Data Breach Trends in the Financial Sector
February 23rd, 2012
Financial institutions are, it seems, doing a better job at protecting customer data than most industries. This is the conclusion one reaches when looking at the latest data in the Chronology of Data Breaches from the Privacy Rights Clearinghouse. Overall, the CDB has 2929 breaches in the 2005–2012 timeframe, involving 544,591,013 records (yup, more than [...]
Will a £500,000 Fine Help Drive Better Data Security?
April 2nd, 2010
The Arizona State Senate recently approved SB 1334, designed to prohibit texting while driving. Violators would face a $50 fine, which would be upped to $200 if they are involved in an accident while texting. Texting (including writing, sending or reading a written message on your cell phone or similar device) while driving will be [...]
HITECH Breach Data: the Good, the Bad, and the Ugly
March 1st, 2010
As I’ve discussed before, one of the requirements of the HITECH Act is for the Secretary of the Department of Health & Human Services (HHS) to publish a list of all breaches of healthcare data covered by the HIPAA security rule on a yearly basis. The first such publication has been made, covering the period [...]
7 Things You Need to Know About HITECH
February 17th, 2010
Today, Wednesday, February 17, 2010, marks one year since the HITECH Act of 2009 passed. This means that most of the Act’s provisions are now enforceable – particularly, the breach notification and penalties aspect of the Act. While most healthcare organizations are concerned about the “meaningful use” requirement, for us in the IT security space [...]
Now Playing – Cybersecurity: The Broken Record
February 8th, 2010
Recently Dennis Blair, director of national intelligence, presented the Annual Threat Assessment of the U.S. Intelligence Community to the Senate Select Committee on Intelligence and painted a much starker picture of the current state of cybersecurity in the country compared to his testimony last year. According to Blair, the United States confronts a dangerous combination [...]
Malicious Attacks and Botnets Fuel Data Breach Costs
February 1st, 2010
The latest fifth annual US Cost of a Data Breach study by the Ponemon Institute and sponsored by PGP was released this week. [Disclosure: Lumension has a relationship with the good folks at Ponemon.] The key findings of this report are well articulated in the Executive Summary … US organizations continue to experience an increased [...]
Does the Data Accountability and Trust Act Bill Have Wings?
December 16th, 2009
Last week, the House passed the Data Accountability and Trust Act bill that would provide a law for notifying potential victims of identity theft whenever their electronically stored personal information is exposed. It’s now on to the Senate for their review and vote. If it does pass through the Senate, it will have implications across [...]
How Serious is the US Government about Cybersecurity?
November 10th, 2009
October was National Cybersecurity Awareness month. What did this initiative accomplish? Not much, I’m afraid. The fact that a lot of people in the private sector don’t even know it was Cybersecurity Month speaks to the problems we face in ensuring that people take cybersecurity seriously. We still don’t really understand the value of cybersecurity [...]
Why Governator’s Veto of New CA Data Breach Law is a Bad Idea
October 21st, 2009
Gosh, my apologies dear readers (Hi Mom), it’s been a while since I’ve written a post … not for a lack of news, but my day job has kept me hoppin’ lately. But the news out of California was enough to jolt me out of my lethargy. Seems the Governator has vetoed SB 20, the [...]
Operationalizing Endpoint Security: Striking a Balance between IT Operations and IT Security
September 24th, 2009
Gartner recently released a report on operationalizing endpoint security – on how signature-based anti-malware is losing effectiveness in the face of an overwhelming volume of threats. I have a few thoughts about the report’s findings and what organizations can do to better protect their endpoints. As the Gartner report made clear, signature-based anti-malware is losing [...]



FREE Scanner
Free eBook &
Over 48% of IT Directors say that mobile devices represent the greatest network security threat.



