes non-security people

Follow me on this, your security team includes non-security people

A successful security professional will tap into an organization's entire employee base to get results. And the benefits will go both ways.

Skills in Demand Specialized IT project managers are in demand

Specialized IT project managers are in demand

For moving core apps to the cloud or implementing new systems in companies' internal environments, IT project managers are in great demand.

Opinions Me and my job: Marty Edwards, ICS-CERT

Me and my job: Marty Edwards, ICS-CERT

Marty Edwards' job is to coordinate efforts between the government and the private sector.

2 Minutes On

2 minutes on: The rule of war

As nations engage with one another in shadowy conflicts taking place in the digital sphere, experts are questioning whether treaties and rules that were created for kinetic fighting apply to a new era of combat.

Threat of the Month Threat of the month: pdf.exe.zip files

Threat of the month: pdf.exe.zip files

For our May issue's "threat of the month," we focused on pdf.exe.zip files, an old-style email executable attachment attack.

Opinions

Debate: Is advanced malware no longer a problem when administrator rights are removed?

In this month's debate, experts discuss if advanced malware is still a persistent challenge after administrator rights are removed.

Opinions Trained pros should lead discovery

Trained pros should lead discovery

Employees lack the training to collect and preserve email and electronic evidence.

Opinions Executive order can provide boost

Executive order can provide boost

The rule may help leaders better understand the impact of cyber risks, says PwC's David Burg and Laurie Schive.

Opinions Money talks, but at what cost?

Money talks, but at what cost?

Are we creating a cyber professional salary bubble that will eventually burst, asks Holly Ridgeway, SVP and CISO enterprise systems at PNC.

Opinions Spotting the "black swans" of security

Spotting the "black swans" of security

How can it be that firms can feel confident in their security technology investments and their people, yet ultimately still believe that they remain at great risk?

Opinions Me and my job: Blake Frantz, Center for Internet Security

Me and my job: Blake Frantz, Center for Internet Security

A brief Q&A with Blake Frantz, director of benchmark development, security benchmarks division, Center for Internet Security (CIS).

Threat of the Month Threat of the month: Universal Plug and Play vulnerabilities

Threat of the month: Universal Plug and Play vulnerabilities

April's "threat of the month" are Universal Plug and Play (UPnP) vulnerabilities, which allow attackers to execute arbitrary code.

Debate

Debate: China is the top cyber threat to the United States

In this month's debate, two experts discuss whether or not China is the top cyber threat to the United States.

Opinions BlackBerry back in the game

BlackBerry back in the game

Thanks to BYOD, gone are the days of one single mobile device manufacturer or model to support, says Dimension Data Americas' Darryl Wilson.

Opinions Decoding the cloud

Decoding the cloud

Unfortunately, data security and regulatory compliance requirements do not evaporate in the public cloud, says Vormetric's Ashvin Kamaraju.

Opinions Cyber war, this is not

Cyber war, this is not

Espionage and fraud in cyber is not an armed conflict, says SystemExpert's Jonathan Gossels.

Opinions You are an APT target

You are an APT target

Cyber espionage is at an all-time high, and businesses across the United States are being targeted and breached, says Phillip Ferraro, CISO, DRS Integrated Defense Systems and Services.

Editorial

Sidestepping the humdrum

Among the humdrum there are cyber events cropping up here and there that breed excitement.

Opinions A new perspective: Compromised computing

A new perspective: Compromised computing

Lets just stop preventing what seems to be unavoidable and figure out how to enable our users to operate securely on a completely compromised device.

Opinions The five-step privilege management checklist for financial organizations

The five-step privilege management checklist for financial organizations

Finance companies should adopt an approach of least privilege, which takes into account security and productivity by granting users only the rights necessary to carry out their jobs.

Opinions Worry more about the cubicle dweller and less about the Chinese hacker

Worry more about the cubicle dweller and less about the Chinese hacker

While intellectual property theft at the hands of regular employees may not yield the provacative headlines as a Chinese military unit spreading APTs from an office in Shanghai, the former scenario is the more likely one.

Opinions IT security: Luxury or commodity in these uncertain times?

IT security: Luxury or commodity in these uncertain times?

Security professionals must toe the delicate line of assessing and responding to legitimate risk and being mindful of an organization's needs. Working in their favor is belief that protecting sensitive data is a fundamental component of any business operation.

Opinions PCI compliance in the cloud decoded

PCI compliance in the cloud decoded

As interest in the public cloud remains strong, a security expert makes sense of new recommendations for securing payment card data in those environments.

Opinions Eight creative strategies to address the sophisticated adversary

Eight creative strategies to address the sophisticated adversary

Tupac Shakur once sang, "The old way isn't working so it's on us to do what we gotta do to survive." That too goes for information security professionals, who are being tested like they've never been tested before.

