After an 11 month hiatus, I have returned to the Computerworld blog. I had a lot of fun writing for them before and I am thrilled that they would have me back! Here is the first posting of 2010 ...
"Application service providers offer a centralized control point to deliver secure services for millions of its subscribers. Let’s hope that more social networking application providers follow Facebook’s and Comcast’s example by making it easy to acquire endpoint security software, and by enhancing its own internal vigilance. In the meantime, consumers with a paid anti-virus subscription are advised to act quickly in getting free protection from the likes of Avast!, AVG, or Microsoft..."
Friday, January 22, 2010
Tuesday, December 29, 2009
Web security strategy
Check out SearchSecurity.com for the latest:
If you haven't focused on an enterprise-wide Web security strategy then it's time for a reality check. It's safe to assume that various parts of your organization are using Web applications and a cloud computing infrastructure or services, and the time to wrap a security strategy around that is now.
If you haven't focused on an enterprise-wide Web security strategy then it's time for a reality check. It's safe to assume that various parts of your organization are using Web applications and a cloud computing infrastructure or services, and the time to wrap a security strategy around that is now.
Wednesday, December 16, 2009
Microsoft and EC settle their IE dispute
Good to see the European Union competition commissioner has finally come to its senses and settled its silly and costly business practices lawsuit against Microsoft over the bundling of Internet Explorer into Windows.
This seemed like pure harassment to me – browsers are free, users can easily download and install any browser they want, and service providers could have included or recommended browsers if their customers demanded help. In fact, you could even argue that ubiquitous feature-rich free browsers have worked to everyone’s benefit (though I do not believe Microsoft set the market price of free).
Anyway, Microsoft and the European Commission are now in agreement. Microsoft has agreed to give the user a choice of leading browsers in versions of Windows and presumably the EC can find better things to do.
This seemed like pure harassment to me – browsers are free, users can easily download and install any browser they want, and service providers could have included or recommended browsers if their customers demanded help. In fact, you could even argue that ubiquitous feature-rich free browsers have worked to everyone’s benefit (though I do not believe Microsoft set the market price of free).
Anyway, Microsoft and the European Commission are now in agreement. Microsoft has agreed to give the user a choice of leading browsers in versions of Windows and presumably the EC can find better things to do.
Tuesday, December 15, 2009
Lessons from CoreStreet
CoreStreet is the most recent security company fire sale – selling to ActivIdentity for “approximately” $20 million. Usually this means that the investors get some money back, the founders get some candy so they’ll bring their next idea back to the VC’s, and everyone else gets new business cards. CoreStreet gave it a good go – they had sharp mathematicians and a new idea for authentication, but could not find a sustainable and repeatable business. There are at least 2 things that other struggling security companies may be able to learn from CoreStreet:
Keep your messaging simple. CoreStreet is in the “distributed credential validation solutions” segment. You cannot expect a security team to evaluate, recommend or buy a product that they do not fully understand or have an expressed need for. When I first talked with them, CoreStreet described proofs and math models to authenticate signatures when a certificate authority was unavailable. I was in over my head in about 30 seconds, and I like to think I’m pretty good at authentication and math. If you are looking to increase sales traction, make sure your messaging is easily understood and directly addresses an important business need.
Try to diversify from government dominated customer base. When it comes to security, government agencies often have unique solution requirements that do not translate well into the commercial world. You can make a business serving the federal government if your company reaches a critical mass, but if you are not cash flow positive you need to have alternatives. While CoreStreet attracted business from defense-oriented agencies, it couldn’t translate its technology to the commercial sector. The company had no options and no place to grow, except perhaps by acquisition to a vendor that can service outstanding government contracts.
There is a tough year coming up and we will see more security vendors like CoreStreet with tired investors and shuttered doors in 2010.
Keep your messaging simple. CoreStreet is in the “distributed credential validation solutions” segment. You cannot expect a security team to evaluate, recommend or buy a product that they do not fully understand or have an expressed need for. When I first talked with them, CoreStreet described proofs and math models to authenticate signatures when a certificate authority was unavailable. I was in over my head in about 30 seconds, and I like to think I’m pretty good at authentication and math. If you are looking to increase sales traction, make sure your messaging is easily understood and directly addresses an important business need.
Try to diversify from government dominated customer base. When it comes to security, government agencies often have unique solution requirements that do not translate well into the commercial world. You can make a business serving the federal government if your company reaches a critical mass, but if you are not cash flow positive you need to have alternatives. While CoreStreet attracted business from defense-oriented agencies, it couldn’t translate its technology to the commercial sector. The company had no options and no place to grow, except perhaps by acquisition to a vendor that can service outstanding government contracts.
There is a tough year coming up and we will see more security vendors like CoreStreet with tired investors and shuttered doors in 2010.
Database activity monitoring lacks security lift
Posted to SearchSecurity ...
The IBM acquisition of Guardium Inc., a privately-held database activity monitoring (DAM) vendor, is far from a validation statement of DAM as a viable security market segment.
