<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>The Ashimmy Blog</title><link>http://www.ashimmy.com/</link><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/StillsecureAfterAllTheseYears" /><description>Writings on work, kids and network security</description><language>en</language><lastBuildDate>Mon, 06 May 2013 11:07:24 PDT</lastBuildDate><generator>TypePad http://www.typepad.com/</generator><feedburner:info uri="stillsecureafteralltheseyears" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><media:copyright>copyright 2010 all rights reserved</media:copyright><media:thumbnail url="http://ashimmy.podomatic.com/mymedia/thumb/1143272/460%3E_2340028.jpg" /><media:keywords>security,network,security,infosec,IDS,IPS,Vulnerability,endpoint,security,NAC,software</media:keywords><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Technology/Tech News</media:category><itunes:owner><itunes:email>ashimmy@hotmail.com</itunes:email><itunes:name>Alan Shimel</itunes:name></itunes:owner><itunes:author>Alan Shimel</itunes:author><itunes:explicit>no</itunes:explicit><itunes:image href="http://ashimmy.podomatic.com/mymedia/thumb/1143272/460%3E_2340028.jpg" /><itunes:keywords>security,network,security,infosec,IDS,IPS,Vulnerability,endpoint,security,NAC,software</itunes:keywords><itunes:subtitle>Security, technology and the state of things with Mitchell and Alan</itunes:subtitle><itunes:summary>Security, technology and the state of things with Mitchell and Alan</itunes:summary><itunes:category text="Technology"><itunes:category text="Tech News" /></itunes:category><creativeCommons:license>http://creativecommons.org/licenses/by/2.5/</creativeCommons:license><image><link>http://creativecommons.org/licenses/by/2.5/</link><url>http://creativecommons.org/images/public/somerights20.gif</url><title>Some Rights Reserved</title></image><feedburner:emailServiceId>StillsecureAfterAllTheseYears</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><feedburner:browserFriendly>This is an XML content feed. It is intended to be viewed in a newsreader or syndicated to another site, subject to copyright and fair use.</feedburner:browserFriendly><item><title>BYOD Security Scanning</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/vlkscv71WkQ/byod-security-scanning.html</link><category>compliance</category><category>the security industry</category><category>vulnerability management</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Mon, 06 May 2013 11:07:24 PDT</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e201901be0ef47970b</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p><img style="margin: 0px 0px 5px 5px; display: inline" align="right" src="http://www.teamtomarket.biz/Partners/iScan-Online-Logo.jpg"></img>My friends at iScan Online, Billy Austin and Carl Banzhof have just released their latest whitepaper on BYOD Security Scanning.  This is an area of vulnerability scanning and compliance management that is not really being covered by any particular company today.  </p>  <p>Where mobile device management and anti-malware for mobile devices meet, there is a gap. This gap is filled by iScan Online. They can do on demand full vulnerability scans on mobile devices, configurations scans for misconfigurations and data discovery scans for credit card numbers, social<u> </u>security numbers and other personal or confidential data. </p>  <p>This paper highlights the 5 reasons why BYOD security scanning is a must have and what a good BYOD security scanning solution must do.</p>  <p>You can view the paper below or head over to <a href="http://www.iscanonline.com/" target="_blank">iScan Online</a> to download it.</p> <iframe style="margin-bottom: 5px; border-top: #ccc 1px solid; border-right: #ccc 1px solid; border-bottom: #ccc 0px solid; border-left: #ccc 1px solid" height="511" marginheight="0" src="http://www.slideshare.net/slideshow/embed_code/20655216?rel=0" frameborder="0" width="479" marginwidth="0" scrolling="no" mozallowfullscreen="mozallowfullscreen" webkitallowfullscreen="webkitallowfullscreen" allowfullscreen="allowfullscreen"> </iframe>  <div style="margin-bottom: 5px"><strong><a title="BYOD Security Scanning" href="http://www.slideshare.net/iscanonline/byod-security-scanning" target="_blank">BYOD Security Scanning</a> </strong>from <strong><a href="http://www.slideshare.net/iscanonline" target="_blank">iScan Online, Inc.</a></strong> </div>  <div class="zemanta-related">   <h6 class="zemanta-related-title" style="font-size: 1em">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://www.business2community.com/mobile-apps/protecting-your-mobile-device-against-mobile-app-malware-0479880">Protecting Your Mobile Device Against Mobile App Malware</a> (business2community.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.zdnet.com/uk/byod-with-employee-freedom-comes-it-responsibility-7000014126/">BYOD: With (Employee) Freedom Comes (IT) Responsibility</a> (zdnet.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.zdnet.com/mobile-device-management-market-heats-up-ca-technologies-stakes-a-claim-7000014360/">Mobile device management market heats up, CA Technologies stakes a claim</a> (zdnet.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.ashimmy.com/2013/04/byod-security-scanning.html">BYOD Security Scanning</a> (ashimmy.com) </li>      <li class="zemanta-article-ul-li"><a href="http://community.spiceworks.com/topic/332906-what-s-on-your-network-mobile-device-management">What's on your Network? Mobile Device Management</a> (community.spiceworks.com)</li>      <li class="zemanta-article-ul-li"><a href="http://cyberdefend.wordpress.com/2013/05/06/scanner-in-your-pocket/">Scanner in Your Pocket</a> (cyberdefend.wordpress.com)</li>   </ul> </div>  <div class="zemanta-pixie" style="height: 15px; margin-top: 10px"><a title="Enhanced by Zemanta" class="zemanta-pixie-a" href="http://www.zemanta.com/?px"><img class="zemanta-pixie-img" style="border-top-style: none; border-left-style: none; border-bottom-style: none; float: right; border-right-style: none" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=ca610740-d55f-458a-8380-93e32ae8482c"></img></a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=vlkscv71WkQ:ccZN5YwzA54:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=vlkscv71WkQ:ccZN5YwzA54:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=vlkscv71WkQ:ccZN5YwzA54:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=vlkscv71WkQ:ccZN5YwzA54:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=vlkscv71WkQ:ccZN5YwzA54:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=vlkscv71WkQ:ccZN5YwzA54:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=vlkscv71WkQ:ccZN5YwzA54:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=vlkscv71WkQ:ccZN5YwzA54:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/vlkscv71WkQ" height="1" width="1"/>]]></content:encoded><description>My friends at iScan Online, Billy Austin and Carl Banzhof have just released their latest whitepaper on BYOD Security Scanning. This is an area of vulnerability scanning and compliance management that is not really being covered by any particular company...</description><feedburner:origLink>http://www.ashimmy.com/2013/05/byod-security-scanning.html</feedburner:origLink></item><item><title>Special Offer for Security Bloggers Network Members: The Plateau Effect: Getting from Stuck to Success</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/RSnnGQ9Ty1I/special-offer-for-security-bloggers-network-members-the-plateau-effect-getting-from-stuck-to-success.html</link><category>Books</category><category>security bloggers network</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Thu, 02 May 2013 21:13:59 PDT</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2019101c02bd0970c</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p><img style="margin: 0px 0px 5px 5px; display: inline" alt="Book Image" align="right" src="http://www.plateaueffect.com/images/Plateau_Book.jpg" width="179" height="253"></img><b>An exclusive offer for the <a title="Security Bloggers Network" class="zem_slink" href="http://www.securitybloggers.net/" rel="homepage">Security Bloggers Network</a> - Hugh Thompson Invites you to celebrate the release of the book</b><b> <a href="http://www.plateaueffect.com/">The Plateau Effect</a></b><b> by NYT bestselling author Bob Sullivan and RSA Conference Program Chair Dr. Hugh Thompson.</b></p>  <p>You can get a free signed bookplate from the authors to insert into your book if you:  </p>  <p>1. Tell your readers about the book’s publication using the hashtag #PlateauEffect on your social media before May 4th </p>  <p>2. Send a link to your tweet or screenshot of your blog or Facebook post to <a href="mailto:PlateauContest@gmail.com">PlateauContest@gmail.com</a> </p>  <p>3. For the first 50 we receive (sorry, U.S. only), we'll mail you the book plate! </p>  <p>The book will be available on May 2nd at bookstores and through <a href="http://www.amazon.com/The-Plateau-Effect-Getting-Success/dp/0525952802">Amazon.</a> </p>  <p>Hugh Thompson is a friend of the SBN, so if you can give it a shout out and help a friend out! </p>  <div class="zemanta-pixie" style="height: 15px; margin-top: 10px"><a title="Enhanced by Zemanta" class="zemanta-pixie-a" href="http://www.zemanta.com/?px"><img class="zemanta-pixie-img" style="border-top-style: none; border-left-style: none; border-bottom-style: none; float: right; border-right-style: none" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=9b681aac-230c-4215-a618-1b357a08e65e"></img></a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=RSnnGQ9Ty1I:K-nBVDTE2Fk:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=RSnnGQ9Ty1I:K-nBVDTE2Fk:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=RSnnGQ9Ty1I:K-nBVDTE2Fk:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=RSnnGQ9Ty1I:K-nBVDTE2Fk:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=RSnnGQ9Ty1I:K-nBVDTE2Fk:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=RSnnGQ9Ty1I:K-nBVDTE2Fk:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=RSnnGQ9Ty1I:K-nBVDTE2Fk:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=RSnnGQ9Ty1I:K-nBVDTE2Fk:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/RSnnGQ9Ty1I" height="1" width="1"/>]]></content:encoded><description>An exclusive offer for the Security Bloggers Network - Hugh Thompson Invites you to celebrate the release of the book The Plateau Effect by NYT bestselling author Bob Sullivan and RSA Conference Program Chair Dr. Hugh Thompson. You can get...</description><feedburner:origLink>http://www.ashimmy.com/2013/05/special-offer-for-security-bloggers-network-members-the-plateau-effect-getting-from-stuck-to-success.html</feedburner:origLink></item><item><title>Great Customer Service Cannot Overcome Mediocre Products</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/GuG1KinzfbA/great-customer-service-cannot-overcome-mediocre-products.html</link><category>family</category><category>Web/Tech</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Wed, 01 May 2013 19:48:02 PDT</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e201901bc13fc7970b</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<div class="zemanta-img" style="float: right; margin: 1em; display: block; width: 140px"><a href="http://www.crunchbase.com/company/shutterfly"><img style="border-top: medium none; border-right: medium none; border-bottom: medium none; border-left: medium none; display: block" alt="Image representing Shutterfly as depicted in C..." src="http://www.crunchbase.com/assets/images/resized/0000/2266/2266v1-max-450x450.png" width="130" height="50"></img></a>     <p class="zemanta-img-attribution" style="font-size: 0.8em">Image via <a href="http://www.crunchbase.com/">CrunchBase</a></p> </div>  <p>This is a great question for a business school class, but there are also real life situations where this is more than a mental exercise. The very survival of a business and the livelihood of all its employees can hang in the balance. </p>  <p>My case in point for this blog post is Shutterfly.  I have been a Shutterfly member/customer since it first started around the time my younger son was born. Over the years I have stored literally thousands of pictures and videos on Shutterfly, ordered prints and recently created share sites for all of the sports teams I coach.  </p>  <p>Shutterfly has some great things you can do and buy with your digital pictures. I never bought a lot of products, but they looked very nice.  </p>  <p>The situation changed a couple of months ago when I decided to order some photo products with photos from oldest son’s Bar Mitzvah.  I ordered some larger prints, leather bound photo books, acrylic prints, etc.  I think the prices Shutterfly charges are fair and didn’t have a problem with them.</p>  <p>Unfortunately about half of the products I have ordered have had to be refunded or returned.  Each and every time the folks at Shutterfly have been great. In fact on one of them they said my photo book was being delayed, but they were sending me a free cheaper photo book to make up for it. That one came with a mistake and they sent me another free one.  After a few weeks they finally sent me the original book I ordered and when it came, it was literally falling apart.  </p>  <p>Again the customer service folks were very nice. They gladly refunded the price and told me to keep the book. But frankly after spending 10’s of hours working on the book, I was disappointed that it was all for nothing.</p>  <p>I really want to keep using Shutterfly. I want to be a customer and buy products so they stay in business. I like the company and think their customer service is tops. But how long and how many times can you put up with sub-quality products before enough is a enough?  What do you think?  Customer service can make up for some product issues, but when does it tip over to the point of no return?</p>  <p>Am interested to you hear your thoughts on this.</p>  <div class="zemanta-pixie" style="height: 15px; margin-top: 10px"><a title="Enhanced by Zemanta" class="zemanta-pixie-a" href="http://www.zemanta.com/?px"><img class="zemanta-pixie-img" style="border-top-style: none; border-left-style: none; border-bottom-style: none; float: right; border-right-style: none" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=58258af4-4ae0-4d7f-a6c5-07db83fc0f8e"></img></a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=GuG1KinzfbA:quinywax47M:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=GuG1KinzfbA:quinywax47M:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=GuG1KinzfbA:quinywax47M:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=GuG1KinzfbA:quinywax47M:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=GuG1KinzfbA:quinywax47M:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=GuG1KinzfbA:quinywax47M:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=GuG1KinzfbA:quinywax47M:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=GuG1KinzfbA:quinywax47M:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/GuG1KinzfbA" height="1" width="1"/>]]></content:encoded><description>Image via CrunchBase This is a great question for a business school class, but there are also real life situations where this is more than a mental exercise. The very survival of a business and the livelihood of all its...</description><feedburner:origLink>http://www.ashimmy.com/2013/05/great-customer-service-cannot-overcome-mediocre-products.html</feedburner:origLink></item><item><title>What and How to tell your customers about a Data Breach</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/meUTybEthUs/what-and-how-to-tell-your-customers-about-a-data-breach.html</link><category>General Security</category><category>IBM</category><category>identity theft</category><category>Midmarket</category><category>security tips</category><category>the security industry</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Tue, 30 Apr 2013 18:45:18 PDT</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e201901bba031a970b</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p><a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2019101afe327970c-pi"><img title="Data-Breach-Photo" style="border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin: 0px 0px 5px 5px; display: inline; border-top-width: 0px" border="0" alt="Data-Breach-Photo" align="right" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e201901bba0315970b-pi" width="315" height="237"></img></a> If your midmarket enterprise is like most, sooner or later you will be the victim of a data breach. Data breaches are never fun, but how and what you tell your customers can be the difference between minimizing the impact to your company’s bottom line and a full-fledged disaster. </p>  <p>Informing your customers about everything you know and taking reasonable precautions will always work better than sugar coating and trying to minimize the potential damage. Trying to minimize the situation to your customers so as to not panic them could wind up costing you customers in the long run. </p>  <p>As a case in point I want to contrast two recent data breach cases. One is the case of local deals vendor LivingSocial and the other is the video rental service Vudu. </p>  <p>I recently received the following email from Living Social: </p>  <p><i>IMPORTANT INFORMATION</i> </p>  <p><i>LivingSocial recently experienced a cyber-attack on our computer systems that resulted in unauthorized access to some customer data from our servers. We are actively working with law enforcement to investigate this issue.</i> </p>  <p><i>The information accessed includes names, email addresses, date of birth for some users, and encrypted passwords -- technically 'hashed' and 'salted' passwords. We never store passwords in plain text.</i> </p>  <p><i>Two things you should know:</i> </p>  <p><i>1.     The database that stores customer credit card information was not affected or accessed.</i> </p>  <p><i>2.     If you connect to LivingSocial using Facebook Connect, your Facebook credentials were not compromised.</i> </p>  <p><i>You do not need to take any action at this time, but we wanted to be sure you were fully informed of what happened.</i> </p>  <p><strong><i>The security of your information is our priority.</i></strong><i> We always strive to ensure the security of our customer information, and we are redoubling efforts to prevent any issues in the future.</i> </p>  <p><i>Please note that LivingSocial will never ask you directly for personal or account information in an email. We will always direct you to the LivingSocial website - and require you to login - before making any changes to your account. Please disregard any emails claiming to be from LivingSocial that request such information or direct you to a website that asks for such information.</i> </p>  <p><i>If you have additional questions about this process, the "Create New Password" button on </i><a href="http://livingsocial.com/"><i>LivingSocial.com</i></a><i> will direct you to a page that has instructions on creating a new password and answers to frequently asked questions.</i> </p>  <p><i>We are sorry this incident occurred, and we look forward to continuing to introduce you to new and exciting things to do in your community.</i> </p>  <p><i>Sincerely,      <br>Tim O'Shaughnessy, CEO</i> </p>  <p><i></i></p>  <p>Now, I understand that LivingSocial wants to minimize the potential damage here. To me though they have made two crucial errors. One is that they are giving their customers the impression that because their passwords were encrypted (actually salted and hashed), there is a low likelihood that they would be useable. This is not necessarily true. In fact there have been several cases and much written about the relative ease that hackers have in cracking these passwords. </p>  <p>Based upon their opinion that there is a low likelihood of these passwords being compromised, they tell their customers that they do not have to do anything at this time, but if they want to change their passwords they can. Knowing that these passwords could be compromised why not make everyone change their passwords? It would seem a rather trivial thing to do and ensure the integrity of your customer’s accounts to force a password change. In a similar situation you should strongly lobby for mandatory password resets. </p>  <p>Secondly again LivingSocial is telling their customers that they don’t have to do anything. But clearly customer names, email addresses and dates of birth were stolen. It doesn’t take much for a criminal to take that, match it up with public record information and quickly gather enough information to start using a false identity for nefarious purposes. </p>  <p>While some states mandate complimentary credit watch services for customers in these kinds of cases, at least suggesting to be on the lookout for fraudulent credit transactions and suggesting a credit watch service seems called for here. </p>  <p>Again in the interest of keeping customers calm and downplaying this breach, customers could be potentially at greater risk. The breach happened already, breaches happen. Good security practice and customer service should require you to place the bar high in terms of protecting and warning your customers. </p>  <p>As I mentioned earlier, Vudu also recently had a breach. Here is the email I received regarding that one: </p>  <p><i>Dear alan,     <br>We want to let you know that there was a break-in at the VUDU offices on March 24, 2013, and a number of items were stolen, including hard drives.       <br>Our investigation thus far indicates that these hard drives contained customer information, including names, email addresses, postal addresses, phone numbers, account activity, dates of birth and the last four digits of some credit card numbers. It's important to note that the drives did NOT contain full credit card numbers, as we do not store that information. Additionally, please note if you have never set a password on the VUDU site and have only logged in through another site, your password was not on the hard drives.       <br>While the stolen hard drives included VUDU account passwords, those passwords were encrypted. We believe it would be difficult to break the password encryption, but we can't rule out that possibility given the circumstances of this theft. So we think it's best to be proactive and ask that you be proactive as well.       <br><strong>SECURITY PRECAUTIONS:</strong>      <br>If you had a password set on the VUDU site, we have taken the precaution of expiring and resetting that password. To create a new password, go to </i><a href="http://www.vudu.com/"><i>www.vudu.com</i></a><i>. Click the "Sign In" button at the top of the page. Enter your current username and current password when prompted, then follow the instructions to reset your password securely. Also, if you use your expired VUDU password on any other sites, we strongly recommend that you change it on those sites as well.      <br>As always, remember that VUDU will never ask you for personal or account information in an e-mail. Please use caution if you receive any emails or phone calls from anyone asking for personal information or directing you to a web site where you are asked to provide personal information.       <br>As an added precaution, we are arranging to have AllClear ID protect your identity for one year at no cost to you. We have </i><a href="http://click.email.vudu.com/?qs=4f99f941641305e86c763726c65dfd841422ffd0079101ed5793b809efe1aea6"><i>FAQs</i></a><i> on our web site (</i><a href="http://click.email.vudu.com/?qs=4f99f941641305e86c763726c65dfd841422ffd0079101ed5793b809efe1aea6"><i>vudu.com/passwordreset</i></a><i>) to answer questions on the incident and to more fully describe how to use the AllClear ID service. We have reported this incident to law enforcement and are cooperating fully with their investigation. We want you to know that we take this matter very seriously, and we apologize for any inconvenience this may have caused you.      <br>Thank you,       <br><strong>Prasanna Ganesan</strong>      <br></i><em>Chief Technology Officer, VUDU</em> </p>  <p>Can you see the difference? VUDU also states that the passwords were encrypted and unlikely to be cracked, but nevertheless they have expired everyone’s password forcing you to pick a new one. They are also making arrangements for ID protection for one year. </p>  <p>This makes me feel that VUDU is serious about protecting me and is not sugar coating or minimizing the consequences of the data breach. To me this is text book on how to communicate a breach to your customers. </p>  <p>In both cases I don’t blame VUDU or LivingSocial for being victims of data theft. It can and does literally happen to everyone. Also both companies are successful businesses. But as a midsize enterprise how you communicate a breach to your customers can communicate an awful lot. </p>  <p>If your company is the victim of a breach, follow best practices to inform and most importantly protect your customers. </p>  <p><a href="http://goo.gl/t3fgW"><img title="IBM" border="0" alt="IBM" align="left" src="http://www.ashimmy.com/.a/6a00d83451e4d369e201630255b2b7970d-pi" width="240" height="97"></img></a> </p>  <p><em>This post was written as part of the </em><em><a href="http://goo.gl/t3fgW"><i>IBM for Midsize Business</i></a></em><i> <em>program, which provides midsize businesses with the tools, expertise and solutions they need to become engines of a smarter planet. I’ve been compensated to contribute to this program, but t</em>he opinions expressed in this post are my own and don't necessarily represent IBM's positions, strategies or opinions.</i> </p>  <p><em></em></p>  <div class="zemanta-related">   <h6 class="zemanta-related-title" style="font-size: 1em">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://www.dailyfinance.com/on/livingsocial-hacked-passwords-phishing-scams-identity-theft/">What Hacked LivingSocial Users Actually Need to Worry About</a> (dailyfinance.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.networkworld.com/news/2013/041013-vudu-video-service-resets-customer-268568.html?source=nww_rss">Vudu video service resets customer passwords after hard drives theft</a> (networkworld.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.pcworld.com/article/2036610/why-changing-your-livingsocial-password-won-t-save-you.html">Why changing your LivingSocial password won't save you</a> (pcworld.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.cio-today.com/story.xhtml?story_id=87802">What Enterprises Can Learn from the LivingSocial Hack</a> (cio-today.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.securityorb.com/2013/04/50000000-usernames-passwords-lost-livingsocial-special-offers-site-hacked/">50,000,000 usernames and passwords lost as LivingSocial "special offers" site hacked</a> (securityorb.com) </li>      <li class="zemanta-article-ul-li"><a href="http://allthingsd.com/20130427/livingsocial-hack-update-investigation-ongoing-while-emails-out-to-50-million-users/">LivingSocial Hack Update: Investigation Ongoing, While Emails Out to 50 Million Users</a> (allthingsd.com)</li>      <li class="zemanta-article-ul-li"><a href="http://www.bauer-power.net/2013/04/vudu-forces-password-changes-after-data.html">Vudu Forces Password Changes After Data Breach</a> (bauer-power.net)</li>   </ul> </div>  <div class="zemanta-pixie" style="height: 15px; margin-top: 10px"><a title="Enhanced by Zemanta" class="zemanta-pixie-a" href="http://www.zemanta.com/?px"><img class="zemanta-pixie-img" style="border-top-style: none; border-left-style: none; border-bottom-style: none; float: right; border-right-style: none" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=4c9ad21c-b8a9-4a67-ae37-a6fe4b0f9cfe"></img></a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=meUTybEthUs:vpfNVxUnyac:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=meUTybEthUs:vpfNVxUnyac:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=meUTybEthUs:vpfNVxUnyac:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=meUTybEthUs:vpfNVxUnyac:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=meUTybEthUs:vpfNVxUnyac:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=meUTybEthUs:vpfNVxUnyac:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=meUTybEthUs:vpfNVxUnyac:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=meUTybEthUs:vpfNVxUnyac:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/meUTybEthUs" height="1" width="1"/>]]></content:encoded><description>If your midmarket enterprise is like most, sooner or later you will be the victim of a data breach. Data breaches are never fun, but how and what you tell your customers can be the difference between minimizing the impact...</description><feedburner:origLink>http://www.ashimmy.com/2013/04/what-and-how-to-tell-your-customers-about-a-data-breach.html</feedburner:origLink></item><item><title>If IBM X-Force were running the IT department</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/P27U9ZBfLo8/if-ibm-x-force-were-running-the-it-department.html</link><category>education</category><category>General Security</category><category>IBM</category><category>identity theft</category><category>IDS/IPS</category><category>Midmarket</category><category>vulnerability management</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Fri, 26 Apr 2013 09:37:58 PDT</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017eea981c09970d</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>IBM’s X-Force research team recently released their “<a href="http://public.dhe.ibm.com/common/ssi/ecm/en/wgl03027usen/WGL03027USEN.PDF">2012 Trend and Risk Report</a>”. The report is a great look back at last year and is full of metrics and analysis on the kinds of threats and risks seen across the spectrum of different verticals last year in information security. It also has some excellent advice on how to institute and operate a successful information security and risk management program. If you are interested in security (and who isn’t?) you should definitely download and give it a read.<a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017d4323c739970c-pi"><img title=" xforce report graphic" style="border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; float: none; margin: 5px auto; display: block; border-top-width: 0px" border="0" alt=" xforce report graphic" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e201901b9aac98970b-pi" width="480" height="276"></img></a> </p>  <p>One section I wanted to highlight and expand on though was the “<b>If IBM X-Force were running the IT department</b>” section. Here is the X-Force’s top 10 list to make you more secure. This is especially relevant for mid-market companies who may not have the budget or resources to do everything they might like around risk and threats. If you could check each of these ten off you would have the foundation of a solid strategy </p>  <p>1. <b>Perform regular third party external and internal security audits</b> – Many organizations are so reluctant to bring in an outside party to conduct security audits. I am not sure if it is a case of now wanting to share dirty laundry with outsiders or a case of “ignorance is bliss”, but either way it is a mistake. Having a security expert come in on a regular basis to give you a “hacker’s eye view” is one of the best ways to see really how your security plan holds up. My recommendation is a full internal and external audit annually, with external only audits quarterly if possible. </p>  <p>2. <b>Control your endpoints</b> – This used to be a whole lot easier. The advent of BYOD has made control of your endpoints more like being the sheriff in the Wild West. Of course it is probably futile to try and prohibit BYOD devices from accessing your network, data and applications. A more realistic goal may be to at least have a mobile device management solution in place. The first step is to have policies defining what is acceptable in terms of endpoints, what configurations are required, what applications can be accessed and what security should be installed on them. Regular security scanning, including vulnerability and configuration testing should be mandatory across the board! Of course traditional company owned devices are a lot easier to manage and control. </p>  <p>3. <b>Segment sensitive systems and information</b> – You need to treat your high value assets as high value. That means giving them an extra level of protection. This starts with segmenting them off from rest of the network. Too many mid-size organizations run flat networks where once you have access to the network, you can see and access everything on the network. This is obviously a mistake. High value assets should be segregated out from the rest of the network. Access and even visibility to these networks should be on a “need to know” basis. This can be accomplished using VLANs, firewalls and identity and access control. </p>  <p>4. <b>Protect your network via basics (firewalls, anti-virus, intrusion prevention devices, etc.)</b> – Too many of us are always lusting after and chasing the latest and greatest shiny new technology widgets. A perfect example of this is the latest infatuation with some of the newest threat detection technologies that run incoming packets in sandboxes before allowing them into the network. While new technologies can be exciting and effective, they should not be instituted at the expense of the “meat and potatoes” of your security program. They may not be sexy, but firewalls, AV and IPS are still front line tools for the defense. A recent report by 451 Research about the “Real Cost of Security” by Wendy Nather showed that most CISOs would still pick AV and firewall among their top choices in building out a security program. You should too! </p>  <p><b>5. Audit your web applications</b> – Web application security is perhaps the hottest area of security today. An increasing percent of attacks are targeting web applications. SQL injection, cross-site scripting, drive by attacks have all become all too common in the news. There are different aspects to securing web applications. It starts with secure code development. Building security into the development process is a great way to start with a strong foundation. Just as having a 3<sup>rd</sup> party audit is a must, an audit of your web, including not only the code but the implementation as well should be performed before an app is deployed and after every change to code and infrastructure. There are any number of firms that can perform this type of test for you. </p>  <p>6. <b>Train end users about phishing and spearphishing</b> – This sounds like a no brainer, but you would be surprised how many companies don’t take the time for security awareness training. It is even more important today when so many of the most sophisticated attacks actually start with a targets spearphish aimed at a key person in your organization. Recognizing phishing attempts and not to click on links in email, social media or anywhere unless you are sure of who sent it and where it goes is a must if you hope to keep your organization out of the next headlines. </p>  <p>7. <b>Search for bad passwords</b> – This can be automated and strong password requirements can be built into many applications today. Passwords still represent one of the weakest links in our security technology. At some point hopefully 2-factor authentication, biometrics and other technologies may make passwords obsolete. But until then we are stuck with them. Passwords like 123456 and password are just not acceptable and should not be allowed. Password managers offer lots of choices so that users don’t have to remember strong passwords. Also requirements to change passwords regularly should be instituted and enforced. </p>  <p>8. <b>Integrate security into every project plan</b> – Microsoft did this years ago with their Trustworthy Computing initiative and it forever changed Windows. Security is too important to be an afterthought bolted on after the fact. Everything you do or plan to do has to be seen through the prism of security. Failing to do so could wind up putting your organization at dire risk. </p>  <p>9. <b>Examine the policies of business partners</b> – We live in an interconnected world, no one exists in a vacuum. However, our partners often have to have access to our data and systems in order to work with us. However, they can also represent a vector into our systems for hackers and criminals. You must institute a policy on what and how 3<sup>rd</sup> parties have to show before they are given access to your network. Also this should be regularly audited and re-examined. </p>  <p>10. <b>Have a solid incident response plan</b> – It is not a question of if, but when something is going to happen. Do not let your pride and ego get in the way of putting in a place a plan to do when you have an incident. While you are at it, you should have a worst case scenario as part of your planning. Today’s threat and risk landscape means you should assume that you will have security incidents. How you respond to these incidents as a mid-market company could mean the difference between survival or not of the organization. Well thought out incident response plans make all of the difference in the world in the fluid, fast moving situations that follow discovery of a security incident. </p>  <p>There is a whole lot more in this great report from the IBM X-Force team. Go download it and read it at least twice! </p>  <p></p>  <p><a href="http://goo.gl/t3fgW"><img title="IBM" border="0" alt="IBM" align="left" src="http://www.ashimmy.com/.a/6a00d83451e4d369e201630255b2b7970d-pi" width="240" height="97"></img></a> </p>  <p><em>This post was written as part of the </em><em><a href="http://goo.gl/t3fgW"><i>IBM for Midsize Business</i></a></em><i> <em>program, which provides midsize businesses with the tools, expertise and solutions they need to become engines of a smarter planet. I’ve been compensated to contribute to this program, but t</em>he opinions expressed in this post are my own and don't necessarily represent IBM's positions, strategies or opinions</i> </p>  <p><em></em></p>  <div class="zemanta-related">   <h6 class="zemanta-related-title" style="font-size: 1em">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://blog.c24.co.uk/2013/04/04/email-security-its-every-employees-business/">Email Security: It's Every Employee's Business</a> (c24.co.uk) </li>      <li class="zemanta-article-ul-li"><a href="http://blog.bullguard.com/2013/03/spearphishing-made-easy.html">How Spearphishing Is Being Made Easy</a> (bullguard.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.zdnet.com/the-second-most-important-byod-security-defense-user-awareness-7000011738/">The second most important BYOD security defense: user awareness</a> (zdnet.com)</li>      <li class="zemanta-article-ul-li"><a href="http://www.net-security.org/secworld.php?id=14680">8 in 10 companies suffered web-borne attacks</a> (net-security.org)</li>   </ul> </div>  <div class="zemanta-pixie" style="height: 15px; margin-top: 10px"><a title="Enhanced by Zemanta" class="zemanta-pixie-a" href="http://www.zemanta.com/?px"><img class="zemanta-pixie-img" style="border-top-style: none; border-left-style: none; border-bottom-style: none; float: right; border-right-style: none" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=4f677e7d-631b-4557-9c76-100a6cf7d3c3"></img></a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=P27U9ZBfLo8:fTz_fjEkDCk:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=P27U9ZBfLo8:fTz_fjEkDCk:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=P27U9ZBfLo8:fTz_fjEkDCk:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=P27U9ZBfLo8:fTz_fjEkDCk:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=P27U9ZBfLo8:fTz_fjEkDCk:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=P27U9ZBfLo8:fTz_fjEkDCk:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=P27U9ZBfLo8:fTz_fjEkDCk:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=P27U9ZBfLo8:fTz_fjEkDCk:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/P27U9ZBfLo8" height="1" width="1"/>]]></content:encoded><description>IBM’s X-Force research team recently released their “2012 Trend and Risk Report”. The report is a great look back at last year and is full of metrics and analysis on the kinds of threats and risks seen across the spectrum...</description><media:content url="http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~5/OvDgqbIyQeI/WGL03027USEN.PDF" fileSize="10548540" type="application/pdf" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>IBM’s X-Force research team recently released their “2012 Trend and Risk Report”. The report is a great look back at last year and is full of metrics and analysis on the kinds of threats and risks seen across the spectrum...</itunes:subtitle><itunes:author>Alan Shimel</itunes:author><itunes:summary>IBM’s X-Force research team recently released their “2012 Trend and Risk Report”. The report is a great look back at last year and is full of metrics and analysis on the kinds of threats and risks seen across the spectrum...</itunes:summary><itunes:keywords>security,network,security,infosec,IDS,IPS,Vulnerability,endpoint,security,NAC,software</itunes:keywords><feedburner:origLink>http://www.ashimmy.com/2013/04/if-ibm-x-force-were-running-the-it-department.html</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~5/OvDgqbIyQeI/WGL03027USEN.PDF" length="10548540" type="application/pdf" /><feedburner:origEnclosureLink>http://public.dhe.ibm.com/common/ssi/ecm/en/wgl03027usen/WGL03027USEN.PDF</feedburner:origEnclosureLink></item><item><title>Webinar: Who Moved the Cheese in Security</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/ahYhI4XWx_g/webinar-who-moved-the-cheese-in-security.html</link><category>Current Affairs</category><category>education</category><category>General Security</category><category>links and appearances</category><category>network convergence</category><category>virtualization</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Mon, 22 Apr 2013 09:40:42 PDT</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017d4305b401970c</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p><a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e201901b7caa4b970b-pi"><img title="image" style="border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin-left: 0px; display: inline; border-top-width: 0px; margin-right: 0px" border="0" alt="image" align="right" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017d4305b3f5970c-pi" width="256" height="210"></img></a> Tomorrow, April 23, 2013 at 2pm eastern time my friend Dominique Karg of Alien Vault and I are doing a webinar on “Who Moved the Cheese in Security”.  It should be a lot of fun and I invite everyone to listen in and participate.</p>  <p>This grew out of a conversation Dominique and I had after RSA. It was amazing to us that some security executives actually believed that the Cloud, BYOD and such were passing fads. That soon we would return to traditional networks and traditional security. Talk about putting your head in the sand.</p>  <p>We will discuss that not only has the technology changed but how. We will also discuss how attacks and attack vectors have changed.  Finally what should you do and how is success defined.</p>  <p>It should be a great webinar. If you can make it please do.  If not you will be able to listen in to a recording of the webinar, but of course no live questions.  You can register down below or by going to: <a href="http://www.alienvault.com/resource-center/tech-talks/who-moved-the-cheese-in-security">http://www.alienvault.com/resource-center/tech-talks/who-moved-the-cheese-in-security</a></p> <object type="application/x-shockwave-flash" data="https://www.brighttalk.com/clients/flashplatform/viewerdefault/loader.swf" width="705" height="660"><param name="movie" value="https://www.brighttalk.com/clients/flashplatform/viewerdefault/loader.swf"></param><param name="allowscriptaccess" value="always"></param><param name="allowfullscreen" value="true"></param><param name="wmode" value="transparent"></param><param name="flashvars" value="channelid=8887&amp;commid=71113&amp;autoStart=false&amp;fromdc=false&amp;css="></param><a href="https://www.brighttalk.com/channel/8887">A BrightTALK Channel</a></object>  <div class="zemanta-related">   <h6 class="zemanta-related-title" style="font-size: 1em">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://www.net-security.org/secworld.php?id=14536">Security is changing, organizations are unprepared</a> (net-security.org) </li>      <li class="zemanta-article-ul-li"><a href="http://news.softpedia.com/news/Virtualization-and-BYOD-Have-the-Greatest-Impact-on-Security-Study-Finds-334213.shtml">Virtualization and BYOD Have the Greatest Impact on Security, Study Finds</a> (news.softpedia.com) </li>      <li class="zemanta-article-ul-li"></li>      <li class="zemanta-article-ul-li"><a href="http://venturebeat.com/2013/03/16/cyber-security-optimism/">Cyber Security: Why we're scared and why we should be optimistic</a> (venturebeat.com) </li>   </ul> </div>  <div class="zemanta-pixie" style="height: 15px; margin-top: 10px"><a title="Enhanced by Zemanta" class="zemanta-pixie-a" href="http://www.zemanta.com/?px"><img class="zemanta-pixie-img" style="border-top-style: none; border-left-style: none; border-bottom-style: none; float: right; border-right-style: none" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=946e4c61-e6fc-40cf-ac54-1b2d734f3adc"></img></a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=ahYhI4XWx_g:YfNu4lFaj94:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=ahYhI4XWx_g:YfNu4lFaj94:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=ahYhI4XWx_g:YfNu4lFaj94:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=ahYhI4XWx_g:YfNu4lFaj94:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=ahYhI4XWx_g:YfNu4lFaj94:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=ahYhI4XWx_g:YfNu4lFaj94:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=ahYhI4XWx_g:YfNu4lFaj94:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=ahYhI4XWx_g:YfNu4lFaj94:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/ahYhI4XWx_g" height="1" width="1"/>]]></content:encoded><description>Tomorrow, April 23, 2013 at 2pm eastern time my friend Dominique Karg of Alien Vault and I are doing a webinar on “Who Moved the Cheese in Security”. It should be a lot of fun and I invite everyone to...</description><feedburner:origLink>http://www.ashimmy.com/2013/04/webinar-who-moved-the-cheese-in-security.html</feedburner:origLink></item><item><title>What is the Real Cost of Security?</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/F9ad5DcK3aU/what-is-the-real-cost-of-security.html</link><category>CISO</category><category>General Security</category><category>IBM</category><category>IDS/IPS</category><category>podcasting</category><category>security tips</category><category>the security industry</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Mon, 15 Apr 2013 07:54:12 PDT</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017eea436940970d</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>You were just hired as the Chief Information Security Office (CISO) of a mid-market one thousand employee company. Your first day on the job you are told that the company really hasn’t done anything about information security to this point. You need to submit your prioritized plan and budget by the end of the week! What do you do? This is exactly the scenario that Wendy Nather, Senior Research Director of 451 Research put to literally dozens of CISOs. What they picked, what they think it may cost and the actual cost may really surprise you. Wendy’s new report, “<a href="https://451research.com/report-long?icid=2298">The Real Cost of Security</a>” (warning this is not free unless you are a 451 client) details her findings and analysis.