# BrainWave Consulting Company, L.L.C. > ​ Providing Managed Services, CyberSecurity and Compliance for the SMB Market ## Posts - [FileHash v5.4: Parsing webpages for hashes](https://brainwavecc.com/blogs/filehash-v5-4-parsing-webpages-for-hashes/): FileHash v5.4 has recently been released, and we’ve added some URL parsing to find hashes that can be compared to existing files via the -y and –hl parameters Instead of having to manually obtain the checksums for files you want to compare, before you can use the appropriate FileHash parameter, you can now perform the validation against the checksums found on webpages directly.  This is great for any manual or automated process you’re using, such as when you download your favorite Linux ISO, and want to make sure your download has the correct checksum. If you just want to see […] - [FileHash: Major Update v5.0](https://brainwavecc.com/blogs/filehash-major-update-v5-0/): FileHash v5.0 has just been released, and it comes with a focus on making it easier to automate the following two things: A couple of these features (-g and -x, in particular) have been requested by different users for a while, and I was finally able to pursue their implementation. Let’s take some time here to review a few of those intended use cases, and see how the many available FileHash options come into play. Remember, while FileHash can absolutely be used on a one-off, ad hoc basis, the real reason I developed it was to facilitate automation that I […] - [Increased Vigilance is Strongly Recommended](https://brainwavecc.com/blogs/increased-vigilance-is-strongly-recommended/): There is every indication that businesses and networks in Western countries are very likely to face increased cybersecurity attacks in the near- to mid-term. Here are some things to consider and for the protection of personal and commercial networks (to include those of schools and churches). The geopolitical realities of our planet have a bearing on our personal and corporate cybersecurity posture, and there is credible evidence to suggest that things are going to be a bit rough for a while. While it is true that very few entities can thwart a direct and dedicated attack from a well-funded attacker, […] - [Protecting and Recovering Your Social Media Accounts](https://brainwavecc.com/blogs/protecting-and-recovering-your-social-media-accounts/): The number of cybersecurity attacks against social media accounts is rapidly increasing, and attackers are often successful in preventing recovery of the accounts, resulting in victims having to totally abandon their former accounts. Here are some steps that should be taken to reduce the risk of a successful attack against your social media account. Cyberattacks against social media accounts are nothing new, but for a variety of reasons, they are becoming more prolific than ever before. It used to be fairly easy to recover from an attack, but as attackers increase their sophistication, victims are frequently finding themselves having to […] - [CyberSecurity 102 for Small Businesses](https://brainwavecc.com/blogs/cybersecurity-102-for-small-businesses/): Phase 2 of the essential cybersecurity steps that small business owners need to consider and implement in 2021 and beyond… - [CyberSecurity 101 for Small Businesses](https://brainwavecc.com/blogs/cybersecurity-101-for-small-businesses/): An introduction to the essential cybersecurity steps small business owners need to consider and implement in 2021 and beyond… - [Yes, You Need to Understand Technology Architecture](https://brainwavecc.com/blogs/yes-you-need-to-understand-technology-architecture/): As a business owner, you are also a data owner, and it is likely that you leverage a fair amount of technology in your business operations. You absolutely need to understand enough about data management and data security in order to make good decisions for your business, its employees, and its customers. - [Preparing for 2021](https://brainwavecc.com/blogs/preparing-for-2021/): Today, I'm going to look at a few personal-level cybersecurity and data privacy items that should be on everyone's list for 2021 preparation. - [SyslogTally: Grabbing Summary Information from Common Syslog Applications](https://brainwavecc.com/blogs/syslogtally-grabbing-summary-information-from-common-syslog-applications/): This past month, I put together a new utility, SyslogTally, because I needed to easily and quickly answer a question pertaining to how frequently various scripts were being used in my environment. Original Need This question about script usage frequency first arose back in June 2020, while trying to identify which scripts should be considered core to the BrainWave Scripting Repository, and which should be considered more ancillary. I determined that one of the easiest ways to establish a definitive answer would be to setup a local syslog server on a typical system, and then modify a core script (SetDrive.BAT) […] - [FileHash: The Quick and Dirty File Integrity Checker](https://brainwavecc.com/blogs/filehash-the-quick-and-dirty-file-integrity-checker/): Once upon a time, I needed to get a quick and dirty file integrity checking process in place for Windows systems so that we could meet a customer compliance requirement that was growing more and more popular. FIM – File Integrity Monitoring At the time, we were evaluating more expensive options like solutions from Tripwire and LogRythm, and we were looking at open source options like OSSEC. While waiting on testing and budget approval and inevitable implementation time, I put together a script which was initially based on Microsoft’s free FCIV utility.  