- Endpoint and NAC Protection
- Network Security Monitoring: Tools and Systems
- Threat and Vulnerability Management
- Virtual Private Network Security
- Wireless Network Security: Setup, Issues and Threats
Email Alerts
-
Royal Holloway 2012: Designing a secure contactless payment system
In his Royal Holloway thesis, Albert Attard proposes a contactless payment system to make card-not-present credit card transactions more secure.Feature
-
MDM, security vendors scramble to address BYOD security issues
Organisations are looking beyond NAC and MDM to resolve BYOD security issues; MDM, security and hybrid vendors are responding with new products.News | 18 May 2012
-
With mobile payments, security teams must move quickly
As employees make payments on their mobile devices, the security team must act quickly to ensure corporate assets remain secure.Tip
-
ISBS 2012 report: Security slow to adapt to new technologies
PwC’s ISBS 2012 report, which will be presented at Infosecurity 2012, shows security teams react too slowly to threats from new technologies.News | 20 Apr 2012
-
Report: Corporate mobile device policy must align security, job roles
In the debate between BYOD and company-issued devices, a new report compares mobile platforms and recommends devices based on users’ job roles.News | 13 Apr 2012
-
Finding Mobile device security training courses for IT admins
Expert Davey Winder suggests some good security training courses for the IT administrator who must manage their organisation’s mobile devices.Ask the Expert
-
Verizon data breach report highlights continuing POS vulnerabilities
Improperly secured point-of-sale systems continue to offer an easy target to cybercriminals according to the 2012 data breach report from Verizon.News | 22 Mar 2012
-
IT security research reveals changing priorities in UK
-
Four mobile device security threats and three tools to manage them
Mobile devices pose very real risks to organisations. Rob Shapland outlines four mobile device security threats and three tools to manage them.Tip
-
Getting serious about tablet security risks and user training
With increasing tablet security risks, the time has come to get serious about user education. UK Bureau Chief Ron Condon prescribes a new mindset.Opinion | 14 Mar 2012
- VIEW MORE ON : Endpoint and NAC Protection
-
Using open source intelligence software for cybersecurity intelligence
Discover the information that may be leaking out of your organisation before hackers use it to launch an attack against your organization.Tip
-
“Click-for-tickets” fraud: Teaching users to sidestep Olympic scams
Attackers are expected to use the Games to foster email and Internet fraud. Learn how to help users sidestep Olympics-related scams.Tip
-
SIEM deployment case study shows patience is required
Williams Lea’s SIEM is already helping reduce manual log reviews. But there’s still a lot of work to be done before the SIEM can be fully deployed.News | 30 Mar 2012
-
Future of SIEM market hinges on past mistakes
The SIEM market had a rocky start, but recent technology advancements have made SIEM products easier and more reliable.News | 29 Mar 2012
-
Using Burp Suite proxy tool to examine client-side requests
The free Burp Suite proxy tool can be used for good or for bad. Expert Rob Shapland provides usage scenarios for both.Tip
-
New Sourcefire firewall with content filtering promises more control
Sourcefire has announced its new firewall with content filtering, which it says will let administrators control users’ activities at a business level.News | 14 Dec 2011
-
London firm offers fixed-price cloud DDoS protection
One company has launched a fixed-price cloud DDoS-protection service for mitigating the ever-present threat of DDoS attacks.News | 16 Nov 2011
-
University IT security pros thwart content piracy with traffic shaping
A traffic-shaping system installed at the University of Exeter quickly yielded huge dividends by blocking illegal piracy of music and films.News | 27 Oct 2011
-
New batch of IDS, IPS evasion techniques are hitting their targets
Stonesoft has discovered 163 new advanced evasion techniques (AET), claiming these AETs can pass below the radar of some IDS, IPS products.News | 12 Oct 2011
-
OpenVAS how-to: Creating a vulnerability assessment report
In this OpenVAS how-to, learn how to use the free scanner to create a vulnerability assessment report and assess threat levels.Tip
- VIEW MORE ON : Network Security Monitoring: Tools and Systems
-
Royal Holloway 2012: A framework for preventing cross-site scripting
Based on his Royal Holloway thesis, Joseph Bugeja proposes a new framework for preventing cross-site scripting attacks.Feature
-
Royal Holloway 2012: An incident response process for armoured malware
An incident response process may be futile when dealing with today’s armoured malware, as explained in this Royal Holloway article.Feature
-
Techniques for preventing a brute force login attack
A brute force login attack can enable an attacker to log in to an application and steal data. Rob Shapland explains how to prevent brute force attacks.Answer
-
Royal Holloway 2012: Risks of multi-tenancy cloud computing
In his Royal Holloway 2012 thesis, Jacobo Ros examines the risks of multi-tenancy cloud computing.Feature
-
“Click-for-tickets” fraud: Teaching users to sidestep Olympic scams
Attackers are expected to use the Games to foster email and Internet fraud. Learn how to help users sidestep Olympics-related scams.Tip
-
File upload security best practices: Block a malicious file upload
Do your Web app users upload files to your servers? Find out the dangers of malicious file uploads and learn six steps to stop file-upload attacks.Answer
-
SOCA takes its website offline in DDoS response
Just days after SOCA shut down carder sites, the agency was the victim of a DDoS attack, leading SOCA to takes its website offline.News | 03 May 2012
-
Adding cybercrime software demos to security awareness training
Security professionals can use screenshots of cybercrime software in security awareness training to convey the serious threats organisations face.Tip
-
International computer crime requires an international response
As international computer crime increases in scope and organisation, countries must work together to reduce threats from global cybercrime.Opinion
-
Infosecurity 2012: Survey proves value of security awareness programme
According to the latest findings from PwC, better end-user security training can pay off in fewer breaches.News | 27 Apr 2012