Vendors including Embarcadero Technologies Inc., IPLocks (acquired by Fortinet Inc.), Lumigent Technologies Inc., Symantec Corp. and Tizor Systems Inc. (acquired by Netezza Corp.), have already given up on the DAM space, leaving companies such as Application Security Inc., Imperva Inc., Secerno Inc. and Sentrigo Inc. fighting to divvy up a total annual market of well less than $100 million. The IBM acquisition of Guardium helps the company gain information management technology and a capability to drive professional service revenues in the data center.
The IBM acquisition of Guardium Inc., a privately-held database activity monitoring (DAM) vendor, is far from a validation statement of DAM as a viable security market segment.
Vendors including Embarcadero Technologies Inc., IPLocks (acquired by Fortinet Inc.), Lumigent Technologies Inc., Symantec Corp. and Tizor Systems Inc. (acquired by Netezza Corp.), have already given up on the DAM space, leaving companies such as Application Security Inc., Imperva Inc., Secerno Inc. and Sentrigo Inc. fighting to divvy up a total annual market of well less than $100 million. The IBM acquisition of Guardium helps the company gain information management technology and a capability to drive professional service revenues in the data center.
Tuesday, December 1, 2009
Health Net breach failure of security policy, technology
I'm back from vacation and Thanksgiving - hope you all had a nice break!
Here is the latest SearchSecurity posting:
"The recent Health Net data breach—affecting some 1.5 million users—is a failure of all aspects of IT security, including the ability to set appropriate policy, communicate that policy to employees and deploy the relevant security technology.
Health Net announced last week that unencrypted records, and the portable external hard drive containing those records, were lost. A loss of this magnitude from normal business practice suggests that either sensitive data accumulated over a long period of time and was not systematically erased when no longer needed, or the user worked on extremely large chunks of data without proper security controls. IT should have been aware of both possibilities and acted to protect the business." ...
Here is the latest SearchSecurity posting:
"The recent Health Net data breach—affecting some 1.5 million users—is a failure of all aspects of IT security, including the ability to set appropriate policy, communicate that policy to employees and deploy the relevant security technology.
Health Net announced last week that unencrypted records, and the portable external hard drive containing those records, were lost. A loss of this magnitude from normal business practice suggests that either sensitive data accumulated over a long period of time and was not systematically erased when no longer needed, or the user worked on extremely large chunks of data without proper security controls. IT should have been aware of both possibilities and acted to protect the business." ...
Friday, November 13, 2009
Audit Ready Data Center Webinar with Accelops
AccelOps has a really interesting approach to management of the technical infrastructure for mid-tier organizations. They do a solid innovative job of going a few extra steps to combine, correlate and analyze data - steps that IT does not have to learn to manually perform. The Audit-Ready Data Center is a webinar in conjunction with ISSA where we talk about the needs of meeting requirements for continuous audit that provides a common language for security discussions with other organizations in the company. Hope you can check it out on the 19th.
Tuesday, November 10, 2009
Press Quote: Tufin extends security lifecycle management
Tufin has a nice vision for helping IT manage network access policies - coordinating rules between firewalls, routers, and switches for consistency and security. It is worth checking out, especially if your network has sensitive data (and what network doesn't).
"Firewall Policy Management functions are only part of the solution when controlling access to sensitive zones within the corporate infrastructure." said Eric Ogren, principal analyst of the Ogren Group. "Access policies that are enforced by high speed switches and routers need to cooperate, and be consistent with firewall rules for effective management of a secure network. Tufin’s approach of converging analysis of leading network and security devices can help enterprises control dynamic networks for compliance and security."
"Firewall Policy Management functions are only part of the solution when controlling access to sensitive zones within the corporate infrastructure." said Eric Ogren, principal analyst of the Ogren Group. "Access policies that are enforced by high speed switches and routers need to cooperate, and be consistent with firewall rules for effective management of a secure network. Tufin’s approach of converging analysis of leading network and security devices can help enterprises control dynamic networks for compliance and security."
How to use Internet security threat reports
A bunch of security threat reports have hit the presses lately. Here are a few thoughts of how IT should use these, as posted in SearchSecurity ...
"The Melissa worm, one of the most prolific email viruses in history, earned its notoriety by forwarding itself to the first 50 people found in a victim's Microsoft Outlook address book. Security researchers celebrated its 10th anniversary earlier this year, and in the decade since Melissa, the world has seen a boom in viruses, Trojans, SQL injection, spam, phishing and drive-by downloads." ...
"The Melissa worm, one of the most prolific email viruses in history, earned its notoriety by forwarding itself to the first 50 people found in a victim's Microsoft Outlook address book. Security researchers celebrated its 10th anniversary earlier this year, and in the decade since Melissa, the world has seen a boom in viruses, Trojans, SQL injection, spam, phishing and drive-by downloads." ...
