Friday, February 8, 2013

PCI Council Releases Guidelines for Cloud Compliance

A new set of guidelines from the PCI Security Standards Council is intended to help merchants and cloud services providers comply with the PCI DSS when handling payment card data on the web.

Image source: Westerfield
Since 2004, the PCI Security Standards Council (PCI SSC) has maintained the Payment Card Industry Data Security Standard (PCI DSS), a proprietary information security standard for the handling of payment card data.

Increasingly, organizations have taken the PCI standard as a guide for implementing security, even if they don't have responsibility for customer payment card data.

What is your CU's position on PCI and cardholder privacy?

Thursday, February 7, 2013

Ex-Employees Say It's OK To Take Corporate Data With Them

New survey finds nearly 70 percent of employees who recently left or were fired from their job say their organizations don't prevent them from using confidential info.

Image source: Flickr
Half of employees say they took corporate data with them when they left their jobs or were fired, and 40 percent plan to use that data in their new positions at other organizations, according to a new report.

Sixty-two percent don't think this practice is wrong, either: They say it's OK to take corporate data with them via their PCs, tablets, smartphones, or cloud file-sharing applications.

Does your CU have data loss policies being enforced for mobile, cloud, and other extrusion channels?

Tuesday, February 5, 2013

Mobile Deposit Combines Best of Both Banking Worlds for Credit Unions

Remote deposit capture, long tied to the PC and desktop scanner, has arrived at its ultimate destination – anywhere, anytime check deposits through popular mobile banking capabilities and smartphones.

Image source: Flikr
Mobile deposit is attractive to consumers and millions of small businesses, a longtime staple of credit union membership.

New technologies have always been the answer to that challenge, and during the last few years, mobile RDC has been in the spotlight.

Does your CU take advantage of this technology?

Monday, February 4, 2013

Anonymous posts over 4000 U.S. bank executive credentials

Anonymous appears to have published login and private information from over 4000 American bank executive credentials its Operation Last Resort, demanding US computer crime law reform.

Image source: Article
A spreadsheet has been published on a .gov website allegedly containing login information and credentials, IP addresses, and contact information of American bank executives.

If true, it could be that Anonymous has released banker information that could be connected to Federal Reserve computers, including contact information and cell phone numbers for U.S. bank Presidents, Vice Presidents, COO's Branch Managers, VP's and more.

Did your CU executives make the list?

Saturday, February 2, 2013

War on terabytes

Ever since the 2001 attacks on the World Trade Centre, banks like Santander have invested billions in safeguarding and duplicating their data centres to protect them from terrorist attacks and natural disasters.

Image source: Blogpost
The threat against banks has, however, evolved. Although the physical infrastructure of the world’s financial system is largely secure, the software that runs on it is not.

Bank bosses and regulators are becoming more concerned by the threat posed to financial stability by networks of hackers that have launched a series of attacks on banks over the past few months.

Read more about the threat trends.

Friday, February 1, 2013

Cases Where Google Gives User Data To Government Don't Involve A Warrant

It may be easier than you think for government entities to demand the private data you’ve stored on Google’s servers.

Image source: Article
Most of the time, it doesn’t even require a judge’s signature.

On Wednesday Google released its semi-annual Transparency Report, its voluntary admission of how many times it removed data from its services or quietly handed users’ information to government agencies in the last six months.

Does your CU allow sensitive information to reside in Google services?

Microsoft pushes subscription model for Office 2013

Available for download now, Office 2013 comes in a wide variety of versions. But Microsoft is hoping that you'll skip the one-time fee for a subscription model that delivers lots of updates to come.

Image source: Article
After existing in preview form since last summer, Office 2013, the next version of Microsoft's productivity software, is now available for download.

Yes, it's a lot more money, and Microsoft accomplishes its goal of keeping you as a customer.

Is your CU sticking with Office 2013?

Tuesday, January 29, 2013

Five Security Trends for 2013

While one of the biggest challenges remains getting the C-suite interested in security, CISOs are increasingly explaining to the front office the business reasons for security.