It ran once a day, and generated sufficient […] - [Putting Off the Inevitable](https://brainwavecc.com/blogs/putting-off-the-inevitable/): There’s a saying in project management that been attributed to Jack Bergman, “there’s never enough time to do it right the first time, but there’s time to dot it over.”  Sadly, many leaders and organizations appear to operate by this maxim. According to a report by ZDNet, somewhere between 200,000 and 240,000 online stores running Adobe’s Magento v1.x technology will reach end of life in June 2020. Why is this a problem?  Well, when a vendor solution gets to End of Life (EOL), it no longer gets any code fixes or other support.  And given that eCommerce sites are notoriously […] - [Learning Lessons from the Avast Breach](https://brainwavecc.com/blogs/learning-lessons-from-the-avast-breach/): Those who fail to learn the lessons of history are destined to repeat them.  Don’t be that organization…  Back in September of 2017, Avast indicated that the network of its recently acquired (July 2017) subsidiary had been infiltrated, and  that its CCleaner application had been compromised.  The compromise, at that time, was first discovered by Cisco, by way of their Talos security team. Earlier this month, Avast admitted that hackers had been able to breach its network again, most likely in pursuit of infecting CCleaner again. There are some important things that should be learned, certainly by Avast, but also […] - [My Kingdom for a Date/Time Manipulator](https://brainwavecc.com/blogs/my-kingdom-for-a-date-time-manipulator/): Of all the console utilities that I have written to support my systems automation endeavors, my first, favorite, and most extensively used utility is: DATEINFO.EXE. Over the years (decades), I have developed many Windows Shell scripts which needed to be able track time backwards and forwards.  Natively, that was cumbersome.  Thankfully, I ran into a utility DOFF.EXE which proved to be very valuable, and I made extensive use of it for a number of years. DOFF had a few limitations of its own, such as only calculating offsets as +/- days, not weeks, months, or years.  (Yes, years is easy, […] - [Spy vs Spy: Key Lessons for Businesses about Cybersecurity](https://brainwavecc.com/blogs/spy-vs-spy-key-lessons-for-businesses-about-cybersecurity/): A few weeks ago, I read an article that provided significant insight into the Spy vs Spy battles between the Unites States and Russia. Title: Russia carried out a ‘stunning’ breach of FBI communications system, escalating the spy game on U.S. soil It was one of the few times in recent months that the headline of an article actually managed to be accurate and not just super-sensational or click-bait. More importantly, however, the article provides lessons that can, and should, be learned by businesses small and large.  It is important for us to realize that these nation state spy games are […] - [To Infinity and Beyond](https://brainwavecc.com/blogs/to-infinity-and-beyond/): Ransomware is skyrocketing – but we really shouldn’t be surprised.  In fact, many in the cybersecurity community saw it coming. To set the tone for what I’m talking about, here are just a few of the recent headlines pertaining to ransomware:   https://www.cnbc.com/2019/08/19/alarm-in-texas-as-23-towns-hit-by-coordinated-ransomware-attack.html https://arstechnica.com/information-technology/2019/08/ransomware-wiper-malware-attacks-have-more-than-doubled-ibm-team-says/ https://venturebeat.com/2019/08/07/vectra-ransomware-attacks-are-spreading-to-cloud-data-center-and-enterprise-infrastructure/ https://www.govtech.com/security/Why-School-Systems-The-Rise-of-Ransomware-in-Public-Schools.html https://www.nytimes.com/2019/08/14/opinion/ransomware.html   I had to go to page 4 of the Google search to get to news from two weeks ago (August 7th).  The following quote from the NY Times article is very telling: But every time a victim pays hundreds of thousands of dollars to a cybercriminal, the payment reinforces the criminals’ faith in […] - [Are breaches really inevitable?](https://brainwavecc.com/blogs/are-breaches-really-inevitable/): Lately, we have been hearing a steady refrain concerning cybersecurity: “It is impossible to guarantee security. Breaches are inevitable.” Is it really so because it is asserted with authority and confidence?  Is it so because it is oft repeated? Inevitably, we are humans, and so our ability to guarantee anything concrete and enduring is similar to our ability to guarantee our own individual existence.  In the sense that I cannot even assure myself that I will be alive tomorrow, or in a week, I can agree that I cannot ensure that my network won’t be breached.  Fine.   So, is that the […] - [On Vulnerabilities and Reporting](https://brainwavecc.com/blogs/on-vulnerabilities-and-reporting/): This past week I read a pretty interesting article, posted on SiliconANGLE, about vulnerabilities found in cloud applications. It had the unfortunate title of: Report finds 34M vulnerabilities across AWS, Google Cloud and Azure This was compounded by the lead off sentence, which is as follows: A new report from Unit 42, the threat intelligence team at Palo Alto Networks Inc. has uncovered 34 million vulnerabilities across leading cloud service providers, highlighting that organizations are struggling with securing cloud installations. The Palo Alto report upon which this article is based, and which you can read here, had a lead sentence that was much more […] - [Webinar: Keeping Secrets Secret](https://brainwavecc.com/blogs/webinar-keeping-secrets-secret/): Join me on a webinar about managing secrets such as passwords, encryption keys, API keys, etc. July 17, 2019 – Keeping Secrets, Secret! How to Manage Highly Sensitive Data to Protect Your Organization