While we need to monitor our employees to protect organization secrets, there's no need to turn the workplace into a bad episode of Big Brother
Continue reading "How To Monitor Employees Without Being A Perv"
Comments(0)You can't protect what you can't see. Use these tools to learn how and where your data is at risk
Continue reading "Take Off The Data Security Blinders"
Comments(2)Blaming the "insider threat" merely hides your real security risks
Continue reading "It's Time to Dump The 'Insider Threat'"
Comments(1)Big Bird, Google, and Facebook participate in first high-profile test flight of new IP protocol amid DDoS threat backdrop
Continue reading "IPv6 Graduation Day"
Comments(4)While many companies deal with the problem of insider threat, there are some practical things that can be done to both prevent and detect insider threat. Always remember, prevention is ideal but detection is a must.
Continue reading "Taming the Beast: Preventing/Detecting Insider Threat"
Comments(5)How to sniff out a rogue insider
Continue reading "Profiling The Evil Insider"
Comments(1)Technology is typically going to serve as the basis for insider threat attacks. One of the major key technology areas is information extraction, and it must be clearly understood so an organization can try to stay one step ahead of the malicious insider.
Continue reading "Understanding The Mindset Of The Evil Insider"
Comments(0)The insider threat is complicated, and most organizations do not fully understand the magnitude of the problem. There are three main reasons why the insider threat has been ignored: Organizations do not know it's happening, it's easy for organizations to be in denial, and organizations fear bad publicity.
Continue reading "Why The Insider Threat Is Ignored"
Comments(0)There are different categories of insider threats, based on the level of access the employee has. There are four types: pure insider, insider associate, insider affiliate, and outside affiliate. Each of these categories also has different motives. Understanding each is a key to building proper preventive and detective defenses.
Continue reading "Different Flavors Of The Insider Threat"
Comments(0)"I trust everyone. It is the devil inside that I do not trust" is a great line from the movie "The Italian Job." Every single person has the potential to do harm if the right circumstances occur. Yes, this includes employees.
Continue reading "Missing The Insider Threat"
Comments(0)Recently there has been a lot of talk about nuclear weapons, terrorism, and peace treaties. At the end of the day, the question remains: how do we protect a country and its citizens from attack? If that is really the purpose of the summits and the meetings, why isn't cybersecurity part of the discussion -- more importantly, the insider threat?
Continue reading "Are We Missing the Point?"
Comments(0)APT is the buzzword everyone is using. Companies are concerned about it, the government is being compromised by it, and consultants are using it in every presentation they give. But people fail to realize that the vulnerabilities these threats compromises are the insider -- not the malicious insider, but the accidental insider who clicks on the wrong link.
Continue reading "Advanced Persistent Threat: The Insider Threat"
Comments(0)Following a Facebook update from a soldier on an upcoming operation, the Israeli Defense Forces (IDF) canceled an operation into the West Bank, illustrating how the connected world makes maintaining operational security (OPSEC) all the more difficult.
Continue reading "Social Networks, Data Leaks, And Operation Security"
Comments(0)New research published by Sophos today reveals a 70 percent increase in the number of companies reporting spam and malware attacks via social networks.
Continue reading "70% Rise In Malware: Time To Block Facebook?"
Comments(0)I was sitting at my desk when my phone rang. I answered, and it was a large pharmaceutical company that was interested in consulting services. It had noticed a trend with one of its foreign competitors. Every time it went to release a new product (in this particular case a new drug), one of its competitors would release a similar drug with a similar name, several weeks before it, beating it to market.
Continue reading "A Real Insider Threat Story"
Comments(0)There is no single thing you can do to prevent an attack from the inside. The concept of defense-in-depth applies here as it does to all areas of security. No single solution is going to make you secure. Only by putting many defense measures together will you be secure, and those measures must encompass both preventive and detective measures.
Continue reading "Stopping Insider Attacks"
Comments(0)The key thing to remember when dealing with insiders is they have access and, in most cases, will exploit the weakest link that gives them the greatest chance of access, while minimizing the chances that they get caught. Why try to break through a firewall and gain access to a system with a private address when you can find someone behind the firewall with full access to the system?
Continue reading "Measuring Insider Risk"
Comments(0)Organizations tend to think once they hire an employee or a contractor, that person is now part of a trusted group of people. Although an organization might give an employee additional access that an ordinary person would not have, why should it trust that person?
Continue reading "Insider Threat Reality Check"
Comments(0)Bill Gates invited me to join his LinkedIN network. OK, so it wasn't really Bill Gates, but as far as my email system, spam filter, and email client were concerned, it's perfectly normal for Gates to send me a LinkedIn invitation.
Continue reading "LinkedIN With 'Bill Gates'"
Comments(0)The upcoming stable release of Metasploit Framework version 3.3 is brimming with awesome new features that will make a lot of penetration testers happy. New features include the ability to take screenshots of exploited systems, while others add raw power, like being able to exploit the unpatched SMBv2 vulnerability in Windows Vista and Server 2008.
Continue reading "Metasploit Adds Exploit For Unpatched Windows SMBv2 Bug"
Comments(0)Last week, I took a shot at the Marines for banning social networks without waiting for the Pentagon to finish looking into the threats posed by members of our armed forces using sites like Facebook and Twitter.
Continue reading "Social Zombies Out For Your Network, Not Brains"
Comments(0)Hell hath no fury like an IT support administrator scorned. At least that's the message being heard loud and clear by firms that are finding their networks at risk of attack from former employees.
Continue reading "IT Admin Gets Jail Time For Sabotaging Ex-Employer's Network"
Comments(0)You know the military's ol' mantra about "loose lips sink ships"? Well, it's being redefined by sites like Twitter, Flickr, and Facebook, according to a great article from Federal Computer Week that discusses the threats social networks pose to operational security.
Continue reading "Maltego: Going On The Offensive *And* Defensive To Defend Against Social Networks"
Comments(0)Securing our company's data is our job. We build up layers of defense to protect it when it is housed within our corporate network and corporate computer systems. Firewalls, VPNs, encryption, and data leakage prevention all help in some way to protect the data that we don't want anyone else to have. Sometimes, however, we are stuck in the situation where we don't control the network or systems that portions of our data ends up on.
Continue reading "Data Leakage Through Nontraditional Networks"
Comments(0)My firm, Secure Network Technologies, was recently hired by a large healthcare provider to perform a security assessment. As part of the job, my partner, Bob Clary, posed as an employee, similar to the "Seinfeld" episode in which Kramer shows up and works at a company where he was never actually hired.
Continue reading "'Kramer' Is In The Building"
Comments(0)