Image source: Article
From compliance, fines, and data loss, to the irreparable harm that could come to the company’s reputation. But there are other important topics in the field, including these five InfoSec trends for 2013.

It’s typical for IT to be heads-down, focused on the many threats coming from many directions.

Does your CU have its head down? Or are you on top of these 5 trends?

iPhone and Android in the office yield higher profits, happier employees

A new survey finds that companies embracing consumer tech are more likely to report increased sales.

Image source: Article
The survey finds that organizations that have adopted consumer tech were 73 percent more likely to report improved sales and new customer acquisitions than BYOD holdouts.

What's more, companies are enjoying intangible benefits from embracing consumer tech, including happier workers.

Are your CU employees happy?

For Fun: Old people icons that don't make sense anymore

What happens when all the things we based our icons on don't exist anymore? Do they just become, ahem, iconic glyphs whose origins are shrouded in mystery?

Image source: Article
For example, the Floppy Disk Icon means "save" for a whole generation of people who have never seen one.

And why are they called Radio Buttons? Because my car radio used to have buttons where only one could be pressed at any time. I miss my 8-track.

What icons don't make sense to you?

Monday, January 28, 2013

Gartner: Mobile Applications, BYOD to Affect Sourcing Strategies

The rising impact of consumerization means that user demand will increase for new and updated IT services.

Image source: Article
Revised mobile strategies, such as bring your own device (BYOD) and mobile applications availability, will expand IT service sourcing requirements as users demand new services.

Sourcing managers should consider these factors when re-evaluating sourcing options, delivery models and vendors, include strong service integration capabilities for IT organizations adopting public cloud models.

What is your CU's sourcing approach for 2013?

Friday, January 25, 2013

BYOD is a misnomer, MDM is stop-gap

BYOD is a misnomer, while current MDM solutions are "stop-gap technologies" preceding full understanding of mobile data management.

Image source: Article
People want access now to data and applications anywhere on any device.

The fact that it happens to be their device, or a different device, or someone else's device, who owns it and who paid for it is kind of what some people think they want to get hung up on. In reality, the real challenge is delivering data and applications to any device anywhere.

Does your CU handle BYOD workflows securely?

Thursday, January 24, 2013

Mastermind Behind Gozi Bank Malware Charged

The mastermind who designed and distributed the Gozi malware — infecting more than a million computers worldwide in order to steal banking and other credentials from tens of thousands of victims — has been charged in New York along with two co-conspirators, according to documents unsealed Wednesday.

Image source: Article
Authorities say the virus infected at least 40,000 computers in the U.S., including more than 160 computers belonging to NASA, and cost victims tens of millions of dollars in losses.

According to court documents, one command-and-control server for the Gozi virus stored more than 3,000 usernames of banking victims. In one case in Feb. 2012, a victim lost more than $200,000 siphoned from his bank account.

What's next? Read the full story to find out.

Wednesday, January 23, 2013

The cloud will impact the way security is consumed

Increased adoption of cloud-based computing is expected to impact the way security is consumed as well as how key government agencies will prioritize security of public cloud infrastructures, according to Gartner.

Image source: Article
The growing importance of public clouds, along with the ever-persistent threat on private and public sectors' infrastructures, is expected to result in the U.S. government declaring them a critical national infrastructure.

Growth rates for cloud-based security services are set to overtake those of traditional on-premises. Is your CU part of this statistic?

Android malware spreads through compromised legitimate Web sites

Over the past 24 hours, our sensor networks picked up an interesting website infection affecting a popular Bulgarian website for branded watches, which ultimately redirects and downloads premium rate SMS Android malware on the visiting user devices.

Image source: Article
The affected Bulgarian website is only the tip of the iceberg, based on the diversified portfolio of malicious domains known to have been launched by the same party that launched the original campaign.

The first variation of the campaign attempts to trick Russian-speaking users into installing a fake version of Adobe’s Flash Player, followed by a second campaign using a fake Android browser as a social engineering theme, and a third campaign which is attempting to trick mobile users into thinking that it’s a new version of Google Play.

Read more about this attack.

