Showing posts with label expert. Show all posts
Showing posts with label expert. Show all posts

Monday, March 14, 2011

How to Become the Go-To Expert on Mobile Security

Back in December, I wrote about the need for an army of mobile security experts to help lock down the mobile devices and the communication paths we all use. The more I read about it, the more I believe that the demand can't be understated. Security is simply not keeping up with the way we work and communicate, and it should be easy to convince a CIO that a strong team of security gurus is far less expensive than a single multimillion-dollar security disaster that could cripple the company's business and damage its reputation.

More on the Need for Mobile Security ExpertsYou know that the day-to-day grind of American business is slowly but surely migrating from desktops to smartphones, tablets and other devices. There are 264.5 million data-capable wireless devices on carrier networks in the U.S. In the first halfof 2010, and they handled 161.5 billion megabytes of data, up some 40 percent from the previous six months, according to the CTIA Semi-Annual Report on Wireless Trends. Gartner says the number of information workers using smartphones worldwide will grow to more than 1 billion by 2014. 

Much of today's wireless traffic consists of email and text messaging. It likely always will, but an increasing percentage of mobile corporate data consists of file attachments and information acquired directly from enterprise servers.

When you look at the applications mobile employees are allowed to use, you see a complete office on the move. A majority of workers use typical office productivity apps - plus CRM, project management, document workflow, and conferencing. Mix in a little HR, accounting and payroll, and you wonder if the airport lounge is the best place to be accessing those types of files.

Anecdotal evidence suggests that IT often doesn't implement tight authentication procedures, even when the device manufacturers provide them in their operating systems. Part of this is because users just hate having to log in every time they turn on their phones. Data encryption, auditing and automatic security software updates are also rare in mobile apps.

Here's What You Do

So what's the opportunity for you? To become the security go-to person on whom IT depends to lock down mission-critical enterprise data when it goes mobile. How do you do that?

Learn how to secure mobile devices by understanding what their operating systems provide in the way of security - and their implementation - even if employees will squawk about the inconvenience of log ins and the like.

Learn how to secure the applications employees use on the go. Features such as encryption are often there. You just have to look for them and activate them.

Secure the communications path between the mobile employee and home base. That means you should become the go-to person for VPNs and firewall maintenance.

Educate the masses. No one wants to be lectured about the dangers of hacking, spying and mobile application spam. But employees need to know about the inherent risks of working remotely with sensitive data, especially if they're doing that work on a personal gadget and not one that's been configured and approved by IT management. The BYOD (bring your own device) trend is growing as users demand to use their own devices. That's one more huge security threat that you, as a security guru, can help to address.

-- Don Willmott

How to Become the Go-To Expert on Mobile Security


Backlink: http://career-resources.dice.com/articles/content/entry/more_on_the_need_for

Tuesday, February 22, 2011

Ending Soon! 50% Off Google AdWords, Plus A Google Expert!

pipeline logo

Google AdWordsToday's Deal:  $75 for $150 worth of Google AdWords

Whether it's for your day job, your hobby business, your pet charity project, or your start-up idea that someday will rule the world,  everyone could use some search engine marketing mojo. But where to start and how to begin? Google has come through with a great deal for Pipeline members. First, they are offering a starter package of AdWords at 50% off. Even cooler, you'll get the support of Google’s specially-trained experts and bidding geniuses via a dedicated Google phone team. 

Why We Chose This Deal:

  • Spend as little per month as you like, and adjust your budget as you track results.
  • AdWords Call Metrics, a new feature, automatically includes a unique phone number in your ads to measure calls you receive from AdWords.
  • Link AdWords to Google Analytics to deepen your understanding of the results, such as how people navigated to your site.
  • Give your webmaster a break! We’ve arranged for a Google expert to be on hand to set you up, answer all of your questions, and take care of the trouble-shooting.

   

What is Pipeline? Find out more >>
Follow Pipeline on Twitter >>

Join the conversation about this story »




Ending Soon! 50% Off Google AdWords, Plus A Google Expert!


Backlink: http://feedproxy.google.com/~r/typepad/alleyinsider/silicon_alley_insider/~3/nj62K1QwDqU/50-off-google-adwords-plus-a-google-expert-2011-2

Friday, November 19, 2010

New Threats Demand Organisational Changes, says IT Security Expert

The information security threat landscape has changed in 2010, taking on a highly targeted form and creating new issues for organisations. To meet this challenge head on, IT Security expert Richard Stiennon from IT Harvest USA has recommended a new organisational structure be adopted.

Speaking ahead of his presentation at CeBIT Australia’s IT Security Conference, Mr Stiennon explained it was not until 2010 that many organisations identified the changing form of threats.

“It’s only in the last 12 months that organisations have begun to realise a fundamental shift in the threatscape”

And as the types of threat evolve, the structure of a security team needs to evolve too, says Stiennon.

“New threats and new environments do require organisational changes. I think that’s what has to happen pretty quickly”

“Only through this organisational change is a company or government organisation going to get on top of this new level of threat”

Stiennon has recently released a suggested structure for a new "cyber defence team".

“I’ve recently gone public with a description of what a cyber defence team would look like. There’s three elements; there would be a research team who is responsible for understanding that threat environment, to understand what’s going on so they can translate those in to what it means for their internal organisation”

“You then need an operational team who goes after already successful attacks”

“The internal operational team would work with the existing infrastructure you’ve got now for handling viruses and patch management but would look deeper in to countering unique instances that have occurred”

“Then finally, a third element is essentially a “red team” - people who are acting as insiders and attempting to find vulnerabilities and methods of attack before the bad guys can”

This proposed team would then report to a new position who would then sit under the CIO, says Stiennon.

“Then working all together and reporting up to a new role - call it a Cyber Defence Commander or something else if you don’t care for the military terminology”

“That person would be responsible probably to the CIO, for making them completely aware of not only the threatscape but the level of exposure that the organisation has”

Stiennon described the Stuxnet attacks as being a recent example of these new types of threat.

“We saw just in the last several months the development of Stuxnet, which is the very, very sophisticated attacks against some control networks inside a manufacturing facility - and possibly a nuclear refinement facility”

This new form meant that the attacker and the target took on a much more personal role, he explains.

“Now, it’s some adversary who has selected a target, which is your data and they are going to be prepared to do whatever they can to get at that data”

Stuxnet and similar attacks meant that traditional forms of protection were now no longer adequate, he said.

“It’s completely different than using classic signature based anti-virus or ITS to just protect your networks from the constant background radiation of attacks that’s always been with us”

Richard Stiennon is presenting at CeBIT Australia’s IT Security Conference, taking place on 29 November in Sydney.

This conference brings together industry leaders to exchange ideas and advice about how they are minimising security threats to their organisations while taking full advantage of today’s open and connected environment.

Find out about the program and full speaker line-up at www.cebit.com.au/it-security.