Data Protection

News

ACMA database keeps finger on Australia’s malware pulse

By CSO staff | 21 May, 2013 12:21

Australian ISPs and universities are sending more than 10,000 emails a day to warn customers their systems appear to be infected by malware – but as few as one in five is ever read by its recipient, statistics from the Australian Communications and Media Authority’s (ACMA’s) Australian Internet Security Initiative (AISI) show.

Bank trojan targets users of Bitcoin exchange Mt Gox

By Liam Tung | 20 May, 2013 10:35

Brazilian hackers on the hunt for banking credentials are now targeting Bitcoin owners with a trick that sends victims to a phishing page when they enter the correct URL for Mt Gox, the online exchange that claims to account for 80 per cent of all Bitcoin trade.

Australian Information Security Association issues blunt warning as National Cyber Security Awareness Week begins

By CSO staff | 20 May, 2013 09:54

Australian Information Security Association (AISA) has today, on the first day of National Cyber Security Awareness Week, taken the opportunity to flag research from its members, releasing an advisory note to the community at large.

Virtual desktops win the security case for Brisbane lawyers

By David Braue | 17 May, 2013 10:17

It may have started out as a way of simplifying an increasingly complicated IT environment, but Brisbane law firm Cooper Grace Ward (CGW) has found its virtual desktop infrastructure (VDI) investment is also delivering improved remote-access security, data protection and integrity of sensitive information.

Despite $1.46b furphy, 2013-14 Budget offers slim pickings for cyber security

By David Braue | 16 May, 2013 10:00

Months on from the government’s bold PR initiative in which it said it would spend $1.46 billion on IT security, the release of the 2013-14 federal budget has shown little additional financial support for this and other cyber security initiatives.

Reviews

Storing in the cloud securely: 30 services compared

By Ashton Mills | 20 June, 2012 14:04 | 10 Comments

In perhaps the most comprehensive roundup on the net, we take a look at cloud storage services for personal and business use from the perspective of the CIO: what they offer, what's important and what to look for.

Review: WatchGuard XTM2050

By Matt Tett | 22 May, 2012 16:09

What is big, flexible, red and costs more than your average mid-range family sedan? Not a HSV—not quite that much—but this top of the range unified threat management (UTM) device (or in this case, XTM– the X presumably being a variable) is definitely in a high performance category. The XTM2050 from WatchGuard is one of a new breed of security devices that packs punch.

Wipe it free: secure wiping software

By Ashton Mills | 03 April, 2012 10:24 | 2 Comments

When it comes retiring PCs at the office or at home, regardless of whether their final destination is a tip or to be sold to recover an investment, it goes without saying that a computer's drives need to be wiped. For the corporate environment, you're going to want to make sure no sensitive data is left behind however benign, and for the home you don't want leave any trace of personal details or credit card transactions that could be picked up and used in identify theft.

Review : Clearswift SECURE Web Gateway 2.5

By Matt Hackling | 20 March, 2012 13:35 | 2 Comments

We were eager for this box to arrive from Clearswift, this kind of kit gets us excited. We were expecting a hardware appliance to be shipped to us, but when opened the box, all we found was a 1RU Dell Server.

Juniper EX4500 review

By Matt Tett | 17 November, 2011 13:47 | 2 Comments

Review of the Juniper EX4500 Ethernet switch. They connect desktops to servers in the data centre via a three-tier system of access, aggregation and core Ethernet switches.

Slideshows

Evolve Security Conference 2013 rolling coverage

By CSO staff | 14 May, 2013 14:31

What a time to be in the IT industry - right now technology is changing almost every aspect of our lives, and as IT professional we have front row tickets!

The decisions we make today will be felt for years to come by the organisations we work for, their owners, their customers, and their partners. (Sanjay Mehta)

Overview of an ISMS implementation across SCADA and IT networks

By Russell Clarke and Mark Jones | 31 January, 2013 09:36

Presentation by Russell Clarke and Mark Jones - Directors of RMSEC.

