ITPC Blog

CISOs: Jacks-of-all trades, Masters-of-one

Have you ever asked yourself the following question: Why is it that information security professionals are told to learn about other disciplines in their organizations, but that others don’t have to learn a thing about security? You’re not alone if you’ve had this experience. I was at dinner with a group of CISOs when one… more »

Researchers Find Flaw in Online Encryption

In an article entitled “Flaw Found in an Online Encryption Method”, the New York Times cites research conducted by Arjen Lenstra, James Hughes, Maxime Augier, Joppe W. Bos, Thorsten Kleinjung, and Christophe Wachter that identifies an error in the RSA algorithm amounting to 99.8%, or 2-in-1000 instances of the algorithm being used. The New York… more »

Nortel Networks Hack and SEC Guidance

The IT networks, systems and applications of the now-defunct Canadian maker of network telecommunications switches were apparently compromised by hackers from China, according to a story written by Siobhan Gorman on the front-page of the Wall Street Journal on February 14, 2012. The WSJ article can be found here: Chinese Hackers Suspected in Long-Term Nortel… more »

Find What You Don’t Know and Can’t See!

More than a few chief information security officers (CISO’s) have told me, “What I really worry about, is what I can’t see and what I don’t know.” When I ask these people, some friends and others acquaintances, to explain this a bit, they all mention obvious threats such as viruses and malware, as well as… more »

IS Your Security Dr. No?

If you are in information security, are you already known as “Dr. No?” If you’re not, is this what the head of information security is called in your organization? Something happened over the course of the past thirty years that turned much of the information security profession into the “Dr. No’s” of the corporate world…. more »

Data Driven Reporting and Communication about IT

In the words of one CEO, “Until they (IT management) presented what it (IT) meant to me, I ignored it (IT). After I got it (the information), we increased spending in some areas pretty dramatically.” We found from the research that with the exception of the best performers — those with the best revenue and… more »

Where’s Your Data – Today?

  Is your data safe? If you are a consumer you may want to check some of the following. If you are in IT, you may want to check your evidence logs. Recent events involving the loss of theft of sensitive information – of those that are known or reported – include events that are… more »

Managing the Benefits and Risks of Mobile Computing

Is the use of Smartphones good for business? The answers are yes and no. Explore some of the compelling benefits, risks, and what the best-in-class are doing to manage both. And, find out why some are avoiding certain mobile devices and why.

Carrier IQ, the Spy Files, and More

Carrier IQ: Where is your data – today? The most recent revelations that your sensitive data and personal data are being controlled, purchased and sold by others came to light last week with the Carrier IQ revelations made by Trevor Eckhart. In addition to his own video detailing what he found, there’s been a deluge… more »

Do You Feel Lucky? Well, do You?

Most organizations are spinning the black-jack wheel, not realizing the odds are stacked against them in the 21st century cyberwar game of cat-and-mouse steal your secrets, got your financial data, steal your customers, plunder your intellectual property and more. Why most organizations? Because 50% are clearly under-spending on information security, while another 4-in-10 should be… more »