Skip to main content

Posts

Showing posts with the label information security
Weekly recap and why you should be concerned about "attackers" even if you have "nothing to hide" Why you should be aware of, defend against, and prevent attackers... even at home: I often hear from future victims "well I don't have anything to hide/anything of value/why would they target me!?" It's really not about you, usually the attackers aren't looking for your data (if they get it, or have easy access to it, they may try to profit from it, but the people doing the compromising aren't usually the same folks that monetize). What the attackers want are compromised systems they can use to do what they want at scale. So if they can compromise 50 systems, they can send 50X the amount of SPAM... 100 systems, 100X, etc. Some operations get paid based on the number of emails they can send per day. Of course the email will likely not just be SPAM, but may also be malicious (ransomware, etc.). http://thehackernews.com/2017/09/linux-ma...

Information Security - What does it mean to you? - Part 3 Y2K all the way!

So where I last left off - 2000 a time of transition for a number of things, the "red hot" internet properties of the '90's started the downward slide that became the recession of the early 2000's and many "internet millionaires" became bankrupt or lost much of their projected net worth. During this time many companies had been focused on growth and establishing an "internet" presence without really having a business plan or an approach to sustain or support the number of systems that were being deployed to the networks. Corporate malfeasance leads to regulation - Enron, WorldCom, Tyco and other companies caused public outrage due to accounting fraud of various magnitudes and the attempted cover-up and complacency of Sr. Management. The result is the Sarbanes-Oxley Act of 2002. While mostly corporate accountability legislation, this triggers a number of compliance initiatives that impact Information Security and compliance. Continued ema...

Information Security - What does it mean to you? - Part 2 new challenges

So we continue the journey with the next evolution of "information security". At this point (1999 - 2000) the motivators for implementing security were small and very little time, effort, and money was spent either on tools, technical training or in preparedness. 1999 was a banner year for malware (viruses, worms, etc.) with most environments being subject to at least one of the major outbreaks (Melissa, Sub7, etc.). Melissa was an interesting one, like many malware infestations to follow, the impact of the worm was that it spread exponentially and impacted the services running on the affected systems. For the first time (for most IT teams) there was an actual outage or impact to having Malware in the environment (other than having to spend the time, to clean it up). This got the attention of (some) execs, and they started to ask the questions like "what could we have done to prevent this?" and "how do we deal with the next virus like this?". Alas ...