Stories by Taylor Armerding

Big Data Investigations: Opportunity and Risk

By Taylor Armerding | 17 May, 2013 13:01

Experts say large-scale security analytics can cut through the noise to find key intelligence. But connecting the dots can lead to legal trouble

Taking copyright fight to ISPs too punitive, say critics

By Taylor Armerding | 05 March, 2013 14:27

Copyright Alert System, which could slow or suspend your Internet service, said to lack due process

Advanced volatile threat: New name for old malware technique?

By Taylor Armerding | 22 February, 2013 00:07

AVTs are not widespread -- yet -- because 'APTs are working just fine,' says Triumfant CEO. But they could one day start a cyberwar, he said

Mandiant gains instant fame after Chinese hack report

By Taylor Armerding | 21 February, 2013 14:18

But report also raised questions about how the report was rolled out, and whether information could have been made public earlier

Chinese Army link to hack no reason for cyberwar

By Taylor Armerding | 20 February, 2013 01:31

Finding of China's involvement in recent hacks in U.S not an act of war because it's cyberespionage, says proponent of active defense

Google Play shares too much personal info, app developer says

By Taylor Armerding | 15 February, 2013 14:42

Some defend Google, but privacy experts say it's a problem

Despite hopeful initiatives, demise of passwords years away

By Taylor Armerding | 14 February, 2013 13:10

FIDO Alliance, DARPA vow to create better authentication, but new systems will have to attract users and providers, say security pros

Executive order on cybersecurity coming, but is it only a 'down payment on legislation'?

By Taylor Armerding | 13 February, 2013 14:21

Based on leaked versions of the order, the White House is expected to put DHS in charge of organizing an cyberthreats information-sharing network

Mobile malware still small, but 'malnets' to rise up

By Taylor Armerding | 12 February, 2013 14:47

With 70 per cent of employees across corporate networks using a personal smartphone or tablet, growing attack surface too big to ignore

Fed stays secretive after Anonymous hack

By Taylor Armerding | 08 February, 2013 14:22

Security experts ask if government won't share information, why should the private sector?

'Sleeper' malware like Nap Trojan nothing new

By Taylor Armerding | 07 February, 2013 14:22

New malware uses common technique to avoid automated analysis, security experts say

Gozi takedown big, but not likely to change threat landscape

By Taylor Armerding | 06 February, 2013 14:19

With Gozi's masterminds indicted, the Trojan has probably run its course. But like with drug cartels, when one falls another rises up

Department of Energy hack exposes major vulnerabilities

By Taylor Armerding | 05 February, 2013 14:34

Security experts say damage probably not serious, but that the implications are

Privacy battle against U.S. drone surveillance ramps up

By Taylor Armerding | 01 February, 2013 14:27

Government and private ever more capable drones has prompted fear of 'a wholesale surveillance state,' and lawmakers are responding

FBI pursuit of Stuxnet leaks reignites whistleblower debate

By Taylor Armerding | 31 January, 2013 13:54

Critics say Obama administration is seeking to quash freedom of the press with efforts to find out who leaked information about the worm

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Trend Micro Mobile Security

Comprehensive enterprise protection for mobile devices

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.