Tuesday, September 29, 2015

Gearing Up for National Cyber Security Awareness Month


Gear Up for National Security Awareness Month with VSS


The security world is gearing up this October to recognize National Cyber Security Awareness Month. For 12 years, the Department of Homeland Security has reached out to people, small and medium-sized business, corporations and younger generations to educate and bring awareness to safety issues surrounding technology and the ever-changing public sharing landscape.

Each week during National Cyber Security Awareness Month, particular topics focus on the most pressing cyber security issues faced today. Our blog posts during October will center around these important messages:

Week 1: General Cyber Security Awareness
With the meteoric rise of major hacks and data thefts, ignorance is no longer a valid defense for organizations. No longer just an IT problem, a strong cyber security plan starts with education and company-wide awareness.

Week 2: Creating a Culture of Cyber Security at Work
The creation of a successful culture of cyber security starts with executive level communication. Along with awareness and situational training, employees should have a support system and escalation process in place to channel any issues to security teams for analysis. A defined, concise security protocol ensures protection at all levels of your organization.

Week 3: Connected Communities: Stay Protected While Always Connected
Today’s social landscape open doors to a wealth of personal information available to anyone with a computer or mobile device. Understanding security measures and controls available within communities reduces the threat of oversharing online. IT and Information Security staff should look to engage local security user groups and network.  Growing a local network provides an additional layer of support and education.

Week 4: Your Evolving Digital Life
As new technology is developed and integrated into our lives, we must continue to demand transparency in data use to ensure ongoing ease of use and control of information.

Week 5: Building the Next Generation of Cyber Professionals
A worldwide shortage of experienced security professionals coupled with the growing demand in the cyber and information security field has led to educators to push for training beginning in elementary or high school. As the field evolves, organizations will need the support of both technical and non-technical candidates.


_______________________________________________________________
VSS helps organizations to reduce their risk exposure across all areas of the enterprise including its people, data, applications, network and servers. By having skills that cover the entire organization, VSS can integrate the best security products and practices to provide clients with an enterprise-wide solution. 
Learn more here.




Wednesday, September 23, 2015

Business Continuity: The Unsung Hero of Security Intelligence





Security breaches continue to climb in frequency and cost, encompassing all industries and raising important personal data privacy concerns. The growing awareness of identity theft and consumers’ concerns about the security of their personal data following a breach contributes to the high cost and lost business that follows. For business continuity, lost business has potentially the most severe financial consequences and has steadily increased over the past three years. As the financial impact of a data breach rises, what some leaders once viewed as a pure technology issue is today seen as a larger business risk.

How Can Organizations Reduce the Risk and Costs of Data Breaches? 

One answer takes a different point of view security professionals may not have considered in the past: aligning security and business continuity for incident response.

Too often, business continuity and disaster recovery stand outside the security function within an organization, with minimal touch points between the teams to ensure the most effective security management for the company. In today’s threat landscape, that needs to change. Organizations that involve their business continuity management personnel in the data breach incident response process experience lower costs and faster recovery times.

Weather the Digital Storm of Attacks. 


Chief Information Security Officers (CISOs) should take advantage of the expertise of and synergy between teams that address both security threats and continuity threats. Business continuity has always aimed to mitigate the impact of business disruptions, including the loss of IT. Security can harness this capability to bolster response planning.

Threats to IT continuity and resilience, whether naturally occurring (as in a flood or hurricane) or intentionally created (as in a distributed denial-of-service attack) disrupt the organization’s ability to function. Secure, continuous availability is a common objective for both security and continuity professionals regardless of the business disruption’s root cause. Professionals on both sides can no longer afford to remain casual in their efforts to involve business continuity and disaster recovery planning in the security response. 

CISOs need to aggressively leverage these teams in their arsenal of weapons to weather the digital storm of attacks. The Business Continuity Institute also noted that this management plays an important role in reducing the total cost of a data breach. According to the “2015 Cost of Data Breach Study: Global Analysis,” conducted by the Ponemon Institute, having business continuity management (BCM) involved in the remediation of the breach reduced the cost by an average of $7.10 per compromised record.

The study also showed that both time to identify and time to contain the data breach incident are substantially lower for organizations that involved BCM. Companies using BCM decreased the mean time to identify (MTTI) a data breach by 27 percent. Moreover, by leveraging BCM, an organization can decrease the mean time to contain (MTTC) the data breach by 41 percent.

In addition to cost and recovery time advantages, the analysis found organizations involving their BCM personnel in the data breach incident response process were 6.8 percent less likely to experience a material data breach involving 10,000 or more compromised records over a one-year period.

Business Continuity and the Cost of a Data Breach.


Aligning business continuity with security includes involvement in planning, budgeting, testing and event response. By doing this, companies can ensure collaboration through proactive teaming across organizations and establish cross-representation.

More importantly, by integrating BCM, security can take advantage of business continuity intelligence on what is most critical, harness strategies already in place for loss of IT and utilize existing BCM communication and crisis management processes for coordination of response for cyber events.

Friday, September 11, 2015

Hidden Warnings: A Look at Indicators of Compromise (IoC)



The check engine light tells you when one of your car’s systems has failed. Your
cellphone alerts you when the battery is low. Your home security system sounds an alarm if it detects an intruder. Your home computer displays a warning message when a device or piece of software malfunctions. From a design perspective, it seems simple: You understand what to look for and you design a monitoring control around it. But what if your task is to reliably detect intrusions within a network or operating system? What if you’re building a system to identify indicators of compromise (IoC)? That is not simple at all.