Tuesday, January 22, 2013

Good Technology’s 2nd Annual State of BYOD Report

Last year, BYOD was on the rise, this year, it’s in full force. Since the release of Good’s first BYOD report in December 2011, we have seen an substantial increase of companies around the globe are embracing BYOD programs to help reduce costs and bolster employee productivity.

Image source: Article
For the 2012 State of BYOD Report, Good Technology surveyed the same set of customers to see how BYOD perceptions and program support practices may have shifted in the last year.

Good’s report specially targets its most organizationally complex, multi-national, and highly-regulated customers in order to better understand how these types of companies were adopting BYOD and to share their best practices.

Where does your CU sit with respect to BYOD?

Thursday, January 17, 2013

Security vendors failing to tackle mobile malware, say CISOs

Smaller point solutions are dominating the market, as traditional vendors get left behind.

Image source: Flickr/greyweed
Malware is still the biggest threat to mobile security, but most mobile device management (MDM) strategies tend to focus on securing the physical device in case of loss of theft, rather than protecting from cyber threats.

Although mobile malware still only represents a tiny fraction of the total amount of malware in the world today, it is growing exponentially.

See why MDM alone is not enough.

Wednesday, January 16, 2013

Security group raises BYOD concerns

The top technologies identified to mitigate risks include encryption, the use of virtual private networks, and remote lock and wipe functionality.

Image source: Article
But, who wants to setup an additional VPN for mobile devices?

GOOD technology offers mobile device management and secure application containers without poking holes in the DMZ.

What is your CU's BYOU strategy to mitigate risk?

Tuesday, January 15, 2013

90% of passwords can be cracked in seconds

More than 90% of user-generated passwords can be made vulnerable to hacking in a matter of seconds, according to new research from Deloitte.

Image source: Article
The problem, researchers said, is that everything that we thought to be true must be reconsidered given advances in technology.

Passwords containing at least eight characters, one number, mixed-case letters and non-alphanumeric symbols used to be considered robust.

What is your CU's password policy?

Yankee Group on Mobile Enterprise Apps

Yankee Group Principal Analyst Chris Marsh comments: “We have, for a good while now, been pointing toward the upcoming goldrush in enterprise mobile applications as companies realize more and more the need and the opportunity for strategic gain in mobilizing existing and reinventing new processes for a mobile age. As an example our surveys show that over the past year the proportion of companies deploying mobile CRM has doubled.

Image source: Article
These application types developed off of the Good Dynamics platform are good exemplars of low-hanging fruit for enterprises but the news here though is less about these specific applications and more about Good marking its move away from a pure-play mobile device management (MDM) vendor.

Has your CU moved beyond pure MDM?

Monday, January 14, 2013

There's no magic pill for security

Too often, New Year's resolutions to get into better shape are derailed because of a lack of realistic planning. The same thing happens in the security sphere.

Image source: Flickr
Real security only comes with a lifestyle change, serious commitment and determination. It requires sweat and pain at times. But the results can be worth all that effort.

Be prepared for the hard work of getting into security shape. Just as there are no magic diet pills, true security doesn't come with buying a product, even if it's from a reputable vendor.

Is your CU prepared?

Friday, January 11, 2013

Banks seek NSA help amid attacks on their computer systems

Major U.S. banks have turned to the National Security Agency for help protecting their computer systems after a barrage of assaults that have disrupted their Web sites.

Image source: Article
The attacks on the sites, which started about a year ago but intensified in September, have grown increasingly sophisticated, officials said.

The NSA, the world’s largest electronic spying agency, has been asked to provide technical assistance to help banks further assess their systems and to better understand the attackers’ tactics.

Will your CU need to call in the NSA? Let's hope not.

Fake LinkedIn notifications lead to phishing and malware

LinkedIn users are once again targeted with a massive and widespread spam campaign that takes the form of a notification about a supposedly received message from a potential new connection.

Image source: Article
Unfortunately, the offered links - although legitimate-looking - take users to compromised sites that either ask them to share private and personal data, or serve them with a variety of malware that steals information and hijacks users’ address book to spam their contacts.

