Showing posts with label Cyber. Show all posts
Showing posts with label Cyber. Show all posts

Monday, April 27, 2020

Pandemic: Human Resource Help

A Resource no one should ignore


As some of you will no doubt know I do a lot of networking on LinkedIn.  I'm always interested in what's growing, what's moving and how to advance the story of our lives here in America.  Many of my professional connections are on LinkedIn and I am thrilled that I can reach into the resource from time to time seek the advice and opinions that they willingly provide.


This post is about exposing a resource whose time has come.  The need is here and people should pay attention to the depth and breathe of posts.  Its about helping others who may really be in a bind due to the downturn (self imposed) of our economy during this pandemic.  As we press forward and reopen our economy the endless opportunities will slowly give rise to America's unlimited potential which should be great news for everyone involved.

In the meantime, Andrew Seaman does a segment on LinkedIn called #Gethired and provides some tremendous resources that I have found to be just terrific and incredibly helpful.  Andrew is a great writer and inserts into his posts another resource of LinkedIn called LinkedIn Learning.  I have viewed many of the videos and taken a number of these courses and found the quality to be top notch.  He quotes experts from the field and links them in his posts for additional value.  I call that bonus points.

A take away from the resume course is in the table I'm inserting below.  Within a few minutes you can brighten your day and freshen up that resume with color and relevance.


Keywords
Tell a story
Contrast/Compare
Never give up

I was also interested in what LinkedIn was saying on its blog.  Yes, if you didn't know it LinkedIn has a blog and this is another terrific resource for all involved.  LinkedIn has managed to pull together a great team of individuals on its platform who do one terrific job of communicating.  That can not be understated.

That's what this post is all about.  Take a look at your LinkedIn account and drive some attention to the posts and resources that LinkedIn personnel and contactors have so handsomely put together in one place for your use.

@andrewseaman #Gethired

Monday, September 17, 2018






WELCOME

 Welcome and yes we are back!  Our target is our clients, our prospects, our friends and family in the industry.  We are passionate about assessing risk, we run deep in security issues and also like to take some time to laugh as well.  We hope each of you enjoy the blog and contribute.

Risk and security discussions start at the top of every organization.  This isn't just jargon.  It is serious and when reading our blog you'll keep this in mind as you read along.  The CEO is the chief risk/security evangelist for your organization.  While we all love to laugh and make light of some things, in earnest we all need to focus when it comes to risk and security.  If the CEO isn't talking about risk and security than it just hasn't become a priority for your organization and your board of directors need to bring him/her in and explain the priorities for your organization.  We point in earnest to the your audit committee and its chairperson.  If things go wrong and they will in even the best organizations the chair of the board of directors audit committee will be the first person interviewed.  

If your like us and become aware of an issue, a solution, a best practice or new application and/or free or pay for tools that you just couldn't let slip by let us know.  If you'd like to be considered for a guest blog entry keep this is in mind: One focused topic, 400 words tops email us at: info@integrissecurity.com.  We know everyone has access to some cool graphics which help understanding the concepts and theories being put forward so choose carefully and send it along.  Our focus is to explain issues as simple as possible and to have the graphics bring the point home.  The ah ha moment.  

SOCIAL MEDIA

Did someone say social media?  In the past we have put our toe in the water with social media.  We plan to go full throttle with social media and may even add to our current setup.  So on our web site you'll see Facebook, LinkedIn, Twitter and of course this Google+ Blogger Blog.  We may expand on this and add You Tube if we think it brings additional value.  We think that we need to bring everyone the full impact of the web via our associated media outlets.  If you want to be part of this and share your wisdom let us know.  Email us: info@integrissecurity.com.

Thanks everyone and welcome back.

Friday, October 21, 2016

Cyber Security Month: Looking for Answers: Part I?


LONG ISLAND BUSINESS NEWS
LI Business New Cyber Conference
Hilton, was once again informative, invigorating and enrolling. With a number of panelists participating, including both the Integris Security CTO, Blake Cornell, and United States Congressman US District 1, Lee Zeldin, nearly 100 individuals attended the breakfast event.
Topics of interest had included Cyber Terrorism, Business Continuity, Government Legislation, Small Business Best Practices and other wide ranging topics. Some of the information shared, information that attendees can use in their day to day business operations.
A goal of Integris Security CTO, Blake Cornell, was to provide “simple and sound information that is short and sweet” further stating that “if your employees are untrained then no amount of technical information will help them understand. You can’t make them understand but you can help them understand”.

Blake Cornell is the CTO of Integris Security LLC.

Sunday, October 16, 2016

Ransomware: Osterman Research Survey for Malwarebytes

https://www.integrissecurity.com/index.php?aboutus=JosephConcannon
Joseph Concannon
Today I receive a note from a friend who said he had fallen victim to a Ransomware attack.  So I figured its a good time to review some up to date expert research.  This review is a product of Integris Security LLC and we gladly share this with the community.

