<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8603369206500400146</id><updated>2011-09-07T20:12:16.638+01:00</updated><title type='text'>Hedging your risk - www.securm.com</title><subtitle type='html'>News bites written in plain English, our blog will contain information about Hacking, Data Theft, Business Continuity and other Information Security related stuff. We will not detail any hacking techniques but we will review for the layman what’s happening out there.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>49</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-1414783289366167289</id><published>2010-12-24T09:09:00.001Z</published><updated>2010-12-24T09:09:48.227Z</updated><title type='text'>It's a Christmas Eve cracker - Xmas special day 24</title><content type='html'>&lt;p class="mobile-photo"&gt;&lt;a href="http://1.bp.blogspot.com/_QqJuA7XTtKA/TRRjXNIGa3I/AAAAAAAAAFA/6PuSkl8HeUI/s1600/Door%2B24-788228.jpg"&gt;&lt;img src="http://1.bp.blogspot.com/_QqJuA7XTtKA/TRRjXNIGa3I/AAAAAAAAAFA/6PuSkl8HeUI/s320/Door%2B24-788228.jpg"  border="0" alt="" id="BLOGGER_PHOTO_ID_5554173490766441330" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p class="mobile-photo"&gt;&lt;a href="http://3.bp.blogspot.com/_QqJuA7XTtKA/TRRjXNTgMtI/AAAAAAAAAFI/9aypHrgmPWc/s1600/Christmas%2Blighta-788706.jpg"&gt;&lt;img src="http://3.bp.blogspot.com/_QqJuA7XTtKA/TRRjXNTgMtI/AAAAAAAAAFI/9aypHrgmPWc/s320/Christmas%2Blighta-788706.jpg"  border="0" alt="" id="BLOGGER_PHOTO_ID_5554173490814268114" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;DIV  style="FONT-STYLE: normal; DISPLAY: inline; FONT-FAMILY: 'Calibri'; COLOR: #000000; FONT-SIZE: small; FONT-WEIGHT: normal; TEXT-DECORATION: none"&gt; &lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;It's Christmas Eve, so in this blog we thought we'd  simply wish everyone a very Merry Christmas and a Happy New Year.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;If you're taking time off between Christmas and New Year  we hope you have a relaxing and enjoyable time. If you're working, we know how  you feel! Either way, just make sure your systems and data are as secure as they  can be. If you would like some pointers, why not take a look at yesterday's  blog, &lt;EM&gt;Your Data security Checklist for the Festive Period.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;To finish, here are a few terrible cracker jokes to  while away some time and try out on your colleagues, family and friends. We're  betting they have probably &lt;STRIKE&gt;suffered&lt;/STRIKE&gt; heard many of them before.  We can't claim the credit for them. They all came out of the crackers at our  rather splendid Christmas bash.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Enjoy!&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=left&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-ansi-language: en"  lang=EN&gt;&lt;FONT color=#ff0000&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Who's the bane of  Santa's life?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-ansi-language: en"  lang=EN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;SPAN&gt;&lt;FONT color=#00b050&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;The elf and safety  officer.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=left&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#ff0000&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;How does Good King Wenceslas like his  pizzas?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#00b050&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Deep and crisp and even.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#ff0000&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;On which side do chickens have most  feathers?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#00b050&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;The outside&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;.&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=left&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-ansi-language: en"  lang=EN&gt;&lt;FONT color=#ff0000&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;What's the slogan for  the Eskimo lottery?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-ansi-language: en"  lang=EN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;SPAN&gt;&lt;FONT color=#00b050&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;You've got to be Inuit to win  it!&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#ff0000&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;What's Santa's favourite  motorbike?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#00b050&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;A Holly Davidson.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B&gt;&lt;SPAN&gt;&lt;FONT  color=#ff0000&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;A man goes to see his doctor and  says, "Doctor, I have a lettuce stuck in my  bottom."&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#00b050&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;The doctor takes a look and replies, "That's just the  tip of the iceberg."&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#ff0000&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;What do frogs wear on their  feet?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#00b050&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Open toad sandals.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#ff0000&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Why are pirates so cool?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#00b050&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Because they Arrrrrrr.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#ff0000&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;What award do the best door knocker makers  receive?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#00b050&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;The no bell  prize.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#ff0000&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;What do you call a man under a pile of  leaves?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#00b050&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Russell.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#ff0000&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;What do you call a woman between two  goalposts?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#00b050&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Annette. &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#ff0000&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Why is it so difficult to teach dogs to  dance?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#00b050&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Because they have two left  feet.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#ff0000&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Which athlete is warmest in  winter?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#00b050&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;A long jumper.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#ff0000&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;What did the shy pebble  say?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT color=#00b050&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;I wish I was a little  boulder.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT  color=#00b050&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;DIV class=Section1&gt; &lt;P style="TEXT-ALIGN: left" class=MsoNormal align=left&gt;&lt;o:p&gt;&lt;FONT  size=3&gt;&lt;/FONT&gt;&lt;/o:p&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-1414783289366167289?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/1414783289366167289/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/its-christmas-eve-cracker-xmas-special.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/1414783289366167289'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/1414783289366167289'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/its-christmas-eve-cracker-xmas-special.html' title='It&apos;s a Christmas Eve cracker - Xmas special day 24'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_QqJuA7XTtKA/TRRjXNIGa3I/AAAAAAAAAFA/6PuSkl8HeUI/s72-c/Door%2B24-788228.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-6125116176359651662</id><published>2010-12-23T08:40:00.000Z</published><updated>2010-12-23T08:41:36.255Z</updated><title type='text'>Your Data Security Checklist for the Festive Period - Xmas special day 23</title><content type='html'>&lt;p class="mobile-photo"&gt;&lt;a href="http://1.bp.blogspot.com/_QqJuA7XTtKA/TRMLQD8zfEI/AAAAAAAAAE4/vDrFPWlqv8E/s1600/Door%2B23-796256.jpg"&gt;&lt;img src="http://1.bp.blogspot.com/_QqJuA7XTtKA/TRMLQD8zfEI/AAAAAAAAAE4/vDrFPWlqv8E/s320/Door%2B23-796256.jpg"  border="0" alt="" id="BLOGGER_PHOTO_ID_5553795136044104770" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;DIV  style="FONT-STYLE: normal; DISPLAY: inline; FONT-FAMILY: 'Calibri'; COLOR: #000000; FONT-SIZE: small; FONT-WEIGHT: normal; TEXT-DECORATION: none"&gt; &lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;DIV  style="FONT-STYLE: normal; DISPLAY: inline; FONT-FAMILY: 'Calibri'; COLOR: #000000; FONT-SIZE: small; FONT-WEIGHT: normal; TEXT-DECORATION: none"&gt; &lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;DIV  style="FONT-STYLE: normal; DISPLAY: inline; FONT-FAMILY: 'Calibri'; COLOR: #000000; FONT-SIZE: small; FONT-WEIGHT: normal; TEXT-DECORATION: none"&gt; &lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;For many businesses the week between Christmas and New  Year is a welcome break, with offices closed and bosses and staff alike taking  time to recharge their batteries.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;But have they done enough to ensure data  security?&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Here's a quick checklist for you to run through over the  next couple of days if your business will be operating at reduced staffing  levels or is closed over the festive period.&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpFirst align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;1.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Will unused  laptops, portable devices and USB devices be locked securely away?&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;2.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Have all  desktop PCs, printers and any other devices that are not required been turned  off? Don't leave PCs logged in or even in locked mode.&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;3.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Are all devices  that hold data at least password protected and, ideally, encrypted?&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;4.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Are desks  clear, with any sensitive documents locked away?&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;5.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Did you make  sure all shredding has been done and/or 'secure' shredding bins have been  collected? And have you checked the waste bins for any sensitive documents that  may not have been disposed of securely? Really! We're serious.&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;6.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Are all your  security applications, particularly server-side, up-to-date and are they set for  automatic update?&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;7.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;If you run  on-site backups, is there enough storage space to last? Have the backups been  properly scheduled to run automatically? Is there any safeguard in place if they  fail?&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;8.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Have you set  your systems to 'notify' you of any problems? Or do you have someone who will be  regularly checking the 'health' of your systems?&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;9.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Do you have a  list of members of IT staff who can be 'on call' in the case of an  emergency?&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpLast align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;10.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt; &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Have you turned the lights off…?&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;DIV class=Section1&gt; &lt;P style="TEXT-ALIGN: left" class=MsoNormal align=left&gt;&lt;o:p&gt;&lt;FONT  size=3&gt;&lt;/FONT&gt;&lt;/o:p&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-6125116176359651662?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/6125116176359651662/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/your-data-security-checklist-for.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/6125116176359651662'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/6125116176359651662'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/your-data-security-checklist-for.html' title='Your Data Security Checklist for the Festive Period - Xmas special day 23'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_QqJuA7XTtKA/TRMLQD8zfEI/AAAAAAAAAE4/vDrFPWlqv8E/s72-c/Door%2B23-796256.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-6202618198550410255</id><published>2010-12-22T10:15:00.001Z</published><updated>2010-12-22T10:15:40.584Z</updated><title type='text'>Does increased spending on IT and data security mean better security? - Xmas special day 22</title><content type='html'>&lt;p class="mobile-photo"&gt;&lt;a href="http://3.bp.blogspot.com/_QqJuA7XTtKA/TRHPzfOajCI/AAAAAAAAAEw/0qUwny03kT0/s1600/Door%2B22-740584.jpg"&gt;&lt;img src="http://3.bp.blogspot.com/_QqJuA7XTtKA/TRHPzfOajCI/AAAAAAAAAEw/0qUwny03kT0/s320/Door%2B22-740584.jpg"  border="0" alt="" id="BLOGGER_PHOTO_ID_5553448298986769442" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;As with many things in life, it's not what you've got  it's what you do with it that counts!&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;What do you  mean&lt;/FONT&gt;&lt;/B&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;?&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;When it comes to IT and data security, simply throwing  money at it will NOT mean you have the best security. You could buy all the top  security applications available and still fall victim to hacking or another type  of data security breach.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;It's all about well thought through implementation of  security applications, robust policies and procedures and, importantly, training  and awareness for staff.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;It's also the case that the best solution for one  business will not necessarily suit another.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;You need to determine your needs, specify a budget and  'cut your cloth accordingly'.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;How do I do  that?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;By keeping things simple and making sure you adopt a  common sense approach. Identify the minimum requirements of good IT and data  security for your business - not all will be technology-based – then build upon  them as and when you need to. As a start you might consider the  following:&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpFirst align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Implementation  of trusted – and compatible - anti-virus, firewall and intrusion detection  applications;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Formulation of  an IT policy document, including a strong but workable password  policy;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Encryption of  data;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;IT &amp;amp; data  security training and awareness;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Lockable  cabinets for laptops, portable devices and USB devices;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Asset/security  tagging of IT equipment;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Keeping data  off laptops, PCs, etc. by 'virtualising' access to data and even applications –  whether through Terminal Services, a VPN or via the Cloud;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Offsite/Cloud-based back-up and Disaster Recovery  solutions;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpLast align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Secure document  shredding and data destruction.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;That sounds  like enough. Is there more?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;It depends upon your business, what it does and, as we  said before, the sort of budget you have.&lt;/FONT&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;If you sell products or services online and process  payment cards, for example, you need to have additional levels of security in  place to ensure you comply with the Payment Card Industry Data Security Standard  (PCI DSS).&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Similarly, if your business is regulated - let's say  you're a Hedge Fund regulated by the Financial Services Authority – you will  have a greater burden of responsibility than non-regulated  businesses.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;That's not to say non-regulated businesses should take  IT and data security any less seriously.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;So you're  saying I should get the basics right first, then reinforce if  necessary?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Exactly!&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;And always make sure that whatever you invest in is what  you really NEED.&lt;/FONT&gt;&lt;/P&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;DIV class=Section1&gt; &lt;P style="TEXT-ALIGN: left" class=MsoNormal align=left&gt;&lt;o:p&gt;&lt;FONT  size=3&gt;&lt;/FONT&gt;&lt;/o:p&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-6202618198550410255?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/6202618198550410255/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/does-increased-spending-on-it-and-data.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/6202618198550410255'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/6202618198550410255'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/does-increased-spending-on-it-and-data.html' title='Does increased spending on IT and data security mean better security? - Xmas special day 22'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_QqJuA7XTtKA/TRHPzfOajCI/AAAAAAAAAEw/0qUwny03kT0/s72-c/Door%2B22-740584.