</p>  <p>I had a chance to sit down and chat with Wendy about the report and its findings for Network World. Below you can listen to our conversation where Wendy provides some detail and depth to the report.</p>  <p>Despite all of the buzz about new and more sophisticated attacks, it was surprising that for the top priorities the oft-maligned technologies of firewall and AV were most often picked. In fact of the top 7 choices among CISOs, almost all of them are tried and true traditional products. I guess the old “no one ever gets fired for buying IBM” is still true today. According to the report, these are the top 7 recommended technologies</p>  <p><a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017eea43687e970d-pi"><img title="clip_image002" style="border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin: 5px 0px; display: inline; border-top-width: 0px" border="0" alt="clip_image002" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017eea436886970d-pi" width="482" height="480"></img></a></p>  <p>Figure 1 courtesy of 451 Research</p>  <p>The difference between the purple and gold lines is those that would recommend the technology if all they had was enough for the bare minimum (purple) versus if they had a blank check (gold).</p>  <p>Beyond the top 7, the next tier of choices represent a little more diversity:</p>  <p><a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017d42cf2d77970c-pi"><img title="clip_image003" style="border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin: 5px 0px; display: inline; border-top-width: 0px" border="0" alt="clip_image003" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017eea4368bf970d-pi" width="526" height="480"></img></a></p>  <p>Figure 2 courtesy of 451 Research</p>  <p>What was interesting about these next 6 is the wider disparity between the gold and purple lines. This indicates that many CISOs considered these more of an optional choice, but not bare minimum. </p>  <p>I was surprised that App Security and App firewalls were not in the top tier of solutions, given that so many attacks today use Port 80 and Web Apps as their vector of choice.</p>  <p>Bringing up the rear in the survey were the following:</p>  <p><a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017eea4368d3970d-pi"><img title="clip_image004" style="border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin: 5px 0px 0px; display: inline; border-top-width: 0px" border="0" alt="clip_image004" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017c38a016e0970b-pi" width="478" height="480"></img></a></p>  <p>Figure 3 Courtesy of 451 Research</p>  <p>You can see here the very wide disparity between some the minimum requirements and blank check scenario. This plainly labels some of these technologies as “nice to haves” but not required. GRC, NAC and Risk Management and Analysis seem to fall into this category by the widest margin. I was disappointed to see Training have such a wide disparity between minimum and blank check. I think dollar for dollar, security awareness training for your organization is some of the most effective security you can buy.</p>  <p>Beyond picking what technologies to buy, the cost of security as detailed in the report may surprise you. 451 Research looked at not only the cost of the technologies (not easy getting prices out of vendors), but also added in the cost of actually running these security solutions. When the total cost was figured in at a minimum an organization is looking at a budget of $250k. A more realistic budget for a 1000 person organization is probably somewhere between $500k and $800k. If you went all the way, you are closer to $1.2m dollars for security! Another metric from the report is that most organizations have about one security admin for every 500 employees.</p>  <p>What about your organization? What technologies have you deployed and what you are planning to deploy? What is your budget? Do you match the 1 to 500 ratio? There is a ton of great info in this report if you buy it or are lucky enough to be a 451 Research customer.</p>  <p>My full conversation with Wendy is here:</p>  <p><iframe height="85" marginheight="0" src="http://ashimmy.podomatic.com/embed/frame/posting/2013-04-04T07_15_04-07_00?json_url=http%3A%2F%2Fashimmy.podomatic.com%2Fentry%2Fembed_params%2F2013-04-04T07_15_04-07_00%3Fcolor%3D43bee7%26autoPlay%3Dfalse%26width%3D440%26height%3D85%26objembed%3D0" frameborder="0" width="440" marginwidth="0" scrolling="no" allowfullscreen="allowfullscreen"></iframe></p>  <p> </p>  <p><a href="http://goo.gl/t3fgW"><img title="IBM" border="0" alt="IBM" align="left" src="http://www.ashimmy.com/.a/6a00d83451e4d369e201630255b2b7970d-pi" width="240" height="97"></img></a> </p>  <p><em>This post was written as part of the </em><em><a href="http://goo.gl/t3fgW"><i>IBM for Midsize Business</i></a></em><i> <em>program, which provides midsize businesses with the tools, expertise and solutions they need to become engines of a smarter planet. I’ve been compensated to contribute to this program, but t</em>he opinions expressed in this post are my own and don't necessarily represent IBM's positions, strategies or opinions.</i> </p>  <p><em></em></p>  <div class="zemanta-related">   <h6 class="zemanta-related-title" style="font-size: 1em">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://www.tripwire.com/state-of-security/it-security-data-protection/connecting-security-to-the-business/wendy-nather-the-best-cisos-are-social-engineering-masters/">Wendy Nather: The Best CISOs are Social Engineering Masters</a> (tripwire.com) </li>      <li class="zemanta-article-ul-li"><a href="https://community.csc.com/community/cio-engage/blog/2013/04/08/the-five-keys-of-effective-security-management">The 5 Keys of Effective Security Management</a> (community.csc.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.eweek.com/security/ibm-cyber-security-practices-key-for-electric-power-sector/">IBM: Cyber-Security Practices Key for Electric Power Sector</a> (eweek.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.techweekeurope.co.uk/news/ibm-security-power-112318">IBM Presents Security Strategies For Power Sector</a> (techweekeurope.co.uk)</li>      <li class="zemanta-article-ul-li"><a href="https://securosis.com/blog/be-careful-what-you-wish-fornow-youre-ciso">Be Careful What You Wish for...Now You're CISO</a> (securosis.com)</li>   </ul> </div>  <div class="zemanta-pixie" style="height: 15px; margin-top: 10px"><a title="Enhanced by Zemanta" class="zemanta-pixie-a" href="http://www.zemanta.com/?px"><img class="zemanta-pixie-img" style="border-top-style: none; border-left-style: none; border-bottom-style: none; float: right; border-right-style: none" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=88736a29-3b4a-4c09-bc60-23c315fd9f23"></img></a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=F9ad5DcK3aU:5X_3WNWWo3g:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=F9ad5DcK3aU:5X_3WNWWo3g:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=F9ad5DcK3aU:5X_3WNWWo3g:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=F9ad5DcK3aU:5X_3WNWWo3g:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=F9ad5DcK3aU:5X_3WNWWo3g:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=F9ad5DcK3aU:5X_3WNWWo3g:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=F9ad5DcK3aU:5X_3WNWWo3g:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=F9ad5DcK3aU:5X_3WNWWo3g:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/F9ad5DcK3aU" height="1" width="1"/>]]></content:encoded><description>You were just hired as the Chief Information Security Office (CISO) of a mid-market one thousand employee company. Your first day on the job you are told that the company really hasn’t done anything about information security to this point....</description><feedburner:origLink>http://www.ashimmy.com/2013/04/what-is-the-real-cost-of-security.html</feedburner:origLink></item><item><title>BYOD Security Scanning</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/seBdq_8EUAo/byod-security-scanning.html</link><category>awards and PR</category><category>VAM</category><category>vulnerability management</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Thu, 11 Apr 2013 14:53:43 PDT</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017c38897e70970b</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>My friends Carl Banzhof and Billy Austin continue to make it happen at <a href="http://www.iscanonline.com/" target="_blank">iScan Online</a>. This is one of my most favorite companies to work with. They are always thinking of new ways to solve problems and fun ways to get the word out. They have been pretty busy too.</p>  <p>After releasing their Android App around RSA, they have been heads down developing the next versions of their apps.&#160; Also they <a href="http://iscanonline.com/downloads/iScanPress040913.pdf" target="_blank">announced</a> that David Raphael, who has worked with Carl and Billy at Citadel and McAfee has joined the team as Director of engineering.</p>  <p>Additionally the company exhibited at the MSPWorld event in Orlando last month.&#160; MSPWorld is run by the MSPAlliance which has over 20,000 members.&#160; <a href="http://iscanonline.com/downloads/iScanPress032813.pdf" target="_blank">iScan Online won the prestigious MSPWorld Cup 2013 as the conference MVP</a>.&#160; The BYOD security scanning message was very near and dear to the attendees. </p>  <p>Now this past week the company released what I think is coolest marketing video I have seen in a while.&#160; </p>  <div id="scid:5737277B-5D6D-4f48-ABFC-DD9C333F4C5D:024ac518-e3ff-4a64-b006-b18c37a64225" class="wlWriterEditableSmartContent" style="float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px"><div id="2164188d-320e-4af3-b0de-0b11d8e9d30a" style="margin: 0px; padding: 0px; display: inline;"><div><a href="http://www.youtube.com/watch?v=SIIbrXW8ZMg&amp;feature=share&amp;list=FLAMi-q9njCKAkTcJx8nzHtw" target="_new"><img src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017eea2d46d0970d-pi" style="border-style: none" galleryimg="no" onload="var downlevelDiv = document.getElementById('2164188d-320e-4af3-b0de-0b11d8e9d30a'); downlevelDiv.innerHTML = &quot;&lt;div&gt;&lt;object width=\&quot;425\&quot; height=\&quot;355\&quot;&gt;&lt;param name=\&quot;movie\&quot; value=\&quot;http://www.youtube.com/v/SIIbrXW8ZMg&amp;hl=en\&quot;&gt;&lt;\/param&gt;&lt;embed src=\&quot;http://www.youtube.com/v/SIIbrXW8ZMg&amp;hl=en\&quot; type=\&quot;application/x-shockwave-flash\&quot; width=\&quot;425\&quot; height=\&quot;355\&quot;&gt;&lt;\/embed&gt;&lt;\/object&gt;&lt;\/div&gt;&quot;;" alt=""></a></div></div></div>  <p>I really like this one! You can get a free scan for your Windows, Mac or Android device right now too by heading over <a href="http://www.iscanonline.com/" target="_blank">iscanonline.com</a></p>  <p>The company will be rolling out some more news soon so stay tuned. In the meantime the mobile and BYOD security market continues white hot.&#160; Keep your eye on iScan Online.</p>  <div class="zemanta-related">   <h6 class="zemanta-related-title" style="font-size: 1em">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://iscanme.wordpress.com/2013/03/28/mvp-mvp-mvp-iscan-online-is-mspworld-world-cup-mvp/">MVP, MVP, MVP - iScan Online is MSPWorld World Cup MVP!</a> (iscanme.wordpress.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.sys-con.com/node/2547316">Iscan Online Announces Android App for Mobile Security Scanning</a> (sys-con.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.pcworld.com/article/2028965/watch-for-mobile-malware-and-targeted-attacks-mcafee-warns.html">Watch for mobile malware and targeted attacks, McAfee warns</a> (pcworld.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.darkreading.com/mobile-security/167901113/security/news/240148925/iscan-online-announces-android-app-for-mobile-security-scanning.html">iScan Online Announces Android App For Mobile Security Scanning</a> (darkreading.com) </li>   </ul> </div>  <div class="zemanta-pixie" style="height: 15px; margin-top: 10px"><a title="Enhanced by Zemanta" class="zemanta-pixie-a" href="http://www.zemanta.com/?px"><img class="zemanta-pixie-img" style="border-top-style: none; border-left-style: none; border-bottom-style: none; float: right; border-right-style: none" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=0bc2cbf3-7c54-4b70-9812-582def0e9a0f" /></a></div></div>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=seBdq_8EUAo:sCAqZLh7Djg:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=seBdq_8EUAo:sCAqZLh7Djg:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=seBdq_8EUAo:sCAqZLh7Djg:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=seBdq_8EUAo:sCAqZLh7Djg:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=seBdq_8EUAo:sCAqZLh7Djg:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=seBdq_8EUAo:sCAqZLh7Djg:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=seBdq_8EUAo:sCAqZLh7Djg:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=seBdq_8EUAo:sCAqZLh7Djg:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/seBdq_8EUAo" height="1" width="1"/>]]></content:encoded><description>My friends Carl Banzhof and Billy Austin continue to make it happen at iScan Online. This is one of my most favorite companies to work with. They are always thinking of new ways to solve problems and fun ways to...</description><media:content url="http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~5/vGC7ZekZ2IM/iScanPress040913.pdf" fileSize="137338" type="application/pdf" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>My friends Carl Banzhof and Billy Austin continue to make it happen at iScan Online. This is one of my most favorite companies to work with. They are always thinking of new ways to solve problems and fun ways to...</itunes:subtitle><itunes:author>Alan Shimel</itunes:author><itunes:summary>My friends Carl Banzhof and Billy Austin continue to make it happen at iScan Online. This is one of my most favorite companies to work with. They are always thinking of new ways to solve problems and fun ways to...</itunes:summary><itunes:keywords>security,network,security,infosec,IDS,IPS,Vulnerability,endpoint,security,NAC,software</itunes:keywords><feedburner:origLink>http://www.ashimmy.com/2013/04/byod-security-scanning.html</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~5/vGC7ZekZ2IM/iScanPress040913.pdf" length="137338" type="application/pdf" /><feedburner:origEnclosureLink>http://iscanonline.com/downloads/iScanPress040913.pdf</feedburner:origEnclosureLink></item><item><title>European Security Blogger Meetup and Awards</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/KGMKky2l_aI/european-security-blogger-meetup-and-awards.html</link><category>awards and PR</category><category>security bloggers network</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Thu, 04 Apr 2013 18:48:39 PDT</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017d4289ad29970c</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p><a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017c385a93a1970b-pi"><img title="security-blogger-meetup-logo" style="border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; float: right; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px" border="0" alt="security-blogger-meetup-logo" align="right" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017d4289ad21970c-pi" width="181" height="125"></img></a>I am happy to report that <a href="http://bhconsulting.ie/securitywatch/?p=1549" target="_blank">Brian Honan</a> with a big hand from <a href="http://blog.uncommonsensesecurity.com/" target="_blank">Jack Daniel</a> and our good friends at <a href="http://www.tenable.com/" target="_blank">Tenable Network Security</a> are putting on the 2nd annual Security Bloggers Meet up during <a href="http://www.infosec.co.uk/" target="_blank">Infosec Europe</a>. </p>  <p>The European Bloggers <a title="Meetup" class="zem_slink" href="http://www.meetup.com/" rel="homepage">Meetup</a> is of course based on the RSA Conference Bloggers Meet up that we hold every year.  From what I understand it was a nice get together last year thanks to Firemon for sponsoring it.  Now in this second year they are going to try and add European Security <a title="Blogger" class="zem_slink" href="http://blogger.com/" rel="homepage">Blogger</a> Awards to the mix as well.</p>  <p>I am both flattered and pleased to see the idea being franchised over across the pond. I am waiting to hear all about it and hope to make it out to the event next year!</p>  <p>In the meantime head over to <a href="http://bhconsulting.ie/securitywatch/?p=1549" target="_blank">Brian’s blog</a> for details and links to register for the event, nominate blogs and vote.</p>  <div class="zemanta-related">   <h6 class="zemanta-related-title" style="font-size: 1em">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://blog.uncommonsensesecurity.com/2013/03/european-security-bloggers-meetup-and.html">European Security Bloggers Meetup and Awards</a> (uncommonsensesecurity.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.ashimmy.com/2013/03/security-blogger-award-winners-2013.html">Security Blogger Award Winners 2013</a> (ashimmy.com)</li>   </ul> </div>    <div class="zemanta-pixie" style="height: 15px; margin-top: 10px"><a title="Enhanced by Zemanta" class="zemanta-pixie-a" href="http://www.zemanta.com/?px"><img class="zemanta-pixie-img" style="border-top-style: none; border-left-style: none; border-bottom-style: none; float: right; border-right-style: none" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=9f6683cc-35fc-4520-956b-7b0d2b1aae13"></img></a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=KGMKky2l_aI:NTAZmhPE-hg:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=KGMKky2l_aI:NTAZmhPE-hg:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=KGMKky2l_aI:NTAZmhPE-hg:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=KGMKky2l_aI:NTAZmhPE-hg:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=KGMKky2l_aI:NTAZmhPE-hg:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=KGMKky2l_aI:NTAZmhPE-hg:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=KGMKky2l_aI:NTAZmhPE-hg:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=KGMKky2l_aI:NTAZmhPE-hg:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/KGMKky2l_aI" height="1" width="1"/>]]></content:encoded><description>I am happy to report that Brian Honan with a big hand from Jack Daniel and our good friends at Tenable Network Security are putting on the 2nd annual Security Bloggers Meet up during Infosec Europe. The European Bloggers Meetup...</description><feedburner:origLink>http://www.ashimmy.com/2013/04/european-security-blogger-meetup-and-awards.html</feedburner:origLink></item><item><title>In Search of . . . the Elusive, Serious, Security Professional</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/_a6Z0k7ecTM/in-search-of-the-elusive-serious-security-professional.html</link><category>SC Magazine</category><category>the security industry</category><category>tradeshows</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Fri, 08 Mar 2013 07:00:25 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017c37678149970b</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<div class="zemanta-img" style="float: right; margin: 1em; display: block; width: 310px"><a href="http://commons.wikipedia.org/wiki/File:CBOSS_girls_%40_3GSM.jpg"><img style="border-top: medium none; border-right: medium none; border-bottom: medium none; border-left: medium none; display: block" alt="CBOSS girls. I'm not usually the kind of a per..." src="http://upload.wikimedia.org/wikipedia/commons/thumb/9/9c/CBOSS_girls_%40_3GSM.jpg/300px-CBOSS_girls_%40_3GSM.jpg" width="300" height="225"></img></a>     <p class="zemanta-img-attribution" style="font-size: 0.8em">(Photo credit: <a href="http://commons.wikipedia.org/wiki/File:CBOSS_girls_%40_3GSM.jpg">Wikipedia</a>)</p> </div>  <p>I read with a smile <a href="http://www.scmagazine.com/the-rsa-conference-expo-floor-offended-me--and-why-i-blame-the-exhibitors/article/283304/?fb_action_ids=10200352356344339&amp;fb_action_types=og.likes&amp;fb_source=ticker&amp;action_object_map=%7B%2210200352356344339%22%3A514715648569900%7D&amp;action_type_map=%7B%2210200352356344339%22%3A%22og.likes%22%7D&amp;action_ref_map=%5B%5D">Winn Shwartau’s rant in SC Magazine</a> about his disappointment at the RSA show floor. While much of what Winn said is true, instead of blaming the people exhibiting on the show floor, maybe Winn and the rest of the attendees should take a good look in the mirror. </p>  <p>Blaming the exhibitors to me is the same as blaming the spammers for spam. There really is a very easy solution here. The same way that spammers would not be in business if people would not click on spam, exhibitors at trade shows like RSA would adopt different methods if they were not getting the results they want using current methods. The facts are that most every exhibitor at RSA gets the leads they want. On top of this as you saw, RSA had to open another exhibit hall this year. I also hear that perhaps as many as 50 other vendors inquired but were shut out of exhibit space. </p>  <p>As my brother used to say when I gained weight on a diet and claimed I wasn’t getting any food in the house, “someone is sneaking it in”. Whatever they are doing it is working, so why change it? Here is a fact for Winn and those who consider themselves security pros, who are beneath what is dished out on the floor at RSA. You are in the minority and perhaps not even the target of the exhibitors. </p>  <p>On the other hand the attendees at RSA Conference exhibits are quite a bunch. I can’t tell you how many people I see walking around with multiple bags full of chotchkes and swag. I call them adult trick or treaters. Then there are the guys who take pictures with the booth babes to show their friends. There are the lottery players who get their badge scanned at every booth in the hopes of getting that free iPad. What about the people drawn to the motorcycles and the cars? What does that have to do with security? For far too many of the people walking that show floor, a sales guy collecting their lead info is all that is required. They don’t want to speak to an engineer. </p>  <p>On top of this do you know how much arm twisting you would have to do to get a sales engineer or similar talent to spend the week on the show floor? There is a reason that the people at these booths are the people they are. They are good enough to do the job. As a security company executive how many engineers should I tie up for the week for the 3 or 4 “real security pros” who might walk by?  </p>  <p>Here is the bottom line, RSA is a good place to find out about new companies and technologies. But if you want a deeper dive, you should set up a time after the craziness of the show to do so.  </p>  <p>Now don’t get me wrong. I have written for years about the fact that we don’t need booth babes. On top of that I understand that most of the booths are manned by marketing and junior sales people who don’t know enough about the technology. Too many of the marketing people try to cover up not having a good message about what they do and why we must have their product with fancy, glitzy marketing. </p>  <p>The fact is that the exhibits at RSA are not any different than the exhibits at Black Hat, Infosec or any number of large security conferences. The tracks at RSA are in my opinion superior, but that is neither here nor there. As an exhibit floor, RSA represents the industry only maybe bigger. Just because it is larger, why should we expect a higher level of technical prowess at the booth? </p>  <p>Speaking as an executive of a firm who exhibited at RSA for more than a few years, I can tell you that getting real live “security pros” like Winn to the booth is a pretty rare occurrence. The best we could hope for was collect names and sift through them separating the real leads from the fluff. We would take one sales engineer (usually the west coast guy) in case someone had a real question. Other than that we made sure everyone could demo the product and knew the high points. </p>  <p>I am not sure what Winn wants, but I know that what the show floor represents at RSA is what the attendees respond to. It is the free market at work. If enough so called security pros stay away from the booth babes, refuse to be scanned and truly walk away from Joe the sales guy, the exhibitors will change their tactics. But until that happens the blame rests squarely in the mirror.</p>  <div class="zemanta-related">   <h6 class="zemanta-related-title" style="font-size: 1em">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://mashable.com/2013/01/11/booth-babes-ces/">CEA on 'Booth Babes': The Name Is the Problem</a> (mashable.com) </li>   </ul> </div>  <div class="zemanta-pixie" style="height: 15px; margin-top: 10px"><a title="Enhanced by Zemanta" class="zemanta-pixie-a" href="http://www.zemanta.com/?px"><img class="zemanta-pixie-img" style="border-top-style: none; border-left-style: none; border-bottom-style: none; float: right; border-right-style: none" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=7054c67f-cf28-475b-857b-0250bedc1827"></img></a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=_a6Z0k7ecTM:s6VZVHQCyLU:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=_a6Z0k7ecTM:s6VZVHQCyLU:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=_a6Z0k7ecTM:s6VZVHQCyLU:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=_a6Z0k7ecTM:s6VZVHQCyLU:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=_a6Z0k7ecTM:s6VZVHQCyLU:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=_a6Z0k7ecTM:s6VZVHQCyLU:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=_a6Z0k7ecTM:s6VZVHQCyLU:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=_a6Z0k7ecTM:s6VZVHQCyLU:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/_a6Z0k7ecTM" height="1" width="1"/>]]></content:encoded><description>(Photo credit: Wikipedia) I read with a smile Winn Shwartau’s rant in SC Magazine about his disappointment at the RSA show floor. While much of what Winn said is true, instead of blaming the people exhibiting on the show floor,...</description><feedburner:origLink>http://www.ashimmy.com/2013/03/in-search-of-the-elusive-serious-security-professional.html</feedburner:origLink></item><item><title>APT  It can happen to anyone, especially you</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/qOjPFTUs5gY/apt-it-can-happen-to-anyone.html</link><category>Current Affairs</category><category>General Security</category><category>IBM</category><category>Midmarket</category><category>phishing</category><category>the security industry</category><category>tradeshows</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Thu, 07 Mar 2013 07:51:09 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017d4192b781970c</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>This past RSA was a memorable one for several reasons. First of all I was glad to see the security industry move off of compliance as its reason for being. Compliance had taken the industry hostage for too many years. It seems that we are now finally focusing back on security and preventing breaches rather than some least common denominator check box model. I think in the long run we will all be more secure for this. </p>  <p>Another thing I saw at RSA was the idea of security using virtualization. It is not just securing virtual environments, but it is using hardened virtual containers to run code and apps to make sure they are not malware and they can’t do any harm to our devices. These hardened virtual containers run on our devices or they can run in the cloud or anywhere in between. The important thing is they can’t (supposedly anyway) get to anything valuable on our networks. If this pans out, it could have a profound impact on the way we secure our data in every segment of the market. </p>  <p>Perhaps one of the biggest trends though was the realization that we are under attack by very sophisticated forces, perhaps even nation states who are using very sophisticated and highly organized techniques. The <a href="http://intelreport.mandiant.com/" target="_blank">report by security company Mandiant</a> on the alleged acts by a unit of the Chinese PLA codenamed APT1 was chilling. </p>  <p>The thing about APT attacks is that no matter whether you are a big company or small, government related or not, you are a target. Midmarket companies should not be fooled into a false sense of security that these attacks are not aimed at you. They are! If you have IP that could be valuable, you are a target. Manufacturing, media, technology and financial companies are all potential targets. Not to be an alarmist, but if you are not doing something about defending yourself against this type of breach¸ you are foolish. </p>  <p>The good news is that many of these attacks while they use 0 day attacks and other unknown exploits almost always start with a simple spearphishing attempt or something similar. Most of these attacks still take place because the weakest link is still the person behind the keyboard. In this regard security awareness training is still a strong tool. If you can afford a 3<sup>rd</sup> party to come in an implement a security training program, you should do so. If not there are plenty of web resources available that you can put together and make your own. So much of this is common sense about not clicking on links you aren’t sure about. </p>  <p>Of course there is no guarantee that even with all of the security awareness training in the world you will prevent an attack from being successful. That is why it is also important to have a plan in place for what to do when something happens. Don’t wait until something happens to figure out what you should do. Assume something is going to happen. </p>  <p>Planning for a breach is as important as trying to prevent a breach. Again this is as important for a midsize firm as it is for a large firm. In fact many security experts say that midsize firms are more of a target than some of the larger organizations. So again, not to be a scaremonger, but you should be planning this for your company right now. Again there are 3<sup>rd</sup> parties who can really help with this. IBM and their partners have lots of options. But there are plenty of resources available on the web that you can use to craft your own plan as well. Don’t let budget stand in the way of your preparedness. </p>  <p>I will write up some more news from RSA around BYOD, Big Data and the Cloud in my next report so stay tuned. </p>  <p><a href="http://goo.gl/t3fgW"><img title="IBM" border="0" alt="IBM" align="left" src="http://www.ashimmy.com/.a/6a00d83451e4d369e201630255b2b7970d-pi" width="240" height="97"></img></a> </p>  <p><em>This post was written as part of the </em><em><a href="http://goo.gl/t3fgW"><i>IBM for Midsize Business</i></a></em><i> <em>program, which provides midsize businesses with the tools, expertise and solutions they need to become engines of a smarter planet. I’ve been compensated to contribute to this program, but t</em>he opinions expressed in this post are my own and don't necessarily represent IBM's positions, strategies or opinions.</i></p>  <div class="zemanta-related">   <h6 class="zemanta-related-title" style="font-size: 1em">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://www.ashimmy.com/2013/01/security-education-because-the-weakest-link-in-the-chain-still-sits-behind-the-keyboard.html">Security Education Because the Weakest Link in the Chain Still Sits Behind the Keyboard</a> (ashimmy.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.virtual-strategy.com/2013/02/27/interactive-security-awareness-training-showcased-security-mentor-rsa-conference-2013">Interactive Security Awareness Training Showcased by Security Mentor at RSA Conference 2013</a> (virtual-strategy.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.prweb.com/releases/prweb2013/2/prweb10464618.htm">MAD Security Launches Industry's First Comprehensive Role-based Security Awareness Training</a> (prweb.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.networkworld.com/community/blog/cloud-providers-become-cloud-security-providers?source=nww_rss">Cloud Providers Become Cloud Security Providers</a> (networkworld.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.networkworld.com/community/blog/mandiant-security-report-chinese-are-coming-chinese-are-coming?source=nww_rss">Mandiant Security Report: The Chinese are coming, The Chinese are coming</a> (networkworld.com) </li>      <li class="zemanta-article-ul-li"><a href="https://threatpost.com/en_us/blogs/rsa-conference-2013-experts-say-its-time-prepare-post-crypto-world-022613">RSA Conference 2013: Experts Say It's Time to Prepare for a 'Post-Crypto' World</a> (threatpost.com) </li>   </ul> </div>  <div class="zemanta-pixie" style="height: 15px; margin-top: 10px"><a title="Enhanced by Zemanta" class="zemanta-pixie-a" href="http://www.zemanta.com/?px"><img class="zemanta-pixie-img" style="border-top-style: none; border-left-style: none; border-bottom-style: none; float: right; border-right-style: none" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=d1da2285-c6d1-4042-bd59-a1813cb0b068"></img></a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=qOjPFTUs5gY:h3r4L0qm63Q:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=qOjPFTUs5gY:h3r4L0qm63Q:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=qOjPFTUs5gY:h3r4L0qm63Q:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=qOjPFTUs5gY:h3r4L0qm63Q:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=qOjPFTUs5gY:h3r4L0qm63Q:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=qOjPFTUs5gY:h3r4L0qm63Q:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=qOjPFTUs5gY:h3r4L0qm63Q:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=qOjPFTUs5gY:h3r4L0qm63Q:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/qOjPFTUs5gY" height="1" width="1"/>]]></content:encoded><description>This past RSA was a memorable one for several reasons. First of all I was glad to see the security industry move off of compliance as its reason for being. Compliance had taken the industry hostage for too many years....</description><feedburner:origLink>http://www.ashimmy.com/2013/03/apt-it-can-happen-to-anyone.html</feedburner:origLink></item><item><title>Webcast on User Activity Monitoring with Spectorsoft and SC Magazine</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/2VAustlW6Qw/webcast-on-user-activity-monitoring-with-spectorsoft-and-sc-magazine.html</link><category>General Security</category><category>links and appearances</category><category>SC Magazine</category><category>the security industry</category><category>tradeshows</category><category>uam</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Wed, 06 Mar 2013 08:26:22 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017d418b22c7970c</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<div class="zemanta-img" style="float: right; margin: 1em; display: block; width: 219px"><a href="http://www.crunchbase.com/company/spectorsoft"><img style="border-top: medium none; border-right: medium none; border-bottom: medium none; border-left: medium none; display: block" alt="Image representing SpectorSoft as depicted in ..." src="http://www.crunchbase.com/assets/images/resized/0005/7669/57669v2-max-450x450.jpg" width="209" height="66"></img></a>    <p class="zemanta-img-attribution" style="font-size: 0.8em">Image via <a href="http://www.crunchbase.com/">CrunchBase</a></p> </div>  <p>My friends at Spectorsoft makers of Spector 360 have invited me to participate in a <a href="http://video.webcasts.com/events/pmny001/viewer/index.jsp?eventid=45586&amp;adid=ssEB2" target="_blank">webinar next Wednesday</a>, the 13th at 2pm eastern time, 10am pacific time.  The webinar is entitled “Getting More Out of DLP”.  It will cover how using Spector 360 can enhance your DLP coverage and give you greater control over controlling your confidential data.</p>  <p>The webinar is being conducted along with the great people over at SC Magazine.  </p>  <p>If you can’t make it live, there will be taped versions available, but no questions then.  You can register for the webinar <a href="http://video.webcasts.com/events/pmny001/viewer/index.jsp?eventid=45586&amp;adid=ssEB2" target="_blank">here</a>.</p>  <p>Hope to hear or see you next Wednesday!</p>  <div class="zemanta-related">   <h6 class="zemanta-related-title" style="font-size: 1em">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://news.softpedia.com/news/SpectorSoft-Releases-SPECTOR-360-7-5-Extends-Support-to-BlackBerry-Smartphones-321620.shtml">SpectorSoft Releases SPECTOR 360 7.5, Extends Support to BlackBerry Smartphones</a> (news.softpedia.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.cio.com/article/726940/Spectorsoft_Expands_Monitoring_to_Include_BlackBerry_Devices?source=rss_security">Spectorsoft Expands Monitoring to Include BlackBerry Devices</a> (cio.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.pcadvisor.co.uk/news/mobile-phone/3420905/spectorsoft-expands-monitoring-include-blackberry-devices/?olo=rss">SpectorSoft expands monitoring to include BlackBerry devices</a> (pcadvisor.co.uk) </li>      <li class="zemanta-article-ul-li"><a href="http://www.pcworld.com/article/2025357/spectorsoft-expands-monitoring-to-include-blackberry-devices.html">SpectorSoft expands monitoring to include BlackBerry devices</a> (pcworld.com)</li>   </ul> </div>  <div class="zemanta-pixie" style="height: 15px; margin-top: 10px"><a title="Enhanced by Zemanta" class="zemanta-pixie-a" href="http://www.zemanta.com/?px"><img class="zemanta-pixie-img" style="border-top-style: none; border-left-style: none; border-bottom-style: none; float: right; border-right-style: none" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=3a6c947d-996f-4d2b-8ba4-ac4cbd6bf09b"></img></a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=2VAustlW6Qw:VLZqW-QHJ-8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=2VAustlW6Qw:VLZqW-QHJ-8:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=2VAustlW6Qw:VLZqW-QHJ-8:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=2VAustlW6Qw:VLZqW-QHJ-8:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=2VAustlW6Qw:VLZqW-QHJ-8:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=2VAustlW6Qw:VLZqW-QHJ-8:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=2VAustlW6Qw:VLZqW-QHJ-8:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=2VAustlW6Qw:VLZqW-QHJ-8:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/2VAustlW6Qw" height="1" width="1"/>]]></content:encoded><description>Image via CrunchBase My friends at Spectorsoft makers of Spector 360 have invited me to participate in a webinar next Wednesday, the 13th at 2pm eastern time, 10am pacific time. The webinar is entitled “Getting More Out of DLP”. It...</description><feedburner:origLink>http://www.ashimmy.com/2013/03/webcast-on-user-activity-monitoring-with-spectorsoft-and-sc-magazine.html</feedburner:origLink></item><item><title>Microsoft Trustworthy Computing Sponsors Security Bloggers Network</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/_RwtuHUK_AI/microsoft-trustworthy-computing-sponsors-security-bloggers-network.html</link><category>education</category><category>General Security</category><category>microsoft</category><category>security bloggers network</category><category>the security industry</category><category>tradeshows</category><category>Web/Tech</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Sat, 02 Mar 2013 03:52:55 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017d4168744e970c</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>I am very pleased to report that once again the good folks over at Microsoft's <a title="Trustworthy computing" class="zem_slink" href="http://en.wikipedia.org/wiki/Trustworthy_computing" rel="wikipedia">Trustworthy Computing</a> Group have agreed to sponsor the <a title="Security Bloggers Network" class="zem_slink" href="http://www.securitybloggers.net/" rel="homepage">Security Bloggers Network</a>.  The SBN has a long history of working with TWC and we are happy to work with them again.</p>  <p><a href="http://aka.ms/SBN-EmailOffer" target="_blank"><img title="SDC_Banner_495x90_v1" style="border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px" border="0" alt="SDC_Banner_495x90_v1" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017c37395038970b-pi" width="506" height="93"></img></a></p>  <p>Microsoft is holding their second annual Security Development Conference in San Francisco, May 14-15, 2013. The conference will feature Scott Charney, Corporate VP Trustworthy Computing, Microsoft; Edna M Conway, Chief Security Strategist Global Supply Chain, Cisco Systems; Brad Arkin, Senior Director of Security Adobe Secure Software, Engineering Team (ASSET).</p>  <p>Conference specialty tracks target three different types of professionals: Engineers, Project Management, and Leadership. Combining keynotes from thought leaders as well as specialized breakout sessions, this conference is a can’t-miss for security professionals at any level. You can <a href="http://aka.ms/SBN-EmailOffer">register now and USING THIS CODE AND SAVE $300 OFF THE REGISTRATION PRICE: <i>SBN@SDC#13</i>!</a></p>  <p><img title="tim" style="float: right; margin: 0px 0px 10px; display: inline" alt="tim raines" align="right" src="http://ashimmy.podomatic.com/mymedia/thumb/1143272/0x0_7918102.jpg" width="119" height="178"></img>I had a chance to chat with director of TWC Tim Raines. We were going to talk about the conference, but Tim and I started talking about the TWC, the world of security and what the challenges on the horizon are. By the time we were done, we never got to the conference, LOL!</p>  <p>Anyway, I think you will find the conversation very interesting. Enjoy and if you can go to the conference.</p> <iframe height="85" marginheight="0" src="http://ashimmy.podomatic.com/embed/frame/posting/2013-03-01T20_45_08-08_00?json_url=http%3A%2F%2Fashimmy.podomatic.com%2Fentry%2Fembed_params%2F2013-03-01T20_45_08-08_00%3Fcolor%3D1c60ff%26autoPlay%3Dfalse%26width%3D440%26height%3D85%26objembed%3D0" frameborder="0" width="440" marginwidth="0" scrolling="no" allowfullscreen="allowfullscreen"></iframe>  <div class="zemanta-related">   <h6 class="zemanta-related-title" style="font-size: 1em">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://www.techweekeurope.co.uk/news/rsa-2013-microsoft-internet-id-schemes-108759">RSA 2013: Microsoft Calls For Global Push On eID Schemes</a> (techweekeurope.co.uk) </li>      <li class="zemanta-article-ul-li"><a href="http://blogs.technet.com/b/trustworthycomputing/archive/2013/02/20/rsa-microsoft-s-keynote-and-sessions-guide.aspx">RSA: Microsoft's Keynote and Sessions Guide</a> (blogs.technet.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.securemaryland.org/2013/02/rsa-keynote-scott-charney/">RSA Keynote Scott Charney</a> (securemaryland.org)</li>   </ul> </div>  <div class="zemanta-pixie" style="height: 15px; margin-top: 10px"><a title="Enhanced by Zemanta" class="zemanta-pixie-a" href="http://www.zemanta.com/?px"><img class="zemanta-pixie-img" style="border-top-style: none; border-left-style: none; border-bottom-style: none; float: right; border-right-style: none" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=2f3812b8-965c-4b5c-9516-93a8b52f3536"></img></a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=_RwtuHUK_AI:G8VfxNYYbBM:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=_RwtuHUK_AI:G8VfxNYYbBM:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=_RwtuHUK_AI:G8VfxNYYbBM:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=_RwtuHUK_AI:G8VfxNYYbBM:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=_RwtuHUK_AI:G8VfxNYYbBM:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=_RwtuHUK_AI:G8VfxNYYbBM:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=_RwtuHUK_AI:G8VfxNYYbBM:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=_RwtuHUK_AI:G8VfxNYYbBM:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/_RwtuHUK_AI" height="1" width="1"/>]]></content:encoded><description>I am very pleased to report that once again the good folks over at Microsoft's Trustworthy Computing Group have agreed to sponsor the Security Bloggers Network. The SBN has a long history of working with TWC and we are happy...</description><feedburner:origLink>http://www.ashimmy.com/2013/03/microsoft-trustworthy-computing-sponsors-security-bloggers-network.html</feedburner:origLink></item><item><title>Security Blogger Award Winners 2013</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/F6weQ2G2BXk/security-blogger-award-winners-2013.html</link><category>amrit williams</category><category>awards and PR</category><category>Martin McKeay</category><category>RSA</category><category>security bloggers network</category><category>Security Incite</category><category>Weblogs</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Fri, 01 Mar 2013 05:24:22 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017ee8d57df3970d</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>Well it was an epic Security Blogger Meetup and awards this year. In many ways it was the best one we have had. But nothing is perfect and we are already planning to be bigger, better and more inclusive next year.  In the meantime I know many folks have been waiting to see who the winners of the Social Security Blogger Awards were.  