Opinions Defining the qualities of cyber warfare

Defining the qualities of cyber warfare

Cyber war is not as common as the mainstream news cycle would have us believe, but its definition is not as cut-and-dry either. Just because nothing is blowing up doesn't mean it isn't happening. It's all about the context.

Opinions The RSA Conference expo floor offended me - and why I blame the exhibitors

The RSA Conference expo floor offended me - and why I blame the exhibitors

From "booth babes" to vapid marketing lingo to directionless conversations with vendor reps, one industry veteran wonders how information security professionals can take the RSA Conference showroom floor seriously.

SC Canada

Bill C-30 falls owing to expense and privacy concerns

After intense opposition from the public, the Canadian government pledged to not introduce additional legislation to monitor online activity.

SC Canada

Critical infrastructure a weak point, says Canadian official

The Canadian government should to make it mandatory for utility companies and others to tighten security, a former official told a security conference.

SC Canada

China-telco partnership fears unwarranted, says Ontario official

The nascent partnership between a Chinese development group and an entrepreneurial hub funded by three levels of Canadian government has raised concerns from an outspoken former security adviser to Nortel Networks.

Editorial

Just get on with it already

Offering up more general guidelines to strengthen the country's critical infrastructure security - as in the president's recent executive order - is all well and good, but without any meaningful and enforceable requirements then, really, what's the point?

Opinions Me and my job: Dominic Vogel IT security analyst

Me and my job: Dominic Vogel IT security analyst

Dominic Vogel, IT security analyst at a financial institution in British Columbia, Canada, shares how he entered the information security field and the challenges he faces.

Debate

Debate: The FTC should have the right to penalize companies for poor data security/privacy practices.

This month's featured debate informs whether the FTC should have the right to penalize companies for poor data security/privacy practices.

Opinions New risks must be valued

New risks must be valued

IT trends - cloud, social networking and BYOD - are making the practice of security management complex, and are forcing organizations to shift to a risk-management perspective.

Opinions Before you take the plunge...

Before you take the plunge...

Prior to a job switch, ask questions to learn if the company you are considering is in good shape, says former Yahoo CISO Justin Somaini.

Opinions Maximizing quality and reliability

Maximizing quality and reliability

Information security executives must work to "engineer" their organizations to be better, faster, cheaper - and more secure, says Rafael Diaz, CISO, state of Illinois.

2013 RSA Keynote Contributors The new fundamentals of security

The new fundamentals of security

We can prepare for whatever is over the horizon by enhancing our security architectures to prioritize our most important assets, while accounting for the changing attack vectors threatening them.

2013 RSA Keynote Contributors A new vision of security for the device tsunami

A new vision of security for the device tsunami

The number of internet-connected devices is increasing exponentially and faster than anyone can manage or secure them.

Opinions The search for the employee who can speak the boss's language

The search for the employee who can speak the boss's language

One of sternest challenges for security professionals is finding the person who can best communicate the significance of data protection to senior management. It can be done, but sometimes it takes a little bit of luck.

Opinions Breaches and implausible deniability

Breaches and implausible deniability

The days of refusing to look for possible IT and security threats with the potential to result in the loss of customer data are over.

Opinions Securing mobile enteprise assets by embracing the app

Securing mobile enteprise assets by embracing the app

As the bring-your-own-device movement becomes commonplace and better managed, it's time for security pros to move their focus toward securing the mobile application.

SC Canada

CRA gets flack for Netfile changes

The Canada Revenue Agency (CRA) has unnerved privacy experts with a change to its electronic tax-filing policy: It has removed several authentication requirements for electronic filers.

SC Canada

Telus snaps up forensics firm

Canadian telecommunications giant Telus is bolstering its security offering with the acquisition of digital security and forensics company Digital Wyzdom.

SC Canada

HRSDC loses 583,000 personal data of Canadians

Human Resources and Skills Development Canada (HRSDC), a department of the Government of Canada, was reeling last month after the personal data of 583,000 Canadians was lost on a portable hard drive.

SC Canada

New report urges security and privacy settings in networks

Behind the rallying cry, "Privacy equals freedom," Ontario's Information and Privacy Commissioner Ann Cavoukian struck a partnership with Oracle to celebrate International Privacy Day: Jan. 28.

SC Canada

Ethical hacking incident brings rewards and expulsion for Canadian college student

A young, Montreal-based computer science student, his former college and the institution's IT provider all found themselves thrust into the media spotlight over the student's stance on ethical hacking.

Opinions Are you ready for BYOD 2.0?

Are you ready for BYOD 2.0?