First, Ransomware is a global issue effecting enormous sized companies as well as my local friend.  Ransomware is a global threat/problem.  We must recognize the size and depth of this issue.  A survey was conducted during June of 2016 that included CIO's, CTO's, CISO's and other executives.  The survey included 165 corporations in the United States as well as companies from around the world.  39% percent of the companies that were contacted were impacted by a ransomware attack in the U.S. alone.  This is truly a global problem and issue but let's keep the focus here at home.  The report shows the various priorities by country.

The FBI talks about Ransomware as a, "an insidious type of malware that encrypts, or locks, valuable digital files and demands a ransom to release them". Integris Security LLC evangelizes through its President, Joseph Concannon the value of Risk Management and the ongoing development of a solid business continuity program.  Concannon states: "this isn't a once a year review, this is a daily, weekly, monthly, quarterly and semi-annual program.  Risk Management opens the eyes of the Executive Team and Boards of Directors".

Second, it comes as no surprise that the survey results identified healthcare and financial services industry as the prime target.  Each are highly dependent upon business critical information according to Osterman Research, Inc.Cyber criminals lay and weight until they find the prime target for an attack; one which they can not recover from due to the lack of ransomware fighting software.  In Osterman's survey U.S. companies were most likely to fall victim to a ransomware attack (79% fell victim according to the survey).

Third, Ransomware ranks the fourth highest security concern for senior executives in the United States as surveyed by Osterman Research, Inc., and more:

 U.S. organizations are also more likely to place a high or very high priority on investing in education and training about ransomware for their end users; and for investing in resources, technology, and funding to address the ransomware problem.

Note well: What the Osterman Research reveals is the power play between tenured industry executives and newly appointed CIO's, CISO's, CTO's learning the mine field of budgeting.  Where do these technology executives make the push to gain budget for their projects and can they convince business unit managers to join their team?  Who pays for training and education and how does that weigh in the balance of getting things done?  Here's how its playing out so far:
Somewhat ironically, however, U.S. organizations are also the least likely to have implemented any sort of ransomware training for their end users, and are among the most likely to offer only minimal training when they actually do so.  U.S. companies rate Ransomware as a high or extremely high priority, unlike their European counterparts in Germany and the UK or Canada which consider it less of a threat. 
Yet the training dollars in the U.S. continue to lag behind.   

The survey that I am reviewing is called, "Understanding The Depth of The Global Ransomware Problem" a report promoted by a company called Malwarebytes
The perceived importance of regular, on-premises backups as a ransomware-recovery tool is quite high among U.S. and German organizations, but somewhat lower among the organizations we surveyed in Canada and the United Kingdom. However, Canadian and UK-based organizations were more likely to use regular, cloud-based backups to recover from ransomware. Other capabilities in place to address ransomware included on-premises ransomware-detection solutions (highest penetration in the U.S.), network segmentation (highest in Germany), and air gaps between data stores and the Internet (highest in Canada).
At Integris Security LLC we point out that segmentation and air gaps are important as well as on-premises backups NOT connected to the network you are backing up.  Strong passwords that are changed every 90 days.  Here are the top 15 Cyber Security Precautions to follow.  Here are some very good tips for enterprise environment security teams to review (FBI):

Here are some tips for dealing with ransomware (primarily aimed at organizations and their employees, but some are also applicable to individual users):
  • Make sure employees are aware of ransomware and of their critical roles in protecting the organization’s data.
  • Patch operating system, software, and firmware on digital devices (which may be made easier through a centralized patch management system).
  • Ensure antivirus and anti-malware solutions are set to automatically update and conduct regular scans.
  • Manage the use of privileged accounts—no users should be assigned administrative access unless absolutely needed, and only use administrator accounts when necessary.
  • Configure access controls, including file, directory, and network share permissions appropriately. If users only need read specific information, they don’t need write-access to those files or directories.
  • Disable macro scripts from office files transmitted over e-mail.
  • Implement software restriction policies or other controls to prevent programs from executing from common ransomware locations (e.g., temporary folders supporting popular Internet browsers, compression/decompression programs).
  • Back up data regularly and verify the integrity of those backups regularly.
  • Secure your backups. Make sure they aren’t connected to the computers and networks they are backing up.

For those at home we strongly recommend backup on USB stick, or other storage drive with proper security "on board" to assess the devices health each time the device is accessed.  Saving important documents to a computer is a thing of the past.  Time to think 2016 and the threats that come with the technological age we live in.  Store important documents in a safe deposit box (whether in paper or USB or storage drive or other form).  If its important, then take the extra security steps.

https://www.stopthinkconnect.org/STOP THINK CONNECT is the U.S. Department of Homeland Security Campaign promoted during Cyber Security Awareness Month (October each year).  However, the evil email attachment continues to lure an seemly endless waterfall of users into the brink.  Nothing beats education and awareness in preventing the lost of your computer to a cyber attack.  While on the computer remember you are not in your living room.  You are in the "Wild West" and everyone's your friend.  You wouldn't leave your front door open at night, so don't leave your computer open either.  
Integris Security LLC grew from our passion for protecting our nation’s critical infrastructures and years of providing industry professionals with best of breed solutions, proven best practices and top notch security education. We work tirelessly to nurture our clients’ TRUST. We will work equally diligently to EARN your trust.


