Wednesday, September 28, 2016

Information Security in Corporate Valuation

What do you look at when considering the corporate valuation of a company?  Chief financial officers pour over spreadsheets, public filings and much more to get a temperature so they can inform investors, boards and others in the decision making process.  Where is Information security in this discussion?  Who is the chairman of the board's audit committee and how comprehensive are the details and reports?  How accurate and truthful are these reports and details?  Who is the chairman of the technology committee and are his/her reports accurate, timely and reflective of the needs of the company to support the basic operations of the company.
Whether your a big box company like Target, credit card processor like Hartland Payment Systems or just one of the largest email giants like YAHOO!  these and many other questions have to be answered, accurately, timely and honestly and yes, sometimes even painfully.

We have all read in the news that VERIZON is on the path to make an offer to Yahoo! with finalization next year and this latest exposure is certainly going to figure large into pricing.  Verizon
will pay a competitive price, but will not buy based on a hunch.  They will skillfully look at every single part of the Yahoo! digital empire and figure out just how much work will be needed to mend the broken system.  Information security practice will loom large as the price for Yahoo! could potentially shrink.  Information security is going to have to push its way into the board room and profit center discussions.  If not the corporate valuation is just not honest and leaves a lot to be desired when looking at the totality of the circumstances concerning corporate valuation.  Assessing a computer environment can be a very straight forward business.  But what we're seeing are limitations put on security professionals or very narrow scoping of projects which is shaving away a more wholesome look into the entire computer enterprise.  This is just a delaying tactic which is putting off the unavoidable.  Auditing should be ongoing quarter to quarter, year to year and used in helping to set budgets for the out years.  Audit chairs should be apart of the internal profit center discussions and everyone should be mindful of function over feature creep without warranted information security checks prior to implementation.  The sales guys are going to have to get involved in security the environment which they play a critical role in.

Integris Security is your trusted IT Security team that can help you as we provide tailored, high quality security solutions based on industry best practices and our principals combined experience of more than eighty years.  Call us for an appointment and free consultation.

Friday, June 24, 2016

Drones: Are they on your radar?

Drones - friend or foe?
Early in the computer industry programmers used to write computer code to automate many functions and features.  As the years progressed the same code was used for more nefarious purposes. Computer code used for these nefarious purposes is commonly called malware: Viruses, Worms and Trojans. 

Now early in the drone industry we are being teased with visions of Amazon dropping boxes in our rear yard, fast food deliveries arriving with piping hot pizza via a drone and many other examples of how the use of this technology can enhance our lives.  The examples are endless.

However, while drones can in fact do much to enhance our lives the use of drones can also be pointed to more nefarious purposes.  Common perimeter defenses can be easily undermined with relatively little effort for the determined attacker.  With a few thousand dollars your intellectual property can vanish in seconds.  Installation of an onboard camera with pan tilt and zoom could steal your ideas right out of your board room.  The drone can do this and more while still being blocks away.  As drones mature and their payload capability increases security directors and facility personnel concerns will only increase.

Integris Security LLC has for years identified both leading and bleeding edge technologies.  Today, we have identified a strategy, a technology and method to address not all but some of the issues concerning drones.  We would like to set an appointment to speak with you and see if this is on your radar screen.  Drones can be managed and can be one less thing that keeps you up at night.

Press Release:
http://tinyurl.com/hjwpt54

FAA News:

http://thecipherbrief.com/article/exclusive/tech/implications-new-faa-commercial-drone-rules-1092

Integris Security Web Site 6/25/16:





Drones: Are they on your radar?

Drones - friend or foe?
Early in the computer industry programmers used to write computer code to automate many functions and features.  As the years progressed the same code was used for more nefarious purposes. Computer code used for these nefarious purposes is commonly called malware: Viruses, Worms and Trojans. 

Now early in the drone industry we are being teased with visions of Amazon dropping boxes in our rear yard, fast food deliveries arriving with piping hot pizza via a drone and many other examples of how the use of this technology can enhance our lives.  The examples are endless.

However, while drones can in fact do much to enhance our lives the use of drones can also be pointed to more nefarious purposes.  Common perimeter defenses can be easily undermined with relatively little effort for the determined attacker.  With a few thousand dollars your intellectual property can vanish in seconds.  Installation of an onboard camera with pan tilt and zoom could steal your ideas right out of your board room.  The drone can do this and more while still being blocks away.  As drones mature and their payload capability increases security directors and facility personnel concerns will only increase.

Integris Security LLC has for years identified both leading and bleeding edge technologies.  Today, we have identified a strategy, a technology and method to address not all but some of the issues concerning drones.  We would like to set an appointment to speak with you and see if this is on your radar screen.  Drones can be managed and can be one less thing that keeps you up at night.

Press Release:


Drones: Are they on your radar?

