Stories by Thor Olavsrud

Most Data Breaches Caused by Human Error, System Glitches

By Thor Olavsrud | 17 June, 2013 18:13

When it comes to data breaches, hackers and organized crime garner most of the headlines, but most data breaches are caused by human errors and system glitches--application failures, inadvertent data dumps, logic errors in data transfer and more. As a result, educating your employees and making sure they're not cutting corners is a big component in preventing data breaches.

Social Sites Beat Retailers and Banks for Consumer Protection and Privacy

By Thor Olavsrud | 10 June, 2013 16:43

For the second year in a row, social media sites (including gaming and dating sites) are leading the way in consumer security and privacy protections, beating out Internet retailers and banks, according to an annual comprehensive audit by the Online Trust Alliance (OTA).

CISOs Must Engage the Board About Information Security

By Thor Olavsrud | 31 May, 2013 16:38 | 1 Comment

Your organization will come under attack. It's not a matter of "if." It's a matter of "when." And security is no longer simply an operational concern. As technology has become the central component of nearly all business processes, security has become a business concern. As a result, information security should sit firmly on the boardroom agenda.

Signature-Based Endpoint Security on Its Way Out

By Thor Olavsrud | 29 May, 2013 14:32

Signature-based blacklisting security technologies are losing the battle against malware, says McAfee, which has streamlined its endpoint security offerings to two suites that it says provide next-generation security for all endpoints, whether PCs, tablets or ATMs.

PayPal says it's time to ditch passwords and PINs

By Thor Olavsrud | 09 May, 2013 20:28

PayPal CISO Michael Barrett took the keynote stage at Interop to announce the impending death of passwords and their replacement with more robust authentication protocols based on an open standard. Apple may lead the way with its next iPhone.

Splunk Adds Statistical Analysis to Enterprise Security App

By Thor Olavsrud | 30 April, 2013 21:08

Analysis of machine-generated data can play an important role in a sophisticated layered defense for your data and systems, but getting there can be challenging even with advanced intelligence platforms.

AP Twitter Hijacking Proves Need for Better Authentication, Encryption

By Thor Olavsrud | 23 April, 2013 21:37

The Associated Press's Twitter account was hijacked this afternoon and used to tweet a false message that reported two explosions at the White House had left U.S. President Barack Obama injured. One security expert says the incident underscores the need to adopt out-of-band two-factor authentication and keystroke encryption.

How your authentication scheme could hurt your business

By Thor Olavsrud | 17 April, 2013 19:30

Consumers often fail to perform transactions online due to authentication failure. But while they struggle, they also distrust websites with weak authentication procedures.

4 Mobile Security Predictions to Help CIOs Plan for the Future

By Thor Olavsrud | 15 April, 2013 14:24

Few things can keep CIOs up at night these days like mobility, particularly bring your own device (BYOD). After all, mobile, consumerization of IT and bring-your-own-device (BYOD) are turning enterprise security models on their heads. Privacy implications--let alone the potential for data loss and data leakage--are enough to make a CIO break out in a cold sweat.

IT Concerns About Targeted Malware Rising

By Thor Olavsrud | 28 March, 2013 13:30

IT and security professionals are increasingly concerned about targeted malware and data breaches. What's worse is that their confidence in their ability to identify and stop them is waning.

Aggressive Mobility Plans Bring Risks, But the Rewards Are High

By Thor Olavsrud | 08 March, 2013 16:41

Mobility is a top-of-mind concern for a majority of CIOs today. Companies that are proactively embracing mobility to transform their businesses are incurring much greater costs associated with mobility incidents, but they are also reaping significant rewards, according to a new study by Symantec.

Digital Certificates Chaos Could Cost Companies $398 Million

By Thor Olavsrud | 04 March, 2013 17:42

Trust. It is the basis of all digital transactions. We trust that our inventory systems are providing the correct information, that the documents we're reading have not been altered, that the entity on the other side of a financial transaction is our bank.

Chinese Government's Link to Cyber Espionage Clearer Than Ever

By Thor Olavsrud | 20 February, 2013 16:09

It's a common belief in the information security world that the Chinese government is behind many of the advanced persistent threats that target companies around the world in an effort to steal their IP and trade secrets. Now one security firm has come forward with years of evidence to link a prolific APT group to a unit inside the Chinese government.

Certificate Authorities Form Group to Educate on SSL Best Practices

By Thor Olavsrud | 15 February, 2013 17:45

Responding to the increasing number of threats aimed at certificate authorities and the ecosystem of trusted online transactions they represent, seven certificate authorities have come together to form an advocacy group to advance security standards and promote best practices.

FIDO Alliance Says, 'Forget Passwords!'

By Thor Olavsrud | 12 February, 2013 19:40

If there's one thing that's become clear in the past several years, according to PayPal CISO Michael Barrett, it's that usernames and passwords--originally conceived in the era of centralized mainframes--have become more of a liability than a protection online.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Secure Virtualization of Business Applications

Run your mission-critical applications in a secure and compliant virtual datacenter, or private cloud.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.