Posts

Big Data Intelligence Driven Security at RSAC

Image
A constant theme from this year’s RSA Conference Europe, is the idea of security intelligence collaboration, namely the capture, sharing and data mining of “Big Data’, to detect and prevent security incidents and attacks, but will it ever take off? The concept of gathering and using big data is nothing new, from Google to your supermarket loyalty card; big data mining has been very successfully used commercially for at least a decade, not to mention the alleged big data mining said to be conducted by the NSA. This collaborative led intelligence approach has potential and I believe it could be effective if conceived and built smartly, however I fear the issue will be with the data sharing. Most of the existing big data models in use are covert, and organisations aren’t collaborating, so they do not share their big data analytics. This is a fairly obvious approach, as the whole idea of mining big data in their case is for commercial advantage and gain. So I imagine ...

RSA Conference: Anonymity is the Enemy of Privacy

Image
‘Anonymity is the Enemy of Privacy’ was a point stressed by Art Coviello, the Executive Chairman of RSA, in the opening keynote of the RSA Conference Europe 2013.   This point is controversial to say the least, especially to a European audience, with mainly Europeans still rocking in the wake of the massive NSA covert internet surveillance allegations against European leaders, and millions of EU citizens. Many privacy advocates hold a polar opposite view to Art, believing anonymity online is a fundamental ingredient for online privacy. Art's perspective also highlights the difference in attitudes towards privacy harboured between the United States and Europe. The European Union was built on its citizen rights, including the right to privacy, a right the EU wishes to see exercised online, whereas the US view tends to be 'privacy is dead', believing the right to online privacy has been given up and the privacy fight lost.

Identity Theft & How to Protect Yourself from ID Theft

Image
HotSpot Shield have created an Identity Theft InfoGraphic which I'm happy to share. InfoGraphic explains the malicious actors behind ID theft, some of the techniques they use and how to protect yourself.  

RSA Conference Europe 2013 Preview

The keynote speaker at this year's RSA Conference Europe  is certainly of interest. Sir Seb Coe was widely applauded as delivering an outstanding Olympic Games in London last year.  The security of the games was always a great concern from the day after it was announced London was to receive the games back in 2007, but it is the cyber security aspect of the games which interests me. The games were subjected to cyber threats, including a specific cyber threat aimed at taking down power supplies to the games stadiums, so it will be fascinating to learn more about the planning, preparation and the testing of the London 2012 cyber defence. I always recommend the RSA Europe Conference to fellow UK security professionals, especially those new to our busy and complex sector.  It’s a great event to learn about the emerging threats, defences and the latest security thinking, with plenty of quality sessions to choose from. The conference is also a great place to network with fe...

2000 to 2013: The Moving Sands of Information Security

Image
I am been in the information security game for a very long time, many of the fundamental security controls haven’t really changed a great deal, and continue to remain best practice, such as deploying anti-virus, patch management and decent firewall management, the business environment where these security controls are applied has radically shifted, especially over the course of the last decade.   So lets take a trip down memory lane back to the year the 2000, the world has just found out that the Y2K bug was a complete none starter, aside from making IT contractors a bob or two. Meanwhile the Internet is starting to find its way into mainstream business, even so secretaries were still being asked if they had any experience in using the Internet during job interviews. And if you had a job title with the word “Cyber” in it, people assumed you were some sort of a Dr.Who extra. Policies Starting with the cornerstone of all good information security management, the informatio...

Security by Staff Responsibility instead Enforced IT Controls

Image
Today IT security controls are enforced on the end user without prejudice, all for the purpose of migrating the human risk. These controls, especially endpoint security controls, are typically applied because it is best practice to do so, and not as a result of a risk assessment.  What if the application of technically enforced security controls was taken as an action of last resort? Can human responsibility be be just as affective as an enforced control? Can it be more advantageous in managing the same risk?   These our my thoughts. Lets take a English FA Premier League football match, there is a risk that spectators in the stands will invade the pitch, and impacting on the match and threatening safety  Yet spectators rarely invade football pitches at English matches, even though they aren't fenced in. A fence is an example of an enforced control meant to prevent fans from accessing the pitch.  My argument is the fans are self re...

iPhone 5S "Touch ID" Fingerprint Security

Image
Apple announced the new iPhone 5S today, the introduction of a new fingerprint recognition access system on the smartphone, called "Touch ID", grabs the security attention. Fingerprint reader is the main button Security of the Fingerprint Reader The fingerprint reader is not like the traditional readers you see on laptops, and is actually part of the main button on the phone. The reader is no security gimmick as it is not a outdated optical reader, which works by taking and comparing a picture of your fingerprint, it is a capacitance reader,which is a more advanced and secure technology. Capacitance readers uses an electrical current to map your fingerprint, measures the minuscule differences in conductivity caused by the raised parts of your fingerprint, which makes it very difficult to defeat. I don't like to advocate the security of anything without inspecting, researching and testing a device myself, but I will say this reader has certainly been designed ...