There is no scenario where the phrase “stored and accessed online” should not be accompanied by the phrase “protected by or behind a firewall”. This potential breach is yet another reminder that we all have a responsibility to protect and safeguard individual and customer data, especially in an online environment. There really are no exceptions.
Month: June 2018
10 Tips for More Secure Mobile Devices
This is good, sound device when managing and securing your mobile devices. Enjoy!
https://www.darkreading.com/mobile/10-tips-for-more-secure-mobile-devices/d/d-id/1332156
‘Have I Been Pwned’ Now Built into Firefox, 1Password
I am very excited to hear of this initiative and to know that this level of awareness is now available through these tools. I have long been a proponent of Firefox and 1Password and have greatly respected the work of Troy Hunt. It is great to see these three come together in a effort to make the online work just a little more aware and safer.
Terrible passwords outlawed in Microsoft’s new Azure tool
Kudos to Microsoft for heading down this path and taking one more step closer to better password security. It is still not a perfect world scenario, but it is better than the basic controls inherent to the OS.
Sophos Weekly Recap
5 Mobile Enterprise Data Concerns to Prepare for Now
This is an interesting list and a conversation worth having as we all plan for the future of mobile data.
Sophos Weekly Recap
Microsoft Patch Tuesday, June 2018 Edition
Please review your environments and patch accordingly.
https://krebsonsecurity.com/2018/06/microsoft-patch-tuesday-june-2018-edition/
https://www.darkreading.com/microsoft-fixes-11-critical-39-important-vulns/d/d-id/1332033
Microsoft reveals which bugs it won’t patch
This is an interesting read – both the article and the draft provided by Microsoft – concerning patch development and an organization’s commitment to address bugs based on severity and defensive layers. I commend Microsoft for their willingness to release this draft and seek public / industry comments.
https://threatpost.com/microsoft-reveals-which-bugs-it-wont-patch/132817/
Chile to revolutionize cybersecurity after the recent cyberattack
Read this article carefully. It appears to be a discussion of how a bank survived a cyber attack and is working to become stronger through lessons learned. The article discussed how preventative controls limited the attack and mitigated the losses. It even discusses two new lines of defense the bank intends to deploy – reaching out to the international community for guidance, and reviewing current cybersecurity frameworks to improve internal processes. What is buried in the last lines of the article is the scariest piece of information about the bank that is largely overlooked. The current existing cybersecurity regulations for the bank dates to 1993. Yes, you read that correctly – 1993.
Due diligence is not revisiting your cybersecurity plan once every couple of decades. Almost every modern security framework discusses at least an annual review with additional reviews any time a new, significant threat is discovered or when a significant change is deployed within the organization. Kudos to Chile for taking steps to modernize, but it never should have taken this long.
https://www.welivesecurity.com/2018/06/14/chile-revolutionize-cybersecurity-cyberattack/