Thursday, October 6, 2016

LIBN Cyber Security Conference - October 6th, 2016

Today's cyber security conference held by the Long Island Business News at the Huntington Hilton was a huge success.  The conference was packed and the panel with headliner U.S. Congressman Lee Zeldin was both informative and far reaching.

A wide range of cyber security topics included  a discussion of the potential federal funding of security awareness strategies like, "If you see something, Say Something".  Attendee's suggested a new cyber security awareness strategy like see something be started. Blake Cornell, CTO Integris Security suggest we use, "Think twice before you click twice".  The simple message was something that everyone agreed was needed.

The panel touched upon some key areas and agreed that security awareness training when implemented correctly brings everyone into the company's security strategy and not just the security team.  Twenty - thirty employees watching the security posture of a company is better than 3-5 employees from the security team.  Chief Security Officers have their hands full and gaining the trust and confidence of all employees to be on the look out makes the CSO's job 100% easier. 

Is it IT or is it Business?  A lively discussion broke out concerning the politics, budgeting and organizational culture in which professional security people work in.  This environment is not always 100% on board with a strong security posture.  General agreement was reached on the theory of security starting from the top down works best.  If the boss is concerned about security so is everyone else.  The next discussion was about whether it was the business or IT department.  Well, this was put to rest quickly.  The IT staff and security personnel need to team with business unit managers and ask them to take ownership for what belongs to them and what is enabling their success. The better the integration with business leaders on function and feature of the computer tools used to bring profits to the business,  the smoother the discussions will be for improvements to strengthen the security budgets so that the profit center environment is safe and secure.  The better everyone will sleep.

Their are a great many things that people can do to keep the internet secure.  Unfortunately their are a great many things which LURE us away from this common sense approach to internet safety.  Changing (long with symbols, CAPS, lowercase letters and numbers) passwords every 90 days is driving a positive change for your safety and security on the internet.  Writing those passwords down and storing them in a secure place is also a good idea. See more ideas on our web site.

For a two hour conference this one was packed with information and many new contacts as well.  Good job to LIBN and we look forward to next years conference and some of the articles to appear in LIBN which should keep everyone on their toes.

For additional information on security tips, visit www.integrissecurity.com.  we have a full page of tips on our web site.

Wednesday, September 28, 2016

Information Security in Corporate Valuation

What do you look at when considering the corporate valuation of a company?  Chief financial officers pour over spreadsheets, public filings and much more to get a temperature so they can inform investors, boards and others in the decision making process.  Where is Information security in this discussion?  Who is the chairman of the board's audit committee and how comprehensive are the details and reports?  How accurate and truthful are these reports and details?  Who is the chairman of the technology committee and are his/her reports accurate, timely and reflective of the needs of the company to support the basic operations of the company.
Whether your a big box company like Target, credit card processor like Hartland Payment Systems or just one of the largest email giants like YAHOO!  these and many other questions have to be answered, accurately, timely and honestly and yes, sometimes even painfully.

We have all read in the news that VERIZON is on the path to make an offer to Yahoo! with finalization next year and this latest exposure is certainly going to figure large into pricing.  Verizon
will pay a competitive price, but will not buy based on a hunch.  They will skillfully look at every single part of the Yahoo! digital empire and figure out just how much work will be needed to mend the broken system.  Information security practice will loom large as the price for Yahoo! could potentially shrink.  Information security is going to have to push its way into the board room and profit center discussions.  If not the corporate valuation is just not honest and leaves a lot to be desired when looking at the totality of the circumstances concerning corporate valuation.  Assessing a computer environment can be a very straight forward business.  But what we're seeing are limitations put on security professionals or very narrow scoping of projects which is shaving away a more wholesome look into the entire computer enterprise.  This is just a delaying tactic which is putting off the unavoidable.  Auditing should be ongoing quarter to quarter, year to year and used in helping to set budgets for the out years.  Audit chairs should be apart of the internal profit center discussions and everyone should be mindful of function over feature creep without warranted information security checks prior to implementation.  The sales guys are going to have to get involved in security the environment which they play a critical role in.

Integris Security is your trusted IT Security team that can help you as we provide tailored, high quality security solutions based on industry best practices and our principals combined experience of more than eighty years.  Call us for an appointment and free consultation.

Thursday, December 18, 2014

Banks: Federal/State Rules

No holiday would be complete with out a stern warning to the banking industry from both state and federal regulators, right?  Ho, ho, ho Merry Christmas - can you please assure us that your security controls are in order!

I was going to review Governor Andrew Cuomo's Department of Financial Services as it pertained to "new" security regulations for chartered banks in New York State.  The Superintendent of the Department of Financial Services initiated a press release and letter to chartered New York financial institutions.  After reviewing the memo I concluded that if all companies implemented the items in the Superintendent's letter, the public and private industries would be in a much better place. 

Then late yesterday the FFIEC (federal financial institutions examination council)  OCC (Office of the Comptroller of Currency) spokesman Joel Anderson spoke up.  Mr Anderson responding in a interview in American Banking Magazine stated, "we already do this" and what's going on in New York is nothing new. 