https://www.drj.com/webinars/schedule/july-17-2019-keeping-secrets-secret-how-to-manage-highly-sensitive-data-to-protect-your-organization.html - [Lurking Behind the Scenes](https://brainwavecc.com/blogs/lurking-behind-the-scenes/) - [Intel CPU vulnerabilities continue...](https://brainwavecc.com/blogs/intel-cpu-vulnerabilities-continue/): Intel continues to have security issues — this one affects MacBooks as well… Also… https://www.wired.com/story/intel-mds-attack-speculative-execution-buffer/ Patches are available, however… On the other hand, AMD is doing very well right now, being implicated in only one of the more than 6 CPU vulnerabilities over the past year+ - [Virtual Credit Card Numbers](https://brainwavecc.com/blogs/virtual-credit-card-numbers/): If your bank supports it, you would do well to consider Virtual Credit Card numbers for online purchases. I was looking around for some good articles that discussed potential pitfalls or problems and found this gem of an article.  Suffice it to say, that the best part of this article is the comments. - [Whose data is it, anyway?](https://brainwavecc.com/blogs/whose-data-is-it-anyway/): It’s not just that we are experiencing big firms getting breached due to sheer negligence, but that no one is going to do anything about it — yet we the people will suffer. First Equifax, then Deloitte. Not only does it appear that the reasons for the breaches were egregious, but the responses thus far have been criminally negligent. [No, I’m not a lawyer, nor do I play one on TV] Until the United States changes it perspective about user data, so that it forces the businesses to get permission from individuals to access financial, health, and other sensitive personal […] - [A look at Microsoft’s SIR v14](https://brainwavecc.com/blogs/a-look-at-microsofts-sir-v14/): So…. I finally had a chance to finish reading the latest full edition of Microsoft’s latest Security Intelligence Report. There’s a lot of really good info in the report. The executive summary also does a good job of highlighting key points.  That said, I had a couple of observations of my own that others might find interesting. Systems Management Overall, the data led me to conclude that people who keep their operating systems up to date – whether we are talking versions or patches/service-packs – are more likely to pay attention to other aspects of security, such as malware protection. While […] - [Dueling Business Mindsets](https://brainwavecc.com/blogs/dueling-business-mindsets/): If there is one lesson that technologists need to understand in order to be successful, it’s that business is ultimately more about people than about process or technology.  At the end of the day, how people think, behave and operate will have be the greatest influence on the success of any organization. With that said, it has been my observation that every single business operates in two contexts or modes.  For now, we’ll call them Mode 1 and Mode 2, where Mode 1 is the normal or typical mode of operation, and Mode 2 is the mode of operation in or around the timeframe of “an incident.” From a technology perspective, […] - [Wise Security Investment Approaches](https://brainwavecc.com/blogs/wise-security-investment-approaches/): A holistic approach to information security needs to address a corporate strategy for buying or building solutions. Such a strategy will have an impact on how a company looks at staffing and technology investments. There are two basic ways to look at major investments of information technology and information security: you can buy or you can build. Option A: The BUY model In this model, an organization selects industry standard tools and technology, and aims to hire above-average to guru-type employees who will integrate the technology into the corporate environment. The staff is reasonably interchangeable in this model, although technology costs are on […] - [The Futility of Blaming IT](https://brainwavecc.com/blogs/the-futility-of-blaming-it/): In recent years, it has become popular sport to blame information technology (IT) departments and IT leaders for failures – real or imagined – which adversely impact business operations.  Even some technology trade journals seem unable to get through a single issue without finding some point upon which to lambast a CTO or CIO for not “stepping up to the plate”, or adding value, or some other business sin. This trend was clearly seen in two recent articles on InformationWeek (6 Ways IT Still Fails The Business and 5 Ways Business Still Fails IT), the first of which generated a firestorm of […] - [Reading Between the Lines of Breach Notifications](https://brainwavecc.com/blogs/reading-between-the-lines-of-breach-notifications/): Back in September 2012, I wrote two articles for Point2Security on how to effectively handle breach notifications: The Who of Post-Breach Communication Post-Breach Communication: The Importance of How & When Sadly, to many organizations are doing something entirely different when it comes to post-breach notifications. I like to take the time to read various breach notifications and see if I can get additional clues from what is said and how it has been said. Let’s take a couple of recent examples and see what we can find: South Carolina Department of Revenue Breach South Carolina Governor Blames IRS Data Breach […] - [Get Real with Information Security](https://brainwavecc.com/blogs/get-real-with-information-security/): In 2012, the writers of malware and the attackers of networks were very busy, using both social engineering and increased technical sophistication to fuel an increased number of attacks. Not incidentally, mobile devices just flew off the shelves this year, with predictions that over 122 million tablets and some 717 million smartphoneswill have been sold when the tally for 2012 is complete. Quite a few of those devices were connected to corporate networks, and even more will be connected next year.  