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-146150300946568602</id><published>2010-12-21T15:42:00.001Z</published><updated>2010-12-21T15:42:08.193Z</updated><title type='text'>10 Website Security Tips - Xmas special day 21</title><content type='html'>&lt;p class="mobile-photo"&gt;&lt;a href="http://2.bp.blogspot.com/_QqJuA7XTtKA/TRDK0K2DTrI/AAAAAAAAAEo/MVnYNLH-1Y4/s1600/Door%2B21-728194.jpg"&gt;&lt;img src="http://2.bp.blogspot.com/_QqJuA7XTtKA/TRDK0K2DTrI/AAAAAAAAAEo/MVnYNLH-1Y4/s320/Door%2B21-728194.jpg"  border="0" alt="" id="BLOGGER_PHOTO_ID_5553161338160893618" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;P style="MARGIN: 0cm 0cm 12pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Your website is your window to the world. By the same  token, it's the world's window to you and there are some people who are more  than happy to smash their way in. It can be one of the most vulnerable  'components' of your overall IT infrastructure if you don't take steps to ensure  it is secure.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 12pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Here are 10 tips for website security:&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraph align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;STRONG&gt;1.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Don't  cut corners&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 35.45pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;It's no good to simply put up a website and leave it to  its own devices. You need to invest time and money in it, not just to keep it  working well and looking good, but also to ensure it is as secure as it can  possibly be.&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraph align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;STRONG&gt;2.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Use  strong passwords&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 35.45pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;We've talked a bit about passwords over the last couple  of weeks in our blogs &lt;I style="mso-bidi-font-style: normal"&gt;2&lt;SUP&gt;nd&lt;/SUP&gt;  factor, NOT X-Factor &lt;/I&gt;and &lt;/FONT&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Gawker hack. What can businesses learn?&lt;/FONT&gt;&lt;/I&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 35.45pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;The more complex passwords are the more secure they will  usually be. And you really should use different passwords for each element of  you website operation, e.g. the Control Panel, any payment processing platform  and your FTP accounts.&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraph align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;STRONG&gt;3.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Stay  up-to-date&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 35.45pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;If you ensure you are running the latest versions of  your website software, Operating System and IT security applications your  website will be far less vulnerable to attack.&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraph align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;STRONG&gt;4.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Check  your host&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 35.45pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Spend time comparing the services of different hosts.  Some offer far more secure hosting than others, with 24/7 active server  monitoring. It's also worth checking if they support SuPHP (see  below).&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraph align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;STRONG&gt;5.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Check  your script&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 35.45pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Hypertext Pre-processor (PHP) is a scripting language  that enables dynamic web pages. It is embedded into HTML source documents that  are then 'translated' into web pages by a server with a PHP processor module.  Standard PHP script is generally 'open access', which means &lt;U&gt;anyone&lt;/U&gt; can  run scripts!&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 35.45pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;suPHP limits access to a single user or group of users  with defined permissions, so only those people to whom you grant access can run  scripts.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 35.45pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;It's important to note that not all hosting providers  offer or support suPHP, so that's something worth checking when deciding upon  your host&lt;/FONT&gt;&lt;SPAN style="DISPLAY: none; mso-hide: all"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -17.85pt; MARGIN: 0cm 0cm 6pt 35.7pt; mso-list: l0 level1 lfo1"  class=MsoListParagraph align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;STRONG&gt;6.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Consider a move to VPS&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoListParagraph align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Virtual Private Server hosting means your website is  hosted separately from other sites. You have far greater control and can usually  customise security measures like firewalls to your own specification, something  that is not generally permitted on shared hosting. It should mean your website  is much more secure.&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpLast align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;STRONG&gt;7.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Restrict file permissions&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 35.45pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;It makes sense to restrict or even block access to  certain files and operations. In some cases you need to change settings to carry  out an installation – effectively set as open – so just make sure that when  you've finished whatever it is you are doing you set them back again and close  the system.&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraph align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;STRONG&gt;8.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Only  link to trusted sites&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 35.45pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;"Open redirects" allow a large number of attacks through  browsers. Ensure your site only links to known and trusted sites, and keep an  eye out for any broken or spurious links that appear. You really don't want bad  links on your site. &lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraph align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;STRONG&gt;9.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Secure  File Transfer&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 35.45pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;When you upload, download and delete files, you need to  make sure the method you are utilising is secure. Use tools like File Transfer  Protocol Secure (FTPS), which employs Secure Socket Layers (SSL), for all  transfers.&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraph align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;10.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Regular  'housekeeping'&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 35.45pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Get into the habit of regularly checking your website.  Ensure updates have been successfully installed, look for code that shouldn't be  there, check all links work as they should and only install trusted updates and  plug-ins.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 35.45pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;DIV class=Section1&gt;&lt;STRONG&gt;&lt;FONT  color=#808080&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-146150300946568602?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/146150300946568602/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/10-website-security-tips-xmas-special.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/146150300946568602'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/146150300946568602'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/10-website-security-tips-xmas-special.html' title='10 Website Security Tips - Xmas special day 21'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_QqJuA7XTtKA/TRDK0K2DTrI/AAAAAAAAAEo/MVnYNLH-1Y4/s72-c/Door%2B21-728194.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-5775184290417836505</id><published>2010-12-20T08:58:00.000Z</published><updated>2010-12-20T08:59:03.924Z</updated><title type='text'>Local authority IT Security in times of austerity - Xmas special day 20</title><content type='html'>&lt;p class="mobile-photo"&gt;&lt;a href="http://1.bp.blogspot.com/_QqJuA7XTtKA/TQ8a2LwrG5I/AAAAAAAAAEg/Y8AVgmekpXA/s1600/Door%2B20-743925.jpg"&gt;&lt;img src="http://1.bp.blogspot.com/_QqJuA7XTtKA/TQ8a2LwrG5I/AAAAAAAAAEg/Y8AVgmekpXA/s320/Door%2B20-743925.jpg"  border="0" alt="" id="BLOGGER_PHOTO_ID_5552686383743310738" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Following last week's announcement of the latest round  in its austerity drive by the UK Coalition Government, councils face the largest  reduction in central funding for local government since the Second World War.  This brings with it the prospect of job losses and cuts in frontline  services.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;There is no easy answer to the question of how best to  make cuts and where they should be made but, to protect frontline services as  best as possible, back-office functions will always suffer.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;IT is frequently an area of back-office that is hit when  such cuts are announced, despite it being essential for any council's day-to-day  operations. And when cuts are made, whether in staff, funding, or both, IT  security can suffer.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;So what could councils do to reduce expenditure on IT  whilst maintaining or possibly even improving upon their current infrastructure,  service levels and, most importantly ensuring security is not  compromised?&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Collaborate.&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;One answer might be to look at collaboration, or sharing  of IT infrastructure, with a single regional support centre and IT professionals  who serve more than one council. This could be self-managed or outsourced to a  service-provider. It would ensure the focus is not just upon IT provision, but  also upon maintaining the security of systems &amp;amp; data. The possible downside  to this solution could be the initial set-up/migration costs.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Move to The  Cloud.&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;An alternative would be for councils to virtualise the  greater part of their IT 'provision' by progressively migrating it to The  Cloud.&lt;/FONT&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT  style="FONT-SIZE: 14pt"&gt;*&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt; This  offers the advantage of specialist application support for users, meaning IT  staff can concentrate on key functions; it would simplify IT as a service, by  reducing layers of provision and making application/software licensing more  straightforward; and it should, over time, reduce costs.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;It would also offer councils the prospect of  collaboration without the need to invest in and maintain shared  infrastructure.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Most importantly, security would be maintained, if not  enhanced.&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpFirst align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Data would be  held and backed-up off-site in highly secure data vaults;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Data would be  encrypted at all times; &lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;There is no  need for data to be loaded on to any PC, laptop or other device;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpLast align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Being  Cloud-based could potentially make the transition to 2nd factor authentication a  far more viable proposition.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;It's too early to know what steps councils will take,  but it's certain there are difficult times ahead. &lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;FONT style="FONT-SIZE: 14pt"&gt;*  &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN&gt;&lt;FONT style="FONT-SIZE: 9pt"&gt;Cloud computing is a new  way of delivering IT services over the Internet. It facilitates the sharing of  resources, software and data, and its biggest selling point is the fact it does  away with the need for businesses to invest heavily in IT infrastructure because  everything can be hosted off-site. To read our blog about The Cloud click  &lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 9pt"&gt;&lt;A  href="http://blog.securm.co.uk/2010/11/what-is-cloud.html"&gt;&lt;SPAN&gt;here&lt;/SPAN&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;SPAN&gt;&lt;FONT  style="FONT-SIZE: 9pt"&gt;.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;DIV class=Section1&gt; &lt;P style="TEXT-ALIGN: left" class=MsoNormal align=left&gt;&lt;o:p&gt;&lt;FONT  size=3&gt;&lt;/FONT&gt;&lt;/o:p&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-5775184290417836505?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/5775184290417836505/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/local-authority-it-security-in-times-of.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/5775184290417836505'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/5775184290417836505'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/local-authority-it-security-in-times-of.html' title='Local authority IT Security in times of austerity - Xmas special day 20'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_QqJuA7XTtKA/TQ8a2LwrG5I/AAAAAAAAAEg/Y8AVgmekpXA/s72-c/Door%2B20-743925.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-3164685789833959268</id><published>2010-12-19T13:04:00.001Z</published><updated>2010-12-19T13:04:10.835Z</updated><title type='text'>Gawker hack. What can businesses learn? - Xmas special day 19</title><content type='html'>&lt;p class="mobile-photo"&gt;&lt;a href="http://4.bp.blogspot.com/_QqJuA7XTtKA/TQ4Cy1EI3vI/AAAAAAAAAEY/90XvqF5y3mQ/s1600/Door%2B19-750836.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/_QqJuA7XTtKA/TQ4Cy1EI3vI/AAAAAAAAAEY/90XvqF5y3mQ/s320/Door%2B19-750836.jpg"  border="0" alt="" id="BLOGGER_PHOTO_ID_5552378462855552754" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;DIV class=Section1&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;We published a blog on 12&lt;SUP&gt;th&lt;/SUP&gt; December 2010,  titled "&lt;I style="mso-bidi-font-style: normal"&gt;2&lt;SUP&gt;nd&lt;/SUP&gt; factor NOT  X-Factor"&lt;/I&gt;. In it we discussed the importance of a robust password policy,  how to formulate passwords and the use of additional authentication  measures.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;On 15&lt;SUP&gt;th&lt;/SUP&gt; December, the BBC reported that a US  Celebrity Gossip site called &lt;EM&gt;Gawker&lt;/EM&gt;, which operates one of the world's  most popular blog networks, had been subjected to a major hacking attack. The  attack was instigated by an organisation that calls itself Gnosis. After the  hacking, details of 1.3 million accounts, including 'a significant number' of  passwords, were published online by the group.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 12pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;As a result, millions of users are being asked to change  their passwords, not just for the &lt;I style="mso-bidi-font-style: normal"&gt;Gawker  &lt;/I&gt;site, but also for sites like Twitter, Yahoo and LinkedIn. Even the online  game site, &lt;I style="mso-bidi-font-style: normal"&gt;World of&lt;/I&gt; &lt;I  style="mso-bidi-font-style: normal"&gt;Warcraft&lt;/I&gt;, is asking some users to reset  passwords.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Why are all  these sites taking such measures?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;I  style="mso-bidi-font-style: normal"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Gawker&lt;/FONT&gt;&lt;/I&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt; will  obviously be requiring users to change their passwords because it is the site  that has been hacked and compromised, but other sites face potential problems  for two main reasons:&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpFirst align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;1.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Many users  'interlink' the various sites so they can share a feature of interest from G&lt;I  style="mso-bidi-font-style: normal"&gt;awker&lt;/I&gt; in Twitter, or tell friends about  a spectacularly high score in &lt;I style="mso-bidi-font-style: normal"&gt;World of  Warcraft&lt;/I&gt;, for instance. This can mean some 'sharing' of  passwords.&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpLast align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;2.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Significant  numbers of users do not have different passwords for each and every site they  are signed up to.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;The attack also highlighted just how insecure passwords  were. Apparently the favourites amongst &lt;I  style="mso-bidi-font-style: normal"&gt;Gawker&lt;/I&gt; users were 123456, password and  12345678. So users are being asked to make their passwords stronger.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;It also revealed underlying flaws in &lt;I  style="mso-bidi-font-style: normal"&gt;Gawker's&lt;/I&gt; overall infrastructure  security, something the site's boss has admitted was a serious issue, according  to a report that appeared in &lt;I style="mso-bidi-font-style: normal"&gt;The  Register&lt;/I&gt; yesterday (18&lt;SUP&gt;th&lt;/SUP&gt; December). &lt;/FONT&gt;&lt;I  style="mso-bidi-font-style: normal"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Gawker&lt;/FONT&gt;&lt;/I&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt; is now  planning to overhaul its security processes by introducing 2&lt;SUP&gt;nd&lt;/SUP&gt; factor  authentication.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;What is the  significance to my business?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;If your employees use the same passwords for social  networking and personal online activities, like shopping and banking, as they  use in the work environment, compromises like this will be of concern. If one of  your employees has a social networking account or, worse still, their home PC  compromised, someone could gain unauthorised access your systems as a  result.