This phenomenon sees applications designed for consumers - such as Dropbox, Skype, Google Apps, WordPress, GoToMyPC - finding their way into the corporate tool box.

Opinions Skills in demand: Automation systems professionals

Skills in demand: Automation systems professionals

The increase of systems automation and monitoring within manufacturing companies has led to increased demand for certified automation systems professionals.

Opinions Me and my job: Mike Lang, University of Connecticut

Me and my job: Mike Lang, University of Connecticut

This month's "Me and my job" features the University of Connecticut's senior network technician, Mike Lang.

Opinions

Debate: Hacktivist group Anonymous will take a backseat to extremist groups in 2013

This month's debate covers Hacktivist group Anonymous. Will they take a backseat to more extremist groups in 2013?

Opinions Big Data can fight malware

Big Data can fight malware

The ever-changing nature of malware generates anomalous network behavior that can be detected by leveraging large corpuses of data collected from multiple observation points.

Opinions Sharing is caring: Take advantage of ISAC

Sharing is caring: Take advantage of ISAC

Security pros should be less secretive, says New York City CISO Dan Srebnick.

Opinions The cloud will shake markets

The cloud will shake markets

The data center business model must evolve with cloud's demands, says NJVC's Kevin Jackson.

Opinions Of crime and punishment

Of crime and punishment

I was dismayed and disturbed by the suicide of Aaron Swartz, which only added to well-rooted revulsion for the relentlessness of legal actions against him.

Opinions Applying NAC to mobile

Applying NAC to mobile

A more substantial enterprise mobility framework can be conceived with a combination of NAC, MDM and MAM based on organizational requirements.

Opinions Want security awareness training? Think outside the box

Want security awareness training? Think outside the box

If properly cultivated through effective education programs, employees can shed the moniker of "weakest link" and become an organization's greatest security asset.

Opinions Policies, employee awareness can help solve BYOD dilemmas

Policies, employee awareness can help solve BYOD dilemmas

There's no denying that CSOs will have to deal with bring-your-own-device sooner or later, but ultimately it will lead to an enhanced workforce.

SC Canada

Canada infrastructure vulnerable to cyber attack, RCMP report

Canada remains vulnerable to cyber attacks by "terrorist groups [which] have expressed interest in developing the capabilities for computer-based attacks against Canada's critical infrastructure."

SC Canada

Personal data of 583K Canadian students at risk after breach

The personal information of about 583,000 former post-secondary students is unaccounted for, as a result of a breach of security at the agency responsible for issuing student loans.

SC Canada

Canadian report on ethical hacking sidestepped

The Canadian government has no plans to follow the recommendations made in a report it commissioned into ethical hacking.

Opinions Tumblr's troll: A wake-up call for social networks

Tumblr's troll: A wake-up call for social networks

When seeking to attack social networking sites, miscreants don't even have to bother with the client or the server, yet a similar outcome could result. Now is the time for these platforms to prepare for what's to come.

Opinions Inside out: The vanishing perimeter and rising role of security

Inside out: The vanishing perimeter and rising role of security

When building new systems, security must be as foundational as performance and capability. Because without such a model, the risks associated with today's IT environments will only worsen.

Nominations BYOD testing MDM

BYOD testing MDM

Bring-your-own-device (BYOD) has emerged as an institution in corporate America today - but does the acronym stand for bring your own device or bring your own disaster?

Opinions

Debate: Bug bounty programs

Debate: Bug bounty programs - offering monetary rewards to researchers - help make companies more secure.

Opinions Legislation: Friend or foe?

Legislation: Friend or foe?

The proposed Cyber Intelligence Sharing and Protection Act (CISPA) is galvanizing government and industry over whether we need federally mandated security legislation and what it should look like.

Features Nurturing females for STEM posts

Nurturing females for STEM posts

If we want the best minds, we can no longer look to only half the population, says Karen Purcell.

Editorial Starting the year off with a...bang?

Starting the year off with a...bang?

As we start 2013 off, I'm pretty sure that information security leaders everywhere are glad to hear all those predictions about their budgets getting a boost this year (and that the Mayans were wrong).

Opinions Can't beat 'em? Insure against 'em.

Can't beat 'em? Insure against 'em.

If no one can guarantee an organization is hack-proof, then perhaps it's time for a more practical approach - cyber liability insurance.

Opinions Top 7 end-user security priorities for 2013

Top 7 end-user security priorities for 2013

As employees use more consumer-grade applications and access more corporate data from unmanaged mobile devices, the network perimeter continues to disappear - along with IT's ability to enforce appropriate security controls.

Opinions Outlook for mobile

Outlook for mobile

BYOD has empowered the modern workforce, improved productivity and allowed companies to deliver better services to customers and partners. Forrester sees a continuation of this trend into 2013 and beyond.