Cloud computing is real. Bring Your Own Device (BYOD) is real.  Businesses are trying to do more with less, and […] - [Job Hunting: It’s All About Relationships](https://brainwavecc.com/blogs/job-hunting-its-all-about-relationships/): Earlier this week, I read an article about unemployment and the struggles of those coming out of college and graduate school who are seeking jobs. A surprising number of people were simply spouting the rhetoric that people who don’t have jobs are simply lazy and feeling entitled. May God have mercy on those who posted, such that they never have to be out of work in this economy.  The whole planet is not divided into Lazy and Successful.  At least some of the people who are successful (or deemed so by society) are quite lazy, and some of the hardest […] - [Securing Your Storage - Part 1](https://brainwavecc.com/blogs/securing-your-storage-part-1/): If you’re going to make use of cloud-based storage, it is a good idea to ensure that you keep it secure.  Unless you are absolutely, positively certain that you will never, ever put anything in there that you wouldn’t want to find in a public place, you’re going to need to consider encryption. Even if you don’t care about the data, you should really be looking at encryption options. I’m currently using storage from DropBox, Box.com, SugarSync, SkyDriveand (as of a couple days ago) SpiderOak.  And, no, I don’t have GoogleDrive, nor do I plan to get it.  They’ll have to settle for my Google+, GMail and […] - [I’m Tired of Registration Walls](https://brainwavecc.com/blogs/im-tired-of-registration-walls/): Note to the heads of sales, marketing, and web site development: I’m tired of your registration walls (regwalls), and will no longer be supporting them. I realize that you want to know who is looking at the materials you are producing, that you are trying to measure the ROI of your promotional endeavors, and that you are seeking for any and every means to monetize the interactions you have with existing and potential customers.  I get all that, butI’ve had quite enough, thank you.  I do NOT want to sign-up or register on yet-another-website before I can actually get access to […] - [So, You Want To Be a Technology Consultant?](https://brainwavecc.com/blogs/so-you-want-to-be-a-technology-consultant/): Doesn’t everyone want to be a consultant? Probably not…  There are some clear advantages to working for yourself, and there are some clear disadvantages. Likewise, there are some PROs and CONs of working for someone else, and it for each person to determine for himself if consulting is right for him.  The only question I am trying to answer today is how to enter the realm of technology consulting for those who might be so inclined. Yes, there is more than one way to become a successful technology consultant. I’m not here to suggest or provide any magic formulas, but […] - [Managing Your Personal Security](https://brainwavecc.com/blogs/managing-your-personal-security/): In the past few days, we learned that Global Payments Inc, a middle-man credit checking company, suffered a breach of its systems starting in January of this year.  It has been speculated that up to 10 million card holders might be at risk. Even with the growing trend of these types of attacks, your personal security both online and offline is still heavily dependent upon your own behavior.  The sites you visit, your personal account management and password policies, and the data you post online can all help or undermine your personal security. There has been quite a bit of noise about […] - [The Privacy and Security Implications of Misusing Technology](https://brainwavecc.com/blogs/the-privacy-and-security-implications-of-misusing-technology/): If you haven’t already heard of Carrier IQ, you need to do some serious web searching, as they are swiftly becoming the new name in technology misuse on a massive scale. Over 6 years ago, Sony installed a rootkit with their music software in the name of Digital Rights Management.  On some level, they have never recovered from the consumer backlash that followed, and many were supremely gratified to see them suffer one of the most extensive network break-ins on record earlier this year. Well, the folks at Carrier IQ (CIQ) have greatly expanded on Sony’s misuse of technology, and the implications are only now being assessed.  […] - [My Workplace Technology Wish List](https://brainwavecc.com/blogs/my-workplace-technology-wish-list/): It is not every day that one gets an opportunity to put together a wish list of technology solutions that could be used to drive a modern, highly productive workplace. So, let’s begin our If Money Were No Object quest… Every office has desktops and notebooks, and they’ll continue to be useful for quite some time. To make them even more useful, we’d equip all of our systems with solid state drives (SSDs) and hybrid drives using SSD technology, such as those from OCZ Technologies. The reduction in boot times and application load times will more than pay for the technology over the life of these […] - [Guess What? Technology is not easy](https://brainwavecc.com/blogs/guess-what-technology-is-not-easy/): It might seem that way because of how ubiquitous it is, but technology is not really easy.  