Stories by Ellen Messmer

SunGard brings cloud service to disaster recovery

By Ellen Messmer | 15 May, 2013 21:57

Can the old guard in business continuity and disaster-recovery services thrive in an era when the companies are looking at new ways to process business data? SunGard Data Systems, with decades of experience in availability services, is feeling the pinch as some business clientele move data to the cloud. But SunGard says it's pushing forward with innovations that are making it a public cloud provider as well with the kind of application availability it says will be hard to match elsewhere.

Online gaming company recounts fighting for survival vs. DDoS attacks

By Ellen Messmer | 14 May, 2013 18:08

Fighting denial-of-service attacks has become a matter of survival for some businesses that find their websites getting smashed and network flooded by attackers. Online gaming company SG Interactive says it's under constant attack and the only way to keep going is to set up an anti-DDoS defense.

McAfee rethinks consumer security service delivery

By Ellen Messmer | 14 May, 2013 06:12

McAfee, part of Intel, today announced a profound shift in how it distributes and prices its consumer security products by introducing LiveSafe, a service that combines anti-malware plus a score of other capabilities, such as anti-theft protection and a so-called "safety deposit box" in the cloud that can only be accessed by means of the user's face or voice biometric.

McAfee taps Intel to offer high-throughput intrusion-prevention system

By Ellen Messmer | 09 May, 2013 20:39

McAfee is taking advantage of its new owners by rolling out a high-throughput intrusion-prevention system (IPS) family built on Intel technology.

Cisco gets tough: Details ruggedized switches for harsh environments

By Ellen Messmer | 07 May, 2013 14:29

Cisco, which wants to expand its clout into the industrial networks used by power-generation utilities to support the electric grid, today announced an expansion of its "smart grid" portfolio with ruggedized and low-latency switches and other equipment intended for use in electric-power distribution systems.

Facebook 'Trusted Contacts' lets you pester friends to recover account access

By Ellen Messmer | 02 May, 2013 18:33

Facebook Thursday said it’s making available globally a feature called "Trusted Contacts" that lets users select three to five friends who can help users recover account access such as if they forget their password.

Companies explore self-detonating data as security control

By Ellen Messmer | 02 May, 2013 18:33

The popular Snapchat photo-messaging app used mainly by Android and iOS mobile device owners to share images that then self-destruct after 10 seconds is the sort of security idea that businesses say can help them secure online transactions with business partners.

‘Content spoofing’ a major website vulnerability, study finds

By Ellen Messmer | 02 May, 2013 12:27

A close look at vulnerabilities in about 15,000 websites found 86 per cent had at least one serious hole that hackers could exploit, and “content spoofing” was the most prevalent vulnerability, identified in over half of the sites, according to WhiteHat Security’s annual study published today.

Control and security of corporate open-source projects proves difficult

By Ellen Messmer | 30 April, 2013 18:02

Open source has become a staple for software development in the enterprise, but keeping track of it and maintaining security for it remains an elusive goal, according to a survey of more than 3,500 data architects and developers published today by Sonatype, which provides component lifecycle management products and also operates the Central Repository for downloading open-source software.

Trend Micro seeks to make Amazon Web Services more secure

By Ellen Messmer | 30 April, 2013 14:08

Trend Micro today announced a slate of cloud-based security services that it says protect servers for Amazon Web Services (AWS) customers.

The bottom line on phishing

By Ellen Messmer | 29 April, 2013 19:20

Phishing attacks on enterprises can be calamitous in terms of compromised networks or damaged brand names, and the Anti-Phishing Working Group (APWG), which aggregates and analyzes phishing trends data worldwide, offers some of the best insight from industry into what's occurring globally in terms of this cybercrime. The following list of frequently asked questions about phishing is derived from the APWG's April report that covers the period July-December 2012 worldwide.

McAfee offers one-time passwords for single sign-on cloud service

By Ellen Messmer | 25 April, 2013 16:16

McAfee Thursday announced it’s providing a one-time password function as part of its Cloud Single Sign On service for more securely provisioning and de-provisioning hundreds of cloud-based services for enterprise use.

DHS use of deep packet inspection technology in new net security system raises serious privacy questions

By Ellen Messmer | 24 April, 2013 20:23

To protect the federal civilian agencies against cyberthreats, the Department of Homeland Security (DHS) is preparing to deploy a more powerful version of its EINSTEIN intrusion-detection system that’s supposed to detect attacks and malware, especially associated with e-mail. But since this version of EINSTEIN is acknowledged by DHS to be able to read electronic content, it’s raising privacy concerns.

Business students to get HP-designed technical course for cloud, mobile, security issues

By Ellen Messmer | 23 April, 2013 19:21

College business students need to gain a grasp of technical issues related to cloud computing, big data, security and other network issues they're likely to come across in their careers, so HP is now offering its first technical associate certification for them to cover these topics while in college.

Chinese cyber-espionage rising, says Verizon annual report

By Ellen Messmer | 23 April, 2013 02:16

Cyber-espionage originating from China has become a top source of data breach incidents, according to an annual report from Verizon. The report found Chinese spying and theft of sensitive corporate information, such as intellectual property, accounted for about 20% of the 621 data breach cases last year that Verizon analyzed.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Open Space Security Suite

Kaspersky Open Space Security provides complete business protection in a single integrated suite of applications that work seamlessly across all platforms.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.