This is what New York DFS said they would look for:

New Rules: NYS
  • Corporate governance, including organization and reporting structure for cyber security related issues;
  • Management of cyber security issues, including the interaction between information security and core business functions, written information security policies and procedures, and the periodic reevaluation of such policies and procedures in light of changing risks;
  • Resources devoted to information security and overall risk management;
  • The risks posed by shared infrastructure;
  • Protections against intrusion including multi-factor or adaptive authentication and server and database configurations;
  • Information security testing and monitoring, including penetration testing;
  • Incident detection and response process, including monitoring;
  • Training of information security professionals as well as all other personnel;
  • Management of third-party service providers;
  • Integration of information security into business continuity and disaster recovery policies;
  • Cyber security insurance coverage and other third party protections
These are all things we at Integris Security does.

New York State then went on to list more topics which chartered banks in NYS would be expected to furnish.  We list them here for your review:


1.  Provide the CV and job description of the current Chief lnformation Security Officer or the individual otherwise responsible for information security, describe that individual's information security training and experience, and identify all reporting lines for that individual, including all committees and managers. In addition, provide an organization chart for your institution's IT and information security functions.
2.  Describe the extent to which your institution maintains information security policies and procedures designed to address the information security goals of confidentiality, integrity, and availability. Provide copies of all such information security policies.
3.  Describe how data classification is integrated into information risk management policies and procedures.
4.  Describe your institution's vulnerability management program as applicable to servers, endpoints, mobile devices, network devices, systems, and applications.
5.  Describe the organization's patch management program including how updates, patches, and fixes are obtained and disseminated, whether processes are manual or automated, and how often they occur.
6.  Describe identity and access management systems employed by the organization for both internal and external users, including all administrative, logical, and physical controls and whether such controls are preventive, detective, or corrective in nature.
7.  Identify and describe the current use of multi-factor authentication for any systems or applications.
8.  Describe your institution's due diligence process regarding information security practices that is used in vetting, selecting, and monitoring third-party service providers.
9.  Describe all application development standards utilized by the organization, including the use of a secure software development life cycle, and the extent to which security and privacy requirements are assessed and incorporated into the initial phases of the application development process.
10. Provide a copy of, to the extent it exists in writing, or otherwise describe, the organization's incident response program, including how incidents are reported, escalated, and remediated.
11. Describe the extent to which information security is incorporated into the organization's BCP/DR plan, how and how often the BCP/DR is tested, and the results of the most recent test.
12. Describe any significant changes to the institution's IT portfolio over the last 24 months resulting from mergers, acquisitions, or the addition of new business lines.

 Analysis:

It is a positive step forward for New York State Department of Financial Services to require its chartered financial institutions to meet minimum guidelines for the security of its information technology processes.  These security baselines are critically important not just to financial services institutions but to all public and private entities.  Since NYS has published these official rules it should now become the benchmark or de facto standard by which all other organizations are measured against.  These rules are appropriate and an outstanding starting point for any one who is not sure where to start.

The federal government provides an seemingly endless amount of guidance for the protection of information technology assets.  The fed's use the NIST framework and numerous NIST publications to assist everyone involved in the security of IT assets.  The federal regulators have been the go to professionals in the banking space for establishing standards so its not unusual to hear from Mr. Anderson of OCC or any of the regulators who are apart of the FFIEC. 

What is the news with this New York letter?  The federal regulators often calibrate their examinations according asset size.  Thus larger institutions receive more intense evaluation then smaller organizations.  However, New York has a very specific set of rules in which every institution must be prepared to comply with.  This is not a little matter and could have significant cost ramifications. 

Lastly, I have for years heard from administrators, mangers and CISO's who have tried to get budget authority to make the purchases necessary to secure their environments.  I am suggesting that security personnel use the NYS standards to present to CFO's as justification for future purchases.

http://dfs.ny.gov/about/press2014/pr1412101.htm

http://dfs.ny.gov/banking/bil-2014-10-10_cyber_security.pdf

www.americanbanker.com/news/bank-technology/occ-our-cybersecurity-exams-are-plenty-detailed-too-1071708-1.html

http://www.americanbanker.com/

Monday, June 9, 2014

What's Your Risk Tolerance?


                 Where's your army?

At  Integris Security we're asking the question who do you have protecting  your data and your information?  What's your risk tolerance?

Do you have an army of security professionals that are well trained and well informed?  If you are new to your environment have you conducted a full audit and/or do you have a full audit program in place?  Are you truly ready for a Red Team to come in and test your defenses?

If you're not scanning, testing and performing a critical analysis of your systems, people and workplace, then you just aren't testing and might as well leave the front doors open, leave the userid's and  passwords on the desk all day long and don't purchase another defensive tool. 

At Integris Security we perform system scanning as a good low level way to reveal vulnerabilities and to create of punch list to work on.  We conduct penetration testing because it takes testing several steps deeper and provides a full analysis on what's going on inside your environment.  But while all of these things are good they are really not good enough.  A network topology and architecture review would also be a great start but still not good enough.  You need to understand your risk tolerance.  In order to do this you need to understand your total environment.