- VIEW MORE ON : Threat and Vulnerability Management
-
A pen tester’s perspective on creating a secure password
A pen tester explains the importance of creating a secure passwordTip
-
How to ensure secure email exchange with external business partners
When sensitive documents are frequently travelling back and forth between a company and its business partners, email security becomes very important. In this expert response, Peter Wood gives advice on how to create a secure email exchange.Ask the Expert
-
New cloud VPN service improves application acceleration, security
A new cloud VPN service offered by Aruba Networks Inc., called VBN 2.0, promises to make it easier and more secure for remote users to connect to the VPN.Article | 05 Apr 2010
-
Expert calls SSL protocol vulnerability a non issue
The researchers who discovered the SSL vulnerability warn that it could have far reaching affects and are working with a consortium of vendors to coordinate an industry-wide fix.Article | 05 Nov 2009
-
DNSSEC deployment challenges can be overcome
DNSSEC isn't a cure-all for DNS security issues. It won't stop drive-by attacks, protect against denial-of-service attacks or any other kind of attacks that piggyback on top of the DNS and depend upon social engineering for success. But it does block cache poisoning attacks and DNS hijacking, a problem that represents a major threat to ecommerce on the Internet. DNSSEC deployments are moving forward. Early adopters are beginning to develop best practices and education materials for upgrading systems and properly configuring devices to handle DNSSEC requests. Federal agencies are required to adopt DNSSEC by the end of the year for .gov domains. .Org was the first domain that signed on to DNSSEC. .Edu signed on to DNSSEC this week with its 6,000 registrants. .Net and .com are expected to sign on by 2011. In this interview, Lance Wolak, director of product management at PIR, which manages the .org domain and Ram Mohan, executive vice president and chief technology officer of Afilias Ltd. share their experiences and the road ahead for DNSSEC deployments.Interview | 11 Sep 2009
-
How to integrate the security of both physical and virtual machines
According to a recent Gartner Inc. research report, 60% of virtual machines will be less secure than their physical counterparts through 2009. Michael Cobb explores the challenges of securing a mixed infrastructure of physical and virtual machines.Tip
-
Companies tackle iPhone security with remote access features
Secure remote access and better management could turn the popular toy into a true business tool.Article | 17 Feb 2009
-
Q&A: Paul Dorey on DLP, deperimeterisation
Paul Dorey is one of the pioneers of information security as a profession. He worked on early security measures at the investment bank Barclays PLC and has most recently been director of digital security for global oil company BP Corp., a role that he will relinquish at the end of this year.
He has advised governments on security, he sits on the European Advisory Board for ISC2, and is also an advisor to the European Network and Information Security Agency (ENISA). Dorey is also a founder member of the Jericho Forum and chairman of the fledgling Institute of Information Security Professionals (IISP).
Here he talks about some of the technological and professional challenges facing companies and people working in information security today.Interview | 19 Sep 2008
-
How to patch Kaminsky's DNS vulnerability
When Dan Kaminsky revealed the details of his recently discovered DNS flaw at this year's Black Hat briefings in Las Vegas, it confirmed what many in the security community already feared: that it was one of the most important discoveries in years, and that enterprises must take urgent action. In this tip, Mike Chapple details why an exploit could be devastating, and what organizations should do to protect their end users.Tip
-
Network telescopes are vital to beating security threats
The latest article in our Royal Holloway series describes how network telescopes operate by searching the dark areas of the internet where no legitimate traffic needs to go.Article | 17 Apr 2008
- VIEW MORE ON : Virtual Private Network Security
-
The new EU data protection regulation: Planning for compliance
The new data protection rule will impact businesses worldwide. Discover quick wins for SMBs and projects for large businesses to move to compliance.Tip
-
MDM, security vendors scramble to address BYOD security issues
Organisations are looking beyond NAC and MDM to resolve BYOD security issues; MDM, security and hybrid vendors are responding with new products.News | 18 May 2012
-
With mobile payments, security teams must move quickly
As employees make payments on their mobile devices, the security team must act quickly to ensure corporate assets remain secure.Tip
-
Infosecurity 2012 Europe: Conference news and highlights
Get the latest news and important research from the Infosecurity 2012 Europe conference, including coverage on security threats and data breaches.Guide
-
Getting serious about tablet security risks and user training
With increasing tablet security risks, the time has come to get serious about user education. UK Bureau Chief Ron Condon prescribes a new mindset.Opinion | 14 Mar 2012
-
Taking control of smartphone proliferation while avoiding user anarchy
With smartphone proliferation raging through companies, IT teams are turning to MDMs to keep corporate data safe. Are current MDMs up to the task?Feature | 14 Mar 2012
-
IT in Europe, Security Edition: Smartphone security issues
How can security teams manage devices they don’t control? Find out how to manage smartphone and tablet security threats.Learning Guide
-
Stop phone tracking and GPS data leakage
GPS-enabled smartphones and other GPS devices may leak confidential or sensitive data, making it easy for attackers to target your employees.Tip
-
Swiss bank balances tablet security issues with performance, cost
When a Swiss bank needed solve its tablet security issues, it found a way to secure its devices without sacrificing performance by using virtualisation.News | 02 Dec 2011
-
Roundup: University case studies on innovative security products
Browse this collection of university case studies from colleges that have successfully implemented innovative security products.Tutorial
- VIEW MORE ON : Wireless Network Security: Setup, Issues and Threats