So without further adieu, for the record here are the nominees and winners:</p>  <p><strong>Best Corporate Security Blog</strong></p>  <p>Other nominees:</p>  <p><img alt="" src="https://s.zoomerang.com/i/t.gif"></img><strong>McAfee Blog: </strong><a href="http://blogs.mcafee.com/category/mcafee-labs">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>CloudFlare Blog: </strong><a href="http://blog.cloudflare.com/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>SecureWorks Blog: </strong><a href="http://www.secureworks.com/media/blog/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Solutionary Minds Blog: </strong><a href="http://blog.solutionary.com/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Kaspersky Lab Securelist Blog: </strong><a href="http://www.securelist.com/en/blog">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Veracode Blog: </strong><a href="http://www.veracode.com/blog/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Trend Micro Blog: </strong><a href="http://blog.trendmicro.com/">click here</a></p>  <p>AND THE WINNER IS:</p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Naked Security Blog: </strong><a href="http://nakedsecurity.sophos.com/">click here</a></p>  <p><strong>Best Security Podcast</strong></p>  <p>Other nominees:</p>  <p><img alt="" src="https://s.zoomerang.com/i/t.gif"></img><strong>Liquidmatrix Security Digest: </strong><a href="http://liquidmatrix.libsyn.com/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>EuroTrashSecurity: </strong><a href="http://www.eurotrashsecurity.eu/index.php/Main_Page">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>SANS Internet Storm Center: </strong><a href="https://isc.sans.edu/podcast.html">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Southern Fried Security: </strong><a href="http://www.southernfriedsecurity.com/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Risky Business: </strong><a href="http://risky.biz/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Sophos Security Chet Chat: </strong><a href="http://www.sophos.com/en-us/security-news-trends/podcasts.aspx">click here</a></p>  <p>And the winner is:</p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Paul Dotcom: </strong><a href="http://www.pauldotcom.com/">click here</a></p>  <p><strong>The Most Educational Security Blog</strong></p>  <p>Other nominees:</p>  <p><img alt="" src="https://s.zoomerang.com/i/t.gif"></img><strong>BH Consulting's Security Watch Blog: </strong><a href="http://bhconsulting.ie/securitywatch/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Security Uncorked Blog: </strong><a href="http://securityuncorked.com/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Dr. Kees Leune's Blog: </strong><a href="http://blog.leune.org/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Securosis Blog: </strong><a href="https://securosis.com/blog">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Social-Engineer.org Blog: </strong><a href="http://www.social-engineer.org/blog/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Critical Watch Blog: </strong><a href="http://blog.criticalwatch.com/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>The Security Skeptic Blog: </strong><a href="http://securityskeptic.typepad.com/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img></strong><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>The New School of Information Security Blog: </strong><a href="http://newschoolsecurity.com/">click here</a></p>  <p>And the winner is:</p>  <p><strong>Krebs On Security: </strong><a href="http://krebsonsecurity.com/">click here</a></p>  <p><strong>The Most Entertaining Security Blog</strong></p>  <p>Other nominees:</p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Packet Pushers Blog: </strong><a href="http://packetpushers.net/author/securityprincess/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img></strong><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Securosis Blog: </strong><a href="https://securosis.com/blog">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Errata Security Blog: </strong><a href="http://erratasec.blogspot.com/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Naked Security Blog: </strong><a href="http://nakedsecurity.sophos.com/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Uncommon Sense Security Blog: </strong><a href="http://blog.uncommonsensesecurity.com/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>PSilvas Blog: </strong><a href="http://psilvas.wordpress.com/">click here</a></p>  <p>And the winner is:</p>  <p><strong>J4VV4D's Blog: </strong><a href="http://www.j4vv4d.com/">click here</a></p>  <p><strong>The Blog That Best Represents The Security Industry</strong></p>  <p>Other nominees:</p>  <p><strong>SpiderLabs Anterior Blog: </strong><a href="http://blog.spiderlabs.com/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>1 Raindrop Blog: </strong><a href="http://1raindrop.typepad.com/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Naked Security Blog: </strong><a href="http://nakedsecurity.sophos.com/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>The Firewall (Forbes) Blog: </strong><a href="http://blogs.forbes.com/firewall/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Threat Level (Wired) Blog: </strong><a href="http://www.wired.com/threatlevel/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Securosis Blog: </strong><a href="https://securosis.com/blog">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Michael Peters Blog: </strong><a href="http://michaelpeters.org/">click here</a></p>  <p>And the winner is:</p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Krebs On Security Blog: </strong><a href="http://krebsonsecurity.com/">click here</a></p>  <p><strong>The Single Best Blog Post or Podcast Of The Year</strong></p>  <p>Other nominees:</p>  <p><strong>The Epic Hacking of Mat Honan and Our Identity Challenge: </strong><a href="http://www.identropy.com/blog/bid/88264/The-Epic-Hacking-of-Mat-Honan-and-Our-Identity-Challenge">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Application Security Debt and Application Interest Rates: </strong><a href="http://www.veracode.com/blog/2011/02/application-security-debt-and-application-interest-rates/">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Why XSS is serious business (and why Tesco needs to pay attention): </strong><a href="http://www.troyhunt.com/2012/08/why-xss-is-serious-business-and-why.html">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img></strong><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Levelling up in the real world: </strong><a href="http://idoneous-security.blogspot.com/2012/12/levelling-up-in-real-world.html">click here</a></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Secure Business Growth, Corporate Responsibility with Ben Tomhave: </strong><a href="https://www.brandenwilliams.com/blog/2012/01/19/corporate-responsibility-with-ben-tomhave/">click here</a></p>  <p>And the winner is:</p>  <p><strong>Meet The Hackers Who Sell Spies The Tools To Crack Your PC (And Get Paid Six-Figure Fees): </strong><a href="http://www.forbes.com/sites/andygreenberg/2012/03/21/meet-the-hackers-who-sell-spies-the-tools-to-crack-your-pc-and-get-paid-six-figure-fees/">click here</a></p>  <p><strong>The Security Bloggers Hall Of Fame</strong></p>  <p>The other nominees are:</p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Richard Bejtlich</strong></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Gunnar Peterson</strong></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Naked Security Blog</strong></p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Wendy Nather</strong></p>  <p><strong>And the winner is:</strong></p>  <p><strong>Jack Daniel</strong></p>  <p>Congratulations to all of the nominees and of course congrats to the winners.  See you next year at the Security Bloggers Meetup. If you did not get an invite this year, be sure to write to <a href="mailto:info@securitybloggersnetwork.com">info@securitybloggersnetwork.com</a> requesting to add your blog and be on the list!</p>  <p>Special thanks to our sponsors: Qualys, Sourcefire, Akamai, Fortinet, Barracuda Networks and Jeanne Friedman and the RSA Conference!  Also a special shout out to Trainer Communications for helping with the voting as always!</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=F6weQ2G2BXk:SKXSllCkNak:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=F6weQ2G2BXk:SKXSllCkNak:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=F6weQ2G2BXk:SKXSllCkNak:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=F6weQ2G2BXk:SKXSllCkNak:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=F6weQ2G2BXk:SKXSllCkNak:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=F6weQ2G2BXk:SKXSllCkNak:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=F6weQ2G2BXk:SKXSllCkNak:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=F6weQ2G2BXk:SKXSllCkNak:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/F6weQ2G2BXk" height="1" width="1"/>]]></content:encoded><description>Well it was an epic Security Blogger Meetup and awards this year. In many ways it was the best one we have had. But nothing is perfect and we are already planning to be bigger, better and more inclusive next...</description><feedburner:origLink>http://www.ashimmy.com/2013/03/security-blogger-award-winners-2013.html</feedburner:origLink></item><item><title>Why Not Everyone Can Come to the Security Bloggers Meetup</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/udycP-5UptA/why-not-everyone-can-come-to-the-security-bloggers-meetup.html</link><category>rich mogull</category><category>security bloggers network</category><category>Security Incite</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Wed, 27 Feb 2013 14:25:56 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017ee8c67ef7970d</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p><a href="https://securosis.com/blog/about-the-security-bloggers-meetup"><img title="security-blogger-meetup-logo" style="border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; float: right; padding-top: 0px; padding-left: 0px; margin: 0px 0px 5px 4px; display: inline; padding-right: 0px; border-top-width: 0px" border="0" alt="security-blogger-meetup-logo" align="right" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017d4152ae3a970c-pi" width="208" height="143"></img>Rich Mogul has a good post up</a> about the security <a title="Blog" class="zem_slink" href="http://en.wikipedia.org/wiki/Blog" rel="wikipedia">bloggers</a> meetup today. It gives the history and details of how and why we started the Security Bloggers <a title="Meetup" class="zem_slink" href="http://www.meetup.com/" rel="homepage">Meetup</a>.  I don’t disagree with anything he has to say.</p>  <p>On the other hand I am here in <a title="San Francisco" class="zem_slink" href="http://maps.google.com/maps?ll=37.7793,-122.4192&amp;spn=0.1,0.1&amp;q=37.7793,-122.4192 (San%20Francisco)&amp;t=h" rel="geolocation">San Francisco</a>.  Seeing some of you whom I consider my friends upset about not being invited to a party is upsetting to me.  If you know me, you know that I would gladly take dollars out of my pocket and make sure you drink, eat and have a good time.  But really that is not what it is about. As Rich said we have a waiting list for sponsors, so money is not the issue.  </p>  <p>There are two issues at play here and they are very different. I want to make sure we understand that.</p>  <p><strong>Issue 1</strong>: This is a party for the bloggers by the bloggers.  As Rich wrote, that has always been the idea behind the bloggers meetup and the blogger awards.  It is a marketing free zone. No <a title="Public relations" class="zem_slink" href="http://en.wikipedia.org/wiki/Public_relations" rel="wikipedia">PR</a>, no marketing, only bloggers. If you don’t blog, podcast or write about security, you should not be there. Have people gotten been admitted in years past who didn’t blog? Yes.  Some names always sneak in that we don’t catch. If you were lucky enough to get in one year, doesn’t mean you will next year or even this year though.</p>  <p>Will this change in the future? I really don’t think so, though I think we need to do a better job of defining what qualifies.  We will get started on that as soon as this years event is in the books.</p>  <p><strong>Issue 2</strong>: Just because you are invited, who can you bring with you.  I hear you on this one. I brought my wife out with me to RSA this year for the first time. If she had not already gone home, I would be hard pressed to not bring her with me to the party. Same goes for your significant other, best friend, partying buddy, etc.  But guys it really becomes an issue of space. The location has capacity rules, if we go over the <a title="San Francisco Fire Department" class="zem_slink" href="http://en.wikipedia.org/wiki/San_Francisco_Fire_Department" rel="wikipedia">SFFD</a> can close the whole thing down.  We can’t do it.  As Rich said we will look into a bigger place for next year and look at how we accommodate these kinds of requests.  But for this year, the cake is already baked.</p>  <p>So if I or any of us have offended you, pissed you off or you think we are being <a title="Standard of review" class="zem_slink" href="http://en.wikipedia.org/wiki/Standard_of_review" rel="wikipedia">arbitrary and capricious</a>, please forgive us. We are really do try to throw the best party and awards we can for the security blogger community!  Write to me with suggestions and we will do better next year.</p>  <p>For those two hundred or so of you who did get an invite, I am looking forward to lifting a glass and catching up.</p>  <div class="zemanta-related">   <h6 class="zemanta-related-title" style="font-size: 1em">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="https://securosis.com/blog/about-the-security-bloggers-meetup">About the Security Blogger's Meetup</a> (securosis.com) </li>      <li class="zemanta-article-ul-li"><a href="http://jillianlevi.wordpress.com/2013/02/26/bloggers-are-real-people/">Bloggers Are Real People</a> (jillianlevi.wordpress.com)</li>   </ul> </div>            <div class="zemanta-pixie" style="height: 15px; margin-top: 10px"><a title="Enhanced by Zemanta" class="zemanta-pixie-a" href="http://www.zemanta.com/?px"><img class="zemanta-pixie-img" style="border-top-style: none; border-left-style: none; border-bottom-style: none; float: right; border-right-style: none" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=1fed2b1f-cdfe-4fa6-bc46-8ae31baf945f"></img></a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=udycP-5UptA:UIj_o41yK34:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=udycP-5UptA:UIj_o41yK34:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=udycP-5UptA:UIj_o41yK34:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=udycP-5UptA:UIj_o41yK34:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=udycP-5UptA:UIj_o41yK34:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=udycP-5UptA:UIj_o41yK34:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=udycP-5UptA:UIj_o41yK34:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=udycP-5UptA:UIj_o41yK34:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/udycP-5UptA" height="1" width="1"/>]]></content:encoded><description>Rich Mogul has a good post up about the security bloggers meetup today. It gives the history and details of how and why we started the Security Bloggers Meetup. I don’t disagree with anything he has to say. On the...</description><feedburner:origLink>http://www.ashimmy.com/2013/02/why-not-everyone-can-come-to-the-security-bloggers-meetup.html</feedburner:origLink></item><item><title>Alert Logic Partner Pavilion at RSA 2013</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/qXWsl3wxpC4/alert-logic-partner-pavilion-at-rsa-2013.html</link><category>alert logic</category><category>awards and PR</category><category>cloud</category><category>cloud security</category><category>compliance</category><category>MSSP</category><category>other security companies</category><category>SaaS</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Mon, 25 Feb 2013 09:00:00 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017d41411f93970c</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://en.wikipedia.org/wiki/RSA_Conference" rel="wikipedia" target="_blank" title="RSA Conference">RSA Conference</a> is <strong>THE</strong> <a class="zem_slink" href="http://www.infosecinstitute.com" rel="infosec" target="_blank" title="information security">information security</a> event of the year.  As part of my coverage of this years conference I did a series of podcasts with some cloud/hosting providers who are exhibiting in the Alert Logic Partner Pavilion. This is the third in the series and is with Urvish Vashi, VP of marketing at Alert Logic.</p>
<p>
<a class="asset-img-link" href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017ee8b50a45970d-pi" style="float: left;"><img alt="Urvish" class="asset  asset-image at-xid-6a00d83451e4d369e2017ee8b50a45970d" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017ee8b50a45970d-120wi" style="margin: 0px 5px 5px 0px;" title="Urvish"></img></a>I know Urvish for over 10 years, since our time together at Interliant.  Urvish was the force behind the Partner Pavilion for Alert Logic this year.  Having 5 of the leading hosting/cloud providers exhibiting at the worlds largest security conference may at first blush seem a stretch. After all, are these cloud providers security providers? Yes they are!</p>
<p>Urvish's point is that with partners like Alert Logic, these cloud providers are providing a wide range of best-in-breed cloud security services.</p>
<p>This is just a short 15 minute or so interview, but Urvish gives us some great insights.  Check out what he has to say and be sure to visit the Alert Logic Partner Pavilion on the show floor at RSA!</p>
<p><iframe frameborder="0" height="85" marginheight="0" marginwidth="0" scrolling="no" src="http://ashimmy.podomatic.com/embed/frame/posting/2013-02-22T17_51_36-08_00?json_url=http%3A%2F%2Fashimmy.podomatic.com%2Fentry%2Fembed_params%2F2013-02-22T17_51_36-08_00%3Fcolor%3Df8ae06%26autoPlay%3Dfalse%26width%3D440%26height%3D85%26objembed%3D0" width="440"></iframe></p>
<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles</legend>
<div class="zemanta-article-ul zemanta-article-ul-image" style="margin: 0; padding: 0; overflow: hidden;">
<div class="zemanta-article-ul-li-image zemanta-article-ul-li" style="padding: 0; background: none; list-style: none; display: block; float: left; vertical-align: top; text-align: left; width: 84px; font-size: 11px; margin: 2px 10px 10px 2px;"><a href="http://www.ashimmy.com/2013/02/where-is-ashimmy-at-rsa.html" style="box-shadow: 0px 0px 4px #999; padding: 2px; display: block; border-radius: 2px; text-decoration: none;" target="_blank"><img alt="" src="http://i.zemanta.com/147018511_80_80.jpg" style="padding: 0; margin: 0; border: 0; display: block; width: 80px; max-width: 100%;"></img></a><a href="http://www.ashimmy.com/2013/02/where-is-ashimmy-at-rsa.html" style="display: block; overflow: hidden; text-decoration: none; line-height: 12pt; height: 80px; padding: 5px 2px 0 2px;" target="_blank">Where is AShimmy at RSA?</a></div>
<div class="zemanta-article-ul-li-image zemanta-article-ul-li" style="padding: 0; background: none; list-style: none; display: block; float: left; vertical-align: top; text-align: left; width: 84px; font-size: 11px; margin: 2px 10px 10px 2px;"><a href="https://www.mandiant.com/blog/mandiant-rsa-usa-2013/" style="box-shadow: 0px 0px 4px #999; padding: 2px; display: block; border-radius: 2px; text-decoration: none;" target="_blank"><img alt="" src="http://i.zemanta.com/147349785_80_80.jpg" style="padding: 0; margin: 0; border: 0; display: block; width: 80px; max-width: 100%;"></img></a><a href="https://www.mandiant.com/blog/mandiant-rsa-usa-2013/" style="display: block; overflow: hidden; text-decoration: none; line-height: 12pt; height: 80px; padding: 5px 2px 0 2px;" target="_blank">Mandiant @ RSA USA 2013: Who, What, Where &amp; When</a></div>
<div class="zemanta-article-ul-li-image zemanta-article-ul-li" style="padding: 0; background: none; list-style: none; display: block; float: left; vertical-align: top; text-align: left; width: 84px; font-size: 11px; margin: 2px 10px 10px 2px;"><a href="https://www.brandenwilliams.com/blog/2013/02/22/rsa-conference-2013-you-ready/" style="box-shadow: 0px 0px 4px #999; padding: 2px; display: block; border-radius: 2px; text-decoration: none;" target="_blank"><img alt="" src="http://i.zemanta.com/147322983_80_80.jpg" style="padding: 0; margin: 0; border: 0; display: block; width: 80px; max-width: 100%;"></img></a><a href="https://www.brandenwilliams.com/blog/2013/02/22/rsa-conference-2013-you-ready/" style="display: block; overflow: hidden; text-decoration: none; line-height: 12pt; height: 80px; padding: 5px 2px 0 2px;" target="_blank">RSA Conference 2013, YOU READY!?</a></div>
<div class="zemanta-article-ul-li-image zemanta-article-ul-li" style="padding: 0; background: none; list-style: none; display: block; float: left; vertical-align: top; text-align: left; width: 84px; font-size: 11px; margin: 2px 10px 10px 2px;"><a href="http://www.sys-con.com/node/2544043" style="box-shadow: 0px 0px 4px #999; padding: 2px; display: block; border-radius: 2px; text-decoration: none;" target="_blank"><img alt="" src="http://i.zemanta.com/146445970_80_80.jpg" style="padding: 0; margin: 0; border: 0; display: block; width: 80px; max-width: 100%;"></img></a><a href="http://www.sys-con.com/node/2544043" style="display: block; overflow: hidden; text-decoration: none; line-height: 12pt; height: 80px; padding: 5px 2px 0 2px;" target="_blank">Qualys CEO to Address Security in a Hyperconnected World During Keynote Session at RSA Conference USA 2013</a></div>
</div>
</fieldset></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=qXWsl3wxpC4:q-gMYvlbDQE:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=qXWsl3wxpC4:q-gMYvlbDQE:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=qXWsl3wxpC4:q-gMYvlbDQE:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=qXWsl3wxpC4:q-gMYvlbDQE:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=qXWsl3wxpC4:q-gMYvlbDQE:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=qXWsl3wxpC4:q-gMYvlbDQE:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=qXWsl3wxpC4:q-gMYvlbDQE:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=qXWsl3wxpC4:q-gMYvlbDQE:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/qXWsl3wxpC4" height="1" width="1"/>]]></content:encoded><description>RSA Conference is THE information security event of the year. As part of my coverage of this years conference I did a series of podcasts with some cloud/hosting providers who are exhibiting in the Alert Logic Partner Pavilion. This is...</description><feedburner:origLink>http://www.ashimmy.com/2013/02/alert-logic-partner-pavilion-at-rsa-2013.html</feedburner:origLink></item><item><title>RSA 2013 Navisite at the Alert Logic Partner Pavilion</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/TLvJPJAVqtI/rsa-2013-navisite-at-the-alert-logic-partner-pavilion.html</link><category>alert logic</category><category>awards and PR</category><category>cloud</category><category>cloud security</category><category>links and appearances</category><category>MSSP</category><category>outsourcing security</category><category>SaaS</category><category>tradeshows</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Mon, 25 Feb 2013 07:38:00 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017d41411cc4970c</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<div xmlns="http://www.w3.org/1999/xhtml"><p><a class="zem_slink" href="http://en.wikipedia.org/wiki/RSA_Conference" rel="wikipedia" target="_blank" title="RSA Conference">RSA Conference</a> is <strong>THE</strong> information security event of the
year.  As part of my coverage of this years conference I did a series of podcasts with some cloud/hosting providers who are exhibiting in the Alert Logic Partner Pavilion. This is the second in the series with Chris Patterson of <a class="zem_slink" href="http://www.navisite.com" rel="homepage" target="_blank" title="NaviSite">Navisite</a>.</p>
<p>My friends at Alert Logic have 5 of the largest cloud and hosting providers in the world exhibiting with them this year.  I thought it was worthwhile to expore why these cloud/hosting providers were exhibiting at the largest security conference in the world.</p>
<p>
<a class="asset-img-link" href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017d41411974970c-pi" style="float: left;"><img alt="Chris-patterson-crop" border="0" class="asset  asset-image at-xid-6a00d83451e4d369e2017d41411974970c" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017d41411974970c-800wi" style="margin: 0px 5px 5px 0px;" title="Chris-patterson-crop"></img></a>I caught up with Chris Patterson, VP of Product Management at Navisite.Chris is one of the driving forces behind the Navi cloud.  He also has some great insight into the state
of <a class="zem_slink" href="http://www.symantec.com/cloud-computing-software" rel="symantec" target="_blank" title="Cloud Computing Software ">cloud security</a> and what market drivers are influencing the direction of
future innovation.</p>
<p>Chris shares some great insight into Navisite's offerings
including not just cloud, but security, managed desktop and the state of the
market.</p>
<p><iframe frameborder="0" height="85" marginheight="0" marginwidth="0" scrolling="no" src="http://ashimmy.podomatic.com/embed/frame/posting/2013-02-22T17_46_10-08_00?json_url=http%3A%2F%2Fashimmy.podomatic.com%2Fentry%2Fembed_params%2F2013-02-22T17_46_10-08_00%3Fcolor%3Df8ae06%26autoPlay%3Dfalse%26width%3D440%26height%3D85%26objembed%3D0" width="440"></iframe></p>
