June 17, 2020
|
Perspective
Back in the days when the words DAST/SAST/IAST weren't even mentioned, about 10 years ago, "Mr. Anonymous," the assistant technology manager of a cash-in-transit company, asked us what other security assessments could be performed on their web applications, besides what was then called a "web app penetration test." At the time, we replied (in addition to what was previously called secure) […]
November 26, 2018
|
Perspective
In Chapter 2, “Speed as a Competitive Advantage,” of the book “Time Is Money,” Tammy Everts cites an application security conclusion from the 2013 Radware report that will shake up a common misconception among CISOs regarding denial-of-service (DoS) attacks: Whether it’s a public website or an internal web application, most of us believe that a […]
March 09, 2018
|
Perspective
Repairing IT failures is an inevitable practice, but stakeholders should know that engineers in other industries have been concerned for decades with reducing post-production failures. This same practice should be applied to the technological implementation and development process in every organization, especially now that security problems are so prevalent.
August 02, 2016
|
Perspective
One of the most frightening characteristics of insider fraud is that once it starts, it doesn't stop until someone notices, usually indirectly. Other IT threats cease after a certain period of time, but insider fraud can persist for years. Download the full article here. JaCkSecurity
July 16, 2016
|
Perspective
It was Christmas time. The quality and reputation of a luxury hotel were about to be put to the test. The location? The metro area of the capital of security and espionage stories (Washington, DC, USA). A flaw in the hotel's software security was about to be revealed by one of its guests. Download the article here. JaCkSecurity
July 04, 2016
|
Perspective
Good preparation is the ace up the sleeve of great professionals in the field of illusion, and it is also the starting point for effective incident response management. The life cycle of incident response consists of: (1) preparation, (2) detection/analysis, (3) containment/eradication/recovery, (4) post-incident actions. Good preparation does not necessarily mean more protection, after all […]
July 04, 2016
|
Perspective
A good priest always teaches, "Brother/Sister, first know who you are going to marry, get to know the groom's family very well, and that's how your married life will most likely be." We do the same when we hire. We ask for references, and if possible, we visit past clients. But when it comes to security which is where software factories terribly disappoint their customers how do you do it? JaCkSecurity
July 04, 2016
|
Perspective
The importance of a thorough post-incident forensic analysis and investigation to minimize negative consequences. 57% cite investigating non-malicious incidents as essential and important for their company. 64% cite investigating malicious incidents as essential and important for their company. The information age sets the standard for not leaving incidents unresolved or undetermined. For this reason, Ponemon's statistics […]
July 04, 2016
|
Perspective
The dynamics of business demand almost without you noticing that significant amounts of your company's data be continuously sent by autonomous systems, outsourced personnel, and even your own employees to business process outsourcing systems and/or similar platforms. The problem: Many of these systems are public, vulnerable, and generally haven't been certified by the relevant department.
May 26, 2016
|
Perspective
Myth: High-tech security companies have led their customers to believe that their devices can detect and prevent security breaches. Reality: However, most security breaches are discovered accidentally. The Ponemon Institute (2013) states: 34% of non-malicious breaches (due to illegal network use) are discovered accidentally, and 28% of malicious breaches (targeted attacks) are discovered by […]