Mid-Sized Companies, Big-Time Security Issues
One of the truly unfair things about information security is that the quantity and difficulty of problems don’t scale downward with the size of the organization. A big enterprise has to deal with all sorts of potential threats: APTs, phishing,…
A situational problem requires a situational solution!
A quote posted to Twitter about one of the presentations at the Security BSides conference earlier in the week in San Francisco struck a chord and I wanted to comment on it. It went something like this, ‘Information Security is…
Six months is a long time in Cybersecurity
As we reach the halfway point of 2011 – metaphorically speaking, at least – I think it is time to play a little game.
Correlation across the nation
Enterprises have some of the most sophisticated security platforms ever to help protect their most valuable assets yet hardly a day goes past without news of another serious cyber attack on a major corporation. It’s true that the threat posed…
More Thoughts on “After the Breach”
A couple of days ago, the folks at McAfee put up a very good blog post really delving into the specifics of what to do when you find a data breach. To be clear, there are few days for a…
eIQcast, Episode 19 – “BUSTED! The Heartland Hacker Goes Down”
This past Monday the U.S. Justice Department charged 28 year-old Albert Gonzalez with a series of crimes that resulted in the theft of more than 130 million credit and debit card numbers from late 2006 to early 2008. The indictment…
PCI Is Just the Beginning…
It’s not surprising that many of the folks I talk to continue to focus on PCI-DSS. They handle credit card data, so they have to. What is surprising is the amount of institutional apathy to going beyond the guidance of…
eIQcast, Episode 18 – “eIQ Views on Black Hat”
eIQnetworks Senior Vice President of Strategy Mike Rothman just returned from Black Hat USA 2009 in Las Vegas, which took place from July 25-30, 2009. Mike has been to Black Hat many times, and the more things change, the more…

UNCC Breach Highlights the Need to Think Differently about Cybersecurity
The University of North Carolina-Charlotte (UNCC) recently disclosed that they have discovered over 350,000 student, staff and faculty records – including Social Security numbers – that have been exposed to public access in multiple systems, in some cases for several…