An ISO 27001 certification is a top/down inside look at your environment. 


ISO/IEC 27001:2005, part of the growing ISO/IEC 27000 family of standards, is an information security management system (ISMS) standard published in October 2005 by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC).

If you're sitting on a board of a company it should be something you have in your binder and it needs to be maintained annually with weekly, monthly, quarterly, semi annual and annual updates.  This is a fact driven file that all discussions emanate from.  This certification is something every new CEO should be given once the keys to the kingdom are in his/her hands.  Every single discussion concerning future enhanced functions coming into a company need to flow from this certification.

Consider if you would driving a car without knowlege of how much gas you have left, whether or not you know if your signals or headlights are working.  You would effectively be driving blind.  Don't drive blind, know what's going on around you and respect the incredible complexity which is driving your companies profit center.  Become informed, challenge operators on both the security team as well as those on the business team to bring all the facts to the table.  Make an informed Risk Tolerance decision.  

How can you even begin to know your risk tolerance if you don't know what's in your wheel house?  Call Integris Security and let's get informed together. 


Trust is at the core of Integris Security. We can be counted upon to provide you with the services and intelligence to keep your information, systems and institution secure. Call us and let's get to work on improving your security/risk posture.



Saturday, May 31, 2014

Lessons from the U.S. Veterans Administration

Government run healthcare is suffering from the stiff stench of reality this week as the Veterans Administration emplodes in a wide scale corruption probe in over 46 different facilities - defining systematic corruption which has infected the entire bureaucracy.  What can we learn?

Audits tell part of the story and so does strong management which not only holds those accountable but is in fact in trenches leadership.  Take a hard look at, "Undercover Boss" and ask yourself if the leadership of the VA had been in the trenches could things have been any different.  Clearly the Administrator of the VA was fighting an uphill battle of liars, cheats, and more.  But "Undercover Boss" makes the point: get out of the office and get into the trenches for a reality check.  Now let's see if our USDOJ follows the Veterans Administration IG's report and starts the most necessary criminal investigations to clean the VA once and for all so that our war heros finally get what they deserve - the best health care known to man.

We talk much in this blog about management and boards of directors.  As we should.  Organizations depend on these fine men and women to do the impossible, to be supermen and women.  But the days of hands off management are long gone.  Whether you are in government or the private sector if you haven't gotten that message its high time you did.  Get out of the office and learn the reality of what is going on in the workplace.

We heard much this week about out dated technology and "scheduling".   We worry, is this a sign of times to come in government run healthcare?  Well, those of us in technology know all too well that technology does a backflip and ten steps forward about every 60-90 days.  So if you're thinking of saving money and leveraging your entire corporation and/or government run agency on shoestring that has a one time techology budget - in the immortal words from Brooklyn, NY - forget about it.

Technology is in the worst case an infant, with an appetite that rivals most young U.S. Marines in boot camp.  Belly up to the table because this infant is going to need your undying attention, your understanding and your coddling every single day of the week.  Budgeting and planning for the unexpected are just another great aspect which many who are so quick to adopt technology and outsourcing with an expectation of saving millions may want to slow down and take a deep breath.  Technology implementations are expensive and those seeking to cut to shortcuts are only doing a royal disservice to their companies and agencies and fooling themselves.  While the passing of timely and accurate information is exciting and used correctly can help you turn on a dime....it comes with a fairly large investment and huge reality check on expectations - but not on the information delivered, but on the intense care and ongoing maintainence to systems, controls and people.

Take a hard look at the Veterans Administration of today and ask yourself Mr/Mrs CEO or Agency head...could this be me?  Do I even have a clue?  We hope this as in any number of cases we bring to your attention help you focus not just on security but the fundermentals of leadership and management.

If you need a trusted source and friendly but well grounded reality check give us a call.  We would like your business, but we're not willing to suffer our reputation just to make a buck.

Trust is at the core of Integris Security. We can be counted upon to provide you with the services and intelligence to keep your information, systems and institution secure. Call us and let's get to work on improving your security/risk posture.






Thursday, March 6, 2014

The Russians Are Here...

The Russians Are Here

Estonia, Georgia and now Ukraine...

The Russian are coming, the Russians are coming!  As a modern day Paul Revere we're shouting at the tops of our lungs the Russians are coming!  But what does all this portend for those in the security and cyber security space?

In the sixties, seventies and so forth we were warned and taught in schools that the Communist were going to take over the world.  We were told they would do it without firing one single shot.  Given our current technology revolution has this become a more resolute reality?  Are we feeding our own eventual demise by participating in this ever interconnected world via the web?      

Well, if we look at Estonia, Georgia and now the Ukraine cyber invasions are most definitely front and center of every single world power and nation-state.  We invite your comments and observations as Russia leverages Crimean networks, telecom, communications capabilities and the gas pipeline infrastructure which feeds most of Europe and is most undoubtedly connected to SCADA systems.