Friday, November 6, 2009
Security benefits of virtual desktop infrastructures
Newly posted to SearchFinancialSecurity:
"An emerging technology is helping to solve security issues within the financial industry: virtual desktop infrastructures. With a virtual desktop infrastructure, an organization actually executes desktop applications on servers in the data center, relying on remote display protocols to give the user a localized look and feel. The security benefits of VDI in the data center are clear: IT controls software configurations, assuring that users execute software with the latest patches and upgrades ..."
"An emerging technology is helping to solve security issues within the financial industry: virtual desktop infrastructures. With a virtual desktop infrastructure, an organization actually executes desktop applications on servers in the data center, relying on remote display protocols to give the user a localized look and feel. The security benefits of VDI in the data center are clear: IT controls software configurations, assuring that users execute software with the latest patches and upgrades ..."
Wednesday, November 4, 2009
Two-factor authentication, constant vigilance foils password theft
The latest on passwords at SearchSecurity"
"The state of the art in static password protection policies has left some specialists questioning the usefulness of current password policies.
It's going to take new measures -- a mixture of technology and policy -- to hold users more accountable while addressing new attack methods and the automated connectivity of Web 2.0 behavior..."
"The state of the art in static password protection policies has left some specialists questioning the usefulness of current password policies.
It's going to take new measures -- a mixture of technology and policy -- to hold users more accountable while addressing new attack methods and the automated connectivity of Web 2.0 behavior..."
Thursday, October 29, 2009
Chip and PIN adoption serves lesson for U.S. payment industry
Fresh off the SearchSecurity press:
"First Data Corp. and RSA, the security division of EMC Corp., are the latest major companies working together to encrypt credit card data at the point-of-sale device. This early encryption approach, also offered by other vendors, including ProPay Inc. and Merchant Warehouse, can lower the technical costs of Payment Card Industry Data Security Standard (PCI DSS) compliance, as well as the legal risk of disclosure notifications and the risk of mass information loss. It is a proactive approach that retailers should be evaluating" ...
"First Data Corp. and RSA, the security division of EMC Corp., are the latest major companies working together to encrypt credit card data at the point-of-sale device. This early encryption approach, also offered by other vendors, including ProPay Inc. and Merchant Warehouse, can lower the technical costs of Payment Card Industry Data Security Standard (PCI DSS) compliance, as well as the legal risk of disclosure notifications and the risk of mass information loss. It is a proactive approach that retailers should be evaluating" ...
Tuesday, October 27, 2009
Lumension adds AV to endpoint security offering
Lumension continues to put together the critical pieces of an endpoint security solution. In addition to patching vulnerabilities to reduce the risk of an exploit and application whitelisting with device control to reduce the risk of an attack modifying software, Lumension now adds an attack-centric AV layer to eradicate known threats. Defense in depth only really works if each layer adds a unique complementary technology approach. That way, whatever threat one approach might miss, the next approach is likely to catch. The addition of AV to patching and applicatino whitelisting is a good approach that should work well for Lumension's customers.
I supported Lumension's release activity with the following quote:
Eric Ogren, Principal Analyst, Ogren Group
“As the explosion of viruses and data-stealing crimeware continues to wreak havoc on corporate networks, IT administrators need to take an increasingly more proactive and blended approach to endpoint protection. Lumension now offers solution layers that close system vulnerabilities, identify and remove attacks, and protect against malware from Web 2.0 threats. Organizations that adopt such a coordinated defense will be better-suited to protect against threats, keeping their network, endpoints, and business resistant to the daily influx of newborn malware.”
I supported Lumension's release activity with the following quote:
Eric Ogren, Principal Analyst, Ogren Group
“As the explosion of viruses and data-stealing crimeware continues to wreak havoc on corporate networks, IT administrators need to take an increasingly more proactive and blended approach to endpoint protection. Lumension now offers solution layers that close system vulnerabilities, identify and remove attacks, and protect against malware from Web 2.0 threats. Organizations that adopt such a coordinated defense will be better-suited to protect against threats, keeping their network, endpoints, and business resistant to the daily influx of newborn malware.”
Wednesday, October 21, 2009
DLP technology challenges security costs
New to SearchSecurity:
"Vendors have blurred the functional boundaries between data leakage prevention, digital rights management and even endpoint device control, to the extent that IT should reset expectations for DLP deployments. The recent Burton Group report on DLP summarizes the market from a vendor offerings point of view, with heavy emphasis in vendor rankings given to companies with large market shares and marketing budgets. DLP can be a powerful weapon for security teams balancing threat protection with data protection and acceptable use policies, but only in well-defined business scenarios." ...
"Vendors have blurred the functional boundaries between data leakage prevention, digital rights management and even endpoint device control, to the extent that IT should reset expectations for DLP deployments. The recent Burton Group report on DLP summarizes the market from a vendor offerings point of view, with heavy emphasis in vendor rankings given to companies with large market shares and marketing budgets. DLP can be a powerful weapon for security teams balancing threat protection with data protection and acceptable use policies, but only in well-defined business scenarios." ...
Subscribe to:
Posts (Atom)
