How do you create a Zero Day vulnerability every day?

The answer is easy, don’t correctly manage the people you let into your business! I have been working in Identity and Access Management for over 10 Years, both as the leader of the Identity Services team at JP Morgan Chase and as an Identity Management Architect at RSA. I’ve had countless discussions with customers about…

The post How do you create a Zero Day vulnerability every day? appeared first on Speaking of Security – The RSA Blog and Podcast.

Continue reading How do you create a Zero Day vulnerability every day?

Context in Risk-Based Threat Patterns

Risks come from various sources that are not always possible to identify and subsequently prevent and mitigate in advance. With the growth in cloud, social, mobile and “bring your own device” computing, the size of the attack surface is greater than ever. Many attack scenarios are possible mainly due the complexity of the network’s topology and…

The post Context in Risk-Based Threat Patterns appeared first on Speaking of Security – The RSA Blog and Podcast.

Continue reading Context in Risk-Based Threat Patterns

Major Events and Hacktivism #OpOlympicHacking

Introduction As anyone who tracks attacks on the internet can tell you, Activists using hacking activity, aka “Hacktivists”, have discovered that a relatively basic hacking approach, with buy-in from disenfranchised groups of people, can have significant effects on online businesses. With names like #OpISIS, #OpParis, #OpMonsanto, #OpWhales, #OpKillingBay, #OpKKK, and #OpTrump, you can easily see…

The post Major Events and Hacktivism #OpOlympicHacking appeared first on Speaking of Security – The RSA Blog and Podcast.

Continue reading Major Events and Hacktivism #OpOlympicHacking

Playing Pokemon Go? Read this.

Hands up those who would leave their front door unlocked and all their personal information like passports, identity cards, bank details, their children’s details and even passwords left out for cybercriminals to exploit? Not many of you? Well, you will be surprised because that’s exactly what Pokemon Go players are doing.  If you sign up…

The post Playing Pokemon Go? Read this. appeared first on Speaking of Security – The RSA Blog and Podcast.

Continue reading Playing Pokemon Go? Read this.

Tales from the BlackHat NOC: Learning from the right people

The week I spent in the BlackHat NOC was great exposure to both new and evolving technology and new people. As a team member of the RSA team in the BlackHat NOC I tried to approach my time there by learning as much as I could about not only the data on the network, but how our products function…

The post Tales from the BlackHat NOC: Learning from the right people appeared first on Speaking of Security – The RSA Blog and Podcast.

Continue reading Tales from the BlackHat NOC: Learning from the right people

Tales from the Black Hat NOC: The Stages of Security Adolescence (Part 2)

In Part 1 of “Tales of the Black Hat NOC: The Stages of Security Adolescence,” I discussed the maturation process of the Black Hat NOC, and security strategies in general.  In the blog post below – you can see the adjustments we made and additional steps we took towards optimizing our NOC at Black Hat. …

The post Tales from the Black Hat NOC: The Stages of Security Adolescence (Part 2) appeared first on Speaking of Security – The RSA Blog and Podcast.

Continue reading Tales from the Black Hat NOC: The Stages of Security Adolescence (Part 2)

Your Step-Up Authentication Compass… NIST & SMS – Finding North

An estuary is the area where a river meets the sea (or ocean), where fresh water from the river meets salt water from the sea. The fresh draft of the NIST Digital Authentication Guidance (NIST SP800-63B) has been let loose into the salt waters of the public and certainly provoked some conversation of late around…

The post Your Step-Up Authentication Compass… NIST & SMS – Finding North appeared first on Speaking of Security – The RSA Blog and Podcast.

Continue reading Your Step-Up Authentication Compass… NIST & SMS – Finding North

After Black Hat: Shaming is Easy (When You Don’t Encrypt)

During the Black Hat 2016 NOC outbrief session, Grifter, aka Neil Wyler made a counter-intuitive statement to the crowd of roughly 500, eager to see which of their online activities would be exposed center stage: “I look forward to the day when I can’t see anything you’re doing on the Black Hat network”. Wait… what?…

The post After Black Hat: Shaming is Easy (When You Don’t Encrypt) appeared first on Speaking of Security – The RSA Blog and Podcast.

Continue reading After Black Hat: Shaming is Easy (When You Don’t Encrypt)

A New Generation of Hackers Target the Gaming Industry

Hackers love a crowd. That’s true when it comes to social media networks, government system websites, financial institutions, retailers, and, based on recent headlines, gaming sites.  For an industry projected to be worth nearly $100 billion in 2016, gaming offers a lucrative industry for cybercriminals.  Last year, gaming accounted for 1 in every 50 e-commerce fraud transactions,…

The post A New Generation of Hackers Target the Gaming Industry appeared first on Speaking of Security – The RSA Blog and Podcast.

Continue reading A New Generation of Hackers Target the Gaming Industry

Tales from the Black Hat NOC: The Stages of Security Adolescence (Part 1)

Maturity is often spoken of in the security community as a binary value – “Customer X is mature,” “Customer Y is immature…” This notion was not dispelled at Black Hat where one vendor after another claimed, “Evolve your security. Buy our product and stop breaches today!” But we know that maturity is not binary, and neither is…

The post Tales from the Black Hat NOC: The Stages of Security Adolescence (Part 1) appeared first on Speaking of Security – The RSA Blog and Podcast.

Continue reading Tales from the Black Hat NOC: The Stages of Security Adolescence (Part 1)