Stories by George V. Hulme

City lights: Securing critical infrastructure

By George V. Hulme | 04 March, 2013 18:10

During the 2007 housing crisis, Columbus, Ohio--like most municipalities--faced significant tax shortfalls and revenue constraints.

RSA 2013: Keynotes highlight state of optimism and fear

By George V. Hulme | 27 February, 2013 01:50

Sure, things are tough for security pros right now, note keynote speakers. But all is not lost in the war against cybercrime

RSA 2013: Weatherford outlines 'cyber 9-1-1' plan

By George V. Hulme | 25 February, 2013 23:19

Mark Weatherford, deputy undersecretary for cybersecurity at DHS, wants to set up a cyber 9-1-1 system for critical infrastructure. He outlined his vision today at the Cloud Security Alliance Summit, held as part of the RSA Conference.

Three ID management challenges

By George V. Hulme | 18 December, 2012 17:35 | 1 Comment

Effective identity management is essential to security, regulatory compliance and in some cases even business success. So why is it still so hard for many companies?

Resistance is futile: CISOs talk about embracing change

By George V. Hulme | 06 November, 2012 19:20

The younger IT workforce is bringing major change to organizations -- whether those organizations like it or not.

Global infosec survey finds more talk - but not more action

By George V. Hulme | 24 October, 2012 14:52

Anyone you care to ask will likely--and reasonably--agree that the threats against IT systems and data are serious and organizations need to take appropriate steps to protect their infrastructure and information. But if you look at the practices actually in use at many organizations, it becomes painfully apparent that there's still a wide gulf between ideals and reality.

7 common risk management mistakes

By George V. Hulme | 26 September, 2012 19:28

Executives know they face risks, but they often don't know which risks are real, or what that exposure means to their business.

Secure360: The failure of risk management

By George V. Hulme | 11 May, 2012 23:30 | 1 Comment

IT security and risk professionals who attended the 7th Annual Secure360 Conference earlier this week at the St. Paul River Center in Saint Paul, Minnesota certainly heard a startling earful as the show kicked-off: If they're not managing risk right in their organization, they may, in fact, be the biggest risk their organization faces.

Hacktivists have the enterprises' attention. Now what?

By George V. Hulme | 08 May, 2012 01:57

Enterprise security pros have plenty to worry about: malware, insiders stealing information, an employee leaving an unencrypted notebook full of gigabytes of intellectual property on a train. However, the spate of hacktivist attacks in recent years from groups such as Anonymous and LulzSec has upped the anxiety level. According to a number of recent surveys, Most IT and security professionals see Anonymous as a serious threat to their companies.

StubHub scalps fraudsters

By George V. Hulme | 24 April, 2012 06:00

Robert Capps knows a lot about fraud and transaction-level risk. As senior manager of trust and safety at StubHub, Capps has witnessed just about every trick that can be thrown at a fraudulent transaction. In case you're not aware, since 2000, StubHub has provided a marketplace for event-goers to buy and sell tickets to sporting games, concerts and theater shows.

Embedded system security much more dangerous, costly than traditional software vulnerabilities

By George V. Hulme | 17 April, 2012 04:19

One of the biggest challenges in security today is how the software in our operating systems and applications are so full of holes. And while traditional software makers have made (some) headway in developing more resilient applications, experts say embedded device and systems makers -- from those who create implanted medical devices to industrial control systems -- are eons behind in secure system design and development maturity.

Mind the Byte seeks secure clouds to transmit research

By George V. Hulme | 13 April, 2012 07:41

There's plenty of talk about enterprises building hybrid clouds that contain the appropriate mix of public cloud and private resources. But there's not a lot of choices available to securely move or manage workloads across such disparate environments.

MDM: Part of the mobile security solution?

By George V. Hulme | 10 April, 2012 01:27

The good news for enterprises: Mobile devices are packed with power. A new iPhone is 100 times lighter, 100 times faster, and 10 times less expensive than the luggable notebooks of the early 1980s.

Key advice: Being prepared for when the Cloud really fails

By George V. Hulme | 15 March, 2012 03:49 | 1 Comment

Everything works well in the Cloud, until it doesn't.

Severe space weather: How big a threat?

By George V. Hulme | 14 March, 2012 01:33

Last week a dark spot on the Sun, nearly the size of Jupiter, let go with a massive solar eruption. For a number of days thereafter, scientists around the world waited to see if the discharged solar plasma and charged particles would interfere with communication systems, satellites, computer circuits and even the electrical grid.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Malware Analysis System

(MAS) gives threat analysts hands-on control over powerful auto-configured test environments where they can safely execute and inspect advanced malware.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.