These compromised sites are often located on US, UK, Russian or Italian domains.

Read the full article to learn more.

Tuesday, January 8, 2013

Under the Hood of the Cyber Attack on U.S. Banks

You are probably aware of a wave of DDoS attacks that recently hit several major U.S. banks. Izz ad-Din al-Qassam, a hacker group that claimed responsibility for these attacks, declaring them to be a retaliation for an anti-Islam video that mocked the Prophet Muhammad and a part an on-going “Operation Ababil”.

Image source: Article
So far the attack caused several major disruptions in online and mobile banking services.

Izz ad-Din al-Qassam assured that the cyber-attacks will continue, saying that "from now on, none of the U.S. banks will be safe from our attacks."

Is your CU prepared? See how the attack works to learn more.

Monday, January 7, 2013

CFR Watering Hole Attack

On December 27, we received reports that the Council on Foreign Relations (CFR) website was compromised and hosting malicious content.

Image source: Flickr/Chris Capehart
It was later confirmed that the CFR website was hosting the malicious content as early as Friday, December 21—right before a major U.S. holiday.

The malicious content hosted on the website does appear to use Adobe Flash to generate a heap spray attack against Internet Explorer version 8.0 (fully patched), which was the source of the zero-day vulnerability.

What can your CU do to avoid falling prey to this type of attack? Read the blog to find out.

Wednesday, January 2, 2013

Playing chess with APTs

During a briefing from the top security analyst at one of the Washington-area cyber centers, I got the idea that resisting targeted attacks from sophisticated adversaries (so-called advanced persistent threats, or APTs) is a bit like playing chess at the grand master level.

Image source: Flickr/Frank Black Noir
Security efforts disproportionately emphasize endpoint anti-malware. But users, desktops and devices are only the pawns on the board (who, unfortunately often hold the crown jewels – your data).

Sophisticated attackers adeptly perform the necessary intelligence-gathering to find just the right social vulnerabilities for the person of interest and the right technical vulnerabilities for the device. Once exposed, most useful devices are easily compromised by targeted malware exploits riding on the back of spear phishing or similar attacks.

Is your CU using the rook, or castle, to provide a strong defense in your own chess game?

Thursday, December 27, 2012

Forrester report finds US tablet ownership doubled this year

Forrester Research has come out with its annual report on technology consumption in the US, and tablets are certainly gaining popularity.

Image source: Article
Although slightly lower than Pew Research's figures, Forrester deduced from its nigh 60,000-strong survey that 19 percent of 'mericans over the age of 18 own at least one tablet -- double the number the research outfit noted last year.

The whole report isn't available to the public, but why not use the time you would've spent reading it inspecting what's under the tree, and hoping you'll be responsible for upping those tablet stats in next year's report.

Read the blog to access the report.

Wednesday, December 26, 2012

Public WiFi Threats Dissected

You have heard the loudly voiced fears: Signing onto open, unmanaged, public WiFi networks is about as smart, and safe, as unprotected public sex with strangers.

Image source: Article
Everything up to and including identity theft is blamed on public WiFi -- and yet most of us continue to use it. A recent study, for instance, says 55 percent of mobile devices use public WiFi.

All the threats are reasonably accurately portrayed, but you know what is missing? Quantification of how often users on public WiFi networks are compromised and what costs or damages ensued.

Do you allow your members to bank online using public WiFi? Should you?

Friday, December 21, 2012

From CRM to “Big Data,” why a step back can be a step forward

Are banks in general shying away from technological advances, such as the use of “Big Data” analytics, because the issue is just too complex to get a handle on? Will mobile banking and mobile payments ever become mainstream, and, if so, when?

Image source: Article
A lot of banks can’t afford that kind of research and development and they depend on third parties.

Isn’t one of the arguments that if banks don’t do it, other competitors will?

What is your CU's position on Big Data? Read the article to see what other banks think.

Thursday, December 20, 2012

Banks Spend Way More On Info Tech Than Any Other Business

Measured as a percentage of revenues, financial services firms spend more on IT than any other industry.