<p> </p>
<p>
<a class="asset-img-link" href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017c3711d8e8970b-pi"><img alt="NaviSite-Logo-Color-Vector" class="asset  asset-image at-xid-6a00d83451e4d369e2017c3711d8e8970b" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017c3711d8e8970b-320wi" style="display: block; margin-left: auto; margin-right: auto;" title="NaviSite-Logo-Color-Vector"></img></a><br><br></p>
<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles</legend>
<div class="zemanta-article-ul zemanta-article-ul-image" style="margin: 0; padding: 0; overflow: hidden;">
<div class="zemanta-article-ul-li-image zemanta-article-ul-li" style="padding: 0; background: none; list-style: none; display: block; float: left; vertical-align: top; text-align: left; width: 84px; font-size: 11px; margin: 2px 10px 10px 2px;"><a href="http://www.ashimmy.com/2013/02/where-is-ashimmy-at-rsa.html" style="box-shadow: 0px 0px 4px #999; padding: 2px; display: block; border-radius: 2px; text-decoration: none;" target="_blank"><img alt="" src="http://i.zemanta.com/147018511_80_80.jpg" style="padding: 0; margin: 0; border: 0; display: block; width: 80px; max-width: 100%;"></img></a><a href="http://www.ashimmy.com/2013/02/where-is-ashimmy-at-rsa.html" style="display: block; overflow: hidden; text-decoration: none; line-height: 12pt; height: 80px; padding: 5px 2px 0 2px;" target="_blank">Where is AShimmy at RSA?</a></div>
<div class="zemanta-article-ul-li-image zemanta-article-ul-li" style="padding: 0; background: none; list-style: none; display: block; float: left; vertical-align: top; text-align: left; width: 84px; font-size: 11px; margin: 2px 10px 10px 2px;"><a href="https://www.brandenwilliams.com/blog/2013/02/22/rsa-conference-2013-you-ready/" style="box-shadow: 0px 0px 4px #999; padding: 2px; display: block; border-radius: 2px; text-decoration: none;" target="_blank"><img alt="" src="http://i.zemanta.com/147322983_80_80.jpg" style="padding: 0; margin: 0; border: 0; display: block; width: 80px; max-width: 100%;"></img></a><a href="https://www.brandenwilliams.com/blog/2013/02/22/rsa-conference-2013-you-ready/" style="display: block; overflow: hidden; text-decoration: none; line-height: 12pt; height: 80px; padding: 5px 2px 0 2px;" target="_blank">RSA Conference 2013, YOU READY!?</a></div>
<div class="zemanta-article-ul-li-image zemanta-article-ul-li" style="padding: 0; background: none; list-style: none; display: block; float: left; vertical-align: top; text-align: left; width: 84px; font-size: 11px; margin: 2px 10px 10px 2px;"><a href="http://blog.solutionary.com/blog/bid/94508/Get-Knowledgeable-About-IT-Security-RSA-is-Here-Again" style="box-shadow: 0px 0px 4px #999; padding: 2px; display: block; border-radius: 2px; text-decoration: none;" target="_blank"><img alt="" src="http://i.zemanta.com/147346846_80_80.jpg" style="padding: 0; margin: 0; border: 0; display: block; width: 80px; max-width: 100%;"></img></a><a href="http://blog.solutionary.com/blog/bid/94508/Get-Knowledgeable-About-IT-Security-RSA-is-Here-Again" style="display: block; overflow: hidden; text-decoration: none; line-height: 12pt; height: 80px; padding: 5px 2px 0 2px;" target="_blank">Get Knowledgeable About IT Security: RSA is Here Again!</a></div>
<div class="zemanta-article-ul-li-image zemanta-article-ul-li" style="padding: 0; background: none; list-style: none; display: block; float: left; vertical-align: top; text-align: left; width: 84px; font-size: 11px; margin: 2px 10px 10px 2px;"><a href="http://www.darkreading.com/security-monitoring/167901086/security/news/240149235/alert-logic-releases-new-log-manager-to-integrate-all-customer-environments.html" style="box-shadow: 0px 0px 4px #999; padding: 2px; display: block; border-radius: 2px; text-decoration: none;" target="_blank"><img alt="" src="http://i.zemanta.com/147357767_80_80.jpg" style="padding: 0; margin: 0; border: 0; display: block; width: 80px; max-width: 100%;"></img></a><a href="http://www.darkreading.com/security-monitoring/167901086/security/news/240149235/alert-logic-releases-new-log-manager-to-integrate-all-customer-environments.html" style="display: block; overflow: hidden; text-decoration: none; line-height: 12pt; height: 80px; padding: 5px 2px 0 2px;" target="_blank">Alert Logic Releases New Log Manager To Integrate All Customer Environments</a></div>
</div>
</fieldset></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=TLvJPJAVqtI:4ZSBk5uYIbM:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=TLvJPJAVqtI:4ZSBk5uYIbM:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=TLvJPJAVqtI:4ZSBk5uYIbM:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=TLvJPJAVqtI:4ZSBk5uYIbM:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=TLvJPJAVqtI:4ZSBk5uYIbM:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=TLvJPJAVqtI:4ZSBk5uYIbM:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=TLvJPJAVqtI:4ZSBk5uYIbM:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=TLvJPJAVqtI:4ZSBk5uYIbM:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/TLvJPJAVqtI" height="1" width="1"/>]]></content:encoded><description>RSA Conference is THE information security event of the year. As part of my coverage of this years conference I did a series of podcasts with some cloud/hosting providers who are exhibiting in the Alert Logic Partner Pavilion. This is...</description><feedburner:origLink>http://www.ashimmy.com/2013/02/rsa-2013-navisite-at-the-alert-logic-partner-pavilion.html</feedburner:origLink></item><item><title>Sunguard Availability Services at RSA 2013</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/YdTH6fL_rvE/sunguard-availability-services-at-rsa-2013.html</link><category>awards and PR</category><category>cloud</category><category>cloud security</category><category>other security companies</category><category>podcasting</category><category>RSA</category><category>tradeshows</category><category>Weblogs</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Mon, 25 Feb 2013 06:00:00 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017d4140c398970c</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<div xmlns="http://www.w3.org/1999/xhtml"><p>RSA Conference is <strong>THE</strong> information security event of the
year. Kicking off my coverage of RSA this year is a series of podcasts I did with cloud/hosting providers who are exhibiting this year in the partner pavilion of Alert Logic.  </p>
<p>My friends at Alert Logic have 5 of the largest hosting/cloud providers in the world exhibiting with them. I was curious why these cloud and hosting providers wanted to exhibit at a security conference.</p>
<p>The first provider I spoke with was Sunguard. Specicifally Sunguard Availability Services. I spoke with Cara Camping, Product Manager, Managed Security Services for
Sunguard AS. Cara talks about Sunguard's approach to security
in depth, why they partner with Alert Logic and what they expect from
exhibiting at RSA Conference.</p>
<p><iframe frameborder="0" height="85" marginheight="0" marginwidth="0" scrolling="no" src="http://ashimmy.podomatic.com/embed/frame/posting/2013-02-21T09_19_59-08_00?json_url=http%3A%2F%2Fashimmy.podomatic.com%2Fentry%2Fembed_params%2F2013-02-21T09_19_59-08_00%3Fcolor%3Df8ae06%26autoPlay%3Dfalse%26width%3D440%26height%3D85%26objembed%3D0" width="440"></iframe></p>
<p>Below are two slides that Cara references in our discussion:</p>
<p>
<a class="asset-img-link" href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017c37117cf1970b-pi" style="float: left;"><img alt="Image1" border="0" class="asset  asset-image at-xid-6a00d83451e4d369e2017c37117cf1970b image-full" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017c37117cf1970b-800wi" style="margin: 0px 5px 5px 0px;" title="Image1"></img></a></p>
<p>
<a class="asset-img-link" href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017d4140bfad970c-pi" style="float: left;"><img alt="Slide 2" border="0" class="asset  asset-image at-xid-6a00d83451e4d369e2017d4140bfad970c image-full" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017d4140bfad970c-800wi" style="margin: 0px 5px 5px 0px;" title="Slide 2"></img></a></p>
<p> </p>
<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles</legend>
<div class="zemanta-article-ul zemanta-article-ul-image" style="margin: 0; padding: 0; overflow: hidden;">
<div class="zemanta-article-ul-li-image zemanta-article-ul-li" style="padding: 0; background: none; list-style: none; display: block; float: left; vertical-align: top; text-align: left; width: 84px; font-size: 11px; margin: 2px 10px 10px 2px;"><a href="https://www.brandenwilliams.com/blog/2013/02/22/rsa-conference-2013-you-ready/" style="box-shadow: 0px 0px 4px #999; padding: 2px; display: block; border-radius: 2px; text-decoration: none;" target="_blank"><img alt="" src="http://i.zemanta.com/147322983_80_80.jpg" style="padding: 0; margin: 0; border: 0; display: block; width: 80px; max-width: 100%;"></img></a><a href="https://www.brandenwilliams.com/blog/2013/02/22/rsa-conference-2013-you-ready/" style="display: block; overflow: hidden; text-decoration: none; line-height: 12pt; height: 80px; padding: 5px 2px 0 2px;" target="_blank">RSA Conference 2013, YOU READY!?</a></div>
<div class="zemanta-article-ul-li-image zemanta-article-ul-li" style="padding: 0; background: none; list-style: none; display: block; float: left; vertical-align: top; text-align: left; width: 84px; font-size: 11px; margin: 2px 10px 10px 2px;"><a href="http://www.ashimmy.com/2013/02/where-is-ashimmy-at-rsa.html" style="box-shadow: 0px 0px 4px #999; padding: 2px; display: block; border-radius: 2px; text-decoration: none;" target="_blank"><img alt="" src="http://i.zemanta.com/147018511_80_80.jpg" style="padding: 0; margin: 0; border: 0; display: block; width: 80px; max-width: 100%;"></img></a><a href="http://www.ashimmy.com/2013/02/where-is-ashimmy-at-rsa.html" style="display: block; overflow: hidden; text-decoration: none; line-height: 12pt; height: 80px; padding: 5px 2px 0 2px;" target="_blank">Where is AShimmy at RSA?</a></div>
<div class="zemanta-article-ul-li-image zemanta-article-ul-li" style="padding: 0; background: none; list-style: none; display: block; float: left; vertical-align: top; text-align: left; width: 84px; font-size: 11px; margin: 2px 10px 10px 2px;"><a href="http://www.ashimmy.com/2013/01/security-blogger-awards-finalist-voting-is-now-open.html" style="box-shadow: 0px 0px 4px #999; padding: 2px; display: block; border-radius: 2px; text-decoration: none;" target="_blank"><img alt="" src="http://i.zemanta.com/141202391_80_80.jpg" style="padding: 0; margin: 0; border: 0; display: block; width: 80px; max-width: 100%;"></img></a><a href="http://www.ashimmy.com/2013/01/security-blogger-awards-finalist-voting-is-now-open.html" style="display: block; overflow: hidden; text-decoration: none; line-height: 12pt; height: 80px; padding: 5px 2px 0 2px;" target="_blank">Security Blogger Awards Finalist Voting Is Now Open!</a></div>
</div>
</fieldset></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=YdTH6fL_rvE:W8ut5cPt8lw:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=YdTH6fL_rvE:W8ut5cPt8lw:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=YdTH6fL_rvE:W8ut5cPt8lw:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=YdTH6fL_rvE:W8ut5cPt8lw:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=YdTH6fL_rvE:W8ut5cPt8lw:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=YdTH6fL_rvE:W8ut5cPt8lw:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=YdTH6fL_rvE:W8ut5cPt8lw:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=YdTH6fL_rvE:W8ut5cPt8lw:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/YdTH6fL_rvE" height="1" width="1"/>]]></content:encoded><description>RSA Conference is THE information security event of the year. Kicking off my coverage of RSA this year is a series of podcasts I did with cloud/hosting providers who are exhibiting this year in the partner pavilion of Alert Logic....</description><feedburner:origLink>http://www.ashimmy.com/2013/02/sunguard-availability-services-at-rsa-2013.html</feedburner:origLink></item><item><title>Life Outside the Audit Zone</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/eiBaKmvV33I/life-outside-the-audit-zone.html</link><category>General Security</category><category>IBM</category><category>Midmarket</category><category>pci</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Thu, 21 Feb 2013 07:59:32 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017d4132ad22970c</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p><a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017d4132ad0d970c-pi"><img title="pci crypt" style="border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; float: right; padding-top: 0px; padding-left: 0px; margin: 2px 4px 5px 5px; display: inline; padding-right: 0px; border-top-width: 0px" border="0" alt="pci crypt" align="right" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017c37035a3a970b-pi" width="280" height="291"></img></a>Last week <a href="http://www.ashimmy.com/2013/02/tales-from-the-pci-crypt-life-outside-the-pci-audit-zone.html">I wrote a “Tales from the PCI Crypt</a>” blog article in regard to the <a href="http://iscanme.wordpress.com/2013/01/31/scanning-microsoft-outlook-exposes-cardholder-data-on-80-of-merchants/">findings of iScan Online</a> that many of the merchants they scanned had credit card data contained in their email files. The fallout from that was that many organizations only worry about what is in their “audit zone”. What is the audit zone? It is those devices and those parts of your IT infrastructure that are subject to regulatory compliance or other types of audit. It may also include your policies and process that are subject to audit as well.</p>  <p>A popular strategy for dealing with compliance audits, especially in the mid-market has been to move as much as possible “outside the scope” of the audit. In PCI for instance, if the device is not involved in the recording, storing or transmitting of cardholder data, it is not subject usually to a QSA or other type of PCI audit. But as my friends at iScan Online found out, that is not necessarily the case. While technically, because these devices do have cardholder data they are subject to PCI audit, when asked by the auditor they are usually excluded because they don’t “touch” the cardholder data environment. But in fact they do!</p>  <p>A bigger issue though is that most organizations, especially in the midmarket, seek to do as little as possible to pass compliance. Compliance becomes a substitute for being secure. In the iScan Online case for instance, it was more important to say that sales persons cell phones and tablets are not part of the cardholder data environment so that they were “outside the scope” of PCI. But turns out those devices were vulnerable and had card data. A breach on those devices would not only have PCI consequences, but it could have more dire consequences to the bottom line. For instance according to several breach reports the average cost of a record lost is between 200 and 300 dollars. The average breach has a few thousand records lost. Do the math. That is enough to crater many smaller and midsize companies.</p>  <p>As we are seeing in many IBM Midmarket highlights <a href="http://www.huffingtonpost.com/teresa-zobrist/ibm-taking-the-mobile-path_b_2601205.html">such as this one on the Huffington Post</a>, small and medium business are moving more and more to mobile, phones and tablets. If anyone thinks moving to mobile moves these devices outside of the audit zone they are mistaken. Even if they are not being audited, they represent security risks that must be addressed. You need a strategy for these devices outside of your audit zone.</p>  <p>A successful strategy has to go outside of the audit zone. You need to look at your real security and risk factors. Don’t be fooled into thinking that minimizing your audit profile, minimizes your risk. In fact it could be just the opposite. Minimizing your audit profile, could be at the expense of increasing your risk.</p>  <p>This dilemma is the result of our compliance at all costs mentality which has ruled in infosec for these past years. Checkbox security for compliance sake alone gives us a false sense of security. It does more harm than good. So next time you are looking at a compliance audit, try to think outside the audit zone and do what is best for the security and risk of your organization.</p>  <p><a href="http://goo.gl/t3fgW"><img title="IBM" style="margin: 0px 12px 5px 0px" border="0" alt="IBM" align="left" src="http://www.ashimmy.com/.a/6a00d83451e4d369e201630255b2b7970d-pi" width="240" height="97"></img></a></p>  <p><em>This post was written as part of the </em><em><a href="http://goo.gl/t3fgW"><i>IBM for Midsize Business</i></a></em><i> <em>program, which provides midsize businesses with the tools, expertise and solutions they need to become engines of a smarter planet. I’ve been compensated to contribute to this program, but t</em>he opinions expressed in this post are my own and don't necessarily represent IBM's positions, strategies or opinions.</i></p>  <p><em> </em></p>  <div class="zemanta-related">   <h6 class="zemanta-related-title" style="font-size: 1em">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://iscanme.wordpress.com/2013/01/31/scanning-microsoft-outlook-exposes-cardholder-data-on-80-of-merchants/">Scanning Microsoft Outlook Exposes Cardholder Data on 80% of Merchants</a> (iscanme.wordpress.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.virtual-strategy.com/2013/01/31/8-critical-pci-compliance-requirements-all-businesses-need-know-about">8 Critical PCI Compliance Requirements all Businesses Need to Know About</a> (virtual-strategy.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.tripwire.com/state-of-security/compliance/pci/beyond-the-pci-checkbox-customer-success-story/">Beyond the PCI Checkbox. Customer Success Story.</a> (tripwire.com)</li>      <li class="zemanta-article-ul-li"><a href="http://www.prweb.com/releases/2013/1/prweb10374664.htm">8 Critical PCI Compliance Requirements all Businesses Need to Know About</a> (prweb.com)</li>   </ul> </div>  <div class="zemanta-pixie" style="height: 15px; margin-top: 10px"><a title="Enhanced by Zemanta" class="zemanta-pixie-a" href="http://www.zemanta.com/?px"><img class="zemanta-pixie-img" style="border-top-style: none; border-left-style: none; border-bottom-style: none; float: right; border-right-style: none" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=aff88d74-38f9-4617-9cc0-cbcb2aba7bc5"></img></a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=eiBaKmvV33I:pJIM3hOIW3g:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=eiBaKmvV33I:pJIM3hOIW3g:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=eiBaKmvV33I:pJIM3hOIW3g:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=eiBaKmvV33I:pJIM3hOIW3g:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=eiBaKmvV33I:pJIM3hOIW3g:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=eiBaKmvV33I:pJIM3hOIW3g:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=eiBaKmvV33I:pJIM3hOIW3g:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=eiBaKmvV33I:pJIM3hOIW3g:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/eiBaKmvV33I" height="1" width="1"/>]]></content:encoded><description>Last week I wrote a “Tales from the PCI Crypt” blog article in regard to the findings of iScan Online that many of the merchants they scanned had credit card data contained in their email files. The fallout from that...</description><feedburner:origLink>http://www.ashimmy.com/2013/02/life-outside-the-audit-zone.html</feedburner:origLink></item><item><title>Where is AShimmy at RSA?</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/OxSmYoB4yLI/where-is-ashimmy-at-rsa.html</link><category>awards and PR</category><category>cloud</category><category>cloud security</category><category>Current Affairs</category><category>education</category><category>General Background</category><category>links and appearances</category><category>RSA</category><category>security bloggers network</category><category>the security industry</category><category>tradeshows</category><category>VAM</category><category>vulnerability management</category><category>Web/Tech</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Thu, 21 Feb 2013 07:08:46 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017c37034471970b</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p><img src="http://www.trustedcomputinggroup.org/images/public/resource_media/FA8D8A72-1A4B-B294-D0111BA43767012A.JPG" width="388" height="122"></img>  <p>You can feel the pace rising to a crescendo, you sense it coming. But don’t look now, RSA is just next week.  The last two months have been pretty much a blur in getting ready for the big conference.  As usual I should have done 12 things I didn’t, but the dozens of things I have done is going to have to be enough.  </p>  <p>I am happy to be chairing two panels during RSA week this year.  The first is on Monday, the 25th (also my 23rd wedding anniversary) at the annual and well attended Americas Growth Capital Conference, over at the Westin.  The panel I am chairing is at 11:30 a.m..</p>  <p>The topic is <strong>Cloud Security Services: The Evolution Continues</strong></p>  <p>Here is the abstract:</p>  <blockquote>   <p><em>With the initial gold rush to the cloud it seemed that every security vendor was pushing a cloud security service. Every security company had to have their “story on the cloud” for customers, analysts and investors. But over the months and years we have seen a steady evolution of cloud security services beyond those early “everything but the kitchen sink” strategies. </em></p>    <p><em>More than just putting data and analysis off premises, today’s cloud security services are truly leveraging the unique features of the cloud like elasticity, massive scale and instant on provisioning.</em></p>    <p><em>Just because you can do it in the cloud doesn’t mean the cloud is the best place to do it. As we move beyond the explosion of cloud security services, which types of security services are best suited to the cloud? Which cloud security services will have markets large enough to create substantial business opportunity? Which cloud security services are so disruptive that they will eliminate or replace non-cloud based security services?</em></p>    <p><em>Evolution can be a cruel master, only the strong survive. The losers fall into the trash heap of history. Our panel will tell you who the winners will be in cloud security services.</em></p> </blockquote>  <p>I am joined on the panel by: </p>  <blockquote>   <p><em><strong>Matthew Prince</strong>, Co-Founder, Chief Executive Officer, CloudFlare</em></p>    <p><em><strong>Dave Dewalt</strong>, Chief Executive Officer, Chairman, <a title="FireEye, Inc." class="zem_slink" href="http://www.fireeye.com/" rel="homepage">FireEye</a>, Chairman, Mandiant</em></p>    <p><em><strong>Jay Chaudhry</strong>, Founder, Chief Executive Officer, Zscaler</em></p>    <p><em><strong>Stuart Scholly</strong>, President, Prolexic</em></p>    <p><em><strong>Carson Sweet</strong>, Co-Founder and CEO of </em><a href="http://www.cloudpassage.com/"><em>CloudPassage</em></a></p> </blockquote>  <p>It should be a great panel!</p>  <p>Then on Wednesday I am chairing a great panel at RSA at 9:20 am in room 304 on Ipv6 Vulnerability Management: From Theory to Reality. The agenda:</p>  <blockquote>   <p><em>Join the leading lights of the vulnerability management industry as they carry forward their discussion on the challenges of managing vulnerabilities and network security in an IPv6 network. Where last year the discussion was theoretical, this years panel will focus on actual case studies of standing IPv6 networks in govt., retail, large enterprise and the cloud.