The Shape of Things to Come with Critical Infrastructure Attacks
February 13th, 2013
How many movies have you seen where the fate of humankind depends on a geeky guy sweating in front of a computer? The specific drama varies from movie to movie, but they generally include the need to: hack into a system to get critical information, crack a password, or disable an evil supercomputer bent on [...]
The New York Times Breach: Why AV Failed, What They Should Have Done and What We Accomplish by Letting Them Stay Inside
February 1st, 2013
In yet another example in the saga of personalized malware from foreign nations, specifically China, The New York Times reported Wednesday that the Chinese had carried out an extensive malware campaign against the newspaper giant for the past four months. With this news, we see once again stand alone, signature-based defenses are completely ineffective, especially [...]
How the U.S. Should Fix its Cyber Security Problem
January 30th, 2013
More than 60 years ago, the U.S. created the Center for Disease Control to establish a central repository of information monitoring diseases threatening our population. It was a brilliant idea and in the years since its inception, it has helped the country prevent and manage many disease outbreaks, even eradicating smallpox. If at this point [...]
Monday Morning Patch Blues
January 15th, 2013
Security Pros sure had a tough Monday. Two issues came to a head: the Java plug-in vulnerability and the Internet Explorer vulnerability. Both are being actively exploited, and both have seen patches rushed out on Monday. Let’s take a quick look at them both. Java 0-Day A new vulnerability in Java browser plug-in used by [...]
Time to Get Serious About Upping Your Cyber Security Game
January 9th, 2013
The welcoming in of a New Year always seems to entice once-a-year prophets to dust off their crystal ball and offer predictions for the coming twelve months. The security community is not immune. I’ve read with interest the efforts of various security pundits, consultants, vendors, etc. to provide guidance for their readers, partners, and customers. [...]
October Podcast: State of Security Awards
November 15th, 2012
Welcome to the October wrap up of cyber security happenings. There is never a dull moment in our industry, as I’m sure I’ve said before. And this month was no exception. Please share your comments on the scenarios highlighted this month and always, let me know if there’s an interesting highlight I’ve missed. Download the [...]
For Want of a Nail …
November 14th, 2012
… the kingdom was lost. This real-life cautionary tale, told to me by my colleague’s brother (let’s call him Mr. X), concerns a risk-reward decision gone awry. X’s company is a good-sized global in international construction services company with over $1B in revenue and around 5000 employees; they have about 7000 servers and endpoints under [...]
Sensational Headlines or Real Threats?
October 23rd, 2012
Yesterday, I was joined by a great group of IT security industry pros for a discussion on the recent, highly-sophisticated cyber attacks that continue to make headlines by hitting major U.S. banks and global companies like Saudi Aramco, Adobe and others. Dialing up the rhetoric on these spectacular headlines, the Pentagon jumped in last week [...]
Cyber Security Awareness Month Lumension-Style
October 18th, 2012
The National Cyber Security Alliance has done a very good job of marketing October as National Cyber Security Awareness Month. Many organizations have used this as an opportunity to share basic online safety information with their employees and their communities. Lumension jumped on this worthwhile bandwagon yesterday and sponsored an awareness building event in our [...]
U.S. Firms Face Growing Risk from Chinese Industrial Espionage
October 16th, 2012
The House Intelligence Committee recently issued a scathing report about Chinese telecom equipment firms Huawei and ZTE, accusing them of inserting backdoors into their network equipment so the Chinese government could steal military and industrial secrets from the West. The report prompted a flood of calls from US firms to the House committee complaining about [...]






FREE Scanner
Free eBook
Over 80% of IT Directors say that mobile devices represent a security threat.