Lots of time has been spent trying to hide the core complexity so that every day users can better experience and manage high-end technology, but at the end of the day, the complexity remains somewhere. We’re almost at the end of 2011, and the two things that stand out to me from a technology standpoint are: The magnitude of information security issues that were surfaced this year The magnitude of infrastructure and service outages that were manifested this year And don’t think that […] - [Effectively Managing Risk](https://brainwavecc.com/blogs/effectively-managing-risk/): Despite the significant uptick in information security events on display thus far in 2011, and despite the diversity and caliber of organizations that are being breached, it seems that too many organizations are failing to learn the lessons of the victims. More than that, it appears that when confronted with risks that require assessment, the vast majority of organizations (and their leaders) are unable to accurately make a valid assessment.  They either downplay the likelihood of the risk, or they are paralyzed by the thought of it.  Both attitudes tend toward inaction. Consider how the Japanese downplayed any real risk […] - [To Disclose or not to Disclose](https://brainwavecc.com/blogs/to-disclose-or-not-to-disclose/): …that is the question. Every time a software vendor experiences a vulnerability or releases patches for a serious security issue, the debate about Full Disclosure or Responsible Disclosure gains a little more steam. Just how much information should a vendor disclose about the nature of the vulnerability that it has identified, and how that vulnerability can be exploited? Many vendors take the position that to disclose details about the information puts their customers at risk, as the bad guys can make better use of the details to exploit the vulnerability.  On the other hand, many security professionals point out that […] - [Just ask Sony…](https://brainwavecc.com/blogs/just-ask-sony/): Why should you take your organization’s information security posture seriously? Just ask Sony.  It has been estimated that Sony will spend more than $170 million dollars due to the recent breaches they have suffered.  Personally, I think that the $170M figure is too conservative.  I expect it to get much closer to $300M than $170M. Information Security threats and attacks are rapidly growing in sophistication. Over the years, I have made several posts about the dangers of poor security, each time hoping that the trend with shift from negligence and reactivity to diligence and proactivity.  Alas, I’m still waiting. Here is a synopsis of […] - [Managing Technology-based Risks](https://brainwavecc.com/blogs/managing-technology-based-risks/): Risks exist. You would think that this is so obvious as to not need saying, but too many people appear to operate as though downplaying or ignoring risks have any impact on their reality. That sign announcing “bridge out” isn’t really concerned with how much you believe it or agree with it.  It doesn’t care if you are too busy to deal with it.  All it knows is that unless you happen to be flying by in a plane or helicopter at the time that you read it, it does apply to you.  (It might even apply to you if you are in […] - [Reactive Security: Feel the pain in 2011+](https://brainwavecc.com/blogs/reactive-security-feel-the-pain-in-2011/): We are only one third of the way into 2011, but we have had some of the largest information security breaches of the decade – and the trend does not appear to be slowing down. Here are just a few of the biggest reports for the year: http://www.eweek.com/c/a/Security/RSA-SecurID-Breach-Shows-Why-Everybody-Must-Stay-Vigilant-595858/ http://www.reuters.com/article/2011/04/26/us-sony-stoldendata-idUSTRE73P6WB20110426 http://www.securityweek.com/massive-breach-epsilon-compromises-customer-lists-major-brands http://www.eweek.com/c/a/Security/Anonymous-Attacks-HBGary-Federal-Steals-Corporate-Email-582234/ http://spectrum.ieee.org/riskfactor/computing/it/health-net-data-breaches-affects-19-million-people These attacks are coming so fast and furious, that people don’t have time to digest the impact of the first one before the next one is upon them. For example: Only a few weeks have passed, but for most people, the Sony Playstation Network breach has completely overshadowed the […] - [Maintaining Good Security Practices](https://brainwavecc.com/blogs/maintaining-good-security-practices/): Security is not just a state of being. We are often called to provide an assessment about our present security posture, and usually, the person asking the question is doing so within a very narrow context – one that the may or may not have shared with you. Answering such a question is difficult at best. Imagine walking up to your doctor and asking, “Doc, am I healthy?” If your doctor can answer that without examining you, then one of the following might be true of you and your doctor: you simply have an awesome doctor your doctor that has […] - [Why Your New Technology Purchase Might Disappoint - Part 2](https://brainwavecc.com/blogs/why-your-new-technology-purchase-might-disappoint-part-2/): Last time, I mentioned that inadequate planning is one of the key reasons why your new technology purchase might prove to be disappointing.  This is true not only of planning that occurs once the project has been authorized and assigned an official “Project Manager”, but it also refers to the planning that is used to determine the validity of projects themselves.   The earlier you begin to have problems with planning, the greater the potential pain. It’s time for the second of five principle reasons why many businesses fail to derive the value they could otherwise obtain from their technology investments.  Reason […] - [Why Your New Technology Purchase Might Disappoint](https://brainwavecc.com/blogs/why-your-new-technology-purchase-might-disappoint/): Technology continues to provide many benefits for individuals and businesses, and our increasing dependence upon it is a testament to its overall usefulness.  