10 things I know about preventing ID theft

By Michelle Drolet . 10 Jun 2014

10. Use cash or gift cards The threat of identity theft is reduced dramatically if you don’t use your credit card for all your purchases, so consider using cash or even gift cards to pay your way. 9. PCI compliance is important The payment card industry has a set of security standards for a reason: … Continue reading 10 things I know about preventing ID theft

Towerwall listed among “20 Most Promising Security Consulting Companies”

By Michelle Drolet . 2 Jun 2014

Also named to CRN’s “Women in the Channel” and “The Power 50”     BOSTON – May 12, 2014 – Towerwall (www.towerwall.com), an IT security services provider for small to mid-size businesses, today announced it was selected for inclusion in a list of the 20 “Most Promising Enterprise Security Consulting Companies.” The list was compiled … Continue reading Towerwall listed among “20 Most Promising Security Consulting Companies”

Deciding Between Vulnerability Scanning And Penetration Testing

By Michelle Drolet . 8 May 2014

My clients often confuse scanning and penetration testing. Organisations should be conducting both external vulnerability scans and penetration tests. If you are storing or transmitting data on the Internet, particularly sensitive data such as credit card details, then quarterly scanning is required to validate your PCI compliance. You also need to conduct a penetration test … Continue reading Deciding Between Vulnerability Scanning And Penetration Testing

Data Security Review Issue 2: Know the Threats

By Michelle Drolet . 4 May 2014

Welcome to Issue 2 of the Data Security Review It seems that every time you turn around there is a new data security threat in the news, like Cryptolocker and Heartbleed. Our customers are always asking us how to identify the next “big” threat. Our answer is that you cannot keep up with the hackers, … Continue reading Data Security Review Issue 2: Know the Threats

Is Blind Trust Making You Unsafe?

By Michelle Drolet . 14 Apr 2014

Personal and business relationships rely on trust to function, but blind trust in the digital world is downright dangerous. We’re asked to trust companies all the time. We trust them with personal details and they promise to keep them safe. It’s the same story in the enterprise. One company will entrust another to backup and … Continue reading Is Blind Trust Making You Unsafe?

Towerwall Heartbleed Vulnerability Alert

By Michelle Drolet . 11 Apr 2014

Good Afternoon: The IT infrastructure your organization may use for day-to-day business may be vulnerable because of the Heartbleed vulnerability. Sophos a Towerwall partner has prepared a podcast of the Heartbleed vulnerability, which addresses who is likely affected, workarounds and an offer to help determine if you are vulnerable. http://nakedsecurity.sophos.com/2014/04/10/sscc-142-heartbleed-explained-patches-evaluated-apple-chastised-podcast/ If you think you may … Continue reading Towerwall Heartbleed Vulnerability Alert

Towerwall Information/Vulnerability Alert Vol 13.69: Cisco Security Notice

By Michelle Drolet . 20 Mar 2014

Cisco Security Notice Cisco WebEx Business Suite HTTP GET Parameters Include Sensitive Information CVE ID: CVE-2014-0708 Release Date: 2014 March 18 19:07  UTC (GMT) Last Updated: 2014 March 19 17:58  UTC (GMT)SummaryA vulnerability in Cisco WebEx Business Suite could allow an unauthenticated, remote attacker to view sensitive information transmitted in GET parameters of URL requests.   The vulnerability is due to inclusion of sensitive … Continue reading Towerwall Information/Vulnerability Alert Vol 13.69: Cisco Security Notice

Successful Breakfast Event: From Zero to Data Governance Hero

By Michelle Drolet . 14 Mar 2014

Thanks for all that joined Towerwall at the From Zero to Data Governance Hero breakfast event! Towerwall and Varonis experts gave first-rate information on the importance of pressing data concerns of 2014. Also, Varonis’ speaker gave a great live demonstration on the Data Governance Suite! It was an event well spent! “Towerwall is always looking … Continue reading Successful Breakfast Event: From Zero to Data Governance Hero

Patch Tuesday wrap-up, March 2014 – critical fixes from Microsoft and Adobe

By Michelle Drolet . 11 Mar 2014

by Paul Ducklin on March 12, 2014 We already wrote about Microsoft’s March 2014 patches, noting that, as usually happens, there was an All-Points Bulletin for Internet Explorer coming up. Microsoft doesn’t call them APBs, of course – they are Cumulative Security Updates, with one bulletin covering all the numerous versions, bitnesses and CPU flavors of Redmond’s IE browser. … Continue reading Patch Tuesday wrap-up, March 2014 – critical fixes from Microsoft and Adobe

Towerwall Information Security/Malware Alert Vol 13.67 – Notorious “Gameover” malware gets itself a kernel-mode rootkit…

By Michelle Drolet . 3 Mar 2014

Zeus, also known as Zbot, is a malware family that we have written about many times on Naked Security. We’ve covered it as plain old Zbot. We’ve covered the Citadel variant, which appeared when the original Zbot code was leaked online. We’ve even written about the time it pretended to be a Microsoft fix for CryptoLocker, a completely different … Continue reading Towerwall Information Security/Malware Alert Vol 13.67 – Notorious “Gameover” malware gets itself a kernel-mode rootkit…

Tags