Security marketing and awareness in the enterprise: how Much is enough?

Once of the most challenging items on the list of things to do for today’s CSO/CISO is the development and sustaining of a security awareness program that is appropriate for their particular organization.

The question of how to tailor your communications to suit the various business activities, leadership styles and existing corporate culture can be extremely complex and can have the opposite effect of elevating information security to a de-facto part of an organization’s culture if not approached with great care. [Read more...]

Preparing for Attack: Five Tips for Organisations

According to a recent report by the Department for Business, Innovation and Skills, 87 per cent of small businesses and 93 per cent of large organisations experienced at least one kind of security breach in the past year.  And the cost continues to rise, tripling in the past 12 months as attacks on intellectual property and customer data appear unstoppable. 

No security plan is perfect, yet many organisations still do not factor the inevitability of compromises into their overall defence strategies – instead focusing on what must be done to keep every conceivable type of threat at bay. This is reinforced by a reflexive assumption that new technologies can close every gap attackers need. Yet, research consistently reveals why some attacks can routinely bypass updated layers of network and endpoint security products. More than ever, preparing for an attack must include sealing-off damage and more rapidly restoring systems to trusted states. [Read more...]

Removing assumptions about data integrity

Security of data is not only about encryption and protection – it starts from a basis of whether you’re secure in relying on the data in the first place. Because you know where you receive the data from, that doesn’t mean that that data is as per the original, complete and tamper-free. 

Frequently data is received indirectly, from data aggregators and vendors, from third parties, etc, and it’s therefore important to be able to check what data you receive against the data that its originator created.  Notarisation of digital data has become a requirement so that recipients of data can cross-check it electronically and immediately against the original – particularly where the data is to be used as the basis for contractual agreements and investment decisions. [Read more...]

A Matter of Trust

How should organisations prove that they can be trusted with sensitive data, and build a bond of trust with partners and stakeholders?  Terry Greer-King, UK MD for Check Point, looks at the issues

“That won’t happen to us, ’cause it’s always been a matter of trust.”  This line from Billy Joel’s 1986 hit single could easily describe the approach that many organisations have taken over the past five years to safeguarding the personal, confidential data that they hold. [Read more...]

The problem of search engine poisoning attacks

The problem of search engine poisoning attacks

We’re pleased to invite you to a WebEx we’ll be hosting on May 17th talking about search engine poisoning attacks. [Read more...]