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;We mentioned in our "&lt;I  style="mso-bidi-font-style: normal"&gt;2&lt;SUP&gt;nd&lt;/SUP&gt; factor NOT X-Factor"&lt;/I&gt; blog  that users should ideally have one password per system. It's perhaps worth  adding that this applies equally to personal 'accounts' too and that your  employees should be advised not to use the same passwords for business as they  do for personal computer activity.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="TEXT-ALIGN: left; MARGIN-BOTTOM: 0pt" class=MsoNormal align=left&gt;&lt;SPAN  style="FONT-FAMILY: 'Trebuchet MS','sans-serif'; COLOR: gray; FONT-SIZE: 14pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: background1; mso-themeshade: 128; mso-fareast-language: en-gb"&gt;&lt;FONT  color=#000000&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="TEXT-ALIGN: left; MARGIN-BOTTOM: 0pt" class=MsoNormal align=left&gt;&lt;SPAN  style="FONT-FAMILY: 'Trebuchet MS','sans-serif'; COLOR: gray; FONT-SIZE: 14pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: background1; mso-themeshade: 128; mso-fareast-language: en-gb"&gt;&lt;FONT  color=#000000&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="TEXT-ALIGN: left; MARGIN-BOTTOM: 0pt" class=MsoNormal  align=left&gt;&lt;B&gt;&lt;SPAN  style="FONT-FAMILY: 'Trebuchet MS','sans-serif'; COLOR: gray; FONT-SIZE: 14pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: background1; mso-themeshade: 128; mso-fareast-language: en-gb"&gt;&lt;/SPAN&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="TEXT-ALIGN: left" class=MsoNormal  align=left&gt;&lt;o:p&gt;&lt;/o:p&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-3164685789833959268?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/3164685789833959268/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/gawker-hack-what-can-businesses-learn.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/3164685789833959268'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/3164685789833959268'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/gawker-hack-what-can-businesses-learn.html' title='Gawker hack. What can businesses learn? - Xmas special day 19'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_QqJuA7XTtKA/TQ4Cy1EI3vI/AAAAAAAAAEY/90XvqF5y3mQ/s72-c/Door%2B19-750836.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-8179823830032296959</id><published>2010-12-18T12:53:00.001Z</published><updated>2010-12-18T12:53:55.049Z</updated><title type='text'>Data: From Acquisition to Disposal - Xmas special day 18</title><content type='html'>&lt;p class="mobile-photo"&gt;&lt;a href="http://4.bp.blogspot.com/_QqJuA7XTtKA/TQyu43aqG2I/AAAAAAAAAEQ/8FkkOOzcf6M/s1600/Door%2B18-735050.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/_QqJuA7XTtKA/TQyu43aqG2I/AAAAAAAAAEQ/8FkkOOzcf6M/s320/Door%2B18-735050.jpg"  border="0" alt="" id="BLOGGER_PHOTO_ID_5552004732612647778" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Your business has a legal obligation to fulfil under the  Data Protection Act 1998 when it comes to handling data. It may also have to  consider compliance with the policies and guidelines of a regulatory body. The  bottom line is that you are responsible for the security of your data from  acquisition to 'disposal'.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;There are many things to think about when putting  systems in place for handling data. We couldn't possibly cover everything in  this blog, but we would suggest that there are five broad categories to  consider:&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;OL style="MARGIN-TOP: 0cm; MARGIN-BOTTOM: 0cm" type=1&gt;   &lt;LI    style="TEXT-ALIGN: left; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt"    class=MsoNormal&gt;&lt;B&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Information    Management&lt;/FONT&gt;&lt;/B&gt;&lt;/LI&gt;&lt;/OL&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoNormal align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;A systematic approach to managing company information is  a must. This is commonly referred to as an Information Security Management  System (ISMS) and these can be accredited under an international standard, such  as ISO:270001.&lt;BR&gt;&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt; &lt;OL style="MARGIN-TOP: 0cm; MARGIN-BOTTOM: 0cm" type=1 start=2&gt;   &lt;LI    style="TEXT-ALIGN: left; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt"    class=MsoNormal&gt;&lt;B&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;IT Infrastructure    Security&lt;/FONT&gt;&lt;/B&gt;&lt;/LI&gt;&lt;/OL&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoNormal align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;A Penetration Test will highlight weaknesses and  vulnerabilities in your systems, identify the appropriate measures to deal with  them close the door to attack&lt;B&gt;. &lt;/B&gt;You may already have firewalls, intrusion  detection systems and other electronic monitoring solutions in place. Whilst  these will obviously provide a degree of protection to your IT infrastructure,  software patches and hardware updates can all inadvertently leave your system  vulnerable and open to attack.&lt;BR&gt;&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt; &lt;OL style="MARGIN-TOP: 0cm; MARGIN-BOTTOM: 0cm" type=1 start=3&gt;   &lt;LI    style="TEXT-ALIGN: left; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt"    class=MsoNormal&gt;&lt;B&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Training &amp;amp;    Awareness&lt;/FONT&gt;&lt;/B&gt;&lt;/LI&gt;&lt;/OL&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoNormal align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;All members of staff within your organisation should be  aware of their responsibilities when dealing with your company data. The  implementation of an online programme of training that can be monitored and  measured is certainly something to consider.&lt;BR&gt;&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt; &lt;OL style="MARGIN-TOP: 0cm; MARGIN-BOTTOM: 0cm" type=1 start=4&gt;   &lt;LI    style="TEXT-ALIGN: left; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt"    class=MsoNormal&gt;&lt;B&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Business Continuity    Planning&lt;/FONT&gt;&lt;/B&gt;&lt;/LI&gt;&lt;/OL&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoNormal align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;When disaster strikes, whether fire, flood or a  malicious attack on your IT systems, your business needs to be up and running  again with the minimum of financial and reputational damage. A resilient  Business Continuity plan, taking account of data security and ensuring regular  back-up amongst other things, will provide peace-of-mind to your staff,  stakeholders, suppliers and customers.&lt;BR&gt;&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt; &lt;OL style="MARGIN-TOP: 0cm; MARGIN-BOTTOM: 0cm" type=1 start=5&gt;   &lt;LI    style="TEXT-ALIGN: left; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt"    class=MsoNormal&gt;&lt;B&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Data    Destruction&lt;/FONT&gt;&lt;/B&gt;&lt;/LI&gt;&lt;/OL&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoNormal align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;There will come a point when either the data, or the  systems upon which it is held, are no longer required, but you can't just throw  them away. If the data gets into the wrong hands, and the Information  Commissioner's Office comes knocking at your door, the fact it is old and no  longer of value to your business will be no defence. It's worth identifying a  trustworthy provider of data destruction and IT equipment disposal services who  can issue you with appropriate certification and documentation. It will mean you  can demonstrate you have taken every possible step to ensure the security of  your old data. &lt;/FONT&gt;&lt;/P&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;DIV class=Section1&gt; &lt;P style="TEXT-ALIGN: left" class=MsoNormal align=left&gt;&lt;o:p&gt;&lt;STRONG&gt;&lt;FONT  color=#808080&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/o:p&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-8179823830032296959?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/8179823830032296959/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/data-from-acquisition-to-disposal-xmas.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/8179823830032296959'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/8179823830032296959'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/data-from-acquisition-to-disposal-xmas.html' title='Data: From Acquisition to Disposal - Xmas special day 18'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_QqJuA7XTtKA/TQyu43aqG2I/AAAAAAAAAEQ/8FkkOOzcf6M/s72-c/Door%2B18-735050.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-3057732212214637433</id><published>2010-12-17T06:07:00.001Z</published><updated>2010-12-17T06:07:43.618Z</updated><title type='text'>Are your employees involved &amp; engaged? - Xmas special day 17</title><content type='html'>&lt;p class="mobile-photo"&gt;&lt;a href="http://1.bp.blogspot.com/_QqJuA7XTtKA/TQr-Lxo5MSI/AAAAAAAAAEI/rAkJ2OBATYE/s1600/Door%2B17-763619.jpg"&gt;&lt;img src="http://1.bp.blogspot.com/_QqJuA7XTtKA/TQr-Lxo5MSI/AAAAAAAAAEI/rAkJ2OBATYE/s320/Door%2B17-763619.jpg"  border="0" alt="" id="BLOGGER_PHOTO_ID_5551528968944431394" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Your IT Security is only as strong as it weakest point.  And, as we've said before, the weakest point is usually the human  element.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;A number of our recent blogs have touched upon the  subject of involving and engaging your employees in your IT Security policies  and processes. In those blogs, we've broadly explained why it's a good thing,  but we thought a more detailed blog concentrating upon how you can get them  involved, and the sort of things to consider when you do, would be  helpful.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -17.85pt; MARGIN: 0cm 0cm 6pt 35.7pt; mso-list: l0 level1 lfo1"  class=MsoListParagraph align=left&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;1.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Help them to  understand.&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=left&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;If your employees do not understand the  importance of IT Security they almost certainly won't be able to appreciate the  necessity of policies and procedures. In fact, they may see them as an  imposition, a hindrance, or even something you've put in place just to catch  them out. Negativity is counter-productive and something you really need to get  past. So, how do you help them to understand? Read on. &lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=left&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -17.85pt; MARGIN: 0cm 0cm 6pt 35.7pt; mso-list: l0 level1 lfo1"  class=MsoListParagraph align=left&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;2.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Keep it  simple.&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoListParagraph align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;How many times have you heard this before about so many  things? Well, don't ignore it because it's very, very important in this context.  For your purposes and those of your business, IT policies may need to be  detailed, in-depth and highly technical. But overload and overwhelm employees  and you will struggle to get them to understand. Try things like:&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 72pt; mso-list: l1 level1 lfo2"  class=MsoListParagraph align=left&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Simple, one  page, crib sheets about policies that directly apply to them and their  particular roles;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 72pt; mso-list: l1 level1 lfo2"  class=MsoListParagraph align=left&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Practical,  scenario-based training – don't grind them down with hours of PowerPoint  presentations and technical jargon;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 72pt; mso-list: l1 level1 lfo2"  class=MsoListParagraph align=left&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Regular updates  explaining what to look out for and what they should do or not do if faced with  certain situations.&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -17.85pt; MARGIN: 0cm 0cm 6pt 35.7pt; mso-list: l0 level1 lfo1"  class=MsoListParagraph align=left&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;3.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Make on-going  training and awareness an essential part of your IT Security  processes.&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoListParagraph align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;We've touched upon this in the point above. You need to  train your employees, raise their awareness of issues and keep them updated with  important changes and developments. Testing their knowledge and understanding on  a regular basis is really important, but don't think exams and written  tests.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=left&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Keeping things light-hearted and, dare  we say it…FUN…is a great way to engage your employees. Setting a challenge to  find 10 potential security breaches could be one approach.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=left&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -17.85pt; MARGIN: 0cm 0cm 6pt 35.7pt; mso-list: l0 level1 lfo1"  class=MsoListParagraph align=left&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;4.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Encourage  input from your employees.&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoListParagraph align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Let's say you are considering implementing a new  password policy that requires every employee to have different passwords for  each system they access. You could simply write it up and go ahead with it. No  consultation, just straight to release.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoListParagraph align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;But, if you haven't spoken to your employees and have  failed to explore the practicalities of your proposed policy in the light of  their working practices, how do you know it's workable? What if employees simply  cannot remember every password, but you tell them they mustn't write anything  down? What would the impact be upon your time and the time of other IT staff if  there is a constant need to 'unlock' users and reset passwords? There's also a  good chance it will cause resentment amongst your employees.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoListParagraph align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;We're not suggesting you consult employees on every  single detail, but they are the people using your systems. Not only can they  tell you if certain policies are likely to work, they can also tell you when  things don't seem to be functioning as they should and when there appear to be  problems. This could be feedback – possibly an early warning of a major issue –  that you could miss out on if your employees don't feel they have a  voice.&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -17.85pt; MARGIN: 0cm 0cm 6pt 35.7pt; mso-list: l0 level1 lfo1"  class=MsoListParagraph align=left&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;5.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Ensure buy  in.&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoListParagraph align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;It's great to encourage involvement but you need  employees to really buy-in to your policies and procedures. The best way to do  this is to get them to sign-up. By this we mean you should require them to sign  acknowledgements that:&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -17.85pt; MARGIN: 0cm 0cm 0pt 74.25pt; mso-list: l2 level1 lfo3"  class=MsoListParagraph align=left&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;They have read  and understood what they have been told – this should be required every time  there is a significant change in policy;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -17.85pt; MARGIN: 0cm 0cm 0pt 74.25pt; mso-list: l2 level1 lfo3"  class=MsoListParagraph align=left&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;They are aware  that you expect them to follow policies and procedures;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -17.85pt; MARGIN: 0cm 0cm 0pt 74.25pt; mso-list: l2 level1 lfo3"  class=MsoListParagraph align=left&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;They  acknowledge their responsibilities as a part of the process; and&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -17.85pt; MARGIN: 0cm 0cm 6pt 74.25pt; mso-list: l2 level1 lfo3"  class=MsoListParagraph align=left&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;They are aware  of the consequences of any failure to adhere to policy.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoListParagraph align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;We can see this might seem slightly at odds to our  suggestion the process could be light-hearted and fun, but buy-in and sign-up  are absolutely necessary. It's also the case that they bestow the element of  importance upon the process. It's the only aspect that needs to be  formal.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoListParagraphCxSpLast  align=left&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;The fact is your employees need to  understand your policies in order to apply them and to be aware of the  consequences if they don't. You need them to sign-up to this because, much as  you wouldn't want it to happen, you may have to take disciplinary or even legal  action against an employee in the future. If you have nothing to demonstrate  they had received training and understood their responsibilities, you could end  up with no claim or case. &lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Whilst we've written this blog about involving your  employees in your IT Security policies and procedures, the points above could  equally well apply to all other areas of your business. Involve them and engage  them, then get their buy-in by requiring them to sign-up. It makes good business  sense.&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-3057732212214637433?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/3057732212214637433/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/are-your-employees-involved-engaged.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/3057732212214637433'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/3057732212214637433'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/are-your-employees-involved-engaged.html' title='Are your employees involved &amp; engaged? - Xmas special day 17'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_QqJuA7XTtKA/TQr-Lxo5MSI/AAAAAAAAAEI/rAkJ2OBATYE/s72-c/Door%2B17-763619.