Drones - friend or foe?
Early in the computer industry programmers used to write computer code to automate many functions and features.  As the years progressed the same code was used for more nefarious purposes. Computer code used for these nefarious purposes is commonly called malware: Viruses, Worms and Trojans.  See our updated posts below.

Now early in the drone industry we are being teased with visions of Amazon dropping boxes in our rear yard, fast food deliveries arriving with piping hot pizza via a drone and many other examples of how the use of this technology can enhance our lives.  The examples are endless.

However, while drones can in fact do much to enhance our lives the use of drones can also be pointed to more nefarious purposes.  Common perimeter defenses can be easily undermined with relatively little effort for the determined attacker.  With a few thousand dollars your intellectual property can vanish in seconds.  Installation of an onboard camera with pan tilt and zoom could steal your ideas right out of your board room.  The drone can do this and more while still being blocks away.  As drones mature and their payload capability increases security directors and facility personnel concerns will only increase.

Integris Security LLC has for years identified both leading and bleeding edge technologies.  Today, we have identified a strategy, a technology and method to address not all but some of the issues concerning drones.  We would like to set an appointment to speak with you and see if this is on your radar screen.  Drones can be managed and can be one less thing that keeps you up at night.

Press Release:

http://tinyurl.com/hjwpt54

FAA News:
http://thecipherbrief.com/article/exclusive/tech/implications-new-faa-commercial-drone-rules-1092

Integris Security Web Site 6/25/16:
https://www.integrissecurity.com/index.php?solutions=DroneDefense




Monday, February 9, 2015

Are You A Farmer Maybe A Network Engineer?

John Deer Tractor
While I'm not a farmer at hand I have dabbled with backyard gardening tools and have proudly planted and harvested several groupings of tomato plants and boy were they delicious.  Did I own the tools, the knowledge and the capability?  I thought so...but boy have times changed.

Today I'm reading a wired article and learning that farmers need to improvise and tinker around just as much as any one else in order to keep important and valuable machinery at work - working.  However the article which you can find here: http://www.wired.com/2015/02/new-high-tech-farm-equipment-nightmare-farmers/ tells a story which applies much further then a central Illinois corn farmer sitting on top of his combine.

The story written by Kyle Wiens of Wired brings up a great point.  Who really owns it and what does it hold for me, the owner?  A farmer in Wiens article spends over a hundred thousand for is top flight John Deer Tractor let's say and at the end of the day the question prevails, who really owns it?  You buy a top flight network appliance and we ask you, who really owns it?

While the seller wants you to buy their state of the art machinery or device, they do not release the software, hardware or for that matter everything inside which makes the machine or network device in the very first place so invaluable.  You of course get to ride it sometimes and use it for its intended purpose watch the lights bubble on/off.  You even get to clean it and shine it up with wax and polish if so inclined or just dust it off.  But if this 100,000 dollar baby decides to shut down or its circuits get glued or jammed up what you own is a 100,000 dollar shinny piece of metal and perhaps a bill for getting it towed off your lot or pulled off your network when it decides to shut down.

Like so many things today from a John Deer Tractor to a state of the art upstream protection appliance for your network the question prevails who really owns it?  The point being that you really need to be reading the fine print upon purchase, understand your operating system, learn about the configuration and understand what the long term consequences would be for owning such a machine or device.  In one case after the next we're witnessing not the lack of budget to purchase an upscale machine or network appliance but the long term ongoing problems associated with ownership, such as: maintenance, upgrades, proper configuration, segmentation, alarming and enumeration. 

While I'm not a farmer, things are rapidly changing and we'd better be changing with them or for sure the consequences will lay right in our own laps.  Failure to fully understand the value of modern day machinery/network devices, lack of service level agreements or understanding thereof, maintenance contracts whether your a farmer or network engineer machinery breaks down and so do network devices.  Of course if they are not setup and configured correctly in the first place you could say you're just throwing money out the window.  Times are changing, better be nimble and change with them.  Its not just about buying that state of the art "thing" but understanding the long term consequences of ownership can be just as expensive as "Ownership" in the first instance.  Buyer beware.

Thursday, January 8, 2015

"Support Your Local Police" interview

http://nws.mx/1IwF1bA
Joe Concannon speaks with Steve Malzberg

Integris Security president Joe Concannon was recently on The Steve Malzberg Show on NewsmaxTV.  Steve and Joe discussed the series of "Support Your Local Police" rallies that promote unity with the men and women in blue who serve the communities of New York City.  Watch it on NewsmaxTV  (http://nws.mx/1IwF1bA).

Thursday, December 18, 2014

Banks: Federal/State Rules

No holiday would be complete with out a stern warning to the banking industry from both state and federal regulators, right?  Ho, ho, ho Merry Christmas - can you please assure us that your security controls are in order!

