While security risks are not going away for companies, efficient and secure enterprises will safely reduce the share of security spending by 3 to 6 percent of their overall IT budgets through 2011, according to a new report from Gartner.



Newsletter Archive: 2011
/1215.html" style="color: #000000;">Securing Data In 2012
PCI Will Push for Greater Protection While Cloud Continues to Play Catch-up. PCI compliance and the security of data in the cloud are fast becoming a single issue for businesses. Unfortunately, while compliance and other legislative requirements will become more rigorous, demanding more robust data security that will better protect individuals, the security of that data while it's in the cloud, whether in transit or at rest, is struggling to keep pace.

Date: 2011-12-15


Android Tops Most-Vulnerable Lists, But Is It A Deserved Distinction?
As Android becomes more and more widespread, analysts have brought many vulnerabilities of the OS into the public eye.

Date: 2011-11-21


Cyber Security On The Investor Agenda
US securities regulators have formally asked public companies for the first time to disclose cyber attacks against them, reports Reuters.

Date: 2011-10-19


Hp Unveils Some New Offerings For Cloud Security
Hp (Hewlett Packard) recently acquired the companies ArcSight, Fortify Software, and Tipping Point and with the technology that came with them have come out with a new security platform.

Date: 2011-09-23


Cryptoprocessors As A Viable Security Solution
Encryption is computationally very expensive, but the growing threat of data loss is putting pressure on companies to implement greater security. When it comes to internet security, most corporations don't think to look to cryptoprocessors.

Date: 2011-08-17


Enhancing Secure Communications With Strict Transport Security
New security capabilities in Firefox, Chrome and several other browsers enable web applications to create a more secure browsing experience with users.

Date: 2011-07-13


2011 To Be The Worst Year For Security Breaches
So far this year millions of user accounts have been compromised, and millions of dollars spent in cleaning up the messes. Several other articles are writing about this, saying that 2011 is set to be the worst year ever for security breaches. Online security is certainly not keeping pace with the growth in the amount of data stored online. The mounting number of breaches should alarm all security managers to implement better practices.

Date: 2011-06-22


Possible DNS Hijacking In Phishing Attack On Gmail Accounts
Gmail accounts including some government officials and Chinese activists were recently compromised by a phishing attack. These attacks are not typical--they are spear phishing attacks where the emails are tailored to the person receiving them. The email is typically sent from a person the victim knows well and is disguised as originating from a legitimate Gmail server, possibly through DNS hijacking. Who is to blame for the attacks is still unclear.

Date: 2011-06-03


Looking For A Free Security Alternative? Try Microsoft Security Essentials!
For a long time, especially back in the Microsoft Windows 95-2000 days, the only way to get really secure security software was to pay for it. Recently, Microsoft unveiled its own free software that you can use to protect your computer (along with other computers in a corporate setting) called Microsoft Security Essentials.

Date: 2011-05-12


Bringing Web Application Security To University Students
Over the weekend Mozilla led an open source boot camp at Stanford University with a great lineup of courses including a hands-on web security lab where students performed actual exploits against a vulnerable web application.

Date: 2011-04-29


ACL Reporter Helps Monitor Windows Server Security
Network Systems Managers (NSM) and Managed Service Providers (MSP) will be glad to know that an enterprise-class Windows Server reporting tool is available for free. N-able Technologies is the makers of ACL Reporter, and their tool provides managers a free option to conduct much needed security reports for Windows Server systems.

Date: 2011-04-15


The Lone Comodo-Hacker Theory
In a message posted on pastebin, an individual using the handle of "comodohacker" has claimed responsibility for last week's hack-attack on the Comodo site in which someone was able to gain access to the RAs site and issue 9 SSL Certificates for some major sites such as:

Date: 2011-03-30


SOA Security And Identity Management Practices To Be Covered In Workshop
Enterprise security professionals who are interested in brushing up on topics related to service-oriented architecture and identity management may want to check their schedules. WSO2 intends to hold affordable, day-long workshops in three different U.S. cities before the end of March.

Date: 2011-03-18


IBM Releases New System For Enterprise Security
Enterprises around the world are continually facing new threats, many times on a daily basis. These threats can come from a wide variety of places, such as data leaks, viruses, hacks, and so on. Vulnerabilities can be tough to track across and infrastructure, which is why having the best tools at one's disposal is key. IBM has released a system which if it can do what they claim, could be a game changer.

Date: 2011-02-16


Google Declares Major Security Issues With Internet Explorer
Michal Zalewski is a researcher and engineer at Google who's recent focus has been on "fuzzing," or checking browsers and sites for potential security holes.

Date: 2011-01-28


Five Security Tips For The New Year
As 2010 comes to a close we turn our attention now to the New Year. Since the dawn of the Internet there have been those using it who are up to no good.

Date: 2011-01-13


2010 Archive

2009 Archive

2008 Archive

2007 Archive

2006 Archive