There’s Salt in My Coffee! Now What?
On the surface, you know something isn’t right. Complaints that customers are receiving virus notifications when viewing your company’s website have begun without warning. Some of your sensitive data has been leaked on Twitter accounts and made fully available to the public on Pastebin. Your executive staff receives strange emails that appear to be from your company’s CEO and are sent from the internal mail system requesting that a large amount of money be transferred to an account that is already 30 days late for payment. All these things should raise a red flag. Scenes like these are taking place daily on a wide array of enterprise networks. And they’re causing millions of dollars in damage to companies and governments worldwide, perpetrated by an even wider array of attacker groups, company insiders, state-sponsored consortia and cybercriminal organizations.

Reading Between the Lines: Building a Better Rat Trap With IoC
Let’s say you’re fairly sure that your network may have been compromised. What do you do? There’s a good chance your first response would be to panic. Yet over the last few years, analytic techniques and tools have been developed and made available to the public — some for free, and others for a price. Either way, they can assist with digging in and identifying an IoC on your network, allowing you to build detection capabilities to find the root cause of a specific attack type and prevent breaches from recurring.

__________________________________________________________________________________________
VSS helps organizations to reduce their risk exposure across all areas of the enterprise including its people, data, applications, network and servers. VSS works with best of breed technologies including IBM Security, IBM InfoSphere, CheckPoint, Ping Identity and cloud security partners. By having skills that cover the entire organization, VSS can integrate the best security products and practices to provide clients with an enterprise-wide solution. Learn more here.

The post Hidden Warnings: A Look at Indicators of Compromise (IoC) appeared first on Security Intelligence.

Author:  Dave McMillen

Wednesday, September 2, 2015

Video: IBM Security C-Suites Spotlight - Jamie Giroux, Maximus

"An ounce of prevention is worth a pound of cure:" This video series is dedicated to that exact idea applied to security, security breaches and today's evolving world of security threats. Let's not forget the power of prevention. Join us each week as we deliver a short video geared towards: Intelligence & Analytics, Fraud Detection, Risk Management, Forensics, Compliance and Data Security.

Jamie Giroux is the Vice President of Security Compliance and Audit at Maximus, a provider of managed healthcare, human services, and workforce management within the U.S., Canada, the UK, and Australia. Jamie’s main responsibility is to ensure that the proper security controls are in place at Maximus, and to validate that those programs are adequately protecting the company’s assets, data, and people.

In this C-Suite Spotlight interview, Jamie discusses the challenges for security at a large organization with a global presence, the ways in which security has changed over the past few years, and the areas he will be focused on in the next few years as security continues to evolve.





VSS helps organizations to reduce their risk exposure across all areas of the enterprise including its people, data, applications, network and servers. VSS works with best of breed technologies including IBM Security, IBM InfoSphere, CheckPoint, Ping Identity and cloud security partners. By having skills that cover the entire organization, VSS can integrate the best security products and practices to provide clients with an enterprise-wide solution. Learn more here.

ORIGINALLY
 POSTED ON April 27, 2015
Sourced From IBM's Security Intelligence  http://securityintelligence.com/

Thursday, August 20, 2015

Enterprise Organizations Face More Security Risks Than You Think.

Do you and your security team know all the different scenarios that can happen on any given day at an enterprise organization? To be sure you do, we have created an Infographic to help tell the story.

We know that most companies are on the path to a secure environment. Some organizations have a mature security presence and have enforced policies, while others are just beginning to budget for those first steps to protect organizational infrastructure and data. Here are 3 tips to get you started or keep you on track to reducing business risk.

1.     Taking the right measures.

In order to reduce company wide security risks, start with a focus on Data Security, Malware and Threats. Remember, while it is essential to implement the best security product for your environment, any product is useless without constant care and feeding, otherwise known as maintenance and monitoring.

2.     It’s how you respond that matters.

We all know that breaches are inevitable; it’s how you respond that makes the difference. Having an incident response plan in place that outlines how a breach will be addressed can save you precious time. When creating your plan, be sure to address the following processes:
  •      making an initial assessment
  •         communicating the incident
  •         containing the damage and risk
  •         identifying the type and severity of the compromise
  •        collecting evidence
  •        notifying external agencies if needed
  •        recovering systems
3.     Start making improvements.

One way to improve your data security process is to regularly run user activity reports for file shares and other unstructured data that threat actors may try to access. Better yet, have a system process created to send an alert to your SIEM (Security Information and Event Management) where a security team member can quickly respond within minutes of a violation.

Feel free to download What happens during an average day at Enterprise Organizations Infographic. If you would like a printed copy to hang in your office or common area, please send an email to marketing[at]thinkvss.com with your name and address.




VSS helps organizations to reduce their risk exposure across all areas of the enterprise including its people, data, applications, network and servers. VSS works with best of breed technologies including IBM Security, IBM InfoSphere, CheckPoint, Ping Identity and cloud security partners. By having skills that cover the entire organization, VSS can integrate the best security products and practices to provide clients with an enterprise-wide solution. Learn more here.