Pages

Wednesday, August 16, 2017

Using a SOC2 Report to Evaluate Cloud Providers

There are a few tools that can be used when assessing a cloud service provider, and a SOC 2 report is one of them. If a cloud provider or vendor has a SOC 2 report available, it can be extremely useful to understand the company's controls when it comes to security, availability, processing, integrity, confidentiality and privacy. If the third party cannot provide a SOC 2 report, it's possible that they haven't had an assessment performed, or that they're not willing to disclose this data.
It's always best to receive a Type 2 SOC 2, but many vendors might send over a SOC 3 to prove that work has been completed. The Type 2 SOC 2 report will not only review the controls in question, but will go into detail on the effectiveness of the controls. If possible, try to get a Type 2 SOC 2 from the vendor as a first step. Read more at the link below:
http://searchcloudsecurity.techtarget.com/answer/How-can-enterprises-use-SOC-2-reports-to-evaluate-cloud-providers

Domain Validation Certificates: What are the Security Implications

Let's Encrypt is a free and open certificate authority that enables those that might not be able to afford or configure HTTPS on their web servers to protect their sites.
Using tools in partnership with Let's Encrypt, such as the Electronic Frontier Foundation's Certbot, enables website administrators to freely enable TLS on their sites, and to even automate security functions within cipher suites and other encryption features.
The major goal of Let's Encrypt is to create a secure internet, with all sessions encrypted in transit. Let's Encrypt has major sponsors assisting its community -- including Mozilla, Cisco, Electronic Frontier Foundation, Google, Facebook and others -- that have offered their support for the service. Read more at the link below:

Patching telcom infrastructure can become a challenge

As with many priority systems, patching can become an arduous, and even political battle within an enterprise. These priority systems can be deemed so critical by the organization that patching them is viewed as a risk to the business, which is counter-intuitive when thinking from a security standpoint. This is normally the case when these systems run on outdated or legacy operating systems where installing patches would either void a support agreement or where the organization doesn't have the funds or architecture to test the patches' functionality in a QA environment. Read more at the link below:

http://searchsecurity.techtarget.com/answer/Why-is-patching-telecom-infrastructures-such-a-challenge

How does a privacy impact assessment affect enterprise security

A privacy impact assessment is a review of how an organization handles the sensitive or personal data flowing through their systems. Through this review, the organization -- or potentially a hired third party -- will review internal corporate processes, procedures and even technology to determine how privacy data on users or customers is being stored, collected and processed. This is commonly seen within government agencies and sometimes within organizations storing large amounts of private data on their users or customers, like in healthcare, e-commerce or other industries. Read more at the link below:

http://searchsecurity.techtarget.com/answer/How-does-a-privacy-impact-assessment-affect-enterprise-security

Friday, July 28, 2017

AI and the Future of Cybersecurity: Analyzing & Identifying Cybercrime (Webinar)

On August 17th I'll be co-presenting a webinar with Darktrace on "AI and the Future of Cybersecurity: Analyzing & Identifying Cybercrime".

In today’s world, it is critical to be proactive. Ransomware, malware, insider threat, and IoT are evolving rapidly, which means that prevention tactics must keep up and evolve at an equally rapid pace. Zero day attacks can be detected and prevented when businesses incorporate AI and Machine Learning into their cyber defense strategy.

If you want to learn more, please register for the webinar (seats are limited): http://www.ccsinet.com/ai-future-cybersecurity/

Monday, July 3, 2017

Targeted iPhone Phishing Scams (Trident Zero Day)

Here's the video of an interview I did for News12 regarding iPhone users being targeted for phishing scams related to the Trident zero day. Time to update!

http://longisland.news12.com/story/35241250/cybersecurity-expert-warns-of-scam-targeting-iphone-users

The Rise of Artifical Intelligence in Cyber Security

The rise of behavioral analytics, machine learning, artificial intelligence, or whatever the latest nomenclature is currently being promoted by vendors, has taken the security community by storm and showing no signs of stopping. It's almost impossible not to see these phrases mentioned on new preventative solutions going to market and rightfully so. With an industry accustomed to relying on static signatures, known bad hashes and singular alerting, this technology is a welcome relief for defenders and we've seen the market capitalize on our desire for it. Here's an article I wrote for SC Magazine regarding how AI become the darling of an industry: https://www.scmagazine.com/how-artificial-intelligence-became-the-darling-of-an-industry/article/666778/