• 04 Nov 2008

    It’s up to you….

    When I got into the office this morning I looked up at this little card on my wall titled "Care". It has a quote by Ralph Marston that says "What will you do today that will matter tomorrow?"Wow, I can't think of any stronger statement that sums up our responsibility on this big day for America...for the world. Think long-term people. The world's watching...let's hope we don't stumble....

    Continue Reading...
  • 03 Nov 2008

    Think all the hype over MS08-067 is just that…?

    There's been a TON of talk about the latest vulnerability affecting Windows. Message boards have been lighting up with talk about it, vendors are offering webcasts, it's the talk of the security town. In fact, it's so bad that Microsoft is releasing an "out-of-band" patch to fix the problem.So, is it worth the trouble to patch - especially on seemingly critical servers that you can't afford a patch to take ...

    Continue Reading...
  • 29 Oct 2008

    Only 5 more days until security budget increases are locked in!

    Come Tuesday - election day - maybe you can finally get the money you richly deserve for your information security initiatives. It's a new way of thinking - a new way of life for us here in the U.S. - something we information security professionals can adopt and integrate into our daily work.Here's the mindset of the Neue Regel...follow closely and you'll get that budget increase you deserve:First of all, ...

    Continue Reading...
  • 28 Oct 2008

    My latest security content

    Here are two articles I wrote for SearchEnterpriseDesktop.com:Enhancing patch management with NAPUnauthenticated vs. authenticated security testing Here's an article I wrote for SearchSQLServer.com:New security features in SQL Server 2008 leave some work for you...and finally a podcast I just recorded for SearchEnterpriseDesktop.com:Security Policies for Windows SystemsBe sure to check out www.principlelogic.com/resources.html for all of my information security articles, podcast interviews, webcasts, screencasts and more....

    Continue Reading...
  • 23 Oct 2008

    Huh…most data breaches are preventable??

    You don't say!According to NewsFactor, 87 percent could have been prevented. I would've figured around 99-100%.It's a choice folks. Like Dr. Phil says: You choose the behavior, you choose the consequence....

    Continue Reading...
  • 22 Oct 2008

    A creative customer service mantra

    I just saw this on Webroot's website...Three things we've all experienced in our work and personal lives: At Webroot, we... answer the phonespeak your languagesolve your problem I love it! Hopefully they'll be there when/if I need them. :-)...

    Continue Reading...
  • 21 Oct 2008

    Google’s now in the security assessment business

    It's focused, and targeted, and limited but maybe Google's new service is just what we need to find out where we're weak on the Web??Ha! If it were only that easy....

    Continue Reading...
  • 20 Oct 2008

    Question posed to me about IT operations not being on board with security

    Here's an interesting question someone asked me recently regarding some in-fighting about security along with my brief response on how to fix the problem. I see this ALL the time!:"I work in a company as the sole information security analyst. My job is to identify risks, set policy, and audit our IT environment against the policies I wrote. I am currently working with IT operations staff on mitigating risks based ...

    Continue Reading...
  • 20 Oct 2008

    My latest security content

    Here's an article I wrote for SearchEnterpriseDesktop.com:How to exploit two common Windows vulnerabilitiesHere's an article I wrote for SearchSoftwareQuality.com:Does certification really matter?Be sure to check out www.principlelogic.com/resources.html for all of my information security articles, podcast interviews, webcasts, screencasts and more....

    Continue Reading...
  • 14 Oct 2008

    Great time was had at InfoSec 2008 in Louisville

    I've been traveling quite a bit as of late so I'm a little off kilter. That said, I wanted to post a quick note regarding the Kentuckiana ISSA's 4th annual InfoSec conference I keynoted last week. It was a great show...very good turnout - both attendees and vendors - and VERY well run. In fact, I believe Cindy Woods - the brains/effort behind the show missed her calling. Cindy put ...

    Continue Reading...