Showing posts with label Information security. Show all posts
Showing posts with label Information security. Show all posts

Wednesday, April 22, 2015

RSA2015 – The InfoSec Landscape with Jeremiah Grossman

In a fascinating and fun conversation, InfoSec luminary, web application expert, TEDx speaker and WhiteHat Security Founder, Jeremiah Grossman explains some of the change occurring within information security. Have the never ending breaches changed the way people think about security? How do organizations protect their critical applications in today’s hybrid environments? He also has some fun with the fate of the perimeter and also explains why InfoSec needs security guarantees. And if you ever wondered, learn why many InfoSec folks participate in a Brazilian Jiu Jitsu Smackdown after events like RSA. Is there a connection between personal self-defense and defending against digital attacks?

 

ps

Related

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, May 7, 2014

The Reach of a Breach

It comes as no surprise that the CEO of Target has resigned in the wake of their massive data breach. The 2nd executive, if I remember correctly, to resign due to the mishap. Data breaches are costly according to the most recent Ponemon 2014 Cost of Data Breach Study: United States and the main reason for the steep increase in costs is 'the loss of customers following the data breach due to additional expenses required to preserve the organization's brand and reputation.' The cost of each lost or stolen record, on average, increased from $188 to $201 per record from 2012 to 2013 - a 9% increase.

But that's not all, In 2013, there appeared to be 'an abnormal churn rate' of 15% of customers abandoning companies, especially those in financial services, hit by a breach says Ponemon. I'm always curious about that. I usually avoid stores that have been recently compromised wondering if something is lingering yet think, they gotta be on high alert, especially with law enforcement involved. Maybe it's as safe as it ever will be.

A recent Courion survey of IT security executives showed that 78% of respondents say they're anxious about the possibility of a data breach at their organization. If there were a massive security breach at these companies, 58.8% said 'protecting the privacy of our customers' would be top priority and 62.7% would lament about 'negative publicity affecting the company brand' due to the breach. Maybe that's the problem. They're more worried about their image than they are of protecting our info. It's the 58.8% you want to shop at.

Reaching for more, Symantec’s Internet Security Threat Report (ISTR), Volume 19, shows a big change in cybercriminal habits, revealing the bad guys are plotting for months before pulling off the huge heists – instead of popping quick hits with smaller bounty. One big is worth fifty small. In 2013, there was a 62% uptick in the number of data breaches exposing more than 552 million identities. That's about 10% of the planet's population, give-or-take.

And finally, there have been a few companies that have gone out of business due to a leakage but a few months ago a data breach also closed some Seattle area Catholic schools. According to the Seattle Archdiocese, at least three Roman Catholic parishes and the Archdiocese’s chancery offices had been targeted by a tax-fraud scheme. In order to allow those who were victims time to contact the appropriate institutions during school hours, they cancelled classes. How's that for reach.

ps

Related:

 

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, October 22, 2013

Privacy for a Price

A few weeks ago, I went to my usual haircut place and after the trim at the register I presented my loyalty card.  You know the heavy paper ones that either get stamped or hole-punched for each purchase.  After a certain number of paid visits, you receive a free haircut.  I presented the card, still in the early stages of completion, for validation and the manager said I could convert the partially filled card to their new system.  I just had to enter my email address (and some other info) in the little kiosk thingy.  I declined saying, 'Ah, no thanks, enough people have my email already and don't need yet another daily digest.'  He continued, 'well, we are doing away with the cards and moving all electronic so...'  'That's ok,' I replied, 'I'll pay for that extra/free haircut to keep my name off a mailing list.' 

This event, of course, got me thinking about human nature and how we will often give up some privacy for either convenience or something free.  Imagine a stranger walking up to you and asking for your name, address, email, birthday, income level, favorite color and shopping habits.  Most of us would tell them to 'fill in the blank'-off.  Yet, when a Brand asks for the same info but includes something in return - free birthday dinner, discounted tickets, coupons, personalized service - we typically spill the beans.

Infosys recently conducted a survey which showed that consumers worldwide will certainly share personal information to get better service from their doctors, bank and retailers; yet, they are very sensitive about how they share. Today’s digital consumers are complicated and sometimes suspicious about how institutions use their data, according to the global study of 5,000 digitally savvy consumers.  They also created an infographic based on their findings.

Overall they found:

  • 82 percent want data mining for fraud protection, will even switch banks for more security;
  • 78 percent more likely to buy from retailers with targeted ads, while only 16 percent will share social profile;
  • 56 percent will share personal and family medical history with doctors

...and specific to retail:

  • To know me is to sell to me: Three quarters of consumers worldwide believe retailers currently miss the mark in targeting them with ads on mobile apps, and 72 percent do not feel that online promotions or emails they receive resonate with their personal interests and needs
  • To really know me is to sell me even more: A wide majority of consumers (78 percent) agree that they would be more likely to purchase from a retailer again if they provided offers targeted to their interests, wants or needs, and 71 percent feel similarly if offered incentives based on location
  • Catch-22 for retailers? While in principle shoppers say they want to receive ads or promotions targeted to their interests, just 16 percent will share social media profile information. Lacking these details could make it difficult for retailers to deliver tailored digital offers

Your data is valuable and comes with a price.  While many data miners are looking to capitalize on our unique info, you can always decline.  Yes, it is still probably already gathered up somewhere else; Yes, you will probably miss out on some free or discounted something; Yes, you will probably see annoying pop-up ads on that free mobile app/game and; Yes, you might feel out of the loop. 

