Thursday, July 30, 2009
Critical Update for Adobe Flash Player
Brian Krebs, Washington Post: http://voices.washingtonpost.com/securityfix/2009/07/critical_update_for_adobe_flas.html
Friday, July 24, 2009
Forty-Four Percent of US SMBs Admit to Falling Victim to Cybercrime, According to Latest Panda Security Survey
29 percent of US small and medium-sized businesses lack antispam, 22 percent have no antispyware and 16 percent operate without a firewall - 50 percent lost time or productivity as a result of being infected - 39 percent of respondents said either they or their employees have not received training about IT threats that could affect them. http://finance.yahoo.com/news/FortyFour-Percent-of-US-SMBs-prnews-2714742551.html?x=0&.v=1
Wednesday, July 22, 2009
Social Networking Sites Must Improve Their Security, Says Security Firm
IT security and data protection firm Sophos has called upon social networking websites such as Twitter and Facebook to do more to protect their millions of users, as new research is published examining the first six months of cybercrime in 2009.http://finance.yahoo.com/news/Web-20-Woe-Sophos-Threat-bw-957043460.html?x=0&.v=1
Monday, July 13, 2009
What CEOs Don't Know About Cybersecurity: A new study hints at how often cyberthreats aren't communicated to the boss.
Forbes Magazine: Being the chief executive has its privileges. And one of them may be a blissful ignorance of your company's data breach risks.
According to a study to be released Tuesday by the privacy-focused Ponemon Institute, companies' chief executives tend to value cybersecurity just as--if not more--highly than their executive colleagues. But ... the CEOs interviewed in Ponemon's survey seemed especially unconcerned about cybercrime as a source of data breaches. While 31% named stolen PCs or thumb drives as a source of data loss, only 3% cited malicious hackers as the top threat for their company's data security--about a fifth as many as the lower level employees who cited cybercriminals as the most important threat.
http://www.forbes.com/2009/07/13/poneman-cybersecurity-breaches-technology-security-poneman.html?partner=alerts
According to a study to be released Tuesday by the privacy-focused Ponemon Institute, companies' chief executives tend to value cybersecurity just as--if not more--highly than their executive colleagues. But ... the CEOs interviewed in Ponemon's survey seemed especially unconcerned about cybercrime as a source of data breaches. While 31% named stolen PCs or thumb drives as a source of data loss, only 3% cited malicious hackers as the top threat for their company's data security--about a fifth as many as the lower level employees who cited cybercriminals as the most important threat.
http://www.forbes.com/2009/07/13/poneman-cybersecurity-breaches-technology-security-poneman.html?partner=alerts
Thursday, July 9, 2009
Taking On Small-Business Identity Theft
Business Week: It's a big problem that companies are loath to discuss. But California's amended identity theft laws show that offering protections to smaller companies on par with those for individuals helps tremendously.
http://www.businessweek.com/bwdaily/dnflash/content/jul2009/db2009079_858536.htm
http://www.businessweek.com/bwdaily/dnflash/content/jul2009/db2009079_858536.htm
Sunday, June 14, 2009
An Emerging Information Security Minimum Standard of Due Care
This Guide is a revised version of a paper that first appeared in 2005 in Information Security Management Handbook, Fifth Edition, Volume 2.
The paper examines the emerging body of law surrounding an enterprise’s responsibility for securing information, together with the emerging body of information security management principles and practices for doing so. Seven key information security management elements are identified which we believe constitute an information security minimum standard of due care. Enterprises failing to implement these seven management elements could face significant legal exposure should they suffer a security breach resulting in damage to a 3rd-party.
The paper applies explores the application to information security of appellate rulings in several negligence cases to the questions of Duty of Care and Breach of Duty: Kline v. 1500 Massachusetts Avenue Apartment Corp, United States v. Carroll Towing Co, Texas & P.R v Behymer, T. J. Hooper v. Northern Barge and People Express Airlines v. Consolidated Rail Corp.
http://www.citadel-information.com/
The paper examines the emerging body of law surrounding an enterprise’s responsibility for securing information, together with the emerging body of information security management principles and practices for doing so. Seven key information security management elements are identified which we believe constitute an information security minimum standard of due care. Enterprises failing to implement these seven management elements could face significant legal exposure should they suffer a security breach resulting in damage to a 3rd-party.
The paper applies explores the application to information security of appellate rulings in several negligence cases to the questions of Duty of Care and Breach of Duty: Kline v. 1500 Massachusetts Avenue Apartment Corp, United States v. Carroll Towing Co, Texas & P.R v Behymer, T. J. Hooper v. Northern Barge and People Express Airlines v. Consolidated Rail Corp.
http://www.citadel-information.com/
Wednesday, June 10, 2009
Information Security Standard of Due Care
A very short overview of emerging information security laws, regulations and practitioner standards. http://www.citadel-information.com.
Sunday, June 7, 2009
Citadel Guide: Eight Steps to Protecting Sensitive Middle-Market Data
A short overview of eight critical things management must do to defend against cyber-attack.
http://www.citadel-information.com/
http://www.citadel-information.com/
Saturday, June 6, 2009
Citadel Guide: Effectively Managing Information Security Risk
A guide for senior executives having responsibility for designing and implementing a cost-effective program program to secure critical information assets.
http://www.citadel-information.com/
http://www.citadel-information.com/
Friday, May 29, 2009
Tuesday, February 10, 2009
Average cost of a data breach in 2008 grew to $202 per record, Ponemon Study Says
DarkREADING: Data Breach Costs Rose Significantly In 2008, Ponemon Study Says. Companies report average loss of $6.6 million per breach, study says.
The average cost of a data breach in 2008 grew to $202 per record compromised, an increase of 2.5 percent since 2007 ($197 per record) and 11 percent compared to 2006 ($182 per record), according to the study. The average total cost per reporting company was more than $6.6 million per breach -- up from $6.3 million in 2007 and $4.7 million in 2006 -- and ranged from $613,000 to almost $32 million.
http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=213000466
The average cost of a data breach in 2008 grew to $202 per record compromised, an increase of 2.5 percent since 2007 ($197 per record) and 11 percent compared to 2006 ($182 per record), according to the study. The average total cost per reporting company was more than $6.6 million per breach -- up from $6.3 million in 2007 and $4.7 million in 2006 -- and ranged from $613,000 to almost $32 million.
http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=213000466
Subscribe to:
Posts (Atom)