Helping clients manage their technology for over 30 years.

Corporate data loss: How bad is it? (Part 2 of 2)

Impact of Data Loss on Business Organizations

We have spent over 12 years building our reputation and trust; it is painful to see us take so many steps back due to a single incident.
—Tony Hsieh, CEO, Zappos, after the company suffered a data breach in which 24 million customer records were stolen

Continue reading

Corporate data loss: How bad is it? (Part 1 of 2)

Loss of Sensitive Corporate Data

In the wrong hands, the sensitive data your business depends on becomes a weapon wielded against it. And it’s happening more often every day.

Reports of intellectual property theft and hacktivism abound, and 2011 has been widely described as “the year of the data breach.”

It’s not hard to see why.

In 2011 alone, according to the nonprofit Online Trust Alliance, 126 million data records were compromised in the United States.

Continue reading

Security holes that’ll keep you up at night: Sensitive data in the cloud

Factors impacting Cloud Security

Cloud computing that involves processing sensitive or regulated data in shared environments needs extra scrutiny in terms of security (as well as codifying requirements, defining a cloud services contract, managing the transition from in-house to cloud, and overseeing the resulting mixed IT environment).

Cloud security is at risk when…

  • You don’t have an adequate cloud-oriented governance/risk/compliance framework,
  • The hypervisors in your virtualized infrastructure harbor vulnerabilities that can be exploited,
  • It’s possible to infer information about one virtual machine by observing the state of the shared system from another aspect of the underlying system — which might enable malicious code execution, or
  • When vulnerabilities are introduced by incorrect configuration of a hypervisor and/or its related tools.

Continue reading

Security holes that’ll keep you up at night: Insecure virtual machine deployment

Vulnerabilities of Virtualization

Rare is the information technology professional these days who doesn’t understand the prodigious efficiencies and savings that can be derived from virtualization. Yet, too often virtual machines are deployed insecurely. One Gartner analyst has estimated that 60% of virtualized servers will be less secure than the physical servers they replace.

That’s because too often virtualization projects tend to be developed and deployed without considering security. This can result in vulnerabilities that enable bad guys to compromise the hypervisor/ virtualization layer (e.g., DoS attacks), which can spread to all hosted workloads.

Continue reading

Security holes that’ll keep you up at night: Advanced persistent threats

Impact of Advanced Persistent Threats on IT Security

Malware comes in many flavors. I’m focusing now on one of the most pernicious, advanced persistent threats (APTs), because these frequently use the techniques of zero-day attacks  to remotely manipulate a system while remaining virtually invisible to standard defenses.

Continue reading

Security holes that’ll keep you up at night: Managing the use of social media

Managing the use of Social Media

The ever-richer user information on social media presents an irresistible opportunity for ‘fraudsters.’ Because it’s so easy to research a target online, attackers have developed very effective masquerading and social engineering tactics that can fool even the most sophisticated users.

Continue reading