Category Archives: Uncategorized

OWASP Top 10 Web Application Vulnerabilities – 2013 Edition

I was listening to a podcast a few weeks ago, and the host mentioned that he had been reviewing the show when he realized he had accidentally been listening to an episode that was over a year old. The confusion amassed because, during the news segment, all of the stories were the same as the [...]

Posted in Uncategorized | Tagged , , , , | Leave a comment

Advanced Solutions Arise To Address BYOD Security Needs

2013 has witnessed an accelerated confrontation between BYOD security threats and advanced security solutions. The Problem As more consumer-grade mobile devices enter the work environment, the sophistication and proliferation of malware and other threats will inevitably grow. One security company predicts over a 300 percent rise in malicious and non-secure Android-based apps in 2013 alone, from over [...]

Posted in Uncategorized | Tagged , , , , , | Leave a comment

Data Security is Vital to Prevent Identity Theft

The Federal Trade Commission reports that identity theft is the number one consumer complaint they receive every year. This theft can occur through fraudulent emails, spyware, mobile devices or looking for documents in the trash. It is vital that businesses ensure their employee data is secure at all times. Phishing Fraudulent emails that attempt to get personal [...]

Also posted in Data Security | Tagged , , , , , , | Leave a comment

The Onion’s Data Breach Investigation Revealed Social Engineering

The recent high profile hack of The Onion webzine affords an ideal opportunity to examine what is both the most prolific and yet the most easily defeated cyber-attack method of all time: the phishing expedition. The subsequent data breach investigation revealed that it all started around May 3rd, when a member of the Syrian Electronic [...]

Also posted in Breach Notification | Tagged , , , , , , | Leave a comment

How Much Personal Information Are You Giving Up?

As a professional in the data security field, naturally I am a privacy-conscious person.  And since I do not believe in Government surveillance and cameras on every street corner, I do take extra steps to keep my information private, especially online. It is mind-blowing the amount of personal information people willingly put online, without thinking [...]

Also posted in Data Security, Staying Safe | Tagged , , , , , , | Leave a comment

UnDead Data

In honor of National Zombie awareness month, and my office’s obsession with AMC’s The Walking Dead, we thought it might be fun to discuss the similarities between zombies and data. A zombie is (paraphrasing dictionary.com) the body of a dead person given the semblance of life, usually for some evil purpose (eg, eating your brains). [...]

Posted in Uncategorized | Tagged , , , | Leave a comment

HIPAA Data Breach Response Requirements Continue To Evolve

HIPAA has a variety of requirements that healthcare providers should be aware regarding data security and data breach response. Below are some common questions and responses: What are HIPAA requirements with regard to plans for data loss & recovery? Providers are required to establish a contingency plan to deal with emergencies or events that impact [...]

Also posted in data breach | Tagged , , , , , | Leave a comment

Make BYOD Security a Top Priority

As an increasing number of businesses continue to hop aboard the “bring your own device” (BYOD) bandwagon, many struggle with ensuring that sensitive data is kept out of the hands of unauthorized users. BYOD has been a boon for mobile business users since it allows greater accessibility away from the office while allowing them to carry [...]

Posted in Uncategorized | Tagged , , , , | Leave a comment

Beware of The Perils of Wi-Fi Hotspots

Wireless (also known as Wi-Fi) hotspots, are changing the way people work. Many companies are making the upgrade to wireless networks in the office for both financial savings on equipment and convenience for their employees. They offer mobile PCs with wireless capabilities to their employees so that they can be productive anytime anywhere, while enhancing [...]

Posted in Uncategorized | Tagged , , , , , , | Leave a comment

The Most Vulnerable Part of a Network is…

What do HBGary, RSA, and Apple have in common? They were all victims of a social-engineering attack. There is a common saying in the InfoSec community that the most vulnerable portion of a network is between the monitor and the chair. Due to advancements in vulnerability detection and mitigation techniques, hacking is straying from exploiting [...]

Posted in Uncategorized | Tagged , , , , , | 1 Comment