</em></p> </blockquote>  <p>My fantastic panel for this one is:</p>  <blockquote>   <p><a href="https://ae.rsaconference.com/US13/connect/speakerDetail.ww?PERSON_ID=70BA29941D36343443D63315C27CCFEA&amp;tclass=popup">Wolfgang Kandek - Chief Technology Officer, Qualys </a>      <br><a href="https://ae.rsaconference.com/US13/connect/speakerDetail.ww?PERSON_ID=A05EF868456720C5A7DD7B4036F5C11A&amp;tclass=popup">Ron Gula - Chief Executive Officer and Chief Technical Officer, Tenable Network Security </a>      <br><a href="https://ae.rsaconference.com/US13/connect/speakerDetail.ww?PERSON_ID=5431771EE88F23DB7844E6A2316BCC7B&amp;tclass=popup">HD Moore - Chief Security Officer, Rapid 7 </a>      <br><a href="https://ae.rsaconference.com/US13/connect/speakerDetail.ww?PERSON_ID=4695F9F1A94204245D200D17E8736A24&amp;tclass=popup">Tim Keanini - Chief Research Officer, nCircle </a>      <br><a href="https://ae.rsaconference.com/US13/connect/speakerDetail.ww?PERSON_ID=4ED00E078136D9FA1E54427E922773D9&amp;tclass=popup">Misha Govshteyn - Vice President Emerging Products, Alert Logic </a></p> </blockquote>  <p>Besides that I will of course be at the Security Bloggers Meet up and Security Blogger Awards on Wednesday.  Besides that I will be in and out of meetings and sessions, parties at night and usually at the W bar before heading in for the night.  If you see me, be sure to say hi.</p>  <p>Enjoy RSA, let the fun begin!</p>  <div class="zemanta-related">   <h6 class="zemanta-related-title" style="font-size: 1em">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://www.sys-con.com/node/2544043">Qualys CEO to Address Security in a Hyperconnected World During Keynote Session at RSA Conference USA 2013</a> (sys-con.com) </li>      <li class="zemanta-article-ul-li"><a href="https://www.mandiant.com/blog/rsa-usa-2013-corner/">RSA USA 2013: Right Around The Corner</a> (mandiant.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.ashimmy.com/2013/02/illuminating-the-dark-matter-of-your-network-with-iscan-onlines-opportunistic-scanning.html">Illuminating the Dark Matter of your network with iScan Onlines Opportunistic Scanning</a> (ashimmy.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.virtual-strategy.com/2013/02/20/cloudpassage-ceo-carson-sweet-speak-about-cloud-security-agc%E2%80%99s-west-coast-infosec-and-tec">CloudPassage CEO Carson Sweet to Speak about Cloud Security at AGC's West Coast InfoSec and Technology Growth Conference</a> (virtual-strategy.com)</li>      <li class="zemanta-article-ul-li"><a href="http://news.softpedia.com/news/Zscaler-Unveils-New-Analytics-Technology-to-Provide-Real-Time-Visibility-Into-Global-Traffic-329163.shtml">Zscaler Unveils New Analytics Technology to Provide Real-Time Visibility into Global Traffic</a> (news.softpedia.com)</li>   </ul> </div>  <div class="zemanta-pixie" style="height: 15px; margin-top: 10px"><a title="Enhanced by Zemanta" class="zemanta-pixie-a" href="http://www.zemanta.com/?px"><img class="zemanta-pixie-img" style="border-top-style: none; border-left-style: none; border-bottom-style: none; float: right; border-right-style: none" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=10dcdad7-311e-48a4-86d3-18f3cd326d8b"></img></a></div></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=OxSmYoB4yLI:HgZ7fVZ8mBc:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=OxSmYoB4yLI:HgZ7fVZ8mBc:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=OxSmYoB4yLI:HgZ7fVZ8mBc:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=OxSmYoB4yLI:HgZ7fVZ8mBc:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=OxSmYoB4yLI:HgZ7fVZ8mBc:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=OxSmYoB4yLI:HgZ7fVZ8mBc:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=OxSmYoB4yLI:HgZ7fVZ8mBc:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=OxSmYoB4yLI:HgZ7fVZ8mBc:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/OxSmYoB4yLI" height="1" width="1"/>]]></content:encoded><description>You can feel the pace rising to a crescendo, you sense it coming. But don’t look now, RSA is just next week. The last two months have been pretty much a blur in getting ready for the big conference. As...</description><feedburner:origLink>http://www.ashimmy.com/2013/02/where-is-ashimmy-at-rsa.html</feedburner:origLink></item><item><title>Illuminating the Dark Matter of your network with iScan Onlines Opportunistic Scanning</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/O59gEqH-rBU/illuminating-the-dark-matter-of-your-network-with-iscan-onlines-opportunistic-scanning.html</link><category>cloud</category><category>cloud security</category><category>Current Affairs</category><category>friends</category><category>General Security</category><category>marketing</category><category>McAfee</category><category>other security companies</category><category>patching</category><category>SaaS</category><category>Security Consulting</category><category>Security Incite</category><category>the security industry</category><category>VAM</category><category>vulnerability management</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Tue, 12 Feb 2013 05:19:45 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017ee8737132970d</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p><a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017c36d0778b970b-pi"><img title="iscan-logo" style="border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; float: right; padding-top: 0px; padding-left: 0px; margin: 2px 0px 5px 6px; display: inline; padding-right: 0px; border-top-width: 0px" border="0" alt="iscan-logo" align="right" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017c36d07792970b-pi" width="240" height="76"></img></a>I have written recently about two friends of mine from the security industry, Carl Banzhof and Billy Austin and a company they started called <a href="http://www.iscanonline.com">iScan Online</a>.  Carl and Billy first told me what they were thinking about last spring or so. Over the next months they kept me in the loop as they continued to develop. Over the summer they showed me early versions of a new kind of security scanner they had developed. They started offering free scans in the fall and today they <a href="https://www.iscanonline.com/downloads/iScanPress021213.pdf">officially launched iScan Online</a>.</p>  <p>I have been very impressed with what Carl and Billy are doing. So impressed in fact that I have been helping them with the launch activities and consulting with them over the last few weeks.  I really like what they are doing and the space they play in.  Utilizing the cloud for a SaaS based security scanner, they actually do internal scanning on any device, anytime, anywhere. The internal scan is done on the endpoint itself, so no hardware or virtual appliance necessary, no complicated software. Fast and accurate, it is a great security tool for a BYOD world. They call it Opportunistic Scanning.</p>  <p>The company has written a white paper that I really like and even helped with, that explains what they do. It talks about the dark matter of your network.  What is the dark matter of your network?  Well like the dark matter of our universe, it makes up a large percentage of the mass of your network. These dark devices access your network, but are largely invisible to your current vulnerability management solutions. They are not always on, are not in your office regularly and are not static desktops, servers or infrastructure. Nevertheless they represent a significant risk to your security.  Using iScan Online you can gain visibility to this dark matter. You can download the white paper (without the usual “give me your contact info”) right now from the web site <a href="http://iscanonline.com/downloads/Dark%20Matter_iScan%20Online_Final.pdf">here</a>.</p>  <p>The scans are quick and easy delivered via a web browser plug in, command line or API. They work on PCs and Macs, with mobile apps coming very soon.  The scans themselves are done on the endpoints so thousands of scans can be done at once. iScan Online can scan for traditional vulnerability scans, compliance scans (PCI, HIPAA) and data scans (PAN, PII).  You get instant reports per device and there is a cloud based portal for organization wide reporting that is pretty sophisticated.  You can get a free scan right now so you can see for yourself what it is does and how it works. Go check it out.</p>  <p>Carl and Billy have a lot of experience in this area. Both guys worked at Citadel Security, makers of the Hercules Patch management solution. Carl was the CTO there. Billy went on to be the CSO at SAINT, a vulnerability management company. After the sale of Citadel to McAfee, Carl was a VP over there continuing to work on endpoint security.  Both Carl and Billy are really passionate about what they are doing. iScan Online has already attracted seed investment from a strategic investor and will be expanding in the near future with more capabilities, as well as sales and marketing activities.</p>  <p>I really do like what they have done and how they are doing it. I think this represents a “next gen” approach to vulnerability management, just when we need one. BYOD, mobile and remote workers and offices have left a gap in our vulnerability management coverage, iScan Online’s opportunistic scanning is a great solution to fill that gap. I am looking forward to seeing how the market responds and am happy to be helping them.</p>  <p>Also many thanks to Mike Rothman of Securosis for allowing iScan Online to put a quote from the Securosis <a href="https://securosis.com/research/publication/vulnerability-management-evolution-from-tactical-scanner-to-strategic-platf">Evolution of Vulnerability Management</a> research in the release. What Mike wrote is dead on to the issues that iScan Online solves.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=O59gEqH-rBU:q1_i74toFvY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=O59gEqH-rBU:q1_i74toFvY:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=O59gEqH-rBU:q1_i74toFvY:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=O59gEqH-rBU:q1_i74toFvY:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=O59gEqH-rBU:q1_i74toFvY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=O59gEqH-rBU:q1_i74toFvY:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=O59gEqH-rBU:q1_i74toFvY:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=O59gEqH-rBU:q1_i74toFvY:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/O59gEqH-rBU" height="1" width="1"/>]]></content:encoded><description>I have written recently about two friends of mine from the security industry, Carl Banzhof and Billy Austin and a company they started called iScan Online. Carl and Billy first told me what they were thinking about last spring or...</description><media:content url="http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~5/HiMp2-owivc/Dark%20Matter_iScan%20Online_Final.pdf" fileSize="567310" type="application/pdf" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>I have written recently about two friends of mine from the security industry, Carl Banzhof and Billy Austin and a company they started called iScan Online. Carl and Billy first told me what they were thinking about last spring or...</itunes:subtitle><itunes:author>Alan Shimel</itunes:author><itunes:summary>I have written recently about two friends of mine from the security industry, Carl Banzhof and Billy Austin and a company they started called iScan Online. Carl and Billy first told me what they were thinking about last spring or...</itunes:summary><itunes:keywords>security,network,security,infosec,IDS,IPS,Vulnerability,endpoint,security,NAC,software</itunes:keywords><feedburner:origLink>http://www.ashimmy.com/2013/02/illuminating-the-dark-matter-of-your-network-with-iscan-onlines-opportunistic-scanning.html</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~5/HiMp2-owivc/Dark%20Matter_iScan%20Online_Final.pdf" length="567310" type="application/pdf" /><feedburner:origEnclosureLink>http://iscanonline.com/downloads/Dark%20Matter_iScan%20Online_Final.pdf</feedburner:origEnclosureLink></item><item><title>Ich Ben Ein Bit9er</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/gJkKWfgMgxM/ich-ben-ein-bit9er.html</link><category>Current Affairs</category><category>the security industry</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Fri, 08 Feb 2013 15:42:28 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017ee85897d2970d</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<div xmlns="http://www.w3.org/1999/xhtml"><p><em>“Two thousand years ago the proudest boast was </em><a href="http://en.wikipedia.org/wiki/Civis_Romanus_sum"><em>civis Romanus sum</em></a><em> ["I am a Roman citizen"]. Today, in the world of freedom, the proudest boast is "Ich bin ein Berliner!"... All free men, wherever they may live, are citizens of Berlin, and, therefore, as a free man, I take pride in the words "Ich bin ein Berliner!" ~ President John F. Kennedy, Berlin, June 1963</em></p>
<p>I along with many of you were horrified when we read Bri<a href="http://krebsonsecurity.com/2013/02/security-firm-bit9-hacked-used-to-spread-malware/">an Krebs post today</a> about security firm Bit9 being the victim of a hacking that allowed malware into their customers software which was digitally signed by Bit9 themselves.  Shortly after Bit9 confirmed this with a <a href="https://blog.bit9.com/2013/02/08/bit9-and-our-customers-security/">blog post of their own</a> detailing what happened.</p>
<p><img align="right" alt="" height="78" src="http://cloudfront3.bostinno.com/wp-content/uploads/2011/04/Bit9_Logo.png" style="float: right; margin: 4px 0px 0px 5px; display: inline;" width="181"></img>As you have read it seems some Bit9 assets were not protected with Bit9 software itself, they were compromised and allowed the perps to do their evil deed.  As Jeremiah Grossman says in Brian’s article, obviously Bit9 was only the means to the ends in this attack. By using Bit9 as a conduit into their customers including some sensitive government networks and Fortune 100 customers, they were able to infiltrate and we don’t know what the full results of that are yet.  Nevertheless this is probably every security company’s worst nightmare.  When the security company becomes the risk, it is not a good thing.</p>
<p>Shortly thereafter I started seeing posts on my Facebook timeline of friends in the security business putting up memes with things like “Why the F*^k is my security vendor sending me digitally signed malware”?  But I am sure the Bit9 folks are asking themselves the same question. In fact as my friend Don Macvittie said in a comment on one of those memes, it is a bad day to be over there.  </p>
<p>How right Don is. It is a bad day to be at Big9.  I have friends who work at Bit9.  My heart goes out to them. This is not the first time a security company has been hacked. It happened to RSA not too long ago and it has happened before that.  Here is a news flash, it will happen again too.</p>
<p>In fact it can and does happen to any one of us.  We are all one step away. In fact as part of being in the security profession we are a high profile targets for hackers to make a statement.  I know this first hand from when I was hacked years ago. It really can be anyone of us.  There is no joy in security-ville about one of our own being subjected to this.</p>
<p>I am sure there will be sales people at competitors of Bit9 who will try to move on their customers by leading with this. I say a pox upon them.  Anyone who stoops to such tactics to make a sale are beneath the standards that should be acceptable.</p>
<p>The security industry has matured over the last few years. At least I hope so. At times like this we should close ranks as an industry.  We should say as John F. Kennedy said back in 1963.  On days like today we are all Bit9’ers.  That is the message that we should send as industry to the type of people who do this.  We stand together and are more committed then ever to stopping these criminals from doing what they do. On this day the security industry should stand and say “Ich bin ein Bit9er”</p></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=gJkKWfgMgxM:nWqhifhmTcA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=gJkKWfgMgxM:nWqhifhmTcA:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=gJkKWfgMgxM:nWqhifhmTcA:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=gJkKWfgMgxM:nWqhifhmTcA:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=gJkKWfgMgxM:nWqhifhmTcA:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=gJkKWfgMgxM:nWqhifhmTcA:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=gJkKWfgMgxM:nWqhifhmTcA:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=gJkKWfgMgxM:nWqhifhmTcA:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/gJkKWfgMgxM" height="1" width="1"/>]]></content:encoded><description>“Two thousand years ago the proudest boast was civis Romanus sum ["I am a Roman citizen"]. Today, in the world of freedom, the proudest boast is "Ich bin ein Berliner!"... All free men, wherever they may live, are citizens of...</description><feedburner:origLink>http://www.ashimmy.com/2013/02/ich-ben-ein-bit9er.html</feedburner:origLink></item><item><title>Tales from the PCI Crypt: Life outside the PCI Audit Zone</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/24vZoc6iKn0/tales-from-the-pci-crypt-life-outside-the-pci-audit-zone.html</link><category>compliance</category><category>pci</category><category>security tips</category><category>vulnerability management</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Thu, 07 Feb 2013 08:55:05 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017ee84e9c88970d</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p><a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017d40d9d32a970c-pi"><img title="pci crypt" style="border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; float: right; padding-top: 0px; padding-left: 0px; margin: 0px 0px 4px 4px; display: inline; padding-right: 0px; border-top-width: 0px" border="0" alt="pci crypt" align="right" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017c36ab4d10970b-pi" width="334" height="347"></img></a>My friend Billy Austin is a co-founder of a new company called <a href="http://www.iscanonline.com/">iScan Online</a>. They perform scans on endpoints of all types in what they call an opportunistic basis.  You can read all about them on their website and standby for some big news coming out from Billy, Carl Banzhof and team. </p>  <p>iScan Online is really great for the new PCI internal scanning requirements (11.2 of the DSS). But Billy made a great point in a recent <a href="http://iscanme.wordpress.com/2013/01/31/scanning-microsoft-outlook-exposes-cardholder-data-on-80-of-merchants/">blog post</a> he wrote.  Billy noted that by doing a data scan for PAN (personal account numbers) in an ungodly amount of instances they turned up credit card data in merchants email.  The typical scenario was a sales person (remote usually) or order taker who takes an order over the phone or in person and then “writes it up” for the processing department.  They send the order over via email (usually not encrypted) and of course a copy of the sent mail is stored on the senders machine.  Yikes!</p>  <p>Billy makes an excellent point. The person who receives this mail in most instances will enter the order into a PCI compliant terminal and network. They will probably even delete the email with the card data when they are done.  For all intents are purposes they are PCI compliant.  But what about that sales guy or gal who “lives outside the PCI Audit Zone”?  </p>  <p>Those folks are usually not scanned or subject to the higher PCI standards because on the surface they are isolated from the card processing infrastructure that a QSA looks at or that we normally think of in terms of PCI.</p>  <p>As Billy also points out, too many of us in the PCI world shrug our shoulders and give you the “sorry, outside the scope” face.  Billy calls BS on this and so do I. It is BS.  This is card data that is being floated around in regular email and is being stored on usually non-encrypted, mobile devices which could be easily lost or stolen.</p>  <p>If we are going to truly give a rats you know what about doing something about credit card data being stolen we need to be thinking about life outside the PCI Audit Zone. We need to be thinking about who in an organization comes into contact with card data. If they do, we need to make sure they are following PCI standards as well.  </p>  <p>It makes no sense guarding just the castle, when the valuables can be reached from an outhouse. We need to think about life outside the Audit Zone.</p>  <p>Good job Billy bringing this blind spot to our attention for another tale from the PCI Crypt. </p>  <div class="zemanta-related">   <h6 class="zemanta-related-title" style="font-size: 1em">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://www.prweb.com/releases/2012/12/prweb10226880.htm">Texas PCI-QSA Compliance Consultant Announces 12 Step PCI Remediation Action Plan for Businesses</a> (prweb.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.intechnology.co.uk/IntechnologyBlog/post/2012/04/12/PCI-Dont-end-up-paying-the-price-of-non-compliance.aspx">PCI: Don't end up paying the price of non-compliance</a> (intechnology.co.uk) </li>      <li class="zemanta-article-ul-li"><a href="http://www.prweb.com/releases/2013/2/prweb10393777.htm">G2 Web Services and Sysnet Global Solutions Announce the Launch of their PCI DSS Partnership</a> (prweb.com) </li>      <li class="zemanta-article-ul-li"><a href="https://www.brandenwilliams.com/blog/2013/02/01/pci-releases-ecommerce-guidelines-read-this-first/">PCI Releases eCommerce Guidelines, READ THIS FIRST!</a> (brandenwilliams.com) </li>      <li class="zemanta-article-ul-li"><a href="http://bretthard.in/2013/01/the-pci-asv-process-sucks/">The PCI ASV Process Sucks</a> (bretthard.in)</li>      <li class="zemanta-article-ul-li"><a href="http://blog.solutionary.com/blog/bid/92497/PCI-Compliance-Avoid-the-PCI-Krampus">PCI Compliance - Avoid the PCI Krampus!</a> (solutionary.com)</li>   </ul> </div>  <div class="zemanta-pixie" style="height: 15px; margin-top: 10px"><a title="Enhanced by Zemanta" class="zemanta-pixie-a" href="http://www.zemanta.com/?px"><img class="zemanta-pixie-img" style="border-top-style: none; border-left-style: none; border-bottom-style: none; float: right; border-right-style: none" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=640ab40b-28c7-4d9f-94ab-1b0b9af1f1cf"></img></a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=24vZoc6iKn0:NOC60aKGgV4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=24vZoc6iKn0:NOC60aKGgV4:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=24vZoc6iKn0:NOC60aKGgV4:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=24vZoc6iKn0:NOC60aKGgV4:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=24vZoc6iKn0:NOC60aKGgV4:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=24vZoc6iKn0:NOC60aKGgV4:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=24vZoc6iKn0:NOC60aKGgV4:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=24vZoc6iKn0:NOC60aKGgV4:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/24vZoc6iKn0" height="1" width="1"/>]]></content:encoded><description>My friend Billy Austin is a co-founder of a new company called iScan Online. They perform scans on endpoints of all types in what they call an opportunistic basis. You can read all about them on their website and standby...</description><feedburner:origLink>http://www.ashimmy.com/2013/02/tales-from-the-pci-crypt-life-outside-the-pci-audit-zone.html</feedburner:origLink></item><item><title>Security Blogger Awards Finalist Voting Is Now Open!