Closing the Antivirus Protection Gap
May 16th, 2012
With 50% of IT endpoint operating costs now attributable to malware, is reliance on antivirus as the keystone endpoint security measure the best approach? Instinct tells us no but to be sure, Lumension recently did a comparative analysis on the effectiveness of standalone AV and O/S resident patching solution versus newer technologies, including application whitelisting, [...]
DNSChanger Trojan: Not All Doom and Gloom
May 9th, 2012
If your server(s) have been infected by the DNSChanger Trojan and you’ve not done anything about it, time is running out. You have until July 9, 2012 to get your systems fixed, or you’ll lose internet access until you do. This insidious little Trojan – variously known as TDSS, Alureon, TidServ, and TDL4 malware – [...]
Application Whitelisting: Key Protection Against Targeted Cyber Attacks
August 1st, 2011
The Australian Department of Defence recently updated their Strategies to Mitigate Targeted Cyber Intrusions guidelines, and I think it warrants a little discussion. The relatively short (only two pages!) document from the Cyber Security Operation Centre (CSOC) – part of the Defence Signals Directorate (DSD) – is based on their experience in operational cyber security, [...]
2011 Has Potential to be a Really Bad Year
April 20th, 2011
If we look at how 2010 ended there is perhaps good reason for IT security pros to already be nervous in 2011. According to the end of year report from IBM X-Force, at least 44% of all vulnerabilities disclosed in 2010 had no corresponding patch by end of year. Not only do we have to [...]
Industry Evolution: Innovation vs. Spending; Part 1 of 3
March 30th, 2011
PART I: Is the security industry content to stop innovating because businesses keep buying? (The Problem) Research and development among technology vendors is on the decline. Tech giants, such as HP and IBM, have made cuts to their R&D programs. This may be the case for the security industry as well. At least that seemed [...]
Popularity is Not Necessarily a Good Thing
October 28th, 2010
While Apple proudly proclaims the swelling number of iPhone sales, let me remind IT Security professionals that in the world of network security, popularity is not necessarily a good thing. One of the most important lessons I have learned throughout my career is it is more often popularity – not necessarily insecurity – that drives [...]
Evolution to Intelligent Whitelisting : Part 3 : AV and Application Whitelisting, An Unlikely Couple
September 30th, 2010
Part 3 of a three-part Q&A podcast series with Pat Clawson, Chairman and CEO, Lumension and Patrick O’Grady, Technology Writer, Phoenix Business Journal
Evolution to Intelligent Whitelisting: Part 2: Four Whitelisting Misperceptions to Abandon
September 20th, 2010
Part 2 of a three-part Q&A podcast series with Pat Clawson, Chairman and CEO, Lumension and Patrick O’Grady, Technology Writer, Phoenix Business Journal
Evolution to Intelligent Whitelisting: Part 1: Not Your Father’s Whitelisting
September 13th, 2010
A three-part Q&A podcast series with Pat Clawson, Chairman and CEO, Lumension and Patrick O’Grady, Technology Writer, Phoenix Business Journal
Adjust Your Defenses to the Changing Threat Vector
July 30th, 2010
While our budget-constrained defenses remain relatively static, the threat vector continues to change. Historically in network security, attackers seem to regularly stay one step ahead of defenders. I have watched the arms race unfold for more than two decades as attackers worked their way up the OSI stack from network layer attacks like the infamous [...]




FREE Scanner
Free eBook &
Over 48% of IT Directors say that mobile devices represent the greatest network security threat.