Image source: Article
The reasons for a higher use of IT in the banking industry are manifold. Financial service firms have to fulfill exacting regulatory requirements which translate into IT costs that do not contribute to the firms’ earnings.

Furthermore, banks rely heavily on IT in their back offices as well as their distribution channels.

How much does your CU spend on IT? Read the article to see how you stack up.

Wednesday, December 19, 2012

Using Data and Analytics to Fight Fraud

As financial institutions enhance the data they are willing to apply toward helping alleviate fraudulent activity, it could have a game-changing impact in the fight against fraud.

Image source: expetec1202
Fraud still poses a very real threat to financial institutions and businesses because, in most cases, they bear the majority of the financial burden.

Lawmakers have recently passed legislation designed to detect and protect consumers, businesses and financial institutions from a multitude of fraud schemes, but are laws alone enough to contain the rising threat of fraud?

Does your CU lean on laws to help protect against fraud? Read the article to see what the author of this article has to say.

Tuesday, December 18, 2012

Social Media: The Next Big Payments Platform?

Payments upstarts like Dwolla and Chirpify are aiming to capitalize on social media's popularity.

Image source: Article
But the question remains whether consumers will flock to a system that lets the world know what they're buying.

Watch the video to see where things are headed.

Friday, December 14, 2012

Managing Mobile Risk – Avoiding Information Governance Mine Fields

Despite the challenges, CUs can rein in the information governance risks with common sense and the latest technologies.

Image source: Article
Most Credit Unions don’t practice what they preach when it comes to information governance.

Centralized document management, formal information management lifecycles, and proof of governance policy enforcement have all become non-negotiable elements in many firms’ policy management and enforcement protocols. And they influence firms’ choices of technology.

What does your CU information governance program look like? Read the article to learn more.

Thursday, December 13, 2012

DDoS Attacks Against US Banks Peaked At 60 Gbps

Some of the distributed denial-of-service (DDoS) attacks that targeted the websites of U.S. financial institutions this week have peaked at 60 Gbps.

Image source: NSS Labs
A group calling itself "Izz ad-Din al-Qassam Cyber Fighters" launched a series of DDoS attacks against the websites of several U.S. banks during September and October, severely disrupting online and mobile banking services for extended periods of time.

The attacks are not that much different from the ones in September and October. There are some changes in the tools being used, but they are not significant.

Most banks and their providers are better prepared to defend against DDoS attacks now than they were two months ago. How does your CU stack up?

Tuesday, December 11, 2012

Cyber Terrorists Threaten Fresh Attacks Against U.S. Banks

A group claiming to be aligned with Islamic terrorism that launched a massive attack against U.S. bank websites in the fall has threatened another round, set to start this week.

Image source: Article
n the last round of attacks, security experts told FOX Business the perpetrators created a so-called “botnet” of compromised Web servers that it used to carry out the attack. The Web servers, the experts said, provided more horsepower than the personal computers because of their higher-level access to Internet infrastructure and less limiting bandwidth restrictions.

Without spoiling the article, side channel attacks could threaten cloud security in a big way. It's best to be prepared. Read the article to start getting prepared.

Friday, December 7, 2012

Sophisticated Smartphone Hacking: 36 Million Euros Banking Theft

A sophisticated digital attack involving smart mobile phones has been used to steal 36 million euros or 47 million dollars from corporate and private banking customers across Europe.

Image source: Article
The attack appears to have emanated from cybercrime servers in the Ukraine.

Android and Blackberry mobile devices have been specifically targeted, showing that attacks against Android devices are now a growing trend.

What are your thoughts, observations and views? Read the article to read more about "ZITMO" or "Zeus-In-The-MObile".

Wednesday, December 5, 2012

Sophisticated Zeus Campaign Stole €36 Million From 30,000 Bank Accounts

The Eurograbber campaign, as it has been named, used custom versions of Zeus and Zeus in the mobile (ZITMO) Trojans to bypass the two-factor authentication measures to compromise customer bank accounts.

Image source: Article
The sophisticated Zeus campaign stole an estimated €36 million, or $47 million, from over 30,000 customers across more than 30 banks in Europe this summer.

