EnterpriseSecurity
SecurityProNews
ITmanagement







Top Articles

Proactive Pen-testing on a Shoe-string
[2010-08-30] Networking a machine, regardless of whether or not it is public-facing, means that the computer is allowing remote access to certain ports for certain services. Many personal computers, running either a Unix-like operating system or a Windows-based operating system, have networking and firewall defaults that need to be tightened down.

Follow the Leader: NSA Security Guidance
[2010-08-16] Most all new workstations and consumer hardware is designed and configured for regular public use. The default configuration is meant for fairly non-technical people. People who forget their administration passwords, people who desire a plug and play experience, and people who want things to work out of the box and problems to be fixed automatically. Unfortunately, this usually requires lackadaisical security policies.

Critical MS Security Update Leaves XP SP2 and Windows 2000 Systems Out of Luck
[2010-08-04] Earlier this week, on a Monday and a week before this month's Patch Tuesday, Microsoft uncharacteristically felt compelled to push a security update to remedy a severe system threat that allows remote code execution on all versions of Windows. Security advisories began appearing in mid-July, and Microsoft could not wait a week longer for the second Tuesday of the month, when system administrators expect and plan for system updates and patches, to release the fix.

Cisco Warns Of Security Threats To The Enterprise
[2010-07-22] Businesses need to change their mindset on security to help ensure that their networks and vital corporate information are protected from evolving security threats, according to the Cisco 2010 Midyear Security Report released today.

Cisco Finds Social Networks, Random Devices Pose Security Risks
[2010-06-29] The results of a new enterprise security survey should be reliable; they stem from a poll involving 500 IT security professionals based in five different countries. They're not likely to make enterprise security experts happy, however, as they show that users often disregard rules in order to use social networks and unsupported devices at work.

Efficient Enterprises Forecast To Reduce Security Budgets
[2010-06-15] While security risks are not going away for companies, efficient and secure enterprises will safely reduce the share of security spending by 3 to 6 percent of their overall IT budgets through 2011, according to a new report from Gartner.

Google Said To Be Dumping Windows Over Security Concerns
[2010-06-01] One of the world's most successful technology companies will stop using Microsoft Windows due to security concerns, according to a new report. Unnamed Google employees even hinted that Windows was partly to blame for allowing Chinese hackers to carry out a successful attack.

Increasing Enterprise Security With New Risk Practices
[2010-05-17] I followed up with Steve Culp of Accenture about their announcement of a new Risk Management practice earlier this year. Obviously Accenture has been doing risk management for a long time but they have now brought together people who were already working in this space in different verticals and in their information systems practice as well as people experienced in analytics and created a practice group.

Privacy And Security Could Be Potential Show Stoppers For Enterprise Social Media
[2010-05-04] How about if we finish off another wonderfully busy and inspiring week in the Social Computing space with another thought provoking blog post on the topic of Privacy and Security, perhaps two of the main key themes that keep popping up as potential showstoppers for social software adoption efforts within the corporate world?

Addressing The Security Risks Involved With Social Computing
[2010-04-19] If you have been exposed to Social Computing within the enterprise for a little while now I bet most of you folks out there would probably be able to identify one or two of the main issues that every single corporation has got with regards to the wider adoption of social software tools, both inside and outside of the firewall. Those two issues are actually privacy and security. Oh, and perhaps risk management, too!

McAfee Partners With Riverbed On Enterprise Security
[2010-04-06] McAfee and IT firm Riverbed Technology have announced a partnership that delivers a comprehensive security and wide area network (WAN) optimization solution for organizations with remote offices.

Enterprises Vulnerable to Network Security Problems During Spring Break and Holidays
[2010-03-23] When one thinks of network security, problems surrounding spring break and holidays rarely get mentioned. However,according to a PacketMotion survey, security issues are prevalent during spring breaks and holidays. Specifically, being able to track remote and mobile access, which is increased during breaks due to employees accessing work related networks and email from various locations.

Protecting Your Enterprise Asset Security
[2010-03-10] Readers, I would like your help addressing a question from one of my clients. Please add comments with your thoughts. Consider a scenario where you offer training via online recorded content. Your revenue stream is based on people purchasing the right to watch and listen to your recordings.

Your Password Could Be A Large Security Concern
[2010-02-24] The weakest point of most online accounts are their passwords. This potential security threat can become just that much worse if your password is stolen and you happen to use the same password for a lot of different services.

Addressing The Enterprise Security Concerns With Flash
[2010-02-10] Dennis Fisher of Kaspersky Labs (a security software vendor) wrote an article this month predicting that miscreants will continue focusing their efforts on exploiting Adobe products in 2010.

Physical Security vs Network Security
[2010-01-27] When most people think about security, they think about physical security. Is our build secure? Are our server in a secure location? Is our build monitored to ensure no one can break in? These are the most common questions asked by a company when thinking about security.

Building Better Security Through Cloud Computing Best Practices
[2009-12-23] The Cloud Security Alliance (CSA) issued the second version of its "Guidance for Critical Areas of Focus in Cloud Computing", now available on the Cloud Security Alliance website.

Adding More Security To Your Wordpress Sites
[2009-12-09] It is no huge secret that I have had this WordPress blog hacked twice this year but some consolation is that I am not alone.

Hijackers Expose Serious Security Risk To Enterprise Facebook Users
[2009-11-11] Control your info has taken administrative rights to hundreds of groups on Facebook this morning - which is going to prompt a stampede of fear across the Facebook landscape. Looking at the security of social networking - this is going to be a bad day for many groups on Facebook.

How To Enact Data Privacy Within Your Enterprise
[2009-10-21] We all have a vested interest in how data and data privacy is enacted by companies, regardless of the environment, cloud, mobile (laptop, cell phones), private Data Center, or anything else that is a combination of the above. Companies have a vested interest in keeping their customers data private and clear of distortion or error. Consumers and people in social networks also have a vested interest in making sure that the data they share is not abused or misused.

Protecting Yourself From Email Phishing Attacks
[2009-10-07] A phishing attack is targeting thousands of web-based email users, according to the BBC and Read Write Web. Tens of thousands of users of each site have already been victimized, with the usernames and passwords available on lists.

SEO and Wordpress Security
[2009-09-16] In recent weeks wordpress security, or more correctly the lack of wordpress security has been getting a lot of attention. While most people consider this a site maintenance issue, it has implications that affect your SEO efforts, in this post I'll explain why, and look at some things you can do to protect yourself, and reduce the damage.

Adding Needed Security To SMS And PayPal
[2009-09-03] I bought my early-bird ticket for Reading Twestival this morning,  paying for it via PayPal. The simple purchase transaction I completed in a couple of minutes reminded me how much I place trust in PayPal, partly because of its neat one-time code by SMS message security procedure - what it calls its SMS Security Key - that I find reassuring.

Addressing Security Concerns In Real Time Can Achieve Business Success
[2009-08-19] Karen Mazurkewich suggests that Rapid Response is the key to online success.  Unfortunately a factor that weighs against online ecommerce is that Canadians are more wary about online security.

Huge Security Flaw Within Tag Based Systems
[2009-08-05] Louis Gray pointed out a new reading system yesterday called Lazyfeed, and overall I am pretty happy with it, but like all tag based reading systems, spammers and other miscreants have so corrupted the general tag base to get their message in front of people that tag based systems need something else to make sure they are delivering good valid content for the search strings provided.