When is VeriSign going to learn about Tokenization?
With the RSA/EMC breach still in our minds, and also some of the additional breaches that resulted from the RSA breach, including Lockheed Martin. RSA issued a vaguely worded letter about what data...
View ArticleCloud Contract? You better have data security!
Cloud Security is always a hot topic. However when I read the article “In the Cloud, a data breach is only as bad as your contract”, I raised my eyebrows. In the cloud, a data breach can occur...
View ArticleData Security for Cloud Computing
The cloud is widely recognized as the disruptive technology that is changing the way everyone (from consumers to small businesses to large enterprises) communicates and does business. It comes as no...
View ArticleWhy your most valuable asset is under constant attack
While some are trying to steal your data outright, others are hard at work creating new ways to gain access to that data through an application. They’re attacking your external applications that...
View ArticleGlobal Payments has some explaining to do
I agree that “Global Payments has some explaining to do“. Global Payments said “Based on the forensic analysis to date, network monitoring and additional security measures, the company believes that...
View ArticleMost breaches caused by a lack of data security, Verizon finds
The article, by Jaikumar Vijayan, appeared in Computerworld on April 9, 2012. It concluded despite rising concerns that cyber attacks are growing more and more sophisticated, hackers used relatively...
View ArticleLinkedIn should use security best practices
Last week LinkedIn was hacked. The company confirmed that some of the 6.5 million password hashes leaked online belonged to users of its social network. Researchers have confirmed that the passwords...
View Article94 million Federal Government records exposed
Adam Levin wrote in “94 Million Exposed: The Government’s Epic Fail on Privacy” that the US Federal Government exposed more than 94 million records with personally identifiable information (PII) during...
View ArticleBig Data Security Best Practices
In a recent blog post from Wikibon, Jeff Kelly wrote, “When talking about Big Data, the conversation tends to focus on Data Science and analytics. That is, the stories about Big Data that hit the front...
View ArticleBalancing Privacy and Big Data
In a recent article from the NY Times titled “Big Data is Opening Doors, but Maybe Too Many“, Steve Lohr details the delicate balance of privacy restrictions and the use of Big Data analytics to make...
View ArticleTaking A Proactive Approach To Privacy Security
In a recent New York Times article, Eric Pfanner details the current battle between Google and European Union regulators regarding alleged privacy violations, spurred by Google’s latest privacy policy...
View ArticleTaking Control of Cloud Security
Recently, Isha Suri from Silicon Angle wrote a blog post titled “Cloud Security Still a Murky Issue – As Vendors Move, Vulnerabilities Creep With Them“. In this post, Isha details the rapid adoption of...
View ArticleTaking A Measured Approach to Big Data Security Analytics
Adrian Lane’s recent Securosis blog post, titled “Security Analytics with Big Data [New Series]” outlines the developing issues with SIEM systems and the need for Big Data security analytics. “It’s not...
View ArticlePHI Protection Challenges & Solutions: Lessons Learned from PCI DSS
May 8, 2013, I will be speaking at the VigiTrust event, “How to Prevent Data Breaches in the Healthcare Industry and Surpass HIPAA Compliance,” detailing the challenges in and solutions for protecting...
View ArticleMonetizing Big Data Reserves Brings New Security Concerns
In a recent article in the Wall Street Journal titled, “Phone Firms Sell Data on Customers“, Anton Troianovski details the growing practice of selling “vast troves of data” by big phone companies. I...
View ArticleAddressing Practical Issues with Network SIEM in Large Enterprises
In a recent article on DarkReading.com titled, “Why Are We So Slow To Detect Data Breaches?“, Ericka Chickowski detailed the issues with SIEM that cause so many breaches to go undetected for months....
View ArticleWhich Payment Tokenization Solution Approach Has The Lowest TCO?
I recently fielded a question requesting an analysis of the TCO of the three primary solution approaches to payment processor tokenization: (A) Payment processor in-house tokenization service (B)...
View ArticleDoE Hacked (Again) – Why Data Security Can’t Be Ignored
The Department of Energy recently announced that they had experienced a breach of 14,000 employees’ personal information. While perimeter network security gets a lot of attention, back end security of...
View ArticleAnother Look at 5 Myths of Encrypting and Tokenizing Sensitive Data
In a recent article on CSO Online, Dave Kilgallon reviewed five common myths of encrypting and tokenizing sensitive data, and the misunderstandings that go along with them. While I’m sure his list was...
View ArticleHow Data Security Tips the Scales in Privilege vs. Protection
In his recent blog post on ZDNet, Larry Seltzer exposed the current issues with excess privileges in many organizations. Most importantly, how the principle of “Least Privilege” is often being ignored,...
View Article