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-4185741882976254529</id><published>2010-12-16T08:22:00.001Z</published><updated>2010-12-16T08:22:13.445Z</updated><title type='text'>Disaster Recovery Planning in a nutshell - Xmas special day 16</title><content type='html'>&lt;p class="mobile-photo"&gt;&lt;a href="http://2.bp.blogspot.com/_QqJuA7XTtKA/TQnMNeWpPTI/AAAAAAAAAEA/Bit5b39vsNk/s1600/Door%2B16-733446.jpg"&gt;&lt;img src="http://2.bp.blogspot.com/_QqJuA7XTtKA/TQnMNeWpPTI/AAAAAAAAAEA/Bit5b39vsNk/s320/Door%2B16-733446.jpg"  border="0" alt="" id="BLOGGER_PHOTO_ID_5551192547569253682" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;On 7&lt;SUP&gt;th&lt;/SUP&gt; December 2010, we posted a blog called  &lt;I style="mso-bidi-font-style: normal"&gt;Business Continuity Planning in a  nutshell&lt;/I&gt;. At the end, we promised a similar blog about Disaster Recovery  Planning would be coming soon. Well, soon has come! This is it.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;As we mentioned in the previous blog, a Business  Continuity Plan focuses on &lt;I style="mso-bidi-font-style: normal"&gt;all  &lt;/I&gt;aspects of your business and seeks to put in place procedures to follow in  the event of disaster. It will often include a Disaster Recovery Plan, which  focuses specifically upon IT.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;The first stage of Disaster Recovery Planning naturally  mirrors the first stage of Business Continuity Planning. It includes:&lt;/FONT&gt;&lt;/P&gt; &lt;UL style="MARGIN-TOP: 0cm; MARGIN-BOTTOM: 0cm" type=disc&gt;   &lt;LI style="TEXT-ALIGN: justify; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Identifying the threats and    risks;&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: justify; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Ascertaining the current level    of preparedness;&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: justify; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Documenting normal operating    policies and procedures; &lt;/FONT&gt;   &lt;LI style="TEXT-ALIGN: justify; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Identifying all IT assets –    equipment, software, etc. – and their location;&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: justify; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Listing all key IT equipment and    service providers – e.g. online backup and disaster recovery support – and    their contact details;&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: justify; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Distinguishing between the    critical &amp;amp; non-critical IT functions and determining 'acceptable levels'    of disruption;&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: justify; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Documenting the minimum and    optimum technical requirements to ensure your business can function after a    disaster – e.g. number of servers, PCs, software/applications, access to data,    peripherals, etc.;&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: justify; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Deciding upon the key personnel    and/or minimum staffing requirement to ensure critical IT functions can be    carried out;&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: justify; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Listing the contact details of    the key IT staff members;&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: justify; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Understanding the potential    impact of disaster.&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Disaster Recovery Planning is not a one off process in  exactly the same way as Business Continuity Planning is not. Having written up  your plan documenting the IT department's response in the event of disaster, you  will need to ensure it is regularly reviewed and updated to take account of such  things as changes in IT infrastructure (e.g. new servers), amendments to  policies and processes (e.g. a move to Cloud-based services) and personnel  changes.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Most importantly, any provisions you put in place should  be tested, tested and tested again. If your backups could not be restored or  technology switched from your primary location to a secondary location at a  critical time, all your planning could be for nought and the disaster  exacerbated.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;To steal a line from the Scouting movement: Be  Prepared.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;To read &lt;I&gt;Business Continuity Planning in a  nutshell&lt;/I&gt; click &lt;A  href="http://blog.securm.co.uk/2010/12/business-continuity-planning-in.html"&gt;here&lt;/A&gt;.&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-4185741882976254529?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/4185741882976254529/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/disaster-recovery-planning-in-nutshell.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/4185741882976254529'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/4185741882976254529'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/disaster-recovery-planning-in-nutshell.html' title='Disaster Recovery Planning in a nutshell - Xmas special day 16'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_QqJuA7XTtKA/TQnMNeWpPTI/AAAAAAAAAEA/Bit5b39vsNk/s72-c/Door%2B16-733446.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-7871031134883777926</id><published>2010-12-15T09:59:00.000Z</published><updated>2010-12-15T10:00:03.890Z</updated><title type='text'>The BIG Threat? - Xmas special day 15</title><content type='html'>&lt;p class="mobile-photo"&gt;&lt;a href="http://2.bp.blogspot.com/_QqJuA7XTtKA/TQiRpNl_yYI/AAAAAAAAAD4/AzF02aPoQ6Y/s1600/Door%2B15-703891.jpg"&gt;&lt;img src="http://2.bp.blogspot.com/_QqJuA7XTtKA/TQiRpNl_yYI/AAAAAAAAAD4/AzF02aPoQ6Y/s320/Door%2B15-703891.jpg"  border="0" alt="" id="BLOGGER_PHOTO_ID_5550846677943830914" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;What would you say poses the biggest threat to the  security of your systems and data?&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;- Viruses and Trojans?&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;- Hacking?&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;- Theft or vandalism?&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;- Malicious 'insider activity'?&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;- Failure to follow policies / procedures?&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;If you really think about it, the biggest threat is  posed by people, because none of the above can happen without human  involvement.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;People aren't  responsible for everything though!&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;We're not suggesting every threat involves people -  there's no controlling the elements and not every leaking pipe or electrical  fault will be down to poor installation – but when something goes wrong, there's  often someone behind it.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;You can't do anything about the people who pose the  external threats, like virus attacks, hacking, burglary and vandalism. But what  you can do is take steps to prevent, or make it difficult for them to enact,  those threats&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;By regularly testing your systems for vulnerabilities,  patching them and implementing robust IT security applications, you can reduce  the possibility of a virtual attack.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;To protect your systems from the physical threat, you  can ensure any data is encrypted; minimise the amount of data held on desktops  and laptops; consider locking portable equipment in secure fire safes; and  protect your building's perimeter with CCTV, amongst other things.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;When it comes to employees, there is much more you can  do.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Are you  saying my employees are bad people?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Let's be clear before we go on – we're not for one  minute suggesting your employees knowingly or maliciously pose a threat to your  business. Whilst this can happen, more often than not the threat arises through  a lax attitude towards, or even an ignorance of, IT security.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;However good your written policies and procedures might  be, if people fail to adhere to them they may just as well not have been  formulated.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;So what can I  do?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;We've said it before, and we'll say it again, "Get them  involved! Engage them in the process."&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;People learn and understand more by 'doing'. Encourage  your employees to help you devise the policies and procedures. Incentivise them  to highlight possible issues and threats. It doesn't need to be a financial  incentive – praise is often sufficient!&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;The more they play a part, the more they understand. The  more they understand, the more likely they are to want to see IT security  policies adhered to.&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-7871031134883777926?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/7871031134883777926/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/big-threat-xmas-special-day-15.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/7871031134883777926'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/7871031134883777926'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/big-threat-xmas-special-day-15.html' title='The BIG Threat? - Xmas special day 15'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_QqJuA7XTtKA/TQiRpNl_yYI/AAAAAAAAAD4/AzF02aPoQ6Y/s72-c/Door%2B15-703891.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-2081186151243442762</id><published>2010-12-14T13:44:00.001Z</published><updated>2010-12-14T13:44:48.159Z</updated><title type='text'>Anti-Virus Dos &amp; Don'ts - Xmas special day 14</title><content type='html'>&lt;p class="mobile-photo"&gt;&lt;a href="http://3.bp.blogspot.com/_QqJuA7XTtKA/TQd00P95wzI/AAAAAAAAADw/q0Lr7vBKgzI/s1600/Door%2B14-788160.jpg"&gt;&lt;img src="http://3.bp.blogspot.com/_QqJuA7XTtKA/TQd00P95wzI/AAAAAAAAADw/q0Lr7vBKgzI/s320/Door%2B14-788160.jpg"  border="0" alt="" id="BLOGGER_PHOTO_ID_5550533506745615154" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;DIV&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;We know the initiated amongst you have  probably seen – and even given - plenty of advice about anti-virus (AV) software  before, so we don't want to rake over old ground. But sometimes things bear  repeating, just to reinforce their importance.&lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Here are a few dos and don'ts to consider when it comes  to using AV software for your business:&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=left&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=left&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;The  dos&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;UL style="MARGIN-TOP: 0cm; MARGIN-BOTTOM: 0cm" type=disc&gt;   &lt;LI style="TEXT-ALIGN: left; MARGIN: 0cm 0cm 0pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Do install anti-virus software    on all machines – servers, desktops, laptops, handheld devices, etc.;&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: left; MARGIN: 0cm 0cm 0pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Do read the instructions;&lt;/FONT&gt;     &lt;LI style="TEXT-ALIGN: left; MARGIN: 0cm 0cm 0pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Do keep AV software regularly    updated. If it's set to automatically update, make sure the updates have been    successful and definitions are fully up-to-date;&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: left; MARGIN: 0cm 0cm 0pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Do allow AV software to run in    'real-time'. It shouldn't rely upon the user initiating its operation; it    should always be running;&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: left; MARGIN: 0cm 0cm 0pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Do ensure your AV software scans    everything, including master and boot records as well as memory and system    files. It's not just executables that can cause harm;&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: left; MARGIN: 0cm 0cm 0pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Do enable macro virus    protection;&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: left; MARGIN: 0cm 0cm 0pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Do disable preview screens in    email applications;&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: left; MARGIN: 0cm 0cm 0pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Do maintain, and regularly    review, an AV policy.&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=left&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=left&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;The  don'ts&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;UL style="MARGIN-TOP: 0cm; MARGIN-BOTTOM: 0cm" type=disc&gt;   &lt;LI style="TEXT-ALIGN: left; MARGIN: 0cm 0cm 0pt; mso-list: l1 level1 lfo2"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Don't allow USB devices to be    connected or opened without a &lt;B style="mso-bidi-font-weight: normal"&gt;full&lt;/B&gt;    scan;&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: left; MARGIN: 0cm 0cm 0pt; mso-list: l1 level1 lfo2"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Don't rely upon free AV software    that is limited in its functionality;&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: left; MARGIN: 0cm 0cm 0pt; mso-list: l1 level1 lfo2"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Don't allow    'auto-run'/'auto-open' for any downloaded applications, email attachments,    etc.;&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: left; MARGIN: 0cm 0cm 0pt; mso-list: l1 level1 lfo2"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Don't run Windows Script Hosting    on machines that don't need it. If it's not enabled many virus cannot    function;&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: left; MARGIN: 0cm 0cm 0pt; mso-list: l1 level1 lfo2"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Don't rely solely upon AV    software. It doesn't offer complete protection against all threats; but&lt;/FONT&gt;     &lt;LI style="TEXT-ALIGN: left; MARGIN: 0cm 0cm 0pt; mso-list: l1 level1 lfo2"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Don't simply run other security    applications alongside your AV software without checking for compatibility.    Conflicts can cause compromise.&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt; &lt;DIV&gt;&lt;o:p&gt;&lt;/o:p&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-2081186151243442762?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/2081186151243442762/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/anti-virus-dos-donts-xmas-special-day.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/2081186151243442762'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/2081186151243442762'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/anti-virus-dos-donts-xmas-special-day.html' title='Anti-Virus Dos &amp; Don&apos;ts - Xmas special day 14'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_QqJuA7XTtKA/TQd00P95wzI/AAAAAAAAADw/q0Lr7vBKgzI/s72-c/Door%2B14-788160.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-1886544071291234670</id><published>2010-12-13T21:48:00.001Z</published><updated>2010-12-13T21:48:13.483Z</updated><title type='text'>Looking ahead to 2012</title><content type='html'>&lt;p class="mobile-photo"&gt;&lt;a href="http://4.bp.blogspot.com/_QqJuA7XTtKA/TQaUnZZy17I/AAAAAAAAADo/MeCZPhrsiBE/s1600/Door%2B13-793483.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/_QqJuA7XTtKA/TQaUnZZy17I/AAAAAAAAADo/MeCZPhrsiBE/s320/Door%2B13-793483.jpg"  border="0" alt="" id="BLOGGER_PHOTO_ID_5550286995335600050" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;We're not talking the London Olympics here; it's SHA-3  we're interested in.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;SHA  what?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;SHA-3. It stands for Secure Hash Algorithm 3.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;What's one of  those?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;SHA is one of a number of cryptographic 'hash functions'  published by the National Institute of Standards &amp;amp; Technology (NIST), which  is a US Government organisation responsible for setting information security  standards.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;A Secure Hash Algorithm generates 'hashes', which are  essential for non-repudiation of digital signatures and certificates. In  essence, anything you wish to ensure has 'come from source' should have an  accompanying 'Pre-Computed Hash'. Those of you familiar with Open Source  software will be used to seeing such hashes.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;If you wish to prove non-repudiation of an email source,  you need to provide an email hash. This is usually encrypted using the sender's  private key, meaning it can only be opened by the sender's public key. Once  opened you can see the hash for the message, which proves that the message is  the same as it was when it was sent. As it was encrypted using the sender's  private key, only the sender could have sent it, thus proving non-repudiation.  &lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Hash keys are a bit like digital fingerprints for  data.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;SHA-3 will completely replace SHA-0, SHA-1 and  SHA-2.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;What's wrong  with 0, 1 &amp;amp; 2? Are they no longer secure?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;SHA-0 was withdrawn after the discovery of an  undisclosed flaw. SHA-1 and 'derivatives' have been subjected to serious  attacks, known as 'Dictionary Attacks' and it is feared SHA-2 could be next. But  security is not the only issue. It's also the case that SHAs need to evolve to  meet the increasing demands today's and future technology will place upon  them.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;A serious concern is the effect Quantum computing could  have on cryptanalysis. &lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;What will it  mean for my business?