I was going to review Governor Andrew Cuomo's Department of Financial Services as it pertained to "new" security regulations for chartered banks in New York State.  The Superintendent of the Department of Financial Services initiated a press release and letter to chartered New York financial institutions.  After reviewing the memo I concluded that if all companies implemented the items in the Superintendent's letter, the public and private industries would be in a much better place. 

Then late yesterday the FFIEC (federal financial institutions examination council)  OCC (Office of the Comptroller of Currency) spokesman Joel Anderson spoke up.  Mr Anderson responding in a interview in American Banking Magazine stated, "we already do this" and what's going on in New York is nothing new. 

This is what New York DFS said they would look for:

New Rules: NYS
  • Corporate governance, including organization and reporting structure for cyber security related issues;
  • Management of cyber security issues, including the interaction between information security and core business functions, written information security policies and procedures, and the periodic reevaluation of such policies and procedures in light of changing risks;
  • Resources devoted to information security and overall risk management;
  • The risks posed by shared infrastructure;
  • Protections against intrusion including multi-factor or adaptive authentication and server and database configurations;
  • Information security testing and monitoring, including penetration testing;
  • Incident detection and response process, including monitoring;
  • Training of information security professionals as well as all other personnel;
  • Management of third-party service providers;
  • Integration of information security into business continuity and disaster recovery policies;
  • Cyber security insurance coverage and other third party protections
These are all things we at Integris Security does.

New York State then went on to list more topics which chartered banks in NYS would be expected to furnish.  We list them here for your review:


1.  Provide the CV and job description of the current Chief lnformation Security Officer or the individual otherwise responsible for information security, describe that individual's information security training and experience, and identify all reporting lines for that individual, including all committees and managers. In addition, provide an organization chart for your institution's IT and information security functions.
2.  Describe the extent to which your institution maintains information security policies and procedures designed to address the information security goals of confidentiality, integrity, and availability. Provide copies of all such information security policies.
3.  Describe how data classification is integrated into information risk management policies and procedures.
4.  Describe your institution's vulnerability management program as applicable to servers, endpoints, mobile devices, network devices, systems, and applications.
5.  Describe the organization's patch management program including how updates, patches, and fixes are obtained and disseminated, whether processes are manual or automated, and how often they occur.
6.  Describe identity and access management systems employed by the organization for both internal and external users, including all administrative, logical, and physical controls and whether such controls are preventive, detective, or corrective in nature.
7.  Identify and describe the current use of multi-factor authentication for any systems or applications.
8.  Describe your institution's due diligence process regarding information security practices that is used in vetting, selecting, and monitoring third-party service providers.
9.  Describe all application development standards utilized by the organization, including the use of a secure software development life cycle, and the extent to which security and privacy requirements are assessed and incorporated into the initial phases of the application development process.
10. Provide a copy of, to the extent it exists in writing, or otherwise describe, the organization's incident response program, including how incidents are reported, escalated, and remediated.
11. Describe the extent to which information security is incorporated into the organization's BCP/DR plan, how and how often the BCP/DR is tested, and the results of the most recent test.
12. Describe any significant changes to the institution's IT portfolio over the last 24 months resulting from mergers, acquisitions, or the addition of new business lines.

 Analysis:

It is a positive step forward for New York State Department of Financial Services to require its chartered financial institutions to meet minimum guidelines for the security of its information technology processes.  These security baselines are critically important not just to financial services institutions but to all public and private entities.  Since NYS has published these official rules it should now become the benchmark or de facto standard by which all other organizations are measured against.  These rules are appropriate and an outstanding starting point for any one who is not sure where to start.

The federal government provides an seemingly endless amount of guidance for the protection of information technology assets.  The fed's use the NIST framework and numerous NIST publications to assist everyone involved in the security of IT assets.  The federal regulators have been the go to professionals in the banking space for establishing standards so its not unusual to hear from Mr. Anderson of OCC or any of the regulators who are apart of the FFIEC. 

What is the news with this New York letter?  The federal regulators often calibrate their examinations according asset size.  Thus larger institutions receive more intense evaluation then smaller organizations.  However, New York has a very specific set of rules in which every institution must be prepared to comply with.  This is not a little matter and could have significant cost ramifications. 

Lastly, I have for years heard from administrators, mangers and CISO's who have tried to get budget authority to make the purchases necessary to secure their environments.  I am suggesting that security personnel use the NYS standards to present to CFO's as justification for future purchases.

http://dfs.ny.gov/about/press2014/pr1412101.htm

http://dfs.ny.gov/banking/bil-2014-10-10_cyber_security.pdf

www.americanbanker.com/news/bank-technology/occ-our-cybersecurity-exams-are-plenty-detailed-too-1071708-1.html

http://www.americanbanker.com/