The attack intercepted SMS messages sent to customers to confirm financial transactions.

Does your CU protect your SMS channel? Read the article to see how these banks fell victim to this expensive campaign.

Tuesday, December 4, 2012

Good Vault launches two-factor authentication for iPhones

Good Technology announced Good Vault, a system for adding two-factor authentication to the iPhone 4 and 4S for access to Good for Enterprise email.

Image source: Article
The system will be especially valuable for government agencies and companies in highly regulated industries, such as healthcare and financial services, where it's critical to ensure that data is protected from unauthorized users if an employee's smartphone is lost or stolen.

With the Vault system, one of two sleeves is attached to the iPhone: One that can read a smart card or one that can read a microSD card, he said. Once either of the sleeves is in place, inserting the microSD or smart card becomes one component of the two-factor identification process, while typing in a PIN is the second. Once authenticated, users would have access to Good for Enterprise email.

Read the article to learn more about protecting access to the iOS platform.

Monday, December 3, 2012

Using Cloud for Disaster Recovery

Use of cloud for DR solutions is becoming more common, even the organizations which are not using cloud for mission critical production applications are moving towards using cloud for application DR.

Image source: Article
The article covers some of the best practices and lessons learned from the Cloud DR solutions we have implemented so far.

What does your CU do for disaster recovery? Read the article to see all tips and tricks and best practices.

Friday, November 30, 2012

Bank Agrees to Reimburse Hacking Victim $300K in Precedent-Setting Case

In a case watched closely by banks and their commercial customers, a financial institution in Maine has agreed to reimburse a construction company $345,000 that was lost to hackers after a court ruled that the bank’s security practices were “commercially unreasonable.”

Image source: Article
People’s United Bank has agreed to pay Patco Construction Company all the money it lost to hackers in 2009, plus about $45,000 in interest, after intruders installed malware on Patco’s computers and stole its banking credentials to siphon money from its account.

Although the UCC places some burden on the customer to “exercise ordering care,” the court found that it was unclear what obligations a customer had when the bank’s security system was found to be commercially unreasonable.

How much does your CU have to lose for not taking the right steps to protect your members?

Thursday, November 29, 2012

Online Service Offers Bank Robbers for Hire

An online service boldly advertised in the cyber underground lets miscreants hire accomplices in several major U.S. cities to help empty bank accounts, steal tax refunds and intercept fraudulent purchases of high-dollar merchandise.

Image source: Article
The service, advertised on exclusive, Russian-language forums that cater to cybercrooks, claims to have willing and ready foot soldiers for hire in California, Florida, Illinois and New York.

The proprietors of this service say it will take 40-45 percent of the value of the theft, depending on the amount stolen.

In 2010, the U.S. Justice Department targeted one such network in New York City, charging more than three dozen J1s with knowingly assisting in the theft of funds from organizations that had been victimized by cyber fraud. But was that enough? Read the article to find out more about these e-robbers.

Monday, November 26, 2012

Big Data in Banking: Driving Value in Next Best Action

It’s difficult to read a banking technology article or go to a conference without hearing about big data.

Image source: Article
Most of us now believe that big data is more than just hype, that it can offer business benefits to those that can leverage big data into new business capabilities.

But a common question I hear is “How does it relate to my day-to-day business? What does a “big data” business use case look like?”

What does Big Data look like for your CU?

Monday, November 19, 2012

Best BYOD management: Work zones for smartphones

Anthony Perkins wants employees at BNY Mellon to bring their personal smartphones to work and use those instead of company-issued BlackBerries to access business email, applications and data.

Image source: Scoop.it
But there's a catch: Not all employees are comfortable with the prospect of having their personal phones locked down and controlled as tightly as the BlackBerries that Perkins would like to phase out. That's where the notion of containerization comes in.

Because corporate apps and data are often mixed in with the user's personal content, mobile device management (MDM) tools tend to be very strict when it comes to managing corporate resources on users' phones. Usage policies often apply to the entire device, covering both personal and professional apps and data. Users may not be willing to give up control of their personal phones in exchange for the privilege of using them for business.