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;SHA-3 is being trumpeted as a solution that will offer  better security, more flexibility and will have a 'shelf-life' far exceeding its  predecessors, thus making it a much more attractive investment. It is hoped it  will last at least 20 years.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;If you use 2&lt;SUP&gt;nd&lt;/SUP&gt; factor authentication, process  online payments, encrypt data when transferring it for backup in The Cloud, or  apply digital signatures to emails or documents, you should be eagerly awaiting  2012.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Of course you will need to apply any published patches  from your software vendor as your current configuration will almost certainly  not support the implementation of SHA-3. There may be other concerns as well,  such as backward compatibility for both hardware and software.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;So why isn't  it available yet?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;In 2007, NIST recognised the need for Secure Hash  Algorithms to become more sophisticated and decided to run a competition to  develop SHA-3.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;The competition has only just reached its final round,  with 5 contestants still in the game. The winner is expected to be announced in  early 2012.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;A  competition?&lt;/FONT&gt;&lt;/B&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;!&lt;/FONT&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;  Why?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Yes. It was open to all, from multi-national IT  corporations through to small businesses and university based teams alike.  Interestingly, many of the large IT corporations went out in the first  round.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;This is standard practice for NIST – development of the  Advanced Encryption Standard (AES) was also a 'public' competition. NIST  believes such competition widens the scope and brings new input and potentially  new thinking to its Cryptographic Hash Project.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Is that  safe?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Yes, remember the only things that need to be secure in  a cryptographic chain are the keys. When talking about hashes, nothing is  secret. This is common in the world of cryptography. It allows for constant peer  review and, even better, keeps the algorithms free to use.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Where can I  find out more?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;The best resource is the NIST website. It provides a  wealth of information, some general and some more technical - &lt;A  href="http://csrc.nist.gov/groups/ST/hash/index.html"&gt;http://csrc.nist.gov/groups/ST/hash/index.html&lt;/A&gt;.&lt;/FONT&gt;&lt;/P&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;DIV class=Section1&gt;&lt;STRONG&gt;&lt;FONT  color=#808080&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-1886544071291234670?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/1886544071291234670/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/looking-ahead-to-2012.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/1886544071291234670'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/1886544071291234670'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/looking-ahead-to-2012.html' title='Looking ahead to 2012'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_QqJuA7XTtKA/TQaUnZZy17I/AAAAAAAAADo/MeCZPhrsiBE/s72-c/Door%2B13-793483.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-8943331482182149974</id><published>2010-12-12T14:00:00.001Z</published><updated>2010-12-12T14:00:19.084Z</updated><title type='text'>2nd Factor NOT x-Factor! - Xmas special day 12</title><content type='html'>&lt;p class="mobile-photo"&gt;&lt;a href="http://4.bp.blogspot.com/_QqJuA7XTtKA/TQTVcy_WXVI/AAAAAAAAADg/0dA1UkZGS1k/s1600/Door%2B12-719086.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/_QqJuA7XTtKA/TQTVcy_WXVI/AAAAAAAAADg/0dA1UkZGS1k/s320/Door%2B12-719086.jpg"  border="0" alt="" id="BLOGGER_PHOTO_ID_5549795331527826770" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;If you have computers you have users who almost  certainly have passwords to access those computers. Hopefully you get the  drift.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Passwords are fine as the first line of defence for IT  equipment such as desktops or laptops, so you really should ensure you've got a  good password policy in place. However you choose to implement that policy,  whether through informal training, system controls, or a mix of both, it needs  to encourage your employees to use strong passwords and keep them  safe.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;When it comes to more technical kit, such as Servers,  Network equipment and any devices facing the Internet, you will need both a  strong password policy &lt;I style="mso-bidi-font-style: normal"&gt;and&lt;/I&gt;  2&lt;SUP&gt;nd&lt;/SUP&gt; factor authentication&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;A blog is not the right medium for trying to cover the  ins and outs of a good password policy, or to discuss the best way to implement  2&lt;SUP&gt;nd&lt;/SUP&gt; factor authentication, but we can at least cover some of the  important things to consider.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo1"  class=MsoListParagraphCxSpFirst align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;STRONG&gt;1.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;'Formulation' of passwords&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoListParagraph align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;You may wish to prescribe a certain type of password or,  better still, passphrase. As a minimum, you should enforce the inclusion of a  mixture of uppercase and lowercase letters, and at least two numbers.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Additionally, you should insist that  your users do not use dictionary words, or anything that could be easily guessed  / 'socially engineered, like the name of a loved one, a car registration number  or a date of birth.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;STRONG&gt;2.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Password complexity/strength&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoListParagraph align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;This goes hand-in-hand with point 1. The more complex  passwords are, the more secure they will usually be. The problem is that the  more complex they become, the more difficult they are to remember, particularly  if users have more than one password per system, which ideally they  should.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;A meaningful or even silly phrase  with some letters replaced by numbers – 5ant@H45amas51v3sack - is often easier  to remember than a random series of letters and numbers and can prove to be just  as strong.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;STRONG&gt;3.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;How  long should they be valid for?&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoListParagraph align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;There's no hard-and-fast rule. Many organisations  enforce a periodic change, perhaps every 60 or 90 days. This is an acceptable  practice, but it can cause difficulties for users. If all passwords change at  the same time they have to think of new ones. If they change at different times  there's potential for confusion. It' a case of trying to find a workable  balance.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoListParagraph align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Some organisations insist on a very complex and strong  passwords or passphrases and then lock them down so they never change. This of  course has the disadvantage that if the password is compromised and no-one  realises, whoever has access to the password could gain long-term access to  systems and data.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoListParagraph align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Working in IT, as many of you do, you will be aware that  imposing frequent password changes and insisting upon complex passwords can  adversely affect the view your users have of you, perhaps causing them to see  you as overly authoritarian. It's not a view you would wish to persist but, as  well as educating users about the importance of a robust password policy, there  are things you can do to change their views.&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l0 level1 lfo2; mso-add-space: auto"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Enforce a 'lax'  password changing policy, e.g. 180 days, but ensure passwords are at least 14  characters in length;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l0 level1 lfo2; mso-add-space: auto"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Set up systems  to prevent 'brute force attacks' that lock out passwords, perhaps after 3  unsuccessful attempts on non Internet-facing accounts;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l0 level1 lfo2; mso-add-space: auto"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Tie  Internet-facing accounts to a 2&lt;SUP&gt;nd&lt;/SUP&gt; factor authentication, such as  VeriSign VIP token, which will help to prevent password compromise whilst still  giving flexibility to users.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;STRONG&gt;4.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Security of Passwords&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoListParagraph align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Obviously the ideal situation is for users to remember  all their passwords. You really don't want them written down on Post-it notes  and scraps of paper about the place.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoListParagraph align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;If it's not feasible to expect users to remember  passwords, it may be worth considering keeping a log, but this should be held  very securely and access should only be given to key personnel. It could be  stored in a safe or in an encrypted file on a PC that does not have network or  Internet access.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;In the event of disaster hitting  your business, keeping passwords secure in this way may prove to have been a  wise move.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;What is  2&lt;SUP&gt;nd &lt;/SUP&gt;factor authentication?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Put simply, 2&lt;SUP&gt;nd&lt;/SUP&gt; factor authentication - also  known as two-factor authentication – is, as the name would suggest, a mechanism  whereby more than one thing is required to authenticate a user. So, in addition  to a password or PIN, a user will be required to provide an additional  factor.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;This could be a randomly generated code from a small  electronic device, often called a token, similar to those issued by some banks.  Alternatively, users might have to swipe their finger across a fingerprint  reader, or even have a retinal scan.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;In essence:&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3"  class=MsoListParagraphCxSpFirst align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;First factor =  something the use knows, like a password or PIN; and&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 36pt; mso-list: l2 level1 lfo3"  class=MsoListParagraphCxSpLast align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Second factor =  something the user 'has', such as an electronic token number or  fingerprint.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;DIV class=Section1&gt;&lt;FONT  size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-8943331482182149974?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/8943331482182149974/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/2nd-factor-not-x-factor-xmas-special.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/8943331482182149974'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/8943331482182149974'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/2nd-factor-not-x-factor-xmas-special.html' title='2nd Factor NOT x-Factor! - Xmas special day 12'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_QqJuA7XTtKA/TQTVcy_WXVI/AAAAAAAAADg/0dA1UkZGS1k/s72-c/Door%2B12-719086.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-5192840320325085925</id><published>2010-12-11T08:11:00.001Z</published><updated>2010-12-11T08:11:32.707Z</updated><title type='text'>Ten Top IT Security Essentials - Xmas special day 11</title><content type='html'>&lt;p class="mobile-photo"&gt;&lt;a href="http://3.bp.blogspot.com/_QqJuA7XTtKA/TQMyNOxBu5I/AAAAAAAAADY/JjrCm21g6kQ/s1600/Door%2B11-792708.jpg"&gt;&lt;img src="http://3.bp.blogspot.com/_QqJuA7XTtKA/TQMyNOxBu5I/AAAAAAAAADY/JjrCm21g6kQ/s320/Door%2B11-792708.jpg"  border="0" alt="" id="BLOGGER_PHOTO_ID_5549334368734002066" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;After some of our weightier blogs of recent days, joke  viruses aside, we thought we'd take a short, sharp look at ten things you can do  to ensure the security of your data and systems.&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpFirst align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;1.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Use anti-virus  software and keep it up-to-date. Don't rely on free versions that are not fully  functional;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;2.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Regularly scan  your systems for spyware and malware;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;3.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Install a  firewall;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;4.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Regularly  back-up data and system configurations;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;5.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Restrict  employee access to social networking sites and personal webmail;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;6.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Don't use USB  devices to back-up or store data;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;7.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Don't keep data  on laptops and mobile devices;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;8.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Encourage the  use of complex passwords and change them regularly;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;9.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Implement a  robust process for ensuring systems and software are updated and patched;  and&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpLast align=justify&gt;&lt;SPAN  style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;10.&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt; &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Use Two-Factor Authentication.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;You can probably think of 10 more, maybe even 20. If so,  great! Write them down, add them to the list above and, most importantly,  remember them!&lt;/FONT&gt;&lt;/P&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;DIV class=Section1&gt; &lt;P style="TEXT-ALIGN: left" class=MsoNormal align=left&gt;&lt;o:p&gt;&lt;FONT  size=3&gt;&lt;/FONT&gt;&lt;/o:p&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-5192840320325085925?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/5192840320325085925/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/ten-top-it-security-essentials-xmas.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/5192840320325085925'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/5192840320325085925'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/ten-top-it-security-essentials-xmas.html' title='Ten Top IT Security Essentials - Xmas special day 11'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_QqJuA7XTtKA/TQMyNOxBu5I/AAAAAAAAADY/JjrCm21g6kQ/s72-c/Door%2B11-792708.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-9174919276141650236</id><published>2010-12-10T12:41:00.003Z</published><updated>2010-12-10T18:01:41.929Z</updated><title type='text'>The Ten Worst Viruses? - Xmas special day 10</title><content type='html'>&lt;div class="mobile-photo"&gt;&lt;/div&gt;&lt;div dir="ltr"&gt;&lt;div style="color: black; font-family: 'Trebuchet MS'; font-size: 10pt;"&gt;&lt;div align="left" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;a href="http://2.bp.blogspot.com/_QqJuA7XTtKA/TQIf8K6ZGYI/AAAAAAAAADQ/fSOwcGC52q8/s1600/Door%2B10-779479.jpg" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5549032809455753602" src="http://2.bp.blogspot.com/_QqJuA7XTtKA/TQIf8K6ZGYI/AAAAAAAAADQ/fSOwcGC52q8/s320/Door%2B10-779479.jpg" /&gt;&lt;/a&gt;&lt;span style="font-size: 11pt;"&gt;Here at Securm Towers, our dynamic control centre, we  have to keep ourselves up-to-date with the latest virus and Trojan threats. We  need to know what they are, how they can infect your systems and exactly what  needs to be done to protect against them. If one our clients calls us to say a  Storage Area Network has been infected or a server has been hit, we have to be  equipped to deal with the problem and explain the ramifications of the  infestation.&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Whilst undertaking some serious research, we stumbled  across the following horrific threats to your IT Security. Please read  carefully, and take note.&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoListParagraphCxSpFirst" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;1.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Prozac  Virus&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 11pt;"&gt;: Screws up your RAM but your  processor doesn't care.&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;2.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Viagra  Virus&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 11pt;"&gt;: Expands your hard drive, while  putting too much pressure on your zip drive.&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;3.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Airline  Luggage Virus&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 11pt;"&gt;: You're in London, but  your data is in Taiwan&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;4.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;The UK  Government Virus&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 11pt;"&gt;: Runs every program on  your hard drive simultaneously, but doesn't allow you to accomplish  anything.&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;5.