Tape Over Your Hard Drive Lights: The Latest Security Hardening Measure

When hard disk drives contain super sensitive data, cybersecurity professionals like myself will usually recommend that they shouldn’t be placed in any computers that have an operational TCP/IP stack. There are various ways that internet-connected computers can secure themselves against attack, such as firewalls, IPS devices, antivirus software, and OS configuration. That’s good enough security […]… Read More

The post Tape Over Your Hard Drive Lights: The Latest Security Hardening Measure appeared first on The State of Security.

Continue reading Tape Over Your Hard Drive Lights: The Latest Security Hardening Measure

Making CAPTCHAs Expensive Again: If You’re Using Text-Based CAPTCHAs, You’re Doing It Wrong

CAPTCHAs, these things: A human creation built to foil robots. However, as is ever so common these days, the robots are winning. But! it doesn’t have to be that way. The first CAPTCHAs were created in 2000, and most every CAPTCHA since has remained virtually the same. This becomes problematic when thinking about CAPTCHAs in […]… Read More

The post Making CAPTCHAs Expensive Again: If You’re Using Text-Based CAPTCHAs, You’re Doing It Wrong appeared first on The State of Security.

Continue reading Making CAPTCHAs Expensive Again: If You’re Using Text-Based CAPTCHAs, You’re Doing It Wrong

Level up Your Security Training Through Engagement

We all can agree that security training is critical, but have you ever wondered why your organization does not share your same level of excitement when it comes training time? The majority of organizations struggle with getting employees motivated and enthusiastic about training. Many employees look at training as a quarterly or yearly checkbox with […]… Read More

The post Level up Your Security Training Through Engagement appeared first on The State of Security.

Continue reading Level up Your Security Training Through Engagement

An Incident Response Guide for Home Computer Use or Unwanted Social Media Attention

One of the unpleasant realities of having a ubiquitous and very public online profile through social media is the risk of attracting an unwanted “follower” or “friend” who turns into an online-troll or stalker. Over the past few weeks, I’ve been contacted by a number of folks on “what to do” when bad things start […]… Read More

The post An Incident Response Guide for Home Computer Use or Unwanted Social Media Attention appeared first on The State of Security.

Continue reading An Incident Response Guide for Home Computer Use or Unwanted Social Media Attention

February 2017: The Month in Ransomware

The shortest month of 2017 was relatively slow in terms of ransomware activity, but it gave rise to several disconcerting tendencies in the cybercrime ecosystem. Crypto infections that steal sensitive information along the way, top-notch Android ransomware utilizing dropper techniques, low-cost Ransomware-as-a-Service platforms – all of these took root in February. Overall, 26 new strains […]… Read More

The post February 2017: The Month in Ransomware appeared first on The State of Security.

Continue reading February 2017: The Month in Ransomware

Breaching Physical Security and Causing Mayhem with Wireless Signals

Wireless technology is fast replacing wired technology in most industry sectors where some form of communication between devices is required. The recent surge in Internet Of Things (IoT) devices has also pushed wireless communication to be implemented on more devices than ever before. Benefits such as ease of setup, flexibility in device placement, and improved aesthetics […]… Read More

The post Breaching Physical Security and Causing Mayhem with Wireless Signals appeared first on The State of Security.

Continue reading Breaching Physical Security and Causing Mayhem with Wireless Signals

Deception as a {Free} Post-Breach Detection Tool

The Clifford Stoll’s interesting story of stalking the wily hacker back in the 80s was probably the first time deception was used for catching a hacker. Since then, the technology has changed a lot, but the concept of honeypots and deception in general has remained the same. Despite the undeniable and important role that honeypots […]… Read More

The post Deception as a {Free} Post-Breach Detection Tool appeared first on The State of Security.

Continue reading Deception as a {Free} Post-Breach Detection Tool

Do You Know Where Your Data Is? Prove It…

Many IT decision makers look at assets as hardware, but really they should consider why they have the hardware in the first place. These decision makers remember the very significant investments they made in servers, PCs, firewalls, and so on in order to deploy that new CRM or Electronic Medical Records System. They think of […]… Read More

The post Do You Know Where Your Data Is? Prove It… appeared first on The State of Security.

Continue reading Do You Know Where Your Data Is? Prove It…

Information Security, Cybersecurity, IT Security, Computer Security… What’s the Difference?

Information security, cybersecurity, IT security, and computer security are all terms that we often use interchangeably. I know that I do. I’ve written a lot about those areas for the past several years. I notice that sometimes I switch between the terms in an article simply to avoid repeating the same phrases over and over […]… Read More

The post Information Security, Cybersecurity, IT Security, Computer Security… What’s the Difference? appeared first on The State of Security.

Continue reading Information Security, Cybersecurity, IT Security, Computer Security… What’s the Difference?

New Study: Companies Aren’t Prepared for Cyber Security Threats

In the modern world, it isn’t bank robbers we’re worried about – it’s cyber criminals. They can steal consumer information, alter data so that it gives false insights or remains corrupted for months or even years without notice, and even sell valuable intellectual property to the highest bidder, putting companies under. However, while many understand […]… Read More

The post New Study: Companies Aren’t Prepared for Cyber Security Threats appeared first on The State of Security.

Continue reading New Study: Companies Aren’t Prepared for Cyber Security Threats