Stories by Constantine Von Hoffman

Jack Jones: Numbers game

By Constantine Von Hoffman | 03 August, 2012 23:06

When someone says Jack Jones wrote the book on how to think about information risk, they mean it literally. He created the Factor Analysis of Information Risk (FAIR), which gave security professionals a method of defining and analyzing risk in a way that was more consistent and understandable.

Shelley Stewart: Business view

By Constantine Von Hoffman | 03 August, 2012 23:01

With her broader view of risk and deep knowledge of business, Shelley Stewart has made risk and security management a value creator. The executive director of global security for Cummins, an international manufacturer of diesel engines and power generators, didn't come to the position with the usual background in security.

Kristin Lovejoy: Enabling innovation

By Constantine Von Hoffman | 03 August, 2012 22:44

Imagine for a moment you work for one of the best-known companies in the world, one that made computers an essential part of business. Imagine this company, with more than half a million employees, had let each business unit create its own security systems as long as it followed certain guidelines. Now imagine it's time to replace that with an enterprisewide security architecture. Most people would reasonably imagine this to be a scary, overwhelming project.

Dick Parry: Culture change

By Constantine Von Hoffman | 03 August, 2012 22:38

Over the past 30 years, Novartis's Dick Parry has seen and done almost everything in the security field. He has gone from beat cop all the way up to head of security and information protection for a world-renowned medical research institute. Doing so has meant changing in ways he never anticipated when he started out.

Eric Cowperthwaite: Connect the dots

By Constantine Von Hoffman | 03 August, 2012 22:26

Businesses frequently divide risk and security efforts among several business units or make them specific to a certain place or type of activity: Electronic is separate from physical is separate from financial. However, keeping them all apart makes it impossible to understand how one risk can affect and exacerbate so many others. That's the problem Eric Cowperthwaite, CISO for Providence Health and Services, is most concerned with.

Rick Kelly: Value focus

By Constantine Von Hoffman | 03 August, 2012 22:02

In its more than 200 year-history, Harsco had never had a CSO or even much interest in security. That changed in 2008 when the industrial services company asked Rick Kelly to come in as CSO and create a security and risk function. This was no small task: Harsco has 450 locations in 55 countries and had $3 billion in revenues last year.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

ZENworks® Endpoint Security Management

Get powerful mobile security capabilities, and protect the data the various mobile devices inside your organization.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.