Where is your CU investing in BYOD? Mobile containers or MDM?

Monday, November 12, 2012

imsmartin presents identity theft trends and protections

Sean Martin, CISSP, and founder of imsmartin consulting, presented to a group of over 100 attendees during the Firefighter's National Credit Union Summit. The group represents the growing National Coalition of Firefighters Credit Unions.

Image source: Advioso
Identities are at the core of nearly everything that takes place within a credit union. And, with the number of fraudulent attempts to use a stolen identity increasing dramatically, credit unions must take a good hard look at how they are managing their members' and employees' identities - including the transaction auditing and access control mechanisms surrounding them.

In his presentation, Martin covered the following topics:
  • Identity theft trends
  • Detecting identity-based fraud
  • Tips for consumers
  • Tips for credit unions

Fill in the form at Advioso to obtain a copy of the presentation, along with a few identity theft protection whitepapers from content sponsors TeleSign, Guardtime, and CSID.

Cryptography attack: side-channel cloud threat is all nerd and no knickers

Side-channel attacks are nothing new. Their arrival in the cloud, or rather the potential for a side-channel approach to touch the cloud threat surface, most certainly is though; but is it something you need to worry about?

Image source: Article
In order to answer that, you first have to get your head around what a side-channel attack actually is.

Is the cloud safe from side-channel attacks on crypto keys in a real world scenario or not? Good question. The researchers suggest that there is room for a potential breach within the imperfect isolation of VMs found in public clouds, and advise that 'highly sensitive workloads' should not be stored there.

Without spoiling the article, side channel attacks could threaten cloud security in a big way. It's best to be prepared. Read the article to start getting prepared.

Friday, November 9, 2012

The Day A Computer Virus Came Close To Plugging Gulf Oil

The Shamoon scenario could repeat again with financial companies.

Image source: Article
“If this would happen to the three biggest banks in the U.K., all of their systems went down, all of their servers went down, [it would] mean that people can’t see their bank account online anymore, so they don’t know whether or not they still have money anymore. All the ATMs have a blue screen,” says Schenk.

Is your CU safe from these types of attacks?

Read the article to find out if you are prepared.

'There's an App' for Legal Teams

The catchphrase for the mobile lawyer? "There's an app for that." That may be true, but finding it and making it work for you or your law firm is a journey where law firms should let technology drive the business model.

Image source: imsmartin
This article captures the most presented and discussed applications used by lawyers — specifically looking at them from the perspective of lawyer mobility.

While there are thousands of commercial apps available, the next big wave is in the form of custom apps.

Is your CU building its own apps? Are you building them for your lawyers? Read the article to learn more about a few mobile development platforms.

Security Debate: On-premise or in the cloud?

There are many things that are easier to do in the cloud, but is security one of them?

Image source: Article
Proponents argue that basing security tools in the cloud provide all the benefits of any cloud-based resource, including low cost of entry, simplicity of maintenance/upgrades, etc.

But critics say not so fast. Getting security is hard enough when you control all the resources. Moving them to the cloud just further complicates the job.

Read the article to get these experts' opinion in this Network World Tech Debate.

Guidance on Cloud Security

The banking and financial sector with its strict regulations and need for high security, had always been seen as the last sector, to adopt cloud computing.

Image source: Article
Prior to embarking into cloud computing, organisations must consider a number of threats.

A number of factors also need to be taken into consideration when choosing the proper software security for cloud computing.

This article captures both lists.

Thursday, November 8, 2012

End-users admit ignorance of corporate cloud policies

Already tested by the BYOD movement, security-conscious IT admins are increasingly forced to cope with employees exposing their organization to security risks and unforeseen expenses by signing on to unauthorized cloud services.

Image source: Article
This includes storing customer records on Dropbox, enlisting Amazon Web Services to test beta code, or creating and sharing sensitive documents via Google Docs.

A new study from Symantec titled "The Myth of Keeping Critical Business Information Out of Clouds" points to the chasm between users and IT admins over access to cloud applications.

Read the article to see the survey results.