Cyber Essentials at a small business (20 employees) that keeps all business data within SaaS

Background
I’ve recently joined a rapidly growing small business (from 4 to 20 people in last 12 months) with a very DIY IT setup. It’s fallen to me (I’m a developer so I just happen to be sitting nearest IT world…) to improve their secu… Continue reading Cyber Essentials at a small business (20 employees) that keeps all business data within SaaS

What is a good common approach for encrypted backup/restore on an embedded device?

An embedded device with Linux supports backup/restore of files encrypted with openssl. The idea of backup is: tar -c …. | openssl smime -encrypt -binary -aes-256-cbc -out backupfile.encrypted -outform DER certificate.key and the idea of … Continue reading What is a good common approach for encrypted backup/restore on an embedded device?

Is gamification to encourage increased end user awareness of company security policy a good idea? [closed]

I am a member of the IT security team of a large organization in the financial services industry. I have been with my employer for about 7 years, and am well respected, often serving in advisory capacity to management. Recently we started … Continue reading Is gamification to encourage increased end user awareness of company security policy a good idea? [closed]

Do the organisational policies need to have ownership to ensure accountability?

Policies are the high-level statement from Senior Management. It’s a philosophy for the management to be guided by, and management has the direction to plan, build, run and monitor the activities to achieve the enterprise objectives from t… Continue reading Do the organisational policies need to have ownership to ensure accountability?