Tuesday, 1 June 2010

May 2010 ramblings

I see it's been almost two months since my last blog entry. What poor discipline - sorry. Things have been really hectic here at First Base Technologies, which is my only excuse.

This year's Infosecurity Europe was the best for many years - we invested in a new and larger stand and more staff and the results speak for themselves. Lots of visitors with a better appreciation of what penetration testing is all about and how it fits into PCI-DSS. Better informed discussions about penetration testing as part of Governance, Risk and Compliance too.

Today I had an excellent meeting with Claranet who provide secure hosting in a private cloud. Just what we need - a guarantee of where our data resides for compliance with Data Protection coupled with a cast-iron SLA. And they provide secure networking too. Great stuff.

Thursday, 4 March 2010

Hot topics for 2010 - discuss!

I've just been asked for my "hot topics" in infosecurity for 2010, so I thought it would be interesting to throw these out at you and see what you think, so here goes:

1. Security awareness
It's increasingly obvious that technical controls alone are not providing organisations with the security they need. Staff education and awareness, delivered in a creative and imaginative way, is critical to managing information security in 2010.

2. Cloud computing
Few organisations are giving serious consideration to the security risks inherent in the cloud computing model. Whilst day-to-day operations can be outsourced in this way, the responsibility for security cannot. A combination of technical, legal and audit skills are required to ensure the security of data in the cloud.

3. Defense against cybercrime
Organisations continue to underestimate the devious nature of cyber criminals and have little or no commitment to "thinking like a hacker". This mind set is critical in order to apply budget and resources to the areas where criminals are most likely to attack and to counter their methods effectively.

Opinions anyone?

Monday, 18 January 2010

A Happy New Year for data protection?

UK readers may have noticed that the Information Commissioner’s Office (ICO)­ will have new powers to fine organisations responsible for security breaches from 6 April 2010. Fines of up to £500,000 can be imposed for serious breaches of the Data Protection Act. The ICO press release is here.

Jonathan Armstrong of Duane Morris, with whom I've shared several conference platforms, thinks this will make CEOs and other senior people take more notice and should make some IT security budgets less prone to cuts. As he says, "If the ICO can levy some decent fines early on, people may take more notice." His article is here.

We can only hope that tougher UK legislation will start to make a difference to the lackadaisical attitude of some senior people towards security!

Friday, 27 November 2009

BCS ELITE annual dinner

Last night I attended the BCS ELITE annual dinner - the first for several years, but well worth the wait. It was a black tie event at the Landsdowne Club, where the food and wine was excellent, and the latter flowed in quantity (hence feeling rather fragile today). I was really pleased to find that I was sharing a table with the always entertaining Lord Renwick and his lovely Lady, as well as several other intelligent and erudite folk. What a good start to the festive season :-) This post isn't really much to do with security, but I would recommend ELITE to anyone interested in good conversation and networking with IT people.

Friday, 13 November 2009

ISACA European ISRM Conference

I just spent three extremely useful and enjoyable days at the ISACA Information Security and Risk Management conference in Amsterdam. A great selection of speakers and topics, plus terrific networking opportunities. If you are able to attend next year (in Vienna I believe) it could be a good investment. For US readers, the conference is also held Las Vegas - this year's event was just as stimulating as the European version.