Market Impact of a Data Breach
May 13th, 2013
In my Changeup post the other day, I mentioned that my colleague Paul Henry had saved an organization an estimated $10M (or roughly 15%) in market cap by showing that an intrusion had no material impact. That got me to thinking: what *is* the typical market impact of a breach? And furthermore, how good are [...]
Checkmark Compliance Will Get You Nowhere But Hacked
May 7th, 2012
It used to be the only thing you could count on was death and taxes. But these days, you can bet on hackers going after your organization’s data too. Motives may differ – consider the hackers who want to make a statement and the cyber criminals who look to make a buck – but in [...]
PCI spotlight on Europe
September 23rd, 2010
Alan Bentley, SVP International Sales, Lumension, asks Bob Tarzey, Analyst and Director with Quocirca about the difference between PCI compliance and a strong security posture. Q: PCI standards are designed to be a starting point to helping build a strong security posture. Are retailers/organisations aware that they need to do more than achieve PCI compliance [...]
Breaking Down the ABCs of IT GRC
September 1st, 2009
Organizations continue to be plagued by increasing regulations coming from states and federal governments, industry regulations and internal compliance policies. They are further challenged by the complexities and costs associated with demonstrating compliance while managing the right levels of risks. I recently sat down with Rob Israel, the CIO of John C. Lincoln Health Network, one of Lumension’s customers to [...]
Passing an External Audit Doesn’t Mean You’re Secure
August 14th, 2009
By now, most of us have heard of the data breach that affected Heartland Payment Systems. It’s been front page news, and Heartland themselves went public with news of the breach in January 2009. What many people might not know is that Heartland’s QSA (Qualified Security Assessor) had declared them as PCI compliant shortly before [...]
Naked Truth about Risk and Compliance: Bottom Up Vs. Top Down
June 8th, 2009
There’s no question about it, no matter the differences between line-of-business executives, CIOs and security practitioners, the one thing they all have in common these days is a shared dread of a ten-letter word: compliance. As regulations of technology practices have mounted over the years, most companies have struggled simply to keep ahead of the [...]
Chris’ Security Cache Contemplation: Week 3
June 8th, 2009
Miscellaneous interesting news / tidbits I’ve run across whilst trying to keep up with/clean out my RSS feed … [Yeah, I know it's been a while ... sorry, but it's been a busy week at my day job ... and anyhow, I never said it'd be weekly, just that I'd only do it once a [...]
Where the Money Is
June 8th, 2009
Willie Sutton is reputed to have said (although he didn’t, actually), when asked why he robbed banks, “Because that’s where the money is.” So, we’re not really surprised to learn that a new scam is on to liberate the contents of ATMs, and by more sophisticated means than the skimmers I’ve written about previously. Nope, [...]
Are PCI Requirements Losing their Bite?
June 3rd, 2009
It’s been long discussed in the industry that the requirements for PCI compliance were woefully inadequate and some have gone as far as suggesting that PCI be replaced with some form of an independent governing body that would actually raise the standard rather than simply appeasing the vendors to become compliant. One of the hot [...]
Has Whitelisting Reached the Tipping Point in Endpoint Security?
May 27th, 2009
McAfee, one of the largest AV vendors in the security space, recently acquired Solidcore Systems, a company that sells dynamic whitelisting technology, in a $47 million dollar deal that would add whitelisting capabilities to McAfee’s current product portfolio. While this comes as no surprise, this move by McAfee is just the tipping point for the [...]






FREE Scanner
Free eBook
Over 80% of IT Directors say that mobile devices represent the greatest network security threat.



