post

2013 Global Reputational Risk and IT Study

2013 Reputational Risk Infographic FINAL

Check out the video interview with Jack Danahy on the 2013 Global Reputational Risk and IT Study and please leaving your ratings and feedback on the video landing page. https://ibm.biz/Bdxb3k

post

The Fire Code and Shared Passwords

key pad lock

Here’s a case where a shared password is used to protect businesses all over town, and yet it seems to work. Why?

post

Audit, Surveillance, and Customer Service

brown pants

How a pair of missing pants taught me about audit, surveillance, and customer service and the implications for technology controls.

post

IBM Tech Trends Report for 2012

2012 IBM Tech Trends Report

The 2012 IBM Tech Trends Report on skills gaps in business analytics, cloud computing, mobile technology, and social business and security’s role.

post

Skype Account Hijack Attack: Lessons Learned

relying on the guys in the white hats to prevent attacks like the Skype account hijack attack

What kinds of security controls could have prevented the Skype account hijack attack? Can we do anything except rely on white hat penetration testing?

post

Legitimate Security Through Obscurity

Security Through Obscurity?

There are times when “security through obscurity” is a perfectly legitimate security control tactic, especially against opportunistic attackers.

post

Payment Card Fraud and a Checking Account DMZ

payment card fraud dmz

Could the IT DMZ be used as a model for controlling payment card fraud and help protect against skimming attacks like those at Barnes and Noble?

post

Social Engineering Attack Demographics

social engineering attack vector - the phone

Our common stereotypes of social engineering attacks don’t match up to the latest data in the Verizon 2012 Data Breach Investigations Report.

post

Vulnerability Disclosures and the Hype Curve

Print

Can the rate of vulnerability disclosures of a platform predict its position on the Hype Curve?

post

Protecting The Password File

protecting the password file

RSA announces a new offering to protect password credentials. But is protecting the password file really that difficult?