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Adam and Eve  virus:&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 11pt;"&gt; Takes a couple of bytes out of  your Apple&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;6.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Politically  correct virus:&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 11pt;"&gt; Never calls itself a  "virus", but instead refers to itself as an "electronic  microorganism".&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;7.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Nike  virus:&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 11pt;"&gt; Just Does It!&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;8.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Gallup virus:  &lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 11pt;"&gt;Sixty per cent of the PCs infected will  lose 38 per cent of their data 14 per cent of the time (plus or minus a 3.5 per  cent margin of error).&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;9.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Freudian Virus: &lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 11pt;"&gt;Your computer becomes obsessed  with its own motherboard&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="left" class="MsoListParagraphCxSpLast" style="margin: 0cm 0cm 6pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;10.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Elvis Virus:  &lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 11pt;"&gt;Your computer gets fat, slow and lazy,  then self destructs, only to resurface at random locations around the  world.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-size: 11pt;"&gt;OK, so they're not real…as if you hadn't guessed…but,  we'd be interested to know which, if any, you think is the funniest. Let us know  by taking our poll, which appears on the right of this page. If you weren't  amused, please answer, "I don't think IT security is a laughing  matter."&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-9174919276141650236?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/9174919276141650236/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/ten-worst-viruses-xmas-special-day-10.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/9174919276141650236'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/9174919276141650236'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/ten-worst-viruses-xmas-special-day-10.html' title='The Ten Worst Viruses? - Xmas special day 10'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_QqJuA7XTtKA/TQIf8K6ZGYI/AAAAAAAAADQ/fSOwcGC52q8/s72-c/Door%2B10-779479.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-4976173163315674177</id><published>2010-12-09T18:03:00.001Z</published><updated>2010-12-10T12:28:43.894Z</updated><title type='text'>Laptops and Mobile Devices – equally blessed &amp; cursed? - Xmas special day 9</title><content type='html'>&lt;div class="mobile-photo"&gt;&lt;/div&gt;&lt;div dir="ltr"&gt;&lt;div style="color: black; font-family: 'Trebuchet MS'; font-size: 10pt;"&gt;&lt;a href="http://2.bp.blogspot.com/_QqJuA7XTtKA/TQEaE5P3iVI/AAAAAAAAADI/Zr1Bj8a2dLI/s1600/Door%2B9-743164.jpg" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5548744887286335826" src="http://2.bp.blogspot.com/_QqJuA7XTtKA/TQEaE5P3iVI/AAAAAAAAADI/Zr1Bj8a2dLI/s320/Door%2B9-743164.jpg" /&gt;&lt;/a&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Let's face it laptops and mobile devices are fantastic  things. They allow you and your employees to work and be productive virtually  anywhere in the world. The problem is, portability is equally a blessing and a  curse, which means such devices can cause you a major headache when it comes to  the security of your data and IT systems.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 12pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Of course, if you and your employees take sensible  measures, you can at least ensure you manage and mitigate any risks, if not  eradicate them altogether. Some of them might seem obvious, and not all are  technology-based, but they bear repeating:&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpFirst" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;1.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Don't hold  data on your laptop or device&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 11pt;"&gt;.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraph" style="margin: 0cm 0cm 6pt 36pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Keeping data off laptops and mobile devices and giving  secure access to virtual and/or Cloud-based access to data is the best  solution.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraph" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;span style="font-size: 11pt;"&gt;But you still need to apply common-sense and other  layers of security.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;span style="font-size: 11pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;2.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Don't store  passwords&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 11pt;"&gt;.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;span style="font-size: 11pt;"&gt;If a laptop or device is stolen, and  every password for each protected application and website is 'remembered', your  business and your employee could have a problem or two.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;3.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Don't store  security / authentication 'certificates'. &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;span style="font-size: 11pt;"&gt;In the same way you shouldn't store  passwords. You don't want a stolen device to simply open up your  network.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;4.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Password  protect the device.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;span style="font-size: 11pt;"&gt;The simplest, first line of  protection for any device;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;5.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Password  protection of key documents and data.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;span style="font-size: 11pt;"&gt;If you must keep data on the laptop  or mobile device, make sure it is protected at file level.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;6.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Encryption&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Operating systems, like Windows 7,  and numerous applications allow you to encrypt data and files. Alternatively,  you can invest in specialist encryption applications. Just be sure you back-up  the keys.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;7.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Be wary of  free Wi-Fi services.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;span style="font-size: 11pt;"&gt;If your employees use laptops or  handheld devices over Wi-Fi networks that are not secured, they could be  inadvertently making business sensitive data available to unauthorised  individuals. It's well worth reviewing the security of such devices and your  organisations' policies and procedures for ensuring the security of data held on  them.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;span style="font-size: 11pt;"&gt;You might want to consider providing  those employees who need Internet access on the move with mobile broadband (e.g.  via a USB dongle). If any of them 'roam' extensively, using satellite  communication systems is an option.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;8.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Install  tracking software&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;span style="font-size: 11pt;"&gt;There are numerous applications you  can install on laptops and mobile devices that will send regular location  updates when the device is switched on. If a device is lost or stolen, it may be  possible to track its whereabouts.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;9.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Install data  destruction software.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; This can be triggered by  'brute-force' attempts to crack passwords, or you can trigger it remotely if  your device is switched on and connected to the Internet.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;10.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Use  asset-tagging, marking or engraving.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;span style="font-size: 11pt;"&gt;If a laptop or device is mislaid,  you're more likely to get it back if it's marked up. Tagging also makes stolen  devices more difficult to sell.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;11.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Use a cable  and/or physical device lock.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;span style="font-size: 11pt;"&gt;It's not sophisticated, but it may  well deter the opportunist thief.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-size: 11pt;"&gt;12.&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Be sensible  and be security aware &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraph" style="margin: 0cm 0cm 6pt 36pt;"&gt;&lt;span style="font-size: 11pt;"&gt;OK, so this is a bit of a catch-all, but the truth of  the matter is that people are generally the weakest link in the security chain.  We include under this header such warnings as:&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Don't leave  devices unattended;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Don't allow  strangers to read your screen over your shoulder – consider using a screen  guard; and&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraph" style="margin: 0cm 0cm 12pt 71.7pt; text-indent: -17.85pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Carry the  device in a nondescript holdall, not a bag emblazoned with the manufacturer's or  your company's logo.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;It all boils down to the fact that you need to make both  the physical and technological security of your laptops and mobile devices a  priority and ensure your employees buy in to this.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-4976173163315674177?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/4976173163315674177/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/laptops-and-mobile-devices-equally.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/4976173163315674177'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/4976173163315674177'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/laptops-and-mobile-devices-equally.html' title='Laptops and Mobile Devices – equally blessed &amp; cursed? - Xmas special day 9'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_QqJuA7XTtKA/TQEaE5P3iVI/AAAAAAAAADI/Zr1Bj8a2dLI/s72-c/Door%2B9-743164.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-7223081668962829138</id><published>2010-12-08T14:36:00.002Z</published><updated>2010-12-09T10:35:31.092Z</updated><title type='text'>The Insider Threat 2 - Xmas special day 8</title><content type='html'>&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:WordDocument&gt;   &lt;w:View&gt;Normal&lt;/w:View&gt;   &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:PunctuationKerning/&gt;   &lt;w:ValidateAgainstSchemas/&gt;   &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:Compatibility&gt;    &lt;w:BreakWrappedTables/&gt;    &lt;w:SnapToGridInCell/&gt;    &lt;w:WrapTextWithPunct/&gt;    &lt;w:UseAsianBreakRules/&gt;    &lt;w:DontGrowAutofit/&gt;   &lt;/w:Compatibility&gt;   &lt;w:BrowserLevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;  &lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:LatentStyles DefLockedState="false" LatentStyleCount="156"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt; /* Style Definitions */ table.MsoNormalTable {mso-style-name:"Table Normal"; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-parent:""; mso-padding-alt:0cm 5.4pt 0cm 5.4pt; mso-para-margin:0cm; mso-para-margin-bottom:.0001pt; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; mso-ansi-language:#0400; mso-fareast-language:#0400; mso-bidi-language:#0400;}&lt;/style&gt; &lt;![endif]--&gt;  &lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;span lang="EN-GB"&gt;The recent arrest of Katia Zatuliveter on suspicion of spying emphasises again the ‘insider threat’. We raised it in our blog on 3&lt;sup&gt;rd&lt;/sup&gt; December, when we discussed the lessons businesses could learn after the &lt;i&gt;WikiLeaks&lt;/i&gt; publication of leaked US ‘embassy cables’.*&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;span lang="EN-GB"&gt;In that blog, we recommended businesses should implement a regime of appropriate controls over access to systems data. Effectively ensuring employees have access at a level commensurate with their role.&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;span lang="EN-GB"&gt;Ms. Zatuliveter was working as an aide to Mike Hancock, a Liberal Democrat MP who is a member of the Defence Select Committee. Whilst she denies the charges, the story raises questions over the whole employee vetting and monitoring process.&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;span lang="EN-GB"&gt;In this blog, we thought we’d go beyond the confines of IT security and protocols, because what the two stories highlight is the need for robust Know Your Employee (KYE) policies.&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;b&gt;&lt;span lang="EN-GB"&gt;We check all employees out before we take them on. We’re covered.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;b&gt;&lt;span lang="EN-GB"&gt;&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-GB"&gt;Undertaking the usual routine checks in respect of a potential employee – confirming previous employment, obtaining references and checking educational qualifications – is only a very small part of KYE.&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;span lang="EN-GB"&gt;We would suggest you consider the following:&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="ListParagraphCxSpFirst" style="text-align: left; text-indent: -18pt;"&gt;&lt;span lang="EN-GB" style="font-family: Symbol;"&gt;&lt;span&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB"&gt;Criminal records checks – you will need to have appropriate permission from the prospective employee and checks must be made within the confines of prevailing jurisdictional legislation. In the UK you can now request basic disclosure for any employee;&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="ListParagraphCxSpFirst" style="text-align: left; text-indent: -18pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="ListParagraphCxSpMiddle" style="text-align: left; text-indent: -18pt;"&gt;&lt;span lang="EN-GB" style="font-family: Symbol;"&gt;&lt;span&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB"&gt;Credit checks – again you’ll need the person’s permission but these are a good indicator of any potential financial difficulties;&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="ListParagraphCxSpMiddle" style="text-align: left; text-indent: -18pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="ListParagraphCxSpMiddle" style="text-align: left; text-indent: -18pt;"&gt;&lt;span lang="EN-GB" style="font-family: Symbol;"&gt;&lt;span&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB"&gt;Bankruptcy and Individual Voluntary Arrangement (IVA) searches – see &lt;a href="http://www.insolvency.gov.uk/"&gt;www.insolvency.gov.uk&lt;/a&gt;;&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="ListParagraphCxSpMiddle" style="text-align: left; text-indent: -18pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="ListParagraphCxSpMiddle" style="text-align: left; text-indent: -18pt;"&gt;&lt;span lang="EN-GB" style="font-family: Symbol;"&gt;&lt;span&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB"&gt;Check the Electoral Roll and carry out a Land Registry search – this will provide an indication of whether or not the individual resides at the address provided an/or owns the property;&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="ListParagraphCxSpMiddle" style="text-align: left; text-indent: -18pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="ListParagraphCxSpMiddle" style="text-align: left; text-indent: -18pt;"&gt;&lt;span lang="EN-GB" style="font-family: Symbol;"&gt;&lt;span&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB"&gt;Search births, marriages and even death records;&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="ListParagraphCxSpMiddle" style="text-align: left; text-indent: -18pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="ListParagraphCxSpMiddle" style="text-align: left; text-indent: -18pt;"&gt;&lt;span lang="EN-GB" style="font-family: Symbol;"&gt;&lt;span&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB"&gt;Disqualified Director searches – in the UK you can make these searches at &lt;a href="http://wck2.companieshouse.gov.uk/1845e7f89a9f34b7f1319419ed37b5a1/dirsec"&gt;http://wck2.companieshouse.gov.uk/1845e7f89a9f34b7f1319419ed37b5a1/dirsec&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="ListParagraphCxSpMiddle" style="text-align: left; text-indent: -18pt;"&gt;&lt;span lang="EN-GB"&gt;&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="ListParagraphCxSpMiddle" style="text-align: left; text-indent: -18pt;"&gt;&lt;span lang="EN-GB" style="font-family: Symbol;"&gt;&lt;span&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB"&gt;Carry out your own Internet research – Are there any adverse news items or other mentions? Do they use Facebook, Twitter or other social networking tools and, if so, does their activity raise any concerns;&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="ListParagraphCxSpMiddle" style="text-align: left; text-indent: -18pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="ListParagraphCxSpMiddle" style="text-align: left; text-indent: -18pt;"&gt;&lt;span lang="EN-GB" style="font-family: Symbol;"&gt;&lt;span&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB"&gt;Research referees and their contact details – do they appear genuine or could they be fictitious?&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="ListParagraphCxSpMiddle" style="text-align: left; text-indent: -18pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="ListParagraphCxSpLast" style="text-align: left; text-indent: -18pt;"&gt;&lt;span lang="EN-GB" style="font-family: Symbol;"&gt;&lt;span&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB"&gt;Fill in the gaps – for example, don’t just accept long breaks in employment as ‘career breaks’ or let numerous address changes in a short period of time go unquestioned.