Stories by Ellen Messmer

Want a security pro? For starters, get politically incorrect and understand geek culture

By Ellen Messmer | 29 October, 2012 20:47

While complaints can be heard far and wide that it's hard to find the right IT security experts to defend the nation's cyberspace, the real problem in hiring security professionals is the roadblocks put up by lawyers and human resources personnel and a complete lack of understanding of geek culture, says security consultant Winn Schwartau.

In Pictures: Baddest Botnets of 2012

By Ellen Messmer | 29 October, 2012 13:51

According to security firm Kindsight, these are the Top Ten Worst Botnets this year.

Ernst & Young's IT security survey shows struggle to control cloud computing, social media and mobile risks

By Ellen Messmer | 29 October, 2012 04:53

Many CIOS and chief information security officers are struggling to adapt security practices to a changing environment that includes cloud computing, social media and tablets , according to a survey of 1,850 such IT pros.

BYOD resistance loosening but security practices lacking

By Ellen Messmer | 25 October, 2012 10:50

A survey of 650 information and security professionals about how the "bring your own device" (BYOD) trend is impacting their organizations finds one-quarter of them forbid use of personally owned devices such as smartphones and tablets on the network. However, the majority that do often lack meaningful policies or security controls related to these devices.

Hollywood studios pushing for secure, next-generation "digital home library"

By Ellen Messmer | 24 October, 2012 19:55

Home entertainment today is often provided through a clutter of TVs, tablets, and computers, along with TV specialty boxes for yet more streaming video or music services. But some Hollywood studios are hoping to find better ways to deliver paid content to consumers directly to hard drives and flash storage, according to Cryptography Research, which is working on a futuristic project to do that.

DDoS attacks against banks raise question: Is this cyberwar?

By Ellen Messmer | 24 October, 2012 17:56

It's been a month of crippling denial-of-service attacks on websites operated by U.S. banks and financial services firms. A terrorist organization called Al-Qassam takes credit online, but now the attacks are being blamed on Iran.

Investment firms feeling bullish on BYOD

By Ellen Messmer | 22 October, 2012 18:44

Don't fear the "bring your own device" (BYOD) trend -- take a chance and find out if it works in your organization, say IT managers in the financial industry that let employees make use of their personal smartphones and tablets for work.

Android malware exploding, says Trend Micro

By Ellen Messmer | 22 October, 2012 12:43

The amount of mobile Android malware has surged this year, from a count of 30,000 malware specimens in June to almost 175,000 last month, according to Trend Micro's Security Roundup report for the third quarter of this year.

IBM makes security push with cloud services, products aimed at mobile and Big Data

By Ellen Messmer | 18 October, 2012 07:07

IBM today widened its security offerings with products and cloud-based services focused broadly on both mobile devices and Big Data, both areas where IBM foresees growth as enterprises sort out their strategies toward both.

University hospital putting in place BYOD mobile strategy

By Ellen Messmer | 16 October, 2012 19:38

A teaching hospital based in Israel, Hadassah University Hospital, has devised a plan to be able to support the "bring your own device" (BYOD) wishes voiced by medical staff and students clamoring to use their own mobile devices, while also bringing to bear management and security controls.

Antivirus evaluation puts Kaspersky and Symantec on top

By Ellen Messmer | 16 October, 2012 16:27

Dennis Technology Labs released the results of its latest round of antivirus tests seeking to determine the effectiveness of several commercial anti-malware products, with Kaspersky and Symantec coming out on top.

Microsoft Windows 8 brings malware improvements, says antivirus researcher

By Ellen Messmer | 15 October, 2012 20:44

With Microsoft Windows 8 soon to arrive, aspects of the new operating system related to anti-malware protection and other security features are getting a lot of attention.

Symantec shows off security research and development projects

By Ellen Messmer | 15 October, 2012 15:36

At Symantec Research Labs, Symantec's internal research and development arm, there are a number of projects underway which are likely to emerge as products and services within the next 18 months. Sanjay Sawhney, the senior director of research, product development, recently showed off three projects the company is developing.

Anonymous has falling out with WikiLeaks, calling it 'filthy and rotten'

By Ellen Messmer | 12 October, 2012 15:30

Hactivist group Anonymous has had a serious falling out with WikiLeaks, an ally it long respected as a fighter for providing sensitive information to the public, often surreptitiously obtained from sources in governments and businesses.

Getting forensics data off smartphones, tablets can be tough, experts say

By Ellen Messmer | 12 October, 2012 14:36

Trying to get computer forensics data out of mobile smartphones and tablets in order to conduct investigations is hard -- often much harder than on PCs, laptops or Macs -- and experts say that forensics tools need to improve.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

ZENworks® Endpoint Security Management

Protect against bugs in USB Storage devices

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.