Each day, many, many people make a good living from designing and deploying business solutions which are based on some technology. That said, many businesses fail to derive the value they could otherwise obtain from their technology investments.  There are five (5) principle reasons why this occurs, which I will attempt to cover in a series of articles. Reason #1: Inadequate Planning Despite all the books and articles that have been written on this topic, this problem […] - [The Dangers of Consolidation](https://brainwavecc.com/blogs/the-dangers-of-consolidation/): It has been said that technology in general, and automation in particular, simply make it easier for humans to propagate errors much faster than they could otherwise do so. This morning, I awoke to find that none of my scripts – on any of my machines – had executed overnight.  Hmmmm?!? Initially, I only thought that it was two scripts that I had updated the night before, because those where the logs that I was checking.  And, of course, I had only tested them peripherally, as the changes were relatively minor. Well, it didn’t take more than a couple of minutes to […] - [It’s The Little Things That Get You Every Time…](https://brainwavecc.com/blogs/its-the-little-things-that-get-you-every-time/): Even on the smallest of networks, the failure to pay attention to every detail can make a routine upgrade or migration far more complicated than it needs to be. This year, I’ve had an above average number of mail server related incidents, but in many cases I made things worse by overlooking something small. For instance, there were at least 3 times where something had gone wrong with my mailing list server, and I could have solved it in a few minutes before I left home, but didn’t check until I had gotten to work.  (It doesn’t help that my monitoring […] - [The State of Data Breaches in 2010](https://brainwavecc.com/blogs/the-state-of-data-breaches-in-2010/): I had a chance to review the 2010 Verizon Data Breach Report today, which I was alerted to by ISC.SANS.ORG.  They’ve put together data from 2004 through 2009, and it is quite interesting. These are from confirmed data breach cases. Here were 3 of the scariest stats in the document: 86% of victims had evidence of the breach in their log files 96% of breaches were avoidable through simple or intermediate controls 79% of victims subject to PCI DSS had not achieved compliance In short, 4 out of 5 organizations that were supposed to be compliant with one particular regulation were not.  […] - [It’s Time to Re-evaluate Host-based Security](https://brainwavecc.com/blogs/its-time-to-re-evaluate-host-based-security/): I’ve said it for a few years now, but host-based antivirus is really not working out anymore.  Not with its reliance on signatures to detect malware. Recently, several prominent antivirus vendors have experienced problems with faulty virus definitions:  Faulty McAfee update burns IT execs BitDefender update breaks 64-bit Windows PCs [Clamav-announce] problem with daily.cvd 10938 100% CPU usage with VIPRE definitions 6272 – 6274   Although all of these vendors have promised the obvious improvements to their QA and testing processes (and I have no reason to believe that they are insincere), there is no sign that these problems will diminish […] - [Making Business Sense](https://brainwavecc.com/blogs/making-business-sense/): Long ago, in days or yore, it was common to complain that most information technology leaders and staff were too focused on deploying cool technology just for the sake of technology rather than ensuring that there was valid business justification for what they evaluated and implemented.  CIOs and IT leaders were told to learn the language of the business and focus on things like Return on Investment (ROI), productivity improvements, cost control and revenue enhancement. I’m not here to say that this was a bad thing.  In fact, I have to admit that quite a lot of good has come […] - [The Job Hunting Conundrum](https://brainwavecc.com/blogs/the-job-hunting-conundrum/): Based on a number of surveys taken since the recent economic downturn began, it would appear that there is a fairly substantial disconnect between how employers and employees view the job market and the joys of employment. Within the past two years, many business owners and leaders have made decisions to control their organizations costs in ways that favor themselves over their employees.  The reasoning appears to be that those employees which have not been downsized are only too happy to have *some* employment, and thus will tolerate almost any treatment in the workplace. However, as a USA Today article from August 2009 […] - [Expanding Your Reach with Good Technology Partners](https://brainwavecc.com/blogs/expanding-your-reach-with-good-technology-partners/): I recently read an opinion piece on ComputerWorld about the post-Cloud IT landscape, and it I had a couple thoughts: The author makes a good point that little mention is made of what the world will look like when cloud is the norm… We (both business and technology folks) spend a lot of time focusing on the flavor of the day, and not enough looking at the bigger trends… For years, the pendulum has been swinging between outsourcing and insourcing – between local enterprise computing and remote computing – and this trend will not stop anytime soon.   Here is how the trend tends to play […] - [Charting the Right Course: The IT Manager’s First 90 Days](https://brainwavecc.com/blogs/charting-the-right-course-the-it-managers-first-90-days/): Starting a new position is always an interesting challenge, especially if you have a leadership role.  