In pictures: PM launches cyber safety program

By Hamish Barwick | 17 January, 2013 09:07

Prime Minister Julia Gillard was on hand in Sydney this week to launch a new cyber education module called bCyberwise. Developed by Life Education and McAfee, the program is designed to teach primary school students about online dangers such as becoming `friends' with strangers and cyber bullying. The program will be rolled out to Australian schools from 4 February.

Canberra's EVOLVE.Cloud hit the streets with topline speakers

By CSO staff | 29 October, 2012 10:19

Canberra's EVOLVE.Cloud hit the streets with topline speakers

AusCERT 2012 in pictures: Exhibitors at large

By Hamish Barwick | 16 May, 2012 16:24

The 11th annual information security conference, AusCERT, kicked off on the sunny Gold Coast this week with exhibitors and delegates gathering for three days of talks and networking. This year's theme, Security on the Move, was interpreted in different ways with one vendor arriving in a tank.

Features

2011's biggest security snafus

By Ellen Messmer | 02 December, 2011 06:27

Perhaps it was an omen of what was to come when the city of San Francisco on New Year's Eve 2010 couldn't get a backup system running in its Emergency Operations Center because no one knew the password.

Guide: How to bulletproof your website

By Esther Shein | 29 November, 2011 03:32

'Tis the season to begin ramping up online shopping activity, and for retailers that means doing all they can to ensure their websites are up, highly available and able to handle peak capacity. Looming in many IT managers' minds is the cautionary tale of Target, whose website crashed twice after it was inundated by an unprecedented number of online shoppers when the retailer began selling clothing and accessories from high-end Italian fashion company Missoni.

Security breach

By Matt Rodgers | 22 September, 2011 09:00

No company wants to be associated with a data breach, but if your systems are compromised the fallout can sometimes be more damaging than the act itself.

NEWS FOCUS: Cyber-espionage attacks threaten corporate data in new unrelenting ways

By Ellen Messmer | 08 August, 2011 20:26

Stealthy, sometime long-term cyber-espionage attacks to steal sensitive proprietary information -- what some now call "advanced persistent threats" (APT) -- have become a top worry for businesses.

NEWS FEATURE: Debate rages over how to manage personal mobile devices used for work

By Ellen Messmer | 28 July, 2011 06:47

Increasingly, businesses accept the idea that employees should be able to use their personal mobile devices, such as smartphones and tablets, for work. But debate is raging as to whether these employee-owned devices should be managed and secured exactly as corporate-owned devices might be.

Opinions

Stuxnet, Ethics and the Law

By Nick Morgan | 10 May, 2013 10:16

This first of 3 part series discusses the development of the Stuxnet malware, the legal and ethical issues. This thought provoking article raises questions into cyber terrorism and weather this is for offensive or defensive purposes.

Login to the real world with your Facebook account

By Ian Yip | 09 May, 2013 09:00 | 2 Comments

It seems like every other website we visit today presents us with a “login with a social network” button. We are sometimes presented with a choice, usually between Facebook, Twitter or LinkedIn. But the most common social network encountered is Facebook and the most common scenario where we are offered this option is when we attempt to use a technology-focused service online. This is starting to change and we will start to notice it in a matter of months.

Cyber Security and the CIO Challenge

By Gordon Makryllos | 09 April, 2013 17:07

Cyber security is the double edged sword of modern business. Because the Internet is an evolving technology that carries enormous potential and vulnerability, cyber security embraces questions of internet freedom, network architecture and the economic potential of cyberspace

Establishing a Cloud Broker Model – Part 1

By Puneet Kukreja | 15 March, 2013 16:34 | 1 Comment

Information Security, IT Security, Technology Security, IT Risk and Security and IT Risk Services are all names that organisations use to define a functional unit within their enterprise that is responsible for the security, integrity and operational assurance of their information assets and operating environment.

3 steps to total compromise – why Google’s 86,000 indexed printers should have your IT team jumping.

By Darren Arnott | 06 February, 2013 11:56

There’s been bit of coverage in the technology press about Google’s “Indexing” of tens of thousands of publicly available printers connected directly to the Internet.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

NetIQ Security Manager

NetIQ® Security Manager™ is an industry-leading Security Information and Event Management (SIEM) solution that provides protection for your critical data and systems.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.