Stories by Joan Goodchild

IntegriCell's Aaron Turner: Security managers still don't get mobile security

By Joan Goodchild | 20 May, 2013 18:20

For the past several months, security veteran Aaron Turner has been making the rounds at industry events presenting some pretty disturbing information about the state of mobile security.

Women leaders in security recognized

By Joan Goodchild | 06 May, 2013 15:46

Each year, the Executive Women's Forum announces their "Women of Influence" Awards at their annual EWF event.

Social engineering in penetration tests: 6 tips for ethical (and legal) use

By Joan Goodchild | 23 April, 2013 22:12

Social engineering techniques are frequently part of an overall security penetration test; often used as a way to test an organization's so-called "human network."

Security and vulnerability assessment: 4 common mistakes

By Joan Goodchild | 08 April, 2013 18:21

If you're running a robust security program, you're regularly conducting security and vulnerability assessments of your both your network and physical environments. But in the quest to uncover security gaps and vulnerabilities, slip-ups are often made, too, that make these efforts less effective at having a positive impact.

In Pictures: 9 classic hacking, phishing and social engineering lies

By Joan Goodchild | 19 March, 2013 09:46

Whether it is on the phone, online or in person, here are ten lies hackers, phishers and social engineers will tell you to get what they want

How Blackstone is finding BYOD success with BYOA(pple)

By Joan Goodchild | 04 March, 2013 17:16

Bill Murphy, CTO and managing director at Blackstone, a global investment and advisory firm, knew he wanted to find a way to allow employees to use their own devices for work. The demand was there, and he was increasingly hearing about how adding in BYOD would help productivity.

How Colorado's CISO is revamping the state's information security -- on a $6,000 budget

By Joan Goodchild | 21 February, 2013 15:56

Before Jonathan Trull took over as Chief Information Security Office for the state of Colorado in 2012, he had already been working in the Colorado Office of the State Auditor for a decade. As the Deputy State Auditor, he was responsible for overseeing annual audits of the state's systems.

In Pictures: Security mistakes right at your workspace

By Joan Goodchild | 21 January, 2013 08:17

This workspace contains 10 security mistakes. Can you spot the errors that put confidential information at risk?

5 more tough security questions (and tips on answering them)

By Joan Goodchild | 09 January, 2013 17:47

At first glance, Eric Cowperthwaite, Chief Security Officer at Providence Health and Services in Renton, Washington, doesn't care how excellent a job candidate's credentials and experience look on paper. He wants to see how much of an impression they make on his team.

5 tips to retain great security talent

By Joan Goodchild | 18 December, 2012 00:11

You want the best on your security team. And once you've got them, you want to keep them happy and keep them in your organization.

Securing one million shoppers for the holidays

By Joan Goodchild | 28 November, 2012 20:56

Like all malls in the United States, the Arden Fair Mall in Sacramento is being overrun with shoppers as the holiday season kicks into high gear.

Former Zynga CSO: Innovate or Die

By Joan Goodchild | 05 November, 2012 21:47 | 2 Comments

For the past three years, Nils Puhlmann was head of security for Zynga, the social games company that created mega-hits Farmville and Words With Friends.

In Pictures: 20 notorious worms, viruses and botnets

By Joan Goodchild | 05 November, 2012 08:57

The earliest worms and viruses were created for geeky fun and did little harm - oh, how times have changed. Here are 20 worms, viruses and botnets that show the evolution of malware, from Creeper to Flame.

The 12 Cons of Christmas

By Joan Goodchild | 31 October, 2012 16:21

While the risk of being hacked, conned or having sensitive information stolen is possible all through the year, most security experts agree that the holiday season brings a spike in fraudulent activity, both online and off.

Using security metrics to measure human awareness

By Joan Goodchild | 16 October, 2012 20:03

It's been said that security is hard to measure. Producing measurable results around a lack of problems or incidents is challenging. But the field of security metrics has evolved considerably in recent years, giving security managers more resources to make the case for investing in security programs and technologies.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Identity & Security Management

Identity and Security Management

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.