Those of us in the security space would do well to pay close attention to methods of operation and techniques employed for both offense and defense whether as old as the hills or on the new frontier called the bleeding edge.  The global economy is not going away any day soon and we need to understand the threats-scape, our own infrastructure limits and wherein possible the bolstering of defenses to counter those threats as it may lead directly to our bottom line.  Testing to acceptable baseline defenses and offenses will only get you so far...conducting exercises for real resilience in the face of a MOST determined adversary is as they say, a horse of a different color.

We at Integris Security are here to help you prepare, test and evaluate your enterprise operations with an eye on: Can you survive in this global economy if your adversary has your company in their crosshairs?  Is your staff security aware?  Would you know an attack if it started?  Are your employees asleep at the switch, anchored in a serpentine bureaucracy or are they war-fighters listening, looking and revealing, reporting and proactively taking action?

Lastly, if sixty thousand security related alarms went off at your company would you roll over and go to sleep or more appropriately "RESPOND", "INVESTIGATE" and "REPORT"?

Here are a few links:

http://www.computerweekly.com/news/2240215674/Ukraine-and-Russia-locked-in-a-cyber-stand-off

http://defensetech.org/2008/08/13/cyber-war-2-0-russia-v-georgia/

http://www.computerweekly.com/news/2240215674/Ukraine-and-Russia-locked-in-a-cyber-stand-off

http://www.bbc.com/news/technology-26447200

http://www.huffingtonpost.com/2014/03/04/ukraine-cyberattack-mobile-phones-russia-parliament-security_n_4895287.html

http://www.stratfor.com/weekly/ukraine-and-little-cold-war?utm_source=freelist-f&utm_medium=email&utm_campaign=20140304&utm_term=Gweekly&utm_content=re

Thursday, January 30, 2014


Target Confirms Unauthorized Access...


ANALYSIS:


In recent days we have heard quite a bit about the 2014 Target Breach.  Additionally we have heard about the Neiman-Marcus breach which is said to be independent of the Target event but reports are that the malware used is similar.  Target is now investing billions of dollars to repair both its image and capabilities.  We have been discussing the Target breach and are trying to learn from each aspect of the incident as it becomes public.  The rationale has been to better our own security posture and help improve the overall security posture of the industry as a whole.  This breach investigation will evolve and we at Integris Security will evolve with it and learn as information becomes reliable and forthcoming.

Everything known at this point is speculation and inconclusive until the Target Corporation steps up to the microphone and gives a full autopsy. Not likely to happen any day soon as legal process is just now gathering information.

Law Enforcement (U.S. Secret Service or FBI) is typically very tight lipped about the circumstances and causes (operational details) leading up to such an event like this since they are in various stages of presenting materials to grand juries, attending to hearings, participating in a prosecution, etc..  Normally afterwards which could be a year or better after suspects are declared innocent or a conviction the details slowly pour out and begin to be known.

We are providing here some links which were discussed on weekly conference calls and provided to us by a number of different sources. Target is known as having very strong internal security procedures, posture and no one should take this post to mean target is not helping its own cause.  Previously we have spoken to Target personnel and know full well something seriously went awry. 

We have a deep sense of intrigue which is only natural and want to learn every single detail about this serious beach.  However as security practitioners we must be responsible and utilize some common sense and respect for the internal practitioners with the Security Teams at Target.  The security teams, their tasks, workload, etc these days must be daunting (incident response, business continuity programs and disaster recovery plans will receive plenty of scrutiny this time around).

We are posting from Neiman-Marcus as well even through the two cases have not been connected.

http://www.zdnet.com/neiman-marcus-1-1-million-cards-compromised-7000025513/
http://www.nytimes.com/2014/01/24/business/neiman-marcus-breach-affected-1-1-million-cards.htmlhttp://www.neimanmarcus.com/NM/Security-Info/cat49570732/c.cat?icid=topPromo_hmpg_ticker_SecurityInfo_0114

http://m.computerworld.com/s/article/9245877/Target_says_attackers_stole_vendor_credentials?source=CTWNLE_nlt_security_2014-01-30
http://krebsonsecurity.com/
http://krebsonsecurity.com/2014/01/a-first-look-at-the-target-intrusion-malware/
http://www.cnbc.com/id/101329300
http://www.reuters.com/article/2014/01/12/us-target-databreach-retailers-idUSBREA0B01720140112
http://www.us-cert.gov/ncas/alerts/TA14-002A
http://krebsonsecurity.com/2013/12/sources-target-investigating-data-breach/
http://pressroom.target.com/news/target-confirms-unauthorized-access-to-payment-card-data-in-u-s-stores

This listing is a short list but can lead to many solid sources.  We would also like to acknowledge the SANS organization that provides all of us some well thought out background discussion on this topic in its newsbites publication.  


CONCLUSION: 

Integris Security would be falling short not to mention to our clients and prospects that security awareness starts before a breach, before an employee is let go, before the budget cycle crows no more.  Simple security awareness proves to be an effective first step in a series of steps required to withstand the hailstorm which now befalls Target and others.   Security is not something JUST for those high tech guys and gals to mull over and talk about.  The security discussion from the smallest to the largest corporation starts with the CEO and is a culture he/she causes to infect every single part of the corporation.   This is a difficult thing for some when nothing seems to be happening.  Like fire drills being prepared with worth billions as we now see Target is prepared to spend.  