But, it was still fun to be in some control over my own info leaks.

ps

Related:

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, June 11, 2013

Small Business is a Big Target

If you think that small businesses are not an enticing enough target to breach, think again.  While the media has certainly upped it's coverage over the last couple years pertaining to data loss, many of the headlines involved global brands and tens of thousands records...not the corner deli, the mom/pop shop or the new start up.  Yet a couple of recent reports show that small businesses and start-ups are prime targets for data loss.

The annual, chuck full of stats, Verizon Data Breach Report noted that of the 621 confirmed data breaches, almost half happened at companies with less than 1000 employees and almost 200 at companies with less than 100 employees.  A Symantec report echoed the finding.  In theirs, small businesses with less than 250 employees accounted for 31% of the attacks in 2012, up 18% from 2011.  Symantec also notes that start-ups are especially vulnerable in the early going.

Why are these groups targets?

They have valuable data - intellectual property, financial information, digital identities - but may not have the resources to properly protect that data.  Many large, global companies have beefed up their security in fear of becoming the next headline in a major newspaper.  Thieves usually go after the easiest target - those with limited resources to protect against such an attack.  Thieves may also infiltrate a smaller organization to jump on a global network if a partnership is in place. Take out the villages before entering the capital.  In a start-up's situation, as they quickly launch, employees may be enticed to click a malicious link in an email...which then spreads.  Most startups get infected with malware within the first year.

From marketing organizations to cleaning products to credit repair services, here are some stories of how cyber attacks almost destroyed 5 small businesses.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, April 2, 2013

Mobile Threats Rise 261% in Perspective

A new report from ABI Research indicates that the number of unique mobile threats grew 261% in just two quarters.  As mobile functionality grows so does the vulnerability threat vector as mobile malware is starting to target certain systems.  This is certainly a concern for those organizations rolling out BYOD initiates.  You've heard athletes and coaches talk about giving 110%, which is obviously impossible, but some of the recent mobile malware growth numbers are huge, like on the order of 1700%. 

To gain some perspective, I wanted to know what else in the world is growing at 261%.  Here's what I found.

Real Estate: According to this article, the Guangzhou City Housing Authority in 2012 said, Guangzhou hand house prices rose to 14,044 yuan from 3888 yuan, or up to 261%, while the national the national urban average house rose 143% - if I understood the article correctly.

US Household Debt: This article from June 2012, reported that household debt as a percentage of disposable income from 1989 to 2004, for the first four income quintiles and the top two deciles, the increase in debt per family was 261%, 170%, 131%, 90%, 103%, 93%.  So during the credit boom the poorest families increased their debt, proportionally, the most.  It has now dropped to 2004 levels of around 110% on average.

Mobile Ad Impressions: TechCrunch wrote back in December 2011 (Dec 30th, specifically), that mobile ad impressions on the new (at the time) Kindle Fire grew 261% on Christmas Day 2011.  Mobile ad network Millennial Media reported that as consumers opened and used their new Kindle Fires, ad impressions increased even more. As millions of consumers unwrapped new Kindle Fires, Millennial saw an average daily growth rate of 113 percent.  On December 24, impressions grew 32 percent; and on Christmas day in particular, impressions on the Kindle Fire grew 261%.

mCommerce: Research by IMRG Capgemini e-Retail Sales Index showed that there was solid growth in Internet retail sales in October 2012. British shoppers have been said to spend £6.7billion online and October 2012 saw 261% growth year on year.

Weather/Rainfall: Rainfall in New Delhi during February 2013 was 261% above normal.  Apparently during that month, the active wet spells were a result of stronger than normal westerly winds in upper levels along Delhi latitude.  An official was quoted saying, 'The low level wind anomaly over northwest Bay of Bengal and northeast Arabian Sea was southeasterly which facilitated enhanced moisture convergence over Delhi and adjoining areas.'

Gaming Casinos: A survey of 3,035 New England residents found that more than twice as many Massachusetts residents visited Twin River and Newport Grand Casinos as Rhode Island residents in 2012, continuing a six-year trend that saw the number of visits from Bay State residents to the Lincoln-based casino skyrocket by 261%.  This may change soon however once Massachusetts opens three resort-style casinos.

Payday Loans: Larger banks started to jump into the lucrative payday loan business in 2010 and 2011 since, they can loan $100 for a $7.50 fee, an annualized interest rate of 261%.  As the banks like to point out, it is less than the 400-plus% charged by many payday lenders.

The 1970s: While That 70s Show kicked off the careers of a few actors (T Grace, A Kutcher, M Kunis and others), the 70's was a period of high inflation with overall prices rising 261% during the decade.  According to How Much Would £10 Have Bought You Over The Years?, during the 70s £10 would have bought one of the very first baby car seats for a new family, or a food mixer for a budding chef.

There were a couple others like ACCESS Bank posts 261% profit growth, shares of Time Warner Cable have risen 261% since the spinoff from Time Warner in 2009, and the fact that an income of $30,000 is 261% of the poverty level to qualify for certain provisions of the Affordable Care Act.  261% of anything is a significant jump in growth and clearly the rise mobile malware is no exception.  Hopefully comparing it to other areas that had the same growth helps in understanding the significance today and maybe my blog will have a 261% increase in readership.  I thought about playing 2-6-1 for the Daily 3 lottery but that was drawn on March 30, 2013.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Posted via email from psilva's prophecies

Tuesday, March 5, 2013

Pulse2013 – BIG-IP ASM & IBM InfoSphere Guardium

I meet with F5 Solution Architect Nojan Moshiri to learn about the integration between BIG-IP ASM and IBM’s InfoSphere Guardium offering real time data security along with contextual meta data associated with the SQL data. Each enhances the other to provide both defense-in-depth protection and contextual security information. Powerful stuff.

 

ps

Related:

Technorati Tags: f5,ibm,pulse,ibmpulse,psilva,video,security, database,Guardium, sql,

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]