&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="ListParagraphCxSpLast" style="text-align: left; text-indent: -18pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;b&gt;&lt;span lang="EN-GB"&gt;That’s a lot to do! I haven’t really got the time. &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;span lang="EN-GB"&gt;We’re not saying you have to do all of those things. Nor do we present them as an exhaustive list. They are things to consider and you will find what works best for you. You might apply different levels according to the seniority of the position, for example.&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;span lang="EN-GB"&gt;If you really don’t have the time, you can always outsource it to a specialist agency. Some agencies even provide an identity verification service. Just make sure you are clear what gets checked and that you’re not just paying for ‘a box ticking exercise’.&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;b&gt;&lt;span lang="EN-GB"&gt;So is that it then?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;span lang="EN-GB"&gt;No. It’s also very important to realise that KYE isn’t just about running checks on someone before they start working for you. It’s an on-going process.&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;b&gt;&lt;span lang="EN-GB"&gt;What? You mean continually check them even after employing them?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;span lang="EN-GB"&gt;That’s about the long and the short of it.&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;b&gt;&lt;span lang="EN-GB"&gt;Isn’t that ‘a bit Big Brother’?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;span lang="EN-GB"&gt;The chances are your employees don’t pose a malicious threat to your business and we’re not suggesting you check up on them day in and day out. You could run six monthly review sessions to find out how they are doing, discuss progress and performance, seek to identify any dissatisfaction or disquiet and perhaps put that in context with the overall performance of the department they work in and/or your business as a whole. As with most things in life, there’s no ‘one size fits all’ solution. It’s a case of trying different approaches and finding what best suits your business.&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;span lang="EN-GB"&gt;Importantly you don’t have to approach such a process from the angle of suspicion. It makes good sense from a management and business perspective to show interest in and concern for your employees. After all, you do have a duty of care. You might even make it known that if someone gets into financial difficulties the business will do its best to help them out, perhaps acting as a guarantor to a loan or operating its own loan scheme. If you make them feel happy, safe and well incentivised at work they are more likely to be motivated and productive.&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;span lang="EN-GB"&gt;And if there are concerns over a particular individual, you are more likely to get to hear about it from other members of staff because they will feel compelled to inform you. You will then have an opportunity to establish the truth, or otherwise, of these concerns and take the necessary action.&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;span lang="EN-GB"&gt;For example, it could be rumours are circulating that your finance administrator’s gambling habits have got out of hand and he’s stealing money from the company’s bank accounts. Knowing this you can take appropriate action to address the problem. You may find the rumours are totally unfounded and you can take steps to quash them. On the other hand, you may discover some truth in what’s being said. Although you establish there is no evidence that money has been stolen, you at least have an opportunity to put some additional controls in place at the same time as offering guidance and counselling to the employee.&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;span lang="EN-GB"&gt;* &lt;i&gt;WikiLeaks&lt;/i&gt; continues to publish documents, despite the arrest yesterday, 7&lt;sup&gt;th&lt;/sup&gt; December, of its founder, Julian Assange.&lt;/span&gt;&lt;/div&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-7223081668962829138?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/7223081668962829138/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/insider-threat-2-xmas-special-day-8.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/7223081668962829138'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/7223081668962829138'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/insider-threat-2-xmas-special-day-8.html' title='The Insider Threat 2 - Xmas special day 8'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-1802606710212001243</id><published>2010-12-07T13:34:00.002Z</published><updated>2010-12-07T20:52:52.655Z</updated><title type='text'>Business Continuity Planning in a nutshell - Xmas special Day 7</title><content type='html'>&lt;div class="mobile-photo"&gt;&lt;/div&gt;&lt;div dir="ltr"&gt;&lt;div style="color: black; font-family: 'Trebuchet MS'; font-size: 10pt;"&gt;&lt;a href="http://2.bp.blogspot.com/_QqJuA7XTtKA/TP437QLUA1I/AAAAAAAAAC4/NtI6MRO6S00/s1600/Door%2B7-777493.jpg" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5547933282061255506" src="http://2.bp.blogspot.com/_QqJuA7XTtKA/TP437QLUA1I/AAAAAAAAAC4/NtI6MRO6S00/s320/Door%2B7-777493.jpg" /&gt;&lt;/a&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Business Continuity Planning is essentially putting  processes in place that will ensure your business keeps running after a  disastrous event, like a fire or flood, vandalism or theft of IT equipment, or  even widespread staff illness.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;The first stage of the process includes:&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpFirst" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Identifying the  threats and risks;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Ascertaining  the current level of preparedness; &lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Distinguishing  between the critical &amp;amp; non-critical functions of your business and  determining 'acceptable levels' of disruption;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Documenting the  minimum and optimum technical requirements to ensure your business can function  after a disaster – e.g. number of servers, PCs, software/applications, access to  data, peripherals, etc;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Documenting the  minimum and optimum 'business' requirements – alternative premises (if  appropriate); number of desks, stationery, etc.; &lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Deciding upon  the key personnel and/or minimum staffing requirement to ensure critical  functions can be carried out;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Listing the  contact details of the key staff members;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Identifying key  clients and primary suppliers;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpLast" style="margin: 0cm 0cm 6pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Understanding  the potential impact of disaster.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Based upon this knowledge, you can then establish the  procedures to follow in the event of disaster and formalise your plan in a  printed document that can be referred to before, during and after any  disruption. Its purpose will be to guide response to that disruption and  minimise the impact upon your business. All staff should be aware off its  existence and know how to access it.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;But that's not the end of the process; far from it.  Business Continuity Planning is a continuous cycle and your Business Continuity  Plan will need constant update and review as your business changes and evolves.  Some examples of things you will need to consider are:&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpFirst" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Staff  changes;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Organisational  changes;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;New or  additional premises;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Changes in  client-base;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;New and no  longer used suppliers;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Modified or  replaced technical infrastructure;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;New IT policies  and procedures; and&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpLast" style="margin: 0cm 0cm 6pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Changes in IT  processes – e.g. a move to Cloud-based (off-site) backups.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;You should notify your employees of any changes to the  Business Continuity Plan that directly impact upon them.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;And as well as updating your Business Continuity Plan,  you will also need to test it. This doesn't necessarily mean a full-blown  'drill', but you need to at least be sure primary elements work. Examples of  what you could test include:&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpFirst" style="margin: 0cm 0cm 0pt 39.75pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;The key  personnel call-out process;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 39.75pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;The 'all-staff  notification process';&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 39.75pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;The data  recovery and restore process; and&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpLast" style="margin: 0cm 0cm 6pt 39.75pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;The switch of  technology from primary to secondary location and back.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;A Business Continuity Plan focuses on &lt;i&gt;all&lt;/i&gt; aspects of the business and will  often include a Disaster Recovery Plan specifically focusing on the &lt;span lang="EN"&gt;IT or technology systems that support  business functions&lt;/span&gt;.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Coming soon: &lt;i&gt;Disaster Recovery in a  nutshell&lt;/i&gt;.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-1802606710212001243?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/1802606710212001243/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/business-continuity-planning-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/1802606710212001243'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/1802606710212001243'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/business-continuity-planning-in.html' title='Business Continuity Planning in a nutshell - Xmas special Day 7'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_QqJuA7XTtKA/TP437QLUA1I/AAAAAAAAAC4/NtI6MRO6S00/s72-c/Door%2B7-777493.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-7861486485445551314</id><published>2010-12-06T09:02:00.002Z</published><updated>2010-12-06T13:10:04.958Z</updated><title type='text'>Back-up essentials - Xmas special day 6</title><content type='html'>&lt;div class="mobile-photo"&gt;&lt;/div&gt;&lt;div dir="ltr"&gt;&lt;div style="color: black; font-family: 'Trebuchet MS'; font-size: 10pt;"&gt;&lt;a href="http://2.bp.blogspot.com/_QqJuA7XTtKA/TPymxEh7-ZI/AAAAAAAAACw/RG6nrFMGSg0/s1600/Door%2B6-780582.jpg" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5547492202973493650" src="http://2.bp.blogspot.com/_QqJuA7XTtKA/TPymxEh7-ZI/AAAAAAAAACw/RG6nrFMGSg0/s320/Door%2B6-780582.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;If disaster struck and you lost data or the  configuration settings of your IT systems, how would your business  cope?&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;If you've backed everything up, hopefully all will be  well and you'll be up and running in no time. If you haven't, you could find  yourself in serious difficulties. You really should implement back-up processes.  &lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Surely nobody  &lt;i&gt;forgets&lt;/i&gt; to back-up&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 11pt;"&gt;!&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;It's more common than you'd think but, thankfully the  most businesses are aware of the importance of back-ups. Unfortunately, what  they often forget are some of the fundamentals.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;What are  they?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 0pt 35.7pt; text-indent: -17.85pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Backups should be an integral part of an overall IT  Management Policy and your Business Continuity &amp;amp; Disaster Recovery  Planning;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 0pt 35.7pt; text-indent: -17.85pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Make sure you understand the difference between  'snapshot back-ups' and 'full file back-ups';&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 0pt 35.7pt; text-indent: -17.85pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Data should be regularly backed-up, preferably  daily;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 0pt 35.7pt; text-indent: -17.85pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;System configurations should also be backed up, at least  once a month as a rule-of-thumb;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 0pt 35.7pt; text-indent: -17.85pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Backups should be checked regularly, to ensure they have  run successfully and can be restored;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 0pt 35.7pt; text-indent: -17.85pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;If you run onsite back-ups, you really ought to consider  having an off-site copy, whether that be at one of your business's other  premises or with a provider of online (Cloud-based) back-up services;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 0pt 35.7pt; text-indent: -17.85pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Any offsite or Cloud back-ups should be encrypted during  transfer and at point of storage.&lt;/span&gt;&lt;/div&gt;&lt;div style="color: black; font-family: 'Trebuchet MS'; font-size: 10pt;"&gt;&lt;div class="Section1"&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-7861486485445551314?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/7861486485445551314/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/back-up-essentials.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/7861486485445551314'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/7861486485445551314'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/back-up-essentials.html' title='Back-up essentials - Xmas special day 6'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_QqJuA7XTtKA/TPymxEh7-ZI/AAAAAAAAACw/RG6nrFMGSg0/s72-c/Door%2B6-780582.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-449754389204652840</id><published>2010-12-05T12:28:00.001Z</published><updated>2010-12-10T12:30:21.093Z</updated><title type='text'>Critical Updates - Xmas special day 5</title><content type='html'>&lt;div class="mobile-photo"&gt;&lt;/div&gt;&lt;div dir="ltr"&gt;&lt;div style="color: black; font-family: 'Trebuchet MS'; font-size: 10pt;"&gt;&lt;a href="http://4.bp.blogspot.com/_QqJuA7XTtKA/TPuFj5Ij_GI/AAAAAAAAACo/LM8MypGq4qY/s1600/Door%2B5-743620.jpg" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5547174217715547234" src="http://4.bp.blogspot.com/_QqJuA7XTtKA/TPuFj5Ij_GI/AAAAAAAAACo/LM8MypGq4qY/s320/Door%2B5-743620.jpg" /&gt;&lt;/a&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;We've 'ummed' and 'ahhed' a bit over releasing this  blog. Let's face it, updates and patches are not the subjects of illuminating  conversation. Nor do they make for particularly exciting reading. But we  concluded that, as an IT Security company, we have a responsibility to raise the  issue…and perhaps it will at least make for interesting reading.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Without wishing to state the obvious, the basic activity  of update and patch management can be so important for the 'health' of your  systems and the security of your data.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;For most businesses, the operating systems across their  IT networks are automatically updated as a matter of course. And many  applications, like anti-virus, firewalls and intrusion detection can also be set  to automatic update, as can hardware drivers.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;It's all quite straightforward, until something goes  wrong.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;It's all  automated. I don't need to worry, do I?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;If everything is automated it's easy to assume it will  all run smoothly and to be lulled into a false sense of security. But there  really needs to be human input to the process.&lt;/span&gt;&lt;b&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpFirst" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Do you ensure  that all updates have installed successfully?&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Do you check  there is no incompatibility of patches and updates?&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Do you test the  impact of update and patch installations on your systems?&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpLast" style="margin: 0cm 0cm 6pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Have you made  sure employees cannot block or cancel critical updates?&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;If the answer to any of the above is "No" you should  probably review your policies and procedures.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;But what  could go wrong?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;That's one of those, "How long is a piece of string?"  questions.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;In some cases nothing, even if important updates have  not installed or there is a conflict between a patch on a server and an update  to your firewall. But that will be more down to luck than anything  else.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;You might just find that your systems do not run as  smoothly as they might, with servers and PCs 'crashing'. This could mean more  time spent dealing with IT problems and, of course, it affects the productivity  of business.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;In the worst case, your systems could be left exposed to  viruses and Trojans and, potentially, external attack. &lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;So what can I  do?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;If you've not implemented one already, an update and  patch management policy, with defined procedures, is highly advisable. In simple  terms, it's all about keeping tabs on what updates and patches are available,  identifying any known security issues or conflicts, and recording which updates  and patches have been applied to your IT systems. One critical part of a patch  policy is a release plan with alpha, beta gamma release testing on live and  development systems.