Category Archives: Risk Management

Microsoft TechEd 2009 is Now A Wrap!

Microsoft TechEd 2009 is now a wrap!  My session took home some pretty high scores and from the looks of the evaluations so far at least within the top 10 in the security, identity and access tracks, possibly top 5! By this time next year, I am hopeful that one of the key preventative online risk technologies [...]

Stop Listening to Security People: Focus On The Why Rather Than The What

There, I said it: stop listening to information security people. Before you fire your security vendors, disable those perimeter defenses and toss your security development processes to the fire there’s more to this story you should know. On the front page of MSN.com this morning, there was an article entitled “Stop Listening to Suze Orman” and it reminded [...]

The Dangers of Online Banking: How to Separate the Wheat from the Chaff

I opened up my Web browser this morning and on the front page of MSN.com (yes, yes … I confess my default homepage is still set to MSN) was this article about the dangers of online banking. The article was pretty well written, and it brought to light some very practical things people can do to better protect [...]

“That would require me to actually care about security …”: Inspiring Words From My Developer Friend

At Impacta, one of the core values we have is to always innovate.  Find new, better and more creative ways to solve today and tomorrow’s online risk (security, privacy, etc.) problems. In fact, our company motto is literally ”Innovations that Inpsire” to speak to that core value. I just had one of those unexpected moments today that [...]

Pick the Right Tool for the Job: Penetration Tests, Vulnerability Assessment and IT Security Audits

I had a meeting with a potential Impacta client the other day and they were inquiring about getting a ‘penetration test’ performed against their network.  Upon talking more and more with them, turns out that they needed something much different than a penetration test and I told them this openly. Sure, I could have sold them [...]

How NOT to Conduct a Penetration Test: Recent Rises in a Disturbing Trend

I wanted to blog about a disturbing trend that I’ve been seeing recently. I might be slightly biased here, actually I know I am, but hear me out on this one for just a moment and I think you’ll agree with what I have to say.  I had the chance recently to review the results [...]

Don’t Get Too Caught Up in the Patch Game: How to Tell if a System is “Secure”

An article from Webuser online magazine in the United Kingdom today reported that 98% of home PCs are not secure.  I don’t doubt that number, in fact I am surprised that it’s not higher. What I do disagree with is the definition of ”secure”.  In this report, secure is defined by measuring whether or not the system was up-to-date [...]