Infosec 2009
Posted by The Cynic in Blog, Uncategorized on March 29, 2009
Speak to anyone born before 1975 and they’ll harp on about ‘the good old days’ and how the younger generation of today have everything too easy.
Naturally, being born after 1975, I disagree with the viewpoint. Take education for example. In the olden days you packed kids off to whichever boarding school was furthest from where [...]
Quizzing the recruiter – an interview with Ruth Jacobs
Posted by The Cynic in Interviews, Uncategorized on March 20, 2009
Barclay Simpson (www.barclaysimpson.com) is the leading company in corporate governance recruitment in the UK, and was established in 1989. Ruth Jacobs is an Information Security Recruitment Consultant with Barclay Simpson.
Like most security professionals, my contact with recruitment consultants is limited to times when I am looking for a new job, so I decided to reverse [...]
Ross Anderson does it again
Posted by The Cynic in Blog, News, Uncategorized on March 19, 2009
In what is becoming an attention-grabbing ‘look at me’ trend, Ross Anderson, the much-famed Professor of Security Engineering at Cambridge University has added to his ongoing list of entertaining gripes and accusations, the good Professor has stated that the dedicated cheque and plastic fraud crime unit is funded by banks!
Apparently having banks part fund an [...]
Aunties Botnets
Posted by The Cynic in Uncategorized on March 17, 2009
The British Broadcasting Corporation (BBC) is the world’s largest broadcaster. Having a budget of more than £4 billion, its no wonder there’s little they can’t do in persuit of the greater good.
So, unsurprisingly the BBC would cover the rise in cybercrime. However, as part of their investigation and subsequent program “click” the BBC purchased a [...]
We’re safe, it’s covered it in our policy
Posted by The Cynic in Blog, Uncategorized on March 13, 2009
So apparently the courts have deemed it fine to release a labour peer from jail, even though he was texting on his mobile whilst travelling on the motorway, had a crash and killed 28 year old Martyn Gombar.
Of course, what else would you expect from a country who bought you such lovelies as Garry Glitter, [...]
Privacy Vs security Vs make me famous
Posted by The Cynic in Blog, Uncategorized on March 6, 2009
It gets quite scary when the Government admits that it will cross all moral boundaries in order to prevent those terrorist networks with sleeper cells living right next door to you.
There have been many column inches and heated debates devoted to the security versus privacy argument. How much privacy are you willing to give up [...]
Tips on stamping out Data Leakage & Industrial Espionage during a Recession
Posted by Mark Fullbrook in Guest Column, Uncategorized on March 2, 2009
At a recent monthly gathering of both good and bad hackers in a dingy pub in Leicester Square, I asked them whether the economy was opening up new opportunities for them. The response was an overwhelming yes, with nearly everyone saying that the cut backs had caused jobs to be outsourced and, with less folks [...]
Into the Cloud we go…..have we thought about the security issues?
Posted by David Hobson in Guest Column, Uncategorized on February 26, 2009
A new shift in computing is upon us – Cloud Computing. As our use of computing resources evolves from mainframes to PC’s and networks we are now facing a major shift in the way we work. This could have dramatic effects on the way we use our computers, both for work or play. But the [...]
Toxic information
Posted by The Cynic in Blog, Uncategorized on February 23, 2009
Amongst banks going bankrupt and the economy ever-spiralling downwards, the one thing you can bet on will happen all the time is data loss. Whether it be a payment firm being breached, a retailer with an unsecured network, or employee’s walking out of the office with gigs worth of company sensitive information.
On the flip-side, amidst [...]
Another payment firm breached
Posted by Ifra in News, Uncategorized on February 23, 2009
The Tuscaloosa Federal Credit Union and the Pennsylvania Credit Union Association have both warned that a payment processor other than Heartland has suffered a network intrusion. DataBreaches.net first reported the confirmations.
“While it has been confirmed that malicious software was placed on the processor’s platform, there is no forensic evidence that accounts were viewed or taken [...]
