Stories by Antone Gonsalves

Twitter's two-step authentication a good start, experts say

By Antone Gonsalves | 23 May, 2013 21:19

For celebrities and the average Joe, having two-factor authentication turned on won't protect them against determined hackers, however

IT security vendors seen as clueless on industrial control systems

By Antone Gonsalves | 23 May, 2013 13:50

Even the most innocuous security processes used for traditional IT systems could spell disaster in an ICS

Opinion varies on action against Chinese cyberattacks

By Antone Gonsalves | 20 May, 2013 21:08

New cyberespionage attack by People's Liberation Army prompts calls for action such as sanctions, but experts are mixed on best response

Pressure mounts for building in security during application development

By Antone Gonsalves | 20 May, 2013 13:26

Microsoft survey of IT pros and developers worldwide found only 37% worked for organizations that built products with security in mind

Experts ding DHS vulnerability sharing plan as too limited

By Antone Gonsalves | 17 May, 2013 13:00

Without universally availability, plan could miss smaller businesses hackers could use as an entry point to critical infrastructure companies

Researchers develop industrial systems that watch for security breaches

By Antone Gonsalves | 15 May, 2013 21:35

With the new networking method, devices are able spot a problem unit and then isolate it from the network before it can do any damage

Facebook attacked with credential-harvesting malware

By Antone Gonsalves | 14 May, 2013 22:25

Dorkbot variant infection unusual because the criminals exploited a flaw in the file-sharing site MediaFire to spread the malware

Companies, government unprepared for new wave of cybersabotage

By Antone Gonsalves | 14 May, 2013 13:12

Intelligence not the only part of government that has struggled. Senate has not moved on legislation to back President's order on cybersecurity

Labor Department hackers more sophisticated than most

By Antone Gonsalves | 13 May, 2013 17:15

Security pro says attacks designed for further breaches, noting, 'They're not gathering this information and sending it home for no reason'

Google's five-year plan for authentication: It's complicated

By Antone Gonsalves | 10 May, 2013 13:33

Some of the technology has to be deployed together for maximum security, making the process complicated, said one security expert

Lesson from the Google office hack: Do not trust third-parties

By Antone Gonsalves | 09 May, 2013 13:24

Many Tridium Niagara systems in use today are left unpatched, and the company acknowledges there's a problem with update deployments

Experts wary of Pentagon cybersecurity report fingering China

By Antone Gonsalves | 08 May, 2013 13:29

Marks first time U.S. has accused China of using cyberweapons to steal intellectual property, and gain a military and economic advantage

Cyberattack highlights software update problem in large organizations

By Antone Gonsalves | 07 May, 2013 13:30

Attackers targeting government employees working with nuclear weapons understood departments are using outdated versions of Windows,IE

Experts hope for another failure in next Anonymous attack

By Antone Gonsalves | 05 May, 2013 15:27

Twist in the planned U.S. attack is to target small banks, which are unlikely to have the same level of sophistication in their defenses

Pentagon nod shows Android can be as secure as BlackBerry

By Antone Gonsalves | 05 May, 2013 15:24

Samsung's Knox system for Android devices gets approval for use in government and military like the BlackBerry, once the gold standard

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Central Management System

The (CMS) consolidates the management, reporting, & data sharing of Web MPS, Email MPS, File MPS, and Malware Analysis System (MAS) in an easy-to-deploy, network-based appliance.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.