</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/UaNBzN758y4/security-blogger-awards-finalist-voting-is-now-open.html</link><category>awards and PR</category><category>Chris Hoff</category><category>RSA</category><category>security bloggers network</category><category>the security industry</category><category>Weblogs</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Mon, 28 Jan 2013 09:48:24 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017d408597b7970c</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p><a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017d408597a8970c-pi"><img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: right; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="social security bloggers awards 13" border="0" alt="social security bloggers awards 13" align="right" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2017ee7fa03c7970d-pi" width="345" height="213"></img></a>Well finally I am happy to report that the finalists have been selected and voting for the 5th annual Social Security Blogger Awards is now open!. I know many of you did not understand and were confused by the preliminary rounds of voting. However, our new method of picking finalists has resulted in what we think is our strongest group of finalists ever. </p>  <p>We have many of the blogs and podcasts that have been nominated before (quality is quality), but we also have many new or never before nominated sites as well.  Many thanks to our all star panel of judges who nominated some of the finalists – Bill Brenner of CSO, Kelly Jackson-Higgins of Dark Reading, Wendy Nather of The 451 Group and none other than Beaker himself, Chris Hoff.</p>  <p>Also many thanks to all of the blogs and podcasts who requested to be nominated. Whether you made the finals or not, keep blogging.</p>  <p>You can go vote for your picks <a href="https://s.zoomerang.com/s/SBNFinalVotes">here</a>. As in years past, to vote in the finals you have to be a security blogger or podcaster yourself.  All votes are reviewed by humans, so please just vote once and don’t try to game the system.</p>  <p>Special thanks to Trainer Communications for all of the help with voting and helping. Also special thanks to sponsors of the Bloggers Meetup – Qualys, Fortinet, Sourcefire, Akamai, Barracuda Networks and RSA Conference.</p>  <p>Here are the finalists.  Good luck to them all!  Of course winners will be announced at the Bloggers Meet up at RSA Conference 2013.</p>  <p><strong><font size="3">Best Corporate Security Blog</font></strong> </p>  <p><img alt="" src="https://s.zoomerang.com/i/t.gif"></img><strong>McAfee Blog: </strong><a href="http://blogs.mcafee.com/category/mcafee-labs">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>CloudFlare Blog: </strong><a href="http://blog.cloudflare.com/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>SecureWorks Blog: </strong><a href="http://www.secureworks.com/media/blog/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Solutionary Minds Blog: </strong><a href="http://blog.solutionary.com/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Kaspersky Lab Securelist Blog: </strong><a href="http://www.securelist.com/en/blog">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Veracode Blog: </strong><a href="http://www.veracode.com/blog/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Trend Micro Blog: </strong><a href="http://blog.trendmicro.com/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Naked Security Blog: </strong><a href="http://nakedsecurity.sophos.com/">click here</a> </p>  <p><font size="3"><strong>Best Security Podcast</strong></font> </p>  <p><img alt="" src="https://s.zoomerang.com/i/t.gif"></img><strong>Liquidmatrix Security Digest: </strong><a href="http://liquidmatrix.libsyn.com/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>EuroTrashSecurity: </strong><a href="http://www.eurotrashsecurity.eu/index.php/Main_Page">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Paul Dotcom: </strong><a href="http://www.pauldotcom.com/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>SANS Internet Storm Center: </strong><a href="https://isc.sans.edu/podcast.html">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Southern Fried Security: </strong><a href="http://www.southernfriedsecurity.com/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Risky Business: </strong><a href="http://risky.biz/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Sophos Security Chet Chat: </strong><a href="http://www.sophos.com/en-us/security-news-trends/podcasts.aspx">click here</a> </p>  <p><font size="3"><strong>The Most Educational Security Blog</strong></font> </p>  <p><img alt="" src="https://s.zoomerang.com/i/t.gif"></img><strong>BH Consulting's Security Watch Blog: </strong><a href="http://bhconsulting.ie/securitywatch/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Security Uncorked Blog: </strong><a href="http://securityuncorked.com/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Dr. Kees Leune's Blog: </strong><a href="http://blog.leune.org/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Securosis Blog: </strong><a href="https://securosis.com/blog">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Social-Engineer.org Blog: </strong><a href="http://www.social-engineer.org/blog/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Critical Watch Blog: </strong><a href="http://blog.criticalwatch.com/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>The Security Skeptic Blog: </strong><a href="http://securityskeptic.typepad.com/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Krebs On Security: </strong><a href="http://krebsonsecurity.com/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>The New School of Information Security Blog: </strong><a href="http://newschoolsecurity.com/">click here</a> </p>  <p><strong><font size="3">The Most Entertaining Security Blog</font></strong> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Packet Pushers Blog: </strong><a href="http://packetpushers.net/author/securityprincess/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>J4VV4D's Blog: </strong><a href="http://www.j4vv4d.com/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Securosis Blog: </strong><a href="https://securosis.com/blog">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Errata Security Blog: </strong><a href="http://erratasec.blogspot.com/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Naked Security Blog: </strong><a href="http://nakedsecurity.sophos.com/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Uncommon Sense Security Blog: </strong><a href="http://blog.uncommonsensesecurity.com/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>PSilvas Blog: </strong><a href="http://psilvas.wordpress.com/">click here</a> </p>  <p><font size="3"><strong>The Blog That Best Represents The Security Industry</strong></font> </p>  <p><strong>SpiderLabs Anterior Blog: </strong><a href="http://blog.spiderlabs.com/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Krebs On Security Blog: </strong><a href="http://krebsonsecurity.com/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>1 Raindrop Blog: </strong><a href="http://1raindrop.typepad.com/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Naked Security Blog: </strong><a href="http://nakedsecurity.sophos.com/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>The Firewall (Forbes) Blog: </strong><a href="http://blogs.forbes.com/firewall/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Threat Level (Wired) Blog: </strong><a href="http://www.wired.com/threatlevel/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Securosis Blog: </strong><a href="https://securosis.com/blog">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Michael Peters Blog: </strong><a href="http://michaelpeters.org/">click here</a> </p>  <p><strong><font size="3">The Single Best Blog Post or Podcast Of The Year</font></strong> </p>  <p><strong>The Epic Hacking of Mat Honan and Our Identity Challenge: </strong><a href="http://www.identropy.com/blog/bid/88264/The-Epic-Hacking-of-Mat-Honan-and-Our-Identity-Challenge">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Application Security Debt and Application Interest Rates: </strong><a href="http://www.veracode.com/blog/2011/02/application-security-debt-and-application-interest-rates/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Why XSS is serious business (and why Tesco needs to pay attention): </strong><a href="http://www.troyhunt.com/2012/08/why-xss-is-serious-business-and-why.html">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Meet The Hackers Who Sell Spies The Tools To Crack Your PC (And Get Paid Six-Figure Fees): </strong><a href="http://www.forbes.com/sites/andygreenberg/2012/03/21/meet-the-hackers-who-sell-spies-the-tools-to-crack-your-pc-and-get-paid-six-figure-fees/">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Levelling up in the real world: </strong><a href="http://idoneous-security.blogspot.com/2012/12/levelling-up-in-real-world.html">click here</a> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Secure Business Growth, Corporate Responsibility with Ben Tomhave: </strong><a href="https://www.brandenwilliams.com/blog/2012/01/19/corporate-responsibility-with-ben-tomhave/">click here</a> </p>  <p><strong><font size="3">The Security Bloggers Hall Of Fame</font></strong> </p>  <p><strong>Jack Daniel</strong> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Richard Bejtlich</strong> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Gunnar Peterson</strong> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Naked Security Blog</strong> </p>  <p><strong><img alt="" src="https://s.zoomerang.com/i/t.gif"></img>Wendy Nather</strong> </p>  <div class="zemanta-related">   <h6 style="font-size: 1em" class="zemanta-related-title">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://365.rsaconference.com/blogs/security-blogger-meetup/2012/01/06/and-the-nominees-are">And The Nominees Are . . .</a> (365.rsaconference.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.ashimmy.com/2012/12/social-security-blogger-awards-2013-judges-announced.html">Social Security Blogger Awards 2013 Judges Announced</a> (ashimmy.com) </li>   </ul> </div>  <div style="margin-top: 10px; height: 15px" class="zemanta-pixie"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/?px"><img style="border-bottom-style: none; border-left-style: none; border-top-style: none; float: right; border-right-style: none" class="zemanta-pixie-img" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=73502147-0874-4543-bb85-be7392a11e77"></img></a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=UaNBzN758y4:NwoLIZaZMWA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=UaNBzN758y4:NwoLIZaZMWA:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=UaNBzN758y4:NwoLIZaZMWA:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=UaNBzN758y4:NwoLIZaZMWA:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=UaNBzN758y4:NwoLIZaZMWA:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=UaNBzN758y4:NwoLIZaZMWA:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=UaNBzN758y4:NwoLIZaZMWA:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=UaNBzN758y4:NwoLIZaZMWA:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/UaNBzN758y4" height="1" width="1"/>]]></content:encoded><description>Well finally I am happy to report that the finalists have been selected and voting for the 5th annual Social Security Blogger Awards is now open!. I know many of you did not understand and were confused by the preliminary...</description><feedburner:origLink>http://www.ashimmy.com/2013/01/security-blogger-awards-finalist-voting-is-now-open.html</feedburner:origLink></item><item><title>HIPAA Fines for Smaller Breaches Spells Trouble for Midmarket Healthcare</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/F4EhXl9SIGI/hipaa-fines-for-smaller-breaches-spells-trouble-for-midmarket-healthcare.html</link><category>compliance</category><category>IBM</category><category>Midmarket</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Fri, 25 Jan 2013 14:01:58 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2017c364257cf970b</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<div xmlns="http://www.w3.org/1999/xhtml"><p>A smaller <a href="http://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/honi-agreement.pdf">hospice
in Northern Idaho was fined Fifty Thousand Dollars by the Department of Health
and Human Services</a> (HHS) for a breach that involved the loss of just a few
hundred patient records.  This marks the
first time that a breach of fewer than 500 medical records drew a fine from
HHS. This could be a message that smaller health care providers are now
squarely in the sights of the HIPAA enforcement authorities.</p>
<p>The Hospice of Northern Idaho was the victim of the data
breach when an unencrypted laptop containing patient’s personally identifiable
information (PII) was stolen from a workers car. Though the thief was
apprehended, the laptop was never recovered. Luckily, it seems none of the
sensitive information was used for any type of fraud or theft.</p>
<p>The Hospice itself only has about 100 employees and an equal
amount of volunteers; it claims to serve thousands in its community. The bigger
picture though is that this could have been any midsize or smaller health care
provider. The Hospice is a non-profit and the 50k fine will cut deep. Think
about what a 50k fine would do to any midmarket business.  HIPAA is not just for large health care
providers anymore.</p>
<p>One of the factors at play here is the fact that the stolen
laptop data was not encrypted. HIPAA regulations call for the encryption of all
PII. Many speculate that the reason the HHS came down hard on the hospice is
not that the laptop was stolen, but that the data was not encrypted.</p>
<p>There are many options to encrypt your data and disks today.
On Windows laptops, Microsoft themselves offer a disk encryption tool. There
are free, open source encryption tools like <a href="https://www.google.com/url?sa=t&amp;rct=j&amp;q=&amp;esrc=s&amp;source=web&amp;cd=1&amp;cad=rja&amp;sqi=2&amp;ved=0CDEQFjAA&amp;url=http%3A%2F%2Fwww.truecrypt.org%2F&amp;ei=oWMBUcK0HofxigKZ04GQAQ&amp;usg=AFQjCNH8UXHuTTPFsxxhk9LfQtfx7CG5Pg&amp;bvm=bv.41248874,bs.1,d.eWU">TrueCrypt</a>,
that can also do the job without costing anything for the software.  If the data had been encrypted, the PII would
have been useless even if the laptop was stolen. </p>
<p>Encryption regulations are not just for health care
providers and HIPAA. Other regulations like PCI DSS also call for the
encryption of confidential data. Whether you keep this data only on servers or
on laptops and other endpoints (phones and tablets offer data encryption
options as well), you need to be encrypting confidential data.</p>
<p>The number of records lost here were not many, it should
serve as a wakeup call that this kind of thing can happen to any organization.
Don’t be the next example by HHS or the PCI Council, take the time to encrypt
your confidential data today.</p>
<p><a href="http://goo.gl/S6P7m"><img align="left" alt="IBM" border="0" height="97" src="http://www.ashimmy.com/.a/6a00d83451e4d369e201630255b2b7970d-pi" title="IBM" width="240"></img></a>This post was written as part of the <a href="http://goo.gl/S6P7m">IBM for Midsize Business</a> program, which provides midsize businesses with the tools, expertise and solutions they need to become engines of a smarter planet.</p>
<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles</legend>
<div class="zemanta-article-ul zemanta-article-ul-image" style="margin: 0; padding: 0; overflow: hidden;">
<div class="zemanta-article-ul-li-image zemanta-article-ul-li" style="padding: 0; background: none; list-style: none; display: block; float: left; vertical-align: top; text-align: left; width: 84px; font-size: 11px; margin: 2px 10px 10px 2px;"><a href="http://www.ashimmy.com/2013/01/security-education-because-the-weakest-link-in-the-chain-still-sits-behind-the-keyboard.html" style="box-shadow: 0px 0px 4px #999; padding: 2px; display: block; border-radius: 2px; text-decoration: none;" target="_blank"><img alt="" src="http://i.zemanta.com/138288325_80_80.jpg" style="padding: 0; margin: 0; border: 0; display: block; width: 80px; max-width: 100%;"></img></a><a href="http://www.ashimmy.com/2013/01/security-education-because-the-weakest-link-in-the-chain-still-sits-behind-the-keyboard.html" style="display: block; overflow: hidden; text-decoration: none; line-height: 12pt; height: 80px; padding: 5px 2px 0 2px;" target="_blank">Security Education Because the Weakest Link in the Chain Still Sits Behind the Keyboard</a></div>
<div class="zemanta-article-ul-li-image zemanta-article-ul-li" style="padding: 0; background: none; list-style: none; display: block; float: left; vertical-align: top; text-align: left; width: 84px; font-size: 11px; margin: 2px 10px 10px 2px;"><a href="http://www.prweb.com/releases/2013/1/prweb10316103.htm" style="box-shadow: 0px 0px 4px #999; padding: 2px; display: block; border-radius: 2px; text-decoration: none;" target="_blank"><img alt="" src="http://i.zemanta.com/138226389_80_80.jpg" style="padding: 0; margin: 0; border: 0; display: block; width: 80px; max-width: 100%;"></img></a><a href="http://www.prweb.com/releases/2013/1/prweb10316103.htm" style="display: block; overflow: hidden; text-decoration: none; line-height: 12pt; height: 80px; padding: 5px 2px 0 2px;" target="_blank">What is HIPAA compliant Email? Health BI Reveals the Facts about HIPAA...</a></div>
<div class="zemanta-article-ul-li-image zemanta-article-ul-li" style="padding: 0; background: none; list-style: none; display: block; float: left; vertical-align: top; text-align: left; width: 84px; font-size: 11px; margin: 2px 10px 10px 2px;"><a href="http://ducknetweb.blogspot.com/2013/01/new-hipaa-omnibus-rules-certainly.html" style="box-shadow: 0px 0px 4px #999; padding: 2px; display: block; border-radius: 2px; text-decoration: none;" target="_blank"><img alt="" src="http://i.zemanta.com/139192579_80_80.jpg" style="padding: 0; margin: 0; border: 0; display: block; width: 80px; max-width: 100%;"></img></a><a href="http://ducknetweb.blogspot.com/2013/01/new-hipaa-omnibus-rules-certainly.html" style="display: block; overflow: hidden; text-decoration: none; line-height: 12pt; height: 80px; padding: 5px 2px 0 2px;" target="_blank">New HIPAA Omnibus Rules Certainly Encourage the Use of a Personal Health Record for Patients With Getting Copies of Their Medical Records</a></div>
<div class="zemanta-article-ul-li-image zemanta-article-ul-li" style="padding: 0; background: none; list-style: none; display: block; float: left; vertical-align: top; text-align: left; width: 84px; font-size: 11px; margin: 2px 10px 10px 2px;"><a href="http://www.pcworld.com/article/2025462/how-to-encrypt-almost-anything.html" style="box-shadow: 0px 0px 4px #999; padding: 2px; display: block; border-radius: 2px; text-decoration: none;" target="_blank"><img alt="" src="http://i.zemanta.com/139039073_80_80.jpg" style="padding: 0; margin: 0; border: 0; display: block; width: 80px; max-width: 100%;"></img></a><a href="http://www.pcworld.com/article/2025462/how-to-encrypt-almost-anything.html" style="display: block; overflow: hidden; text-decoration: none; line-height: 12pt; height: 80px; padding: 5px 2px 0 2px;" target="_blank">How to encrypt (almost) anything</a></div>
<div class="zemanta-article-ul-li-image zemanta-article-ul-li" style="padding: 0; background: none; list-style: none; display: block; float: left; vertical-align: top; text-align: left; width: 84px; font-size: 11px; margin: 2px 10px 10px 2px;"><a href="http://www.securitymanagement.com/news/idaho-non-profit-agrees-pay-50000-hipaa-violation-0011498" style="box-shadow: 0px 0px 4px #999; padding: 2px; display: block; border-radius: 2px; text-decoration: none;" target="_blank"><img alt="" src="http://i.zemanta.com/135664552_80_80.jpg" style="padding: 0; margin: 0; border: 0; display: block; width: 80px; max-width: 100%;"></img></a><a href="http://www.securitymanagement.com/news/idaho-non-profit-agrees-pay-50000-hipaa-violation-0011498" style="display: block; overflow: hidden; text-decoration: none; line-height: 12pt; height: 80px; padding: 5px 2px 0 2px;" target="_blank">Idaho Non-Profit Agrees to Pay $50,000 for HIPAA Violation</a></div>
<div class="zemanta-article-ul-li-image zemanta-article-ul-li" style="padding: 0; background: none; list-style: none; display: block; float: left; vertical-align: top; text-align: left; width: 84px; font-size: 11px; margin: 2px 10px 10px 2px;"><a href="http://markcathey.wordpress.com/2013/01/07/idaho-hospice-to-pay-50000-for-hipaa-violation-for-data-breach/" style="box-shadow: 0px 0px 4px #999; padding: 2px; display: block; border-radius: 2px; text-decoration: none;" target="_blank"><img alt="" src="http://i.zemanta.com/136539554_80_80.jpg" style="padding: 0; margin: 0; border: 0; display: block; width: 80px; max-width: 100%;"></img></a><a href="http://markcathey.wordpress.com/2013/01/07/idaho-hospice-to-pay-50000-for-hipaa-violation-for-data-breach/" style="display: block; overflow: hidden; text-decoration: none; line-height: 12pt; height: 80px; padding: 5px 2px 0 2px;" target="_blank">Idaho Hospice to Pay $50,000 for HIPAA Violation for Data Breach</a></div>
</div>
</fieldset></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=F4EhXl9SIGI:6OmTo412npU:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=F4EhXl9SIGI:6OmTo412npU:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=F4EhXl9SIGI:6OmTo412npU:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=F4EhXl9SIGI:6OmTo412npU:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=F4EhXl9SIGI:6OmTo412npU:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=F4EhXl9SIGI:6OmTo412npU:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=F4EhXl9SIGI:6OmTo412npU:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=F4EhXl9SIGI:6OmTo412npU:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/F4EhXl9SIGI" height="1" width="1"/>]]></content:encoded><description>A smaller hospice in Northern Idaho was fined Fifty Thousand Dollars by the Department of Health and Human Services (HHS) for a breach that involved the loss of just a few hundred patient records. This marks the first time that...</description><media:content url="http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~5/OM9Z0vmk4OY/honi-agreement.pdf" fileSize="96287" type="application/pdf; charset=UTF-8" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>A smaller hospice in Northern Idaho was fined Fifty Thousand Dollars by the Department of Health and Human Services (HHS) for a breach that involved the loss of just a few hundred patient records. This marks the first time that...</itunes:subtitle><itunes:author>Alan Shimel</itunes:author><itunes:summary>A smaller hospice in Northern Idaho was fined Fifty Thousand Dollars by the Department of Health and Human Services (HHS) for a breach that involved the loss of just a few hundred patient records. This marks the first time that...</itunes:summary><itunes:keywords>security,network,security,infosec,IDS,IPS,Vulnerability,endpoint,security,NAC,software</itunes:keywords><feedburner:origLink>http://www.ashimmy.com/2013/01/hipaa-fines-for-smaller-breaches-spells-trouble-for-midmarket-healthcare.html</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~5/OM9Z0vmk4OY/honi-agreement.pdf" length="96287" type="application/pdf; charset=UTF-8" /><feedburner:origEnclosureLink>http://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/honi-agreement.pdf</feedburner:origEnclosureLink></item><copyright>copyright 2010 all rights reserved</copyright><media:credit role="author">Alan Shimel</media:credit><media:rating>nonadult</media:rating></channel></rss>
