Securosis Blog

Incite 10/2/2013: Shutdown

Mike Rothman · October 2, 2013

17 years. That’s a long time. The last time the US Government shut down was December 1995 through January 1996. I was working for META Group at the time, probably on an airplane heading to a meeting with some client. I wasn’t married yet. I could sleep in on a Saturday. Those were the days. Life was fundamentally different. Looking back I don’t remember the specifics of what happened during the last shutdown, as that group of politicians battled each other over funding this, that, or the other…

It seems everyone has an opinion about security awareness training, and most of them are negative. Security luminaries have largely panned awareness training as ineffective and a waste of time and money. They use weird analogies, claiming things like we cannot train folks not to eat fast food, so training never works. Are they wrong? We have all sat through endless PowerPoint slides telling us what we can do and cannot do on the Internet. They threaten you with termination unless you follow the…

IE Zero Day Getting Serious

Rich · October 1, 2013

A vulnerability in Internet Explorer has been known and unpatched for two weeks.

According to ThreatPost, an exploit module is now in Metasploit, and real attacks are growing.

I haven’t worked at Gartner for over six years now, so I’m not surprised that many people still think vendors can pay to move up the rankings in a Magic Quadrant. I mean, just look at them. Big vendors almost always show up in the top left or right, so they have to be paying for play.

The Goof Excuse

Mike Rothman · October 1, 2013

Another day, another breach – that’s not novel. A bunch of personal information (including driver’s license numbers) was stolen from Virginia Tech. But having the organization own up to the fact that the breach resulted from a human error is uncommon.

Not the Rut You Think

Rich · September 30, 2013

Over at Network World Anton Gondalves wrote Security industry in ‘rut,’ struggling to keep up with cybercriminals:

Dramatic changes are needed in multiple fronts if the security industry hopes to move ahead of cybercriminals, who are continuously finding new ways to breach corporate systems, experts say.

Summary Haiku

Rich · September 27, 2013

Hurt back yesterday
Too much pain to write much now
Haiku easier

And don’t forget to sign up for our Black Hat cloud security training in December!

Continuous Security Monitoring [New Paper]

Mike Rothman · September 26, 2013

Continuous Monitoring has become an overused and overhyped term in security circles, driven by US Government mandate (now called Continuous Diagnostics and Mitigation). But that doesn’t change the fact that monitoring needs to be a cornerstone of your security program, within the context of a risk-based paradigm. So your pals at Securosis did their best to document how you should think about Continuous Security Monitoring and how to get there.

Cybercrime at the Speed of Light

Rich · September 25, 2013

A few years ago our very own James Arlen presented at Black Hat on the security risks of high-speed trading.

Today I read in The Verge:

Brian Krebs has done some amazing investigative reporting over the years, but this story is an absolute bombshell.

An identity theft service that sells Social Security numbers, birth records, credit and background reports on millions of Americans has infiltrated computers at some of America’s largest consumer and business data aggregators, according to a seven-month investigation by KrebsOnSecurity.