It should go without saying that it is very important to start things off on the right foot.  While it is possible to recover from all but the most egregious of mistakes in the early going, you really want to take advantage of whatever honeymoon period you have been granted (implicitly or explicitly), and set the groundwork for future success. Simply put: A good start gives you a tremendous advantage over a bad one. This is a long post, but should prove useful even if […] - [Timely Breach Disclosure](https://brainwavecc.com/blogs/timely-breach-disclosure/): Yes, we know that information security in an interconnected world is not trivial.  We accept that configuration errors or malicious insiders or new, complex threats might conspire to provide opportunities for a breach.  But who says that it is acceptable that notification and disclosure of a breach be done months or years after the incident? That’s what appears to have happened with TD Ameritrade this past month.  On September 14th, it was reported that TD Ameritrade suffered a breach, in which the names and contact info of all of its customers — over 6 million — was exposed.  They have further indicated that no Social Security […] - [On Being A Technology Change Agent](https://brainwavecc.com/blogs/on-being-a-technology-change-agent/): As I think about it, the title is probably misleading, because being a Technology Manager with change-agent responsibility is not the same as being a Technology Change Agent. In my particular case, I’m not looking to change the technology, necessarily.  In fact, I’m pretty happy with the basic technology infrastructure, at least in terms of product selection.  What does need to be changed are the processes and procedures that surround the technology, or control how and when and why it is used.  This is what usually needs to happen first. Many people make the mistake of choosing the tool and […] - [The Price of Poor Security?](https://brainwavecc.com/blogs/the-price-of-poor-security/): Given the recent spate of breach announcements from companies like Monster.com and TradeFreedom Securities Inc., I’ve been thinking about how poor security is going to impact organizations and consumers over the next few years. Even though there have been an increasing number of attacks over the past 18-24 months, and even though the severity of the attacks is getting worse, consumers and private citizens don’t seem to be too troubled over these incidents, because the relationship between the attacks and actual personal discomfort has not been apparent for many.   And to some extent, many folks see these attacks as inevitable. They aren’t.  Or, rather, they […] - [Compliant or Secure?](https://brainwavecc.com/blogs/compliant-or-secure/): Does fulfilling your regulatory compliance requirements actually lead you to be more secure?  Will your organization automatically attain compliance by pursuing a strict regimen of security practices? In short, is the quest to be compliant complementary, unconnected or mutually exclusive with the quest to be secure? This is the heart of a subject that I have seen discussed rather frequently of late, including in the March 2007 issue of Information Security magazine. Whether or not it is theoretically possible to fulfill most compliance requirements by improving ones security posture, in practice the effort that most organizations make towards being compliant with […] - [The Business-Focused Technologist](https://brainwavecc.com/blogs/the-business-focused-technologist/): These days, you can find a whole lot of discourse in both technology and business periodicals, on the need for technologists to be able to interface with the business, and not just operate a stereotypical geeks in a backroom or basement somewhere.  In many ways, I agree that to ensure long-term success, a technology professional should seek to be as versatile and well-rounded as possible as it pertains to business operations. What I don’t agree with, however, is that these are the only types of technology professionals that will survive or have rewarding careers.  A glance at some of the […] - [Change Management: Are You in Control?](https://brainwavecc.com/blogs/change-management-are-you-in-control/): This month in CIO Magazine is a very interesting article on Change Management which points out that truly innovative companies value discipline as much, if not more, than they do freedom and flexibility of execution. And the difference between those organizations that had high levels of innovation vs. those that didn’t is substantial:  The findings quantified distinctions between IT shops that live for the average and the few that take process leadership seriously. Elite IT performers weren’t just two or three times better than median performers—they were seven or eight times better. High performers—roughly 13 percent of the 98 sampled—contributed on average eight times […] - [Who is Clueless about Technology?](https://brainwavecc.com/blogs/who-is-clueless-about-technology/): An article I read on ZDNet this week laments that fact that politicians as a group are woefully clueless about technology issues, yet keep pressing ahead with projects that are highly dependent on technology such as National ID programs. As some of the comments indicate, that lack of understanding is not limited to technology.  On the other hand, I would say that it’s not just politicians that are clueless about the complexity and effectiveness of technology solutions. There is much written about needed Technology Professionals who are in tune with business issues, and can speak the language of the business, but I would suggest […] - [The Joys of Project Management!](https://brainwavecc.com/blogs/the-joys-of-project-management/): I just saw this comic strip on project management, and it brought tears to my eyes… - [Security: Product vs People and Process](https://brainwavecc.com/blogs/security-product-vs-people-and-process/): One of the hardest concepts to emphasize concerning Information Security is that people and processes are more critical to your overall security posture than products are.   