• 09 Mar 2012

    My upcoming webcast on firewall management

    Join me and AlgoSec's Nimmy Reichenberg next week for a unique discussion on strategies for improving firewall management.We all know it's the elephant in the room...Today's enterprises have firewalls that are so complex and so fragile yet no one's really taking care of them. Any processes that do exist around rule management, rule changes and firewall risk analysis are often manual - and oh so painful.I know, I know, firewalls ...

    Continue Reading...
  • 01 Mar 2012

    My final takeaway from #RSAC

    I said my farewell to the RSA Conference Tuesday evening but had some final thoughts about the show that I wanted to share with you.In addition to the keynotes I talked about, I attended a mock trial session involving malware, a digital certificate acquired for ill-gotten gains, and a healthcare company that ignored all things HIPAA (heard that a million times!) as well as a session by HP's Jacob West ...

    Continue Reading...
  • 28 Feb 2012

    Video: #RSAC 2012 is off and running

    I'm live at the RSA Conference and here are my thoughts on the first two keynotes along with why you need to come to this show....

    Continue Reading...
  • 27 Feb 2012

    Live from #RSAC: Cloud computing’s got some kinks (but you knew that)

    I'm attending the RSA Conference this week and just sat through a panel discussion on cross-jurisdictional issues in the cloud. It was part of the Cloud Security Alliance Summit 2012.Here's what I heard: there are tons of considerations around the management, access and even the e-discovery personal data in the cloud...lots of variables and just as many things still up in the air. I'm convinced that being an information privacy ...

    Continue Reading...
  • 27 Feb 2012

    Video: Seeing the big picture in information security

    Little has been written about this in the context of information security but it's something you've go to consider in every decision you make:...

    Continue Reading...
  • 24 Feb 2012

    CDW-TechTarget seminars are back this year – join me in Atlanta soon

    Great news - I'll be speaking at the CDW-TechTarget roadshows again this year! Our first show kicks off in Atlanta on March 13th and then we start zig-zagging across the country every few weeks until late September. For most of the shows I'll be giving two presentations:Adapting Your Old-School Network Security Agenda to Today's New-School Security Challenges ...and:Ensuring Security Controls in an Anytime, Anywhere Access EnvironmentThere will also be vendor ...

    Continue Reading...
  • 19 Feb 2012

    Got compliance on your mind?

    I figured you did...it seems everyone does these days. However you look at compliance - be it a threat, a security enabler or just a pain in the rear-end - here are some new pieces I've written that may help:Our dangerous overdependence on IT auditingCompliance considerations when disposing old equipmentHow Windows Server 8 can help with complianceEnjoy!Be sure to check out www.principlelogic.com/resources.html for links to all of my information security ...

    Continue Reading...
  • 12 Feb 2012

    SQL injection cheatsheet & tips for getting management on board

    Here's a neat "cheatsheet" on SQL injection by NTObjectives that outlines some common attack strings, commands and so forth. Their SQL Invader SQL injection tool is worth checking out as well. If you're having trouble selling management on the dangers of SQL injection, check out this piece I wrote about it not long ago: SQL Injection – The Web Flaw That Keeps on Giving Ten Ways to Sell Security to ...

    Continue Reading...
  • 10 Feb 2012

    Video: The one infosec skill you need to be working on

    Develop and maintain this one skill and you'll position yourself to be a much more valuable information security professional:  ...

    Continue Reading...
  • 09 Feb 2012

    Video: My new whitepaper on advanced malware and how Damballa Failsafe fits in

    Introduction to the threat we're facing and my new whitepaper The Malware Threat Businesses are Ignoring and How Damballa Failsafe Fits In:  ...

    Continue Reading...