Opinions Top firewall management blunders

Top firewall management blunders

The best run organizations can find a number of blunders lurking in their firewall rules.

Opinions The ghosts of Microsoft: Patch, present and future

The ghosts of Microsoft: Patch, present and future

When you consider how many stakeholders are invested in Microsoft's Patch Tuesday, it's no wonder the monthly affair stirs up so much energy in the cyber world.

Opinions It's the complexity, not the size, that makes DDoS effective

It's the complexity, not the size, that makes DDoS effective

Distributed denial-of-service attacks are becoming more potent, and truth be told, they're often difficult to stop.

Opinions Prediction: BYOD may go away in 2013

Prediction: BYOD may go away in 2013

With a new year come new challenges. But while many see bring-your-own-device gaining momentum, more organizations may be ready to issue their own handhelds to employees.

Opinions Know thyself, or risk being known by attackers

Know thyself, or risk being known by attackers

Understanding your organization's security posture can mean the difference between data that's protected from attackers and a breach that can result in major financial and reputational harm.

Opinions Skills in demand: System engineers

Skills in demand: System engineers

The convergence of communications, VoIP and multimedia systems (video conferencing, webinars, peer-to-peer) has increased the demand for engineers capable of designing and managing systems.

Opinions Me and my job: Brian Calkin, Multi-State ISAC Security Operations

Me and my job: Brian Calkin, Multi-State ISAC Security Operations

A Q&A with Brian Calkin assistant director, Multi-State ISAC Security Operations Center at the Center for Internet Security.

Opinions

2 minutes on: The advancement of DDoS

As the threat landscape continues to evolve, one malicious tactic has stood the test of time: distributed denial-of-service attacks (DDoS).

Editorial The classic fairy tale gone cyber

The classic fairy tale gone cyber

From stealthy to blatant tactics, 2012 has seen them all.

Opinions Comparing programs can yield rewards

Comparing programs can yield rewards

We all know what we spend internally, but how do we get reliable, timely information for comparison purposes?

Opinions Questions for CxOs in a new era

Questions for CxOs in a new era

As network security grows more elusive, CxOs need to ask their IT departments some tough questions.

Opinions Install mobile app safeguards

Install mobile app safeguards

This is the age of bring-your-own-device, and it is too late to turn back now.

Opinions Expect attackers to up their creativity game in 2013

Expect attackers to up their creativity game in 2013

From mobile devices to the cloud to the supply chain and beyond, next year is certain to bring with it fresh set of information security challenges.

Opinions Patent trolls and their effect on security

Patent trolls and their effect on security

Companies that acquire patents for sole purpose of suing other companies is limiting IT security innovation, which, in turn, is making users less safe.

Opinions Is the era of anti-virus over?

Is the era of anti-virus over?

It's true: There are certain attacks that no security technology will be able to stop. But the situation isn't entirely hopeless. How organizations respond to an active threat can make all the difference in the world.

Opinions Making moves on the cyber chessboard

Making moves on the cyber chessboard

As the level of sophistication of digital attacks grows rapidly, targeted organizations must devise a strategic, military-like response.

SC Canada

US, Canada announce cross-border action plan

Public Safety Canada and the U.S. Department of Homeland Security launched an action plan last month to back up a February 2011 border security partnership.

SC Canada

Canada throws money at cybersecurity shortcomings

The Canadian government has unlocked $155 million in funding to bolster cyber security, just as the Auditor General issued a negative report.

Opinions No more trusted endpoints

No more trusted endpoints

The theater of risk has changed from network service-based attacks to attacks against the endpoint.

Opinions

Debate: A White House order on cyber security

Debate: A White House order on cyber security would be a step in the right direction for safeguarding networks.

Opinions Me and my job: Grant Babb, Intel IT

Me and my job: Grant Babb, Intel IT

A Q&A with Grant Babb, proactive investigations program manager for Intel IT.

Opinions The resurgence of security IPOs

The resurgence of security IPOs

Sixty percent of the venture-backed IPOs issued in the third quarter of this year are IT related.

Opinions The good, bad and ugly

The good, bad and ugly

While some instances of Stuxnet and Duqu found their way into seemingly unplanned locations, the majority of occurrences were localized to targeted systems.

Opinions Take to the offense with intel

Take to the offense with intel

Though standards lack, sharing threat data is vital, says EMC's Christopher Harrington.

Editorial When less isn't more

When less isn't more

Among the some 400 attendees at last month's SC Congress New York, fears bandied about crossed various spectrums.

Opinions Building a trustworthy mobility program

Building a trustworthy mobility program

As device adoption continues to grow, the importance of implementing a secure enterprise mobility program cannot be understated.

POLL