That is not to say that products are unimportant. Certainly, any deficiency in one of the three P’s will necessitate compensation from the other two P’s.  But of all three, a deficiency in PRODUCT is the easiest to overcome when sufficient strength exists in the other areas — having the right (and properly trained) people and having appropriate/effective processes. A recent eWeek Research Central blog entry referred to a CIO Insight 2006 survey which shows that not everyone sees inherent security […] - [Is privacy on the Internet a dead concept?](https://brainwavecc.com/blogs/is-privacy-on-the-internet-a-dead-concept/): There is no universal standard of what the acceptable boundaries of privacy are.  The European Union tends to have a more stringent view of what constitutes personal privacy, while the United States seems to favor corporations vs people when it comes to control of user data. Now, the boundaries are being pushed even further by a company called Jigsaw Data which, according to the following report in the San Francisco Chronicle is encouraging people to post the contact information of business users to the web, making them searchable to a far broader audience than originally intended. This is not the same as using a service […] - [A Cost-Effective Infrastructure Deployment Strategy](https://brainwavecc.com/blogs/a-cost-effective-infrastructure-deployment-strategy/): Over the past few days, I have seen at least two posts or articles on a subject I’ve been meaning to write about for quite some time, now.  The first one I saw was by Rob Howard, and although it deals mostly with software development, it struck a chord with me.  Today, I saw a post on Kevin Stone’s blog which referenced a ComputerWorld article discussing a similar issue with network deployments. One of the key ingredients to failed (or marginally successful) technology deployments, is scope creep.  For a variety of reasons, people try to cram as much as possible into each deployment or product version, […] - [Taking Information Security Seriously at Home](https://brainwavecc.com/blogs/taking-information-security-seriously-at-home/): It is very easy to become complacent with Information Security on a home computer or network, even for those who would otherwise preach IT Security in a corporate setting.  There are several reasons why this attitude can develop, even in people whose line of work would otherwise cause them to be more vigilant. Part of the problem is the human tendency to note that ugly things have probably happened to other people because of their carelessness or because they somehow deserved it, but that those things could never happen to us. Another contributing factor is that by having at least some policies […] - [Do we really get Information Security?](https://brainwavecc.com/blogs/do-we-really-get-information-security/): Five years ago, I wrote an article on the challenges of implementing Information Security in an enterprise.  Sad to say, even in the post-911 era, not a whole lot has changed there.  Sometime in the next couple weeks, I’ll write an updated document on what challenges I see today for an IT Security Professional.  Don’t get me wrong — there’s a lot that has changed in terms of threats and tactics, and there are new concerns to address, but unfortunately, there is far too much of the people element that hasn’t changed in a noticable way. A couple of weeks ago, […] - [Net Neutrality and Information Security](https://brainwavecc.com/blogs/net-neutrality-and-information-security/): There’s a very interesting article up on SANS Internet Storm Center concerning the security implications of the proposed Net Neutrality legislation that is being discussed ardently in some circles… Briefly, network neutrality is designed to prevent ISPs from favoring certain websites over others (faster load times) or certain applications over others.  In short, it’s designed for consumer PC environments only (the exact environments that are pretty much the biggest nightmare on the internet). The supporters of network neutrality would allow for filtering of illegal traffic, but the problem comes in with grey areas.  For instance, network neutrality would not allow ISPs to […] - [Innovation Takes More than Inspiration; It Takes Investment, and Persistence](https://brainwavecc.com/blogs/innovation-takes-more-than-inspiration-it-takes-investment-and-persistence/): http://www.cioinsight.com/article2/0,1397,1913188,00.asp Moore’s new book, Dealing with Darwin: How Great Companies Innovate at Every Phase of Their Evolution, just published by Portfolio, argues that innovation by itself is not enough. Innovation also requires an investment strategy that puts your resources where they count, and a people strategy that aligns those resources with the best skills of all your employees. The diagram alone is very thought provoking… It’s certainly a different way of looking at how corporate budgets are typically managed. ## Pages - [Services](https://brainwavecc.com/services/) - [Contact](https://brainwavecc.com/contact/) - [BrainWave Utilities](https://brainwavecc.com/brainwave-utilities/) - [Blog](https://brainwavecc.com/blog/) - [About](https://brainwavecc.com/about/) - [Home](https://brainwavecc.com/) - [The UltraTech Knowledgebase](https://brainwavecc.com/knowledge-base/): [epkb-knowledge-base id=1] [comment]: # (Generated by Hostinger Tools Plugin)