• 28 May 2010

    Where I’ve been + 2 important reading assignments

    Wow, I can't believe it's the end of May....the year's nearly halfway through and I feel like I should still be back in February! After experiencing some family health crises and deaths combined with the busiest year I've ever had with my business (not complaining there!), I've let my blog suffer. I never like to not post for so long but I work to stay true to what I preach ...

    Continue Reading...
  • 21 May 2010

    The compliance crutch mentality rides on

    I believe it was my colleague Kevin Bocek who once said: "Security done right will yield compliance for free. Compliance for compliance sake will always deliver more problems in the end."Why is it so many business leaders keep ignoring this reality?It's funny, I was just thinking about an article I co-authored for CSO Online with Charles Cresson Wood nearly a year ago entitled The Dangers of Over-Reliance on Compliance. Those ...

    Continue Reading...
  • 04 May 2010

    Aim high or aim low, it’s our choice to make

    I love what Michelangelo said:"The greater danger for most of us lies not in setting our aim too high and falling short, but in setting our aim too low and achieving our mark."...reminds me of how easy it is to fall into the trap of complacency and principle of "good enough" with information security....

    Continue Reading...
  • 03 May 2010

    Commercial WEP and WPA key recovery tools

    Ever find yourself needing a wireless network analyzer that's easy to use and doesn't cost an arm and a leg? Well, CommView for WiFi is a great option...It's a product I've talked about for years in both Hacking For Dummies and Hacking Wireless Networks For Dummies. A neat thing about CommView for WiFi are its relatively new WEP and WPA key recovery add-ons. Referred to as WEPKR and WPAKR, they're ...

    Continue Reading...
  • 30 Apr 2010

    Security strategies that lead to success

    Here's a new webcast I recorded where I talk about how to use visibility, control, and simplicity to your advantage to take the pain out of IT and security management:Strategies for Securing your Enterprise for SuccessBe sure to check out www.principlelogic.com/resources.html for all of my information security articles, podcasts, webcasts, videos, Twitter updates, and more....

    Continue Reading...
  • 29 Apr 2010

    IT security roundtable starting soon

    Join me if you can in just over an hour for AppSec's Five Burning Questions: Q2 2010 IT Security Auditor Roundtable. I and others from companies such as Ernst & Young, KMPG, and Protiviti will discuss database audit challenges and share tips and best practices you can implement to ensure database compliance and security.I hope to "see" you there!...

    Continue Reading...
  • 27 Apr 2010

    How to become a better presenter

    There are a lot of unknowns in IT but one thing's for sure: if you're going to be successful in your job and move up the career ladder you have to sharpen your presentation skills. Here's a new piece I wrote that'll help you get started down the right path:Eight tips every IT pro can use towards becoming a better presenter...

    Continue Reading...
  • 26 Apr 2010

    The ultimate SQL Server faux pas, other oversights & solutions

    Here's a new piece I wrote where I talk about one of the root causes of SQL Server security issues:The ultimate SQL Server security faux pas: Overlooked systems...along with some additional oversights:Common oversights with SQL Server audits...and, to top things off, some things you can do to lock down your database environment (SQL Server or not)Meet compliance requirements with improved database security practices...

    Continue Reading...
  • 26 Apr 2010

    Cracking Windows 7 passwords + a bit on BitLocker

    Here's the latest on Windows 7 passwords along with how they can be cracked and some tools for doing so:Cracking passwords in Windows 7I wrote a whitepaper on BitLocker in Windows 7 not long ago and here are some additional thoughts/tips in case you're considering it:Using BitLocker in Windows 7 For additional reading, Paul Thurrott's SuperSite for Windows is a great resource on Windows 7 and more....

    Continue Reading...
  • 26 Apr 2010

    The key to failure

    Bill Cosby said it best: "I don't know the key to success, but the key to failure is trying to please everybody." Be it your current job, your career, information security, IT, whatever - you cannot forget this sage advice....

    Continue Reading...