Three Arrested in Heartland Data Breach
Posted by Ifra in News, Uncategorized on February 16, 2009
Three men in Florida were arrested earlier this week on multiple charges of credit card fraud, and some of the card numbers they allegedly used are tied to the Heartland hack.
The Leon County, FL. Sheriff’s office arrested area residents Tony Acreus, Jeremy Frazier and Timothy Johns, who had allegedly used stolen credit card numbers since [...]
What happens when you lose a CD
Posted by The Cynic in Fun, Uncategorized on February 14, 2009
Between the time a company or government agency loses a cd with a gazillion records of individuals on it and it turning up on the front page of your local newspaper what do you think happens?
Looks like they dedicated a whole film to this subject!
IT Governance Institute Seeks Public Comments on New Risk IT Framework
Posted by Ifra in News, Uncategorized on February 12, 2009
The nonprofit, independent IT Governance Institute is seeking public comment on its new IT risk framework, which is based on the globally recognized COBIT IT governance tool set. Comments on Enterprise Risk: Identify, Govern and Manage IT Risk: The Risk IT Framework (Risk IT) will be accepted through 13 March 2009 at www.itgi.org
While COBIT (Control [...]
White Hat Hacking – An Interview with Marcus Pinto
Posted by Simon in Interviews, Uncategorized on February 11, 2009
Next Generation Security Software ( NGSS , www.ngssoftware.com) is a leading software security firm, with a broad range of clients in the private and government sectors. Marcus is a qualified CHECK team leader with NGSS, and co-author of The Web Application Hacker’s Handbook: Discovering and Exploiting Security Flaws ( John Wiley & Sons, 2007).
Like many [...]
Return on Security Investment
Posted by The Cynic in Blog, Uncategorized on February 8, 2009
Being a man, I have to make blow everything out of proportion when it comes to little aches, pains, headaches and man-flu’s. More often than not, I’ve gone to the Dr. convinced that some bone is fractured into small fragments and that I’ll need bolts and cables to repair them only to be told its [...]
Laundered USB sticks
Posted by The Cynic in Blog, Uncategorized on January 21, 2009
It appears as if USB memory devices are one of the most useful yet dangerous tools ever developed.
Freeing people from the labour of carrying boxes filled with 1.4″ floppy drives, being capable of sharing songs, photos, documents and presentations with ease have made memory sticks very popular.
On the flipside, company’s sometimes use these small, easy [...]
The shadows of security
Posted by The Cynic in Blog, Uncategorized on January 15, 2009
These days if you lift up a rock in your garden, you’ll find fifty different types of infosec types crawling around.
You have the consultants, the IT guru’s, the managers who are neither consultants or IT gurus. In addition you have sub-divisions such as forensic analysts and penetration testers. Or parallel streams as auditors, assurance, risk [...]
Security – the human factor
Posted by Paul Kearney in Guest Column, Uncategorized on January 12, 2009
Protecting a business is as much to do with ‘human factors’ as it is with the IT department, argues Paul Kearney, Head of Enterprise Risk Research at BT Group.
Much can be learned from history. Take, for example, the Trojan Horse – a contraption that was received as a gift during the siege of Troy but [...]
Ahoy there windows 7 Pirates!
Posted by The Cynic in News, Uncategorized on January 6, 2009
Apparently pirate copies of Windows 7, the new Microsoft operating system has leaked onto the P2P file-sharing side of the internet
“Reports suggest that pirate versions of an early build of Windows 7, which is under alpha test with developers, is available for file-sharing on the Internet. Given the low level at which this operating system [...]
2009 the year of information security
Posted by The Cynic in Blog, Uncategorized on January 5, 2009
So it’s the beginning of 2009 and most people are either struggling re-adjusting to work after the holidays or wishing they hadn’t made those over-ambitious new year resolutions.
Well rather than doing the infosec resolutions for 2009, I thought I’d do something far more interesting and write a risk forecast for the upcoming year.
Now I know [...]

