SciCast: Toward a better model for prediction
So, it’s the new year again! I know this because of the many corrections I’ve needed to make when filling out anything with a “date” field on it. So “welcome 2014″: I’ll get used to calling you by...
View ArticleMobile app testing less terrible than it could be
So last night I came across a report from IOActive about some technical testing that they did about mobile banking apps. The results are nicely summarized in an article on their blog entitled,...
View Article2014: The Year of Tough Questions
So, as some of you remember, I’ve periodically guest-posted on various blogs. I’ve mostly stopped doing that because (believe it or not) it takes quite a bit of effort to write a blog post… at least...
View ArticleBYOD Best Practices?
Today, I caught an announcement from Microsoft saying that they released some BYOD Best Practices. Now, as you might imagine, I was very excited by this: after all, Microsoft bought PhoneFactor a...
View ArticleCompetitiveness impacts from BSAFE & Dual_EC_DRBG?
Like most people, I took a bit of time off for the winter break, so have recently been catching up on last week’s stories. Before the holidays, I had been following with interest the discussion about...
View ArticleOn the Security of Coin (and X Rebirth)
X Rebirth came out on Friday, so I hadn’t figured on doing much in the way of blogging this week since I had imagined much of my downtime would be invested in virtual intersteller logistics. That said,...
View ArticlePractical Network Convergence?
There’s an article out there in the aether (OK, by “aether” I really mean it’s Ars) about why merging your networks may not be such a good idea. Essentially, the article addresses “network...
View ArticleThe role of fear in decision making
I came across today (via the always-excellent HelpNet) commentary and coverage resulting from a Gartner press release about the possibel effects of fear on risk management. Anyway, check out the full...
View ArticleIs there an inverse to Boehm’s curve?
So Diana posited something really interesting a few months ago and I’ve been meaning to blog about it ever since; it took a while to do it because (as you’ll see) it involved creating graphics and I’m...
View ArticleMusings on Internet of Things, AppSec, and BioMed
Today was an interesting day for folks who follow Internet of Things research. Specifically, ISACA has out a new survey that includes (among other things) some data about the perceived risks and...
View ArticleThree strategies to align organizational compliance and security goals
To celebrate the 10th anniversary of Cybersecurity Awareness Month, Ed discusses strategies to align information security and compliance efforts in his column on SearchCompliance: This situation has...
View ArticleAMP Firehose Chicago
So you may remember that I had mentioned that I was going to be at Pete Lindstrom’s AMP firehose in NY a while back? Well, long story short, but I did go to it, and I did find it extremely valuable...
View ArticleFive cloud computing security concerns and the products tackling them
In this month’s column for SearchCloudSecurity, Ed looks at a few technology niche areas in enterprise that develop post-cloud: The abundant and rapidly increasing use of cloud services in the...
View ArticleAre current security tools like rearview mirrors?
The other day, I had an opportunity to hear a fantastic presentation from VMWare’s George Gerchow. It was a great discussion (as his discussions usually are) and it cemented something in my mind that...
View ArticleDoes BYOD Increase Risk? Part 2
OK, so the other week, I opened a line of questioning about whether or not BYOD increases risk in enterprise. It got to be fairly long, so I promised a return to the topic at some point. So now, here...
View ArticleDoes BYOD Increase Risk? Part 1
So, the other day I came across an article on the ThreatPost which in turn references a survey from Rapid7 about the implications of BYOD on an organization’s security posture. It’s interesting...
View ArticleAvoiding Unpleasant Cloud Surprises
In this month’s ECommerce Times article, Ed discusses the potential pitfalls of “surprise cloud” and what organizations can do about it: When cloud implementations are under the radar, there may not be...
View ArticleEconomic effects of NSA PRISM compared to PLA’s APT-1
So unless you’ve been living under a rock, chances are you’ve seen the news about NSA’s “PRISM” program. If what we’ve been led to believe is as bad as we think (it might not be – see the “everything...
View ArticleLearn the basics of Bitcoin mining in less than 5 minutes
I think we can probably all agree that it’s important for security professionals to understand the basics of Bitcoin mining. Why? Because Bitcoin mining provides a direct pathway to turn captured CPU...
View ArticleCriticism: A Security Chief’s Most Valuable Resource
This month, Ed discusses the value that candid feedback can have for the CISO: Feedback from the community we serve lets us know what we’re doing well, what we need to work on, and which stakeholder...
View Article