Friday, February 26, 2010

Using user communities to bolster security offerings

Social networking ideas are coming to security, with efficiencies that are likely to .

Secure Passage is introducing a program whereby members can share configuration rules and policies to allow tight alignment between firewalls, routers, and other network devices. This is a really good idea that allows its customers to quickly tighten the security and compliance of their networks while reducing the chances of creating gaping holes in their security profiles. Secure Passage may also find that customers are extending the product into applications and server settings, which could lead SP to a nice growth path.

Computerworld post ...

I thought the Alexa statistics on web site usage were pretty cool. I have always liked numbers and statistics. I did some exploring on US-China-India numbers on web site visitors for a Computerworld article and found the following (hopefully the formatting does not get screwed up):

Company USA India China
Check Point 22.3% 13.8% 4.8%
Cisco 32.2 12.5 4.7
EMC 39.8 13.2 9.8
IBM 18.4 12.5 19.3
Microsoft 20.6 7.5 7.0
NetApp 40.6 18.8 4.9
Symantec 25.3 13.3 3.2
Websense 30.3 7.8 23.9

Lockheed-Martin 49.5 7.0 11.3
Pfizer 47.6 12.9 5.7
Whitehouse.gov 65.7 3.4 3.9

There could be lots of business reasons for some of these numbers such as sales model, or amount of off-shore manufacturing partners, etc. However, the number of visitors from China and India is frequently significantly greater than the number from large industrialized countries including England, Germany and Japan.

If you are in security, you better know your business.

Friday, January 22, 2010

Computerworld blog entry

After an 11 month hiatus, I have returned to the Computerworld blog. I had a lot of fun writing for them before and I am thrilled that they would have me back! Here is the first posting of 2010 ...

"Application service providers offer a centralized control point to deliver secure services for millions of its subscribers. Let’s hope that more social networking application providers follow Facebook’s and Comcast’s example by making it easy to acquire endpoint security software, and by enhancing its own internal vigilance. In the meantime, consumers with a paid anti-virus subscription are advised to act quickly in getting free protection from the likes of Avast!, AVG, or Microsoft..."

Tuesday, December 29, 2009

Web security strategy

Check out SearchSecurity.com for the latest:

If you haven't focused on an enterprise-wide Web security strategy then it's time for a reality check. It's safe to assume that various parts of your organization are using Web applications and a cloud computing infrastructure or services, and the time to wrap a security strategy around that is now.

Wednesday, December 16, 2009

Microsoft and EC settle their IE dispute

Good to see the European Union competition commissioner has finally come to its senses and settled its silly and costly business practices lawsuit against Microsoft over the bundling of Internet Explorer into Windows.

This seemed like pure harassment to me – browsers are free, users can easily download and install any browser they want, and service providers could have included or recommended browsers if their customers demanded help. In fact, you could even argue that ubiquitous feature-rich free browsers have worked to everyone’s benefit (though I do not believe Microsoft set the market price of free).

Anyway, Microsoft and the European Commission are now in agreement. Microsoft has agreed to give the user a choice of leading browsers in versions of Windows and presumably the EC can find better things to do.

Tuesday, December 15, 2009

Lessons from CoreStreet

CoreStreet is the most recent security company fire sale – selling to ActivIdentity for “approximately” $20 million. Usually this means that the investors get some money back, the founders get some candy so they’ll bring their next idea back to the VC’s, and everyone else gets new business cards. CoreStreet gave it a good go – they had sharp mathematicians and a new idea for authentication, but could not find a sustainable and repeatable business. There are at least 2 things that other struggling security companies may be able to learn from CoreStreet:

Keep your messaging simple. CoreStreet is in the “distributed credential validation solutions” segment. You cannot expect a security team to evaluate, recommend or buy a product that they do not fully understand or have an expressed need for. When I first talked with them, CoreStreet described proofs and math models to authenticate signatures when a certificate authority was unavailable. I was in over my head in about 30 seconds, and I like to think I’m pretty good at authentication and math. If you are looking to increase sales traction, make sure your messaging is easily understood and directly addresses an important business need.

Try to diversify from government dominated customer base. When it comes to security, government agencies often have unique solution requirements that do not translate well into the commercial world. You can make a business serving the federal government if your company reaches a critical mass, but if you are not cash flow positive you need to have alternatives. While CoreStreet attracted business from defense-oriented agencies, it couldn’t translate its technology to the commercial sector. The company had no options and no place to grow, except perhaps by acquisition to a vendor that can service outstanding government contracts.

There is a tough year coming up and we will see more security vendors like CoreStreet with tired investors and shuttered doors in 2010.