UPDATE:  3/10/2014

Thanks to our members.  The truth about the Target Breach is getting out.  Here is the latest:

"Troy Leach, the lead security standards architect for the PCI Council, testified March 5 that the vulnerabilities of magnetic-stripe card transactions have to be addressed. But he stressed that a migration to more secure chip card technology that conforms to the Europay, MasterCard, Visa standard would not, by itself, eliminate all security risks. In fact, he contended that the use of chip cards would not have prevented the exposure of card data caused by the malware attacks against Target and Neiman Marcus."

http://www.bankinfosecurity.com/target-hearings-emv-enough-a-6607


UPDATED: 3/13/2014

http://www.businessweek.com/articles/2014-03-13/target-missed-alarms-in-epic-hack-of-credit-card-data

Business week outlines the missed opportunities that TARGET had to stop the bad guys at the front door.  Some generalization about what happened overseas as well as adding to "Who" dropped the ball.  We may live in a global society but what part of the "global" isn't getting the "Security" message - this is not clear.  Assertions have been made that if kept inside the U.S., this security failure would not have happened, but that is easier said then done.  It is to be seen if analyst have the time....with all the blown data breaches if "OUTSOURCING" is in fact a savings or part of the overall cost house.  In this case it would appear as though TARGET may have save some cash by keeping things in the U.S., but all of this is very much UNPROVEN at the time of this post.

Fact was that Target was one of the big box companies at the vanguard of security.  Perhaps in hindsight they have realized that the security staff in place was not as "state of the art" or as "progressive" as one needs to be given the size and complexity of a major corporation.  Then one needs to ponder is this a problem of a CIO, CTO, CISO or other security persons?  Or is this a total miscalculation of the CEO, COO, CFO and do shareholders derserve a say in whether these individuals have earned a long term seat at TARGET?  Truly a let down, a major disappointment of a highly successful retailer here in the U.S.

UPDATED: 3/17/2014
http://www.computerworld.com/s/article/9246942/Major_companies_like_Target_often_fail_to_act_on_malware_alerts

The blog is updated with this article to highlight the fact that technology alone will not solve the IT security issues.  Ongoing professional development, exercises that test the effectiveness of staff with combined with indepth knowledge, skills and abilities about onboarding specific security tools is not cheap, but is the likely candidate for success of any security team.  Combining human resources and effective tools such as Fire Eye is a receipe for success.  Not cheap, but for certain an investment worthy of a healthy report card for any major corporation.

Joseph Concannon

Tuesday, October 1, 2013

Integris Security Tools - Test Yourself Before Your Attackers Do

Integris Security has recently launched their FREE online enabled security tools in conjunction with National Cyber Security Awareness Month.  These tools were typically only available from within a command line interface (CLI) and require low level knowledge of the tools themselves. The Integris Security Tools removes this requirement and extends these tools to within a web browser and even your smart phone. You simply sign up for an account, validate some information and your ready to begin using these tools.  Simply enter a URL/Fully Qualified Domain Name, IP Address and, in some circumstances, a port number.

Depending on the particular scan and the latency between our servers and the target server, scans can take several minutes. Because of this, we've included the capability to have scan results emailed to your registered address. Otherwise, you will receive scan results within your current browsers session.

Available tools currently include the following types of technologies.

  • SSL/TLS Server Strength
  • Port Scanner
  • HTTP Security Scanners
  • Domain Name Checkers
  • Web Framework Scanners
  • DNS Amplification Tester
  • and more...
We're continually investigate adding additional tools to increase the value of our free offering.

We highly encourage you to sign up and begin using these tools to help you increase your security posture.

Our service offerings include capabilities above and beyond these tools. If you require a more thorough, more in depth analysis then do not hesitate to email us at sales (at) integrissecurity (dot) com, call us at +1(516)750-0478 or visit our website at https://www.integrissecurity.com/.

For more information on National Cyber Security Awareness
Month, please visit http://www.staysafeonline.org/ncsam/.

Tuesday, July 23, 2013

Open for Business - Integris Security LLC

www.integrissecurity.com is now live
July 23, 2013             

Good evening everyone,

We broke ground about 40 days ago and here's our story:


