Here’s a good read from @arstechnica on the HBGary story. It’s a fascinating story in and of itself. But the oversights related to information security “best practices” is amazing.
What is it going to take to get people to focus on the basics? Seriously, folks…Forget about all the fancy hack attacks and complex exploits for now and fix the low-hanging fruit. It’s basic triage – stop the bleeding first. Focus on your highest payoff tasks and work your way down the list.
All things considered, by just focusing on the basics of information security controls and testing alone you can achieve top-notch security, relatively speaking, which is light years ahead of where most organizations are today.
“A business associate referred our company to Principle Logic when we were seeking a resource to perform vulnerability /penetration testing for our external and internal networks. We found Kevin Beaver to be professional, well informed, and easy to work with. His testing did not disrupt our networks, and his progress updates were timely.
His final report was very thorough and included security recommendations for our network environment. The executive leadership was so impressed with Kevin’s security expertise, they have extended their agreement to continue to perform periodic testing. We highly recommend Kevin Beaver and Principle Logic as a resource for network security testing.”