Database activity monitoring lacks security lift

Posted to SearchSecurity ...

The IBM acquisition of Guardium Inc., a privately-held database activity monitoring (DAM) vendor, is far from a validation statement of DAM as a viable security market segment.

Vendors including Embarcadero Technologies Inc., IPLocks (acquired by Fortinet Inc.), Lumigent Technologies Inc., Symantec Corp. and Tizor Systems Inc. (acquired by Netezza Corp.), have already given up on the DAM space, leaving companies such as Application Security Inc., Imperva Inc., Secerno Inc. and Sentrigo Inc. fighting to divvy up a total annual market of well less than $100 million. The IBM acquisition of Guardium helps the company gain information management technology and a capability to drive professional service revenues in the data center.

Tuesday, December 1, 2009

Health Net breach failure of security policy, technology

I'm back from vacation and Thanksgiving - hope you all had a nice break!

Here is the latest SearchSecurity posting:

"The recent Health Net data breach—affecting some 1.5 million users—is a failure of all aspects of IT security, including the ability to set appropriate policy, communicate that policy to employees and deploy the relevant security technology.

Health Net announced last week that unencrypted records, and the portable external hard drive containing those records, were lost. A loss of this magnitude from normal business practice suggests that either sensitive data accumulated over a long period of time and was not systematically erased when no longer needed, or the user worked on extremely large chunks of data without proper security controls. IT should have been aware of both possibilities and acted to protect the business." ...

Friday, November 13, 2009

Audit Ready Data Center Webinar with Accelops

AccelOps has a really interesting approach to management of the technical infrastructure for mid-tier organizations. They do a solid innovative job of going a few extra steps to combine, correlate and analyze data - steps that IT does not have to learn to manually perform. The Audit-Ready Data Center is a webinar in conjunction with ISSA where we talk about the needs of meeting requirements for continuous audit that provides a common language for security discussions with other organizations in the company. Hope you can check it out on the 19th.

Tuesday, November 10, 2009

Press Quote: Tufin extends security lifecycle management

Tufin has a nice vision for helping IT manage network access policies - coordinating rules between firewalls, routers, and switches for consistency and security. It is worth checking out, especially if your network has sensitive data (and what network doesn't).

"Firewall Policy Management functions are only part of the solution when controlling access to sensitive zones within the corporate infrastructure." said Eric Ogren, principal analyst of the Ogren Group. "Access policies that are enforced by high speed switches and routers need to cooperate, and be consistent with firewall rules for effective management of a secure network. Tufin’s approach of converging analysis of leading network and security devices can help enterprises control dynamic networks for compliance and security."

How to use Internet security threat reports

A bunch of security threat reports have hit the presses lately. Here are a few thoughts of how IT should use these, as posted in SearchSecurity ...

"The Melissa worm, one of the most prolific email viruses in history, earned its notoriety by forwarding itself to the first 50 people found in a victim's Microsoft Outlook address book. Security researchers celebrated its 10th anniversary earlier this year, and in the decade since Melissa, the world has seen a boom in viruses, Trojans, SQL injection, spam, phishing and drive-by downloads." ...

Friday, November 6, 2009

Security benefits of virtual desktop infrastructures

Newly posted to SearchFinancialSecurity:

"An emerging technology is helping to solve security issues within the financial industry: virtual desktop infrastructures. With a virtual desktop infrastructure, an organization actually executes desktop applications on servers in the data center, relying on remote display protocols to give the user a localized look and feel. The security benefits of VDI in the data center are clear: IT controls software configurations, assuring that users execute software with the latest patches and upgrades ..."

Wednesday, November 4, 2009

Two-factor authentication, constant vigilance foils password theft

The latest on passwords at SearchSecurity"

"The state of the art in static password protection policies has left some specialists questioning the usefulness of current password policies.

It's going to take new measures -- a mixture of technology and policy -- to hold users more accountable while addressing new attack methods and the automated connectivity of Web 2.0 behavior..."

Thursday, October 29, 2009

Chip and PIN adoption serves lesson for U.S. payment industry

Fresh off the SearchSecurity press:

"First Data Corp. and RSA, the security division of EMC Corp., are the latest major companies working together to encrypt credit card data at the point-of-sale device. This early encryption approach, also offered by other vendors, including ProPay Inc. and Merchant Warehouse, can lower the technical costs of Payment Card Industry Data Security Standard (PCI DSS) compliance, as well as the legal risk of disclosure notifications and the risk of mass information loss. It is a proactive approach that retailers should be evaluating" ...