May 17, 2012

BYOD Drives Need for Context-aware Security and Consolidated Management: Aruba Networks Podcast

Bookmark and Share
In seemingly the blink of an eye, we’ve witnessed an evolution from employees carrying almost nothing but Blackberry’s to the bring your own device era, driven by iPhones, iPads, Androids, Windows phones and all manner of computing and communication devices. In the midst of it all is Carousel Industries’ partner Aruba Networks, which builds the wired and wireless networking components and tools that make BYOD possible. To check the pulse of the BYOD movement, we checked in with Robert Fenstermacher, director of product and solutions marketing at Aruba, who brought us up to speed in this information-packed podcast. 4 Steps… Continue Reading ›

Security Breach Roundup: From Human Error to Well-hidden Malware, There’s No Shortage of Threats

Bookmark and Share
This month we’ve got four stories that neatly sum up the challenges IT security professionals face in their attempts to protect corporate data. They include a mix of breaches caused by human error, a lack of encryption, and some cleverly disguised malware. Two States Suffer Medicaid-related Security Breaches This headline from an InformationWeek story pretty much says it all: “2 Medicaid Data Breaches, 1 Weak Link: Employees.” Here’s the story of the latest Medicaid-related breach: The South Carolina Department of Health and Human Services (SCDHHS) discovered on April 10 that an employee of the state’s Medicaid program had transferred personal… Continue Reading ›

State of the Security Marketplace – Fortinet Podcast Interview

Secure-IT-Perimeter

Bookmark and Share
As we’ve previously reported, the IT security threat landscape has changed in the last couple of years, shifting from one dominated by “bored hackers” to one where monetary gain is the primary objective. “[Today] we’re seeing a large component of organized crime, corporate espionage and terrorism,” says Kevin Flynn, senior manager of product marketing for Fortinet, a Carousel Industries partner that is a leader in the unified threat management security space. To properly protect themselves in this environment, companies have to adjust their thinking when it comes to security. Listen to the whole discussion in this information packed podcast. Mind… Continue Reading ›

Unified Threat Management: Strong IT Security Tools for SMBs

IT Security - Unified Threat Management

Bookmark and Share
In a brief discussion the other day with our partner Fortinet, we learned that they had recently received the top marks in the Gartner report on the Unified Threat Management marketplace.  Not that we were all that surprised, Fortinet has been a leading voice and vendor in IT Security since their inception.   A key reason is that small and midsize businesses face the same security threats as large enterprises but are at a distinct disadvantage in terms of being able to defend themselves, since they don’t typically have the budget to spend on security experts. What they need is… Continue Reading ›

Calls for Cooperation and Threats of Doom from RSA Conference

many small light bulbs equal big one

Bookmark and Share
The week-long RSA Conference 2012 security confab wraps up in San Francisco today and after hearing several of the more than a dozen keynote speeches, two themes emerged: companies have to help each other deal with threats and getting hacked is now inevitable. Dealing with Threats Requires Close Cooperation In his opening keynote Art Coviello, Jr., Executive Chairman of RSA, was the first to call for morecooperation in sharing data about threats. Of course, RSA itself was the victim of a well-publicized attack last year, the result of a well-executed phishing attack. The sting of that attack was evident, and… Continue Reading ›

Security Breach Roundup: Short Month, Many Breaches

Bookmark and Share
For this month’s security breach roundup we once again have some big names in the news and perhaps the best headline you’ll ever read in this roundup. A Six-Pack of Security Breaches I love it when others make my job easier, as the fine folks at Ars Technica have with this piece under the headline, “Breaches galore as Cryptome hacked to infect visitors with malware.” (And no, that’s not the gem referenced above; that comes later.) A breach that caused Cryptome.org to infect visitors with virulent malware was one of at least six attacks reported to hit high-profile sites or… Continue Reading ›

4 Best Practices for Developing a Strategy for Mobile Security

Phone with key

Bookmark and Share
Today’s workers are more mobile than ever before, depending on a wide variety of network-enabled electronic devices to get their jobs done. As a result, wireless networks are no longer just a convenience, a nice-to-have feature that impresses visitors to your building. They are crucial to the everyday performance of most any organization. In this kind of environment, companies must have an effective strategy for providing not only mobile communications, but also ensuring the security of those communications. Coming up with such a plan requires a willingness to review how your organization works, and how the needs of your users… Continue Reading ›

3 Approaches to Identifying Mobile Devices

fingerprinting

Bookmark and Share
When it comes to managing wireless devices on your network, you’ve got two basic options: treat the device as a known entity that is allowed to access the corporate network, or as an unknown entity that is not. But there are several ways to make that determination, says Chris Williams, a systems engineer with Carousel Industries, and they are progressively more granular and useful. Fingerprinting and Web Browser Snooping The simplest way to identify a device is through fingerprinting or web browser snooping. With fingerprinting, when the device logs on, it performs a DHCP request. In that request is a… Continue Reading ›

Effective Security Breach Response Takes Planning and Testing

IT Security Breach Response

Bookmark and Share
IT Security breaches are in the news seemingly every day, at companies both large and small. (For evidence, look no further than our own monthly security breach roundups, such as this one and this one.) No company is immune from a potential security breach, so no company should be without a sound breach response plan. “It’s a little like a fire evacuation plan,” says Thorsten Behrens, lead IT security architect for Carousel Industries. “Don’t figure it out when the building’s on fire; do it beforehand.” We talked to Behrens to learn what a good security breach response plan should look… Continue Reading ›

Addressing the Security Issues that Virtualization Presents

Bookmark and Share
Virtualization technology is helping companies save money by consolidating data center infrastructure while increasing their agility in terms of being able to meet business requirements. But the more companies delve into virtualization, the more they realize it’s also creating substantial new challenges in terms of security. Limited Visibility with Virtual Servers The problem stems from the fact that much of the data traffic in a highly virtualized environment is completely invisible to traditional network monitoring and security tools. As Peter Peter McMullen, Cloud Security Specialist at Juniper Networks explained during a recent conversation, “The reason is these tools – whether… Continue Reading ›