Integris Security LLC has grown out of years passion for protecting our city, state and nation, its critical infrastructures and providing industry professionals with the best of breed solutions, practices and top notch security awareness. As things change for us from InfraGard to Integris Security LLC one thing will never change - the importance of nurturing your TRUST.
InfraGard a national public/private program of the FBI is the crossroad that brought us together as individual security professionals and that frames the very basis of our focus as a private security
company. Our security journey at InfraGard is well documented at NYM Infragard. We understand all too well the meaning behind Confidentiality, Availability and Integrity; in part its where we derived our name from. Each member of our staff at Integris is a vetted security professional.
For twelve years we've been taking the calls, learning what keeps you up at night and the utter frustration some of you are going through. The gentle balance of security and functionality continues and is a struggle that many professionals in industry have to deal with as a part of their daily routine. We have been busy identifying products, solutions, building bridges between the public and private sectors by seeding discussions, helping others to manage their expectations by providing our analysis, perspectives and at times putting out some fires. We've taken a bumpy ride with you on Wireless, BYOD, Network Security, DLP, The Cloud, Intelligence and much more. We've asked and will continue to ask the questions over and again what are we protecting, why are we protecting it and who owns the data?
At Integris Security we can help you emphasize and prioritize the importance of what's critical to running the business, in identifying the data to be protected, in testing to identify your vulnerabilities, identification of what and who is on your network, in helping you resolve audit recommendations and provide you with a roadmap for future success.
It all starts with building the trust.
We are very excited to continue the security journey with you and invite you to contact us with your security, risk management needs or if all you need is someone to listen as you walk us through your security/risk management concerns.
  1. www.integrissecurity.com is live

Thursday, July 18, 2013

InfraGard Conference Call 7/17/13

Good afternoon all,

Earlier today I had the good fortune to be on the InfraGard NYC weekly conference call.  We were discussing an issue I raised in our Linked-In Group, Integris Security Insights.  If you'd like to be invited to the group just let us know.  The group is a terrific group of security professionals.

On the linked-in group I try to be mildly provocative and sometimes even a little sarcastic given the incident or situation of the day.  In this weeks post I asked the question do you know who's on your network or what's on your network?

The point is this: too many companies have no idea how to even begin to wrap their hands around these questions.  For larger companies this can get complex.  For smaller to mid sized companies we have something which could answer some of your troubles.  

Take a look at Lan Sweeper as a tool which can help you map your network, count your machines, switches, routers, software licenses and more.  Their may also be some "open source" resources and when and if we find them I'll post it here.

Have a great day!

Joe Concannon

Wednesday, July 17, 2013

Integris Security is coming on line and our security services offering is now in development.  Stay tuned as we ramp things up and take our work from construction to ready for prime time.  Hang with us and be patience.

Friday, March 22, 2013

All Grown Up: GRC Is The New Frontier


Guidance Software is located in Pasadena, California and is recognized as the worldwide industry leader in digital investigative solutions.  The EnCase platform is very well known to industry professionals and to some extent that is both a blessing and a curse.  Guidance Software has grown up and now provides a diversified set of products capturing digital evidence and breaking deeper into enterprise operations.   Some may be surprised as this once thought of detective’s tool is now ready for the board room.

Guidance Software holds its annual CEIC Conference and this year General Michael Hayden will keynote regarding emerging global cyber attack hotspots.  Hayden is a catch and this is not to be missed.  This is the annual May event that Guidance showcases each year and generally is very well received.

The last time I spoke to anyone from Guidance Jim Doyle was running their NYC Sales and consulting operations.  So last night I caught up with one of Guidance’s Sales Executives for the NYC region and we talked.  In this post I’ll  highlight just some of the conversation and how that simple, one off digital forensic product has expanded deep into the enterprise.  

GRC Ready....Are You?
The first place to start here is “EnCase” now featuring version 7.06 in Digital Forensics and available in four flavors Enterprise, Forensic, Portable and Tableau Forensic. Guidance provides powerful and comprehensive instruction and training for those breaking into the product line for the first time and great refresher for those looking back and wondering if they hit all the points.  On line, on-demand training via Adobe Connect is driving even greater saturation into the market place and providing easy and up to date product and web facing familiarity.  Getting to know V7 is a mouse click away for our forensic investigators and enterprise personnel.  Well done Guidance Software.

Wordle Capture
From my point of view I was looking for more information in how Guidance Software is breaking further into the enterprise.  I learned for instance investigators can reach out over the web and remotely capture information needed.  Acquiring data from disk or RAM, documents, images, e-mail, webmail, Internet artifacts, Web history and cache, HTML page reconstruction, RAIDS, workstations, servers and with V7: smartphones and tablets.  Our favorite forensic tool has indeed grown up to be a powerful forensic toolkit standing at the ready.  Something Guidance would label as complete Endpoint Visibility.  Well, not too many years ago that meant visiting every location and seizing computers and/or servers.  The remote capability is a real draw to the product line.

Perhaps one of the more unexpected areas Guidance Software has moved into is the Governance Risk and Compliance areas (GRC).  Frankly I just hadn’t put Guidance Software’s EnCase on my radar for GRC.  But with EnCase Enterprise edition your getting a very powerful software application with powerful automation tools.  The gold standard comes with a price that promises to make some a little queasy.  But the Enterprise Edition is going to let you see over the entire network and report on a wide variety of governance, risk and compliance issues.  For me this brought our dinner conversation last night full circle.  As we then dug into GRC and applications and tools provided by EnCase Enterprise combined with Adobe Connect lessons available right on the web this purchase could be viewed as answering some distressing questions left on the table after your last audit.  Check out Guidance Software and let me know if you find another similar product in the market place that comes close.