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;There are plenty of resources and points of reference on  the web if you have the time and inclination to work it out for yourself.  Alternatively you can speak to an IT security expert who can run vulnerability  tests on your systems, identify any issues or concerns, put them right and make  recommendations for the future.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;It won't cost you the earth and you'll have  peace-of-mind.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-449754389204652840?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/449754389204652840/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/critical-updates-xmas-special-day-5.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/449754389204652840'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/449754389204652840'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/critical-updates-xmas-special-day-5.html' title='Critical Updates - Xmas special day 5'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_QqJuA7XTtKA/TPuFj5Ij_GI/AAAAAAAAACo/LM8MypGq4qY/s72-c/Door%2B5-743620.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-4365686751986182230</id><published>2010-12-04T08:06:00.003Z</published><updated>2010-12-06T13:09:29.266Z</updated><title type='text'>USB Don'ts - Xmas special day 4</title><content type='html'>&lt;div class="mobile-photo"&gt;&lt;/div&gt;&lt;div dir="ltr"&gt;&lt;div style="color: black; font-family: 'Trebuchet MS'; font-size: 10pt;"&gt;&lt;div style="color: black; font-family: 'Trebuchet MS'; font-size: 10pt;"&gt;&lt;div class="Section1"&gt;&lt;a href="http://2.bp.blogspot.com/_QqJuA7XTtKA/TPn2dVO1pYI/AAAAAAAAACg/FP7UTa9AT9E/s1600/Door%2B4-772819.jpg" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5546735399859496322" src="http://2.bp.blogspot.com/_QqJuA7XTtKA/TPn2dVO1pYI/AAAAAAAAACg/FP7UTa9AT9E/s320/Door%2B4-772819.jpg" /&gt;&lt;/a&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Your systems and data are vulnerable if you are lax at  enforcing strict policies and procedures in respect of the use of USB devices.  We'll keep this very simple and list some important USB don'ts:&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpFirst" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Don't allow  connection of any USB device to any machine without a full virus  scan;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Don't allow  .exe installs from USB devices. If it's absolutely necessary to allow installs,  limit them to Administrator level access;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Don't allow  personal use of business issued USB devices;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Don't allow  devices to be taken off-site;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Don't simply  give out devices without keeping a full inventory – type, serial number, when  issued, to whom, data held, etc.;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Don't rely upon  the device-based 'encryption' for the security of data;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Don't use USB  devices for critical backups;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Don't buy USB  devices for business use from online auctions or marketplaces;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Don't connect  your USB device to a computer you do not know or trust;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpLast" style="margin: 0cm 0cm 6pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Don't allow  important / sensitive files to be moved or copied from your network.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;It's by no means an exhaustive list, but it will  hopefully provide food for thought. The golden rule is: If you're not sure,  DON'T USE USB DEVICES.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-4365686751986182230?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/4365686751986182230/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/usb-donts.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/4365686751986182230'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/4365686751986182230'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/usb-donts.html' title='USB Don&apos;ts - Xmas special day 4'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_QqJuA7XTtKA/TPn2dVO1pYI/AAAAAAAAACg/FP7UTa9AT9E/s72-c/Door%2B4-772819.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-5193796059701999602</id><published>2010-12-03T14:34:00.002Z</published><updated>2010-12-03T15:09:50.819Z</updated><title type='text'>The Insider Threat - Xmas special day 3</title><content type='html'>&lt;div dir="ltr"&gt;&lt;div style="color: black; font-family: 'Trebuchet MS'; font-size: 10pt;"&gt;&lt;a href="http://2.bp.blogspot.com/_QqJuA7XTtKA/TPkIEclYzmI/AAAAAAAAACc/fw_4SoATS3k/s1600/Door+3.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_QqJuA7XTtKA/TPkIEclYzmI/AAAAAAAAACc/fw_4SoATS3k/s1600/Door+3.jpg" /&gt;&lt;/a&gt;&lt;span style="font-size: 11pt;"&gt;On Tuesday 30&lt;sup&gt;th&lt;/sup&gt; November, the US State  Department announced it was taking steps to temporarily reduce access to its  database of 'embassy cables'. The move came after &lt;i&gt;WikiLeaks&lt;/i&gt; began the publication of  hundreds of thousands of sensitive, classified and secret documents.&lt;/span&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Was the  information gained by hackers?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;There is no suggestion secure databases were hacked or  accessed by outsiders – as you would expect, US Government systems are protected  by the tightest possible security measures.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;So who was  responsible?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;It's not yet known who accessed and leaked the  information, but it is clear this embarrassing loss of data emanated from inside  a Government organisation or department that had been granted access to the  embassy cable via the US Defense Department's Secret Internet Protocol  (SIPRNet). The system was set up by the Pentagon in the 1990s. Access to the  network was greatly extended after the attacks of September 11&lt;sup&gt;th&lt;/sup&gt; 2001  to facilitate better sharing of intelligence.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Unfortunately, it seems the idea of sharing went a bit  too far.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Surely there  were controls in place!&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;There were plenty of controls in place.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;As we've mentioned, the system itself is as secure as  you can get when it comes to protection from outside attack. And people have to  go through high levels of vetting and security screening before being given  access. However, once access had been granted, the controls over what could be  done with the data seem not to have been so tight.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;As Amit Yoran, a member of President Obama's CSIS  Commission on Cyber Security, says "…once you have access to these classified  systems and are inside their tough perimeter, they have historically been very  trusting. And when you have a trusted insider who is interested in causing harm  or inappropriately accessing and divulging information, that sort of  architecture with strong perimeters is quite flawed."&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;That's not  exclusively an issue for the US government, is it?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Correct.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Whilst this leak of information involves the US  Government, it should resonate across the globe to all types of organisation and  business. It demonstrates 'the insider threat' on a huge scale.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Take any business, particularly of small or medium size.  Many of them will have adequate perimeter security in place for their IT systems  but place little restriction on how data held on those systems can be accessed  and used. &lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;How many of them have escalating levels of access  privilege according to the sensitivity of certain information? How many restrict  copying, editing or printing of files and data? We'd wager it's a fairly small  percentage."&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;But won't  limiting access suggest I don't trust my employees?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;"That's really the wrong way to look at things," says  Lee Barney, Securm's Managing Director. "Ultimately, you need to protect your  data. It's the lifeblood of your business. Your employees should be given  appropriate access to it according to the role they fulfil. For example, a  junior administrator has no need to access key financial data or certain  functions of your Customer Relationship Management system, whilst your Finance  Director does."&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;How do I know  what access levels to impose?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;There's no easy answer to that one and you may find it's  a bit of trial and error. Working with each of your employees to understand what  systems and data they access in order to undertake their day-to-day work, and  why, is obviously important.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;It may be a case of trial and error to some extent but,  as we frequently conclude, it's a matter of taking a common-sense approach and  finding a solution that works best for your business.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="color: black; font-family: 'Trebuchet MS'; font-size: 10pt;"&gt;&lt;div class="Section1"&gt;&lt;div align="left" class="MsoNormal" style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-5193796059701999602?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/5193796059701999602/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/insider-threat-xmas-special-day-3.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/5193796059701999602'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/5193796059701999602'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/insider-threat-xmas-special-day-3.html' title='The Insider Threat - Xmas special day 3'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_QqJuA7XTtKA/TPkIEclYzmI/AAAAAAAAACc/fw_4SoATS3k/s72-c/Door+3.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-731724973991978334</id><published>2010-12-02T20:10:00.004Z</published><updated>2010-12-03T12:11:05.434Z</updated><title type='text'>Protecting your business from domain theft / hijacking - Xmas special day 2</title><content type='html'>&lt;div dir="ltr"&gt;&lt;div style="color: black; font-family: 'Trebuchet MS'; font-size: 10pt;"&gt;&lt;a href="http://1.bp.blogspot.com/_QqJuA7XTtKA/TPjPng6PV9I/AAAAAAAAACY/xBH4NJVfON8/s1600/Door+2.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_QqJuA7XTtKA/TPjPng6PV9I/AAAAAAAAACY/xBH4NJVfON8/s1600/Door+2.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;When you set up your business, you most likely purchased  a domain name or series of domain names. They may include your business name –  www.thisismybusiness.co.uk - or a phrase that perfectly describes the service  you offer – www.wewashdogs.com. Either way, a domain name is the link to your  website and is the 'location' element of your email address.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;The last thing you'd want is for someone else to get  hold of it.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;That couldn't  happen, could it?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Unfortunately, it is the case that you could lose  control of your domain name and not know anything about it until it was too  late.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Really?!  How?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Yes, really.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;There are two main ways you can lose a domain  name.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Expiry – when you buy a domain name, you usually  register it for a period of time, let's say two years. If you fail to renew the  registration for a matter of days, or even hours in some cases, it becomes  available to purchase. If it's purchased by someone unwittingly, you may find  you have some recourse, but unscrupulous individuals know that they can  'legitimately' purchase the name and then hold you to ransom for it.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;You may think it wouldn't be possible to allow a domain  name to expire. But if it's registered to the company that designed your website  and they fail to renew, or worse have gone out of business, you can see how it  could happen.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;'Theft' – If an individual wishes to gain control of  your domain name, they could simply approach a hosting company other than the  one you are registered with, purport to be you and request a transfer. There is  no obligation upon your hosting company to confirm with you that you requested  the transfer. It's hard to believe but it's true.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;The good news is that many domain hosting companies  offer protection from domain theft and also have processes in place to ensure  you as the owner are notified of any requests to transfer.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;So how can I  protect my domain?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Some simple steps will help to ensure your domain name  stays safe:&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpFirst" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Register it in  your business's name;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Keep the  contact details held by your domain company up to date;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Don't let it  expire;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Limit access to  the control panel of your domain;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Ensure your  domain hosting company offers domain theft protection;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpLast" style="margin: 0cm 0cm 6pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Place a  registrar lock on your domain name.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-731724973991978334?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/731724973991978334/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/protecting-your-business-from-domain.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/731724973991978334'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/731724973991978334'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/protecting-your-business-from-domain.html' title='Protecting your business from domain theft / hijacking - Xmas special day 2'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_QqJuA7XTtKA/TPjPng6PV9I/AAAAAAAAACY/xBH4NJVfON8/s72-c/Door+2.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-3540073335446376044</id><published>2010-12-01T18:56:00.002Z</published><updated>2010-12-03T11:07:40.089Z</updated><title type='text'>How to get your employees interested in IT Security - Xmas special day 1</title><content type='html'>&lt;div dir="ltr"&gt;&lt;div style="color: black; font-family: 'Trebuchet MS'; font-size: 10pt;"&gt;&lt;span style="font-size: 11pt;"&gt;&lt;/span&gt;  &lt;br /&gt;&lt;div&gt;&lt;a href="http://3.bp.blogspot.com/_QqJuA7XTtKA/TPjPRn2v6iI/AAAAAAAAACU/4zfxDmC-W4M/s1600/Door+1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_QqJuA7XTtKA/TPjPRn2v6iI/AAAAAAAAACU/4zfxDmC-W4M/s1600/Door+1.jpg" /&gt;&lt;/a&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;IT systems are generally most vulnerable at the user  level. You can write as many policies and procedures as you like, but if your  employees do not understand them, or a lack an appreciation of the impact of  certain actions, your IT Security may not be as robust as you would  wish.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Policies and procedures are just one element of an  effective IT security set-up. Training and awareness are equally important  components.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Through focused training, you can explain the importance  of IT and data security. And by heightening awareness of the implications of  certain actions, you can ensure your employees understand why they are banned  from social networking at work, charging their iPods, or connecting their  personal USB memory sticks to their work PCs, for example.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Training and awareness programmes do not have to be  classroom-based. Encouraging members of staff to identify potential breaches of  security and play a part in on-going IT security reviews can help to demonstrate  issues in a 'real-world' situation.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Engaging your employees in the process, and including  them in the formulation of policies &amp;amp; processes they understand, should  result in tighter IT and data security...and hopefully less 'fire-fighting' for  you.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-3540073335446376044?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/3540073335446376044/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/12/how-to-get-your-employees-interested-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/3540073335446376044'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/3540073335446376044'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/12/how-to-get-your-employees-interested-in.html' title='How to get your employees interested in IT Security - Xmas special day 1'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_QqJuA7XTtKA/TPjPRn2v6iI/AAAAAAAAACU/4zfxDmC-W4M/s72-c/Door+1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-7135341162974099642</id><published>2010-11-29T09:15:00.001Z</published><updated>2010-11-29T09:15:45.166Z</updated><title type='text'>Is this the dawn of a new age of cyber-warfare, cyber-crime and cyber-terrorism?</title><content type='html'>&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;In June this year, a worm by the name of Stuxnet was  discovered by VirusBlokAda, a security firm in Belarus, on the computers of one  of its Iranian clients. The worm was subsequently found to have spread widely  through Iran, India and Indonesia.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Stuxnet is a Windows-specific worm capable of  identifying and reprogramming industrial control systems. It was first thought  that the worm had been designed to steal intellectual property and industrial  secrets. But its first iteration was found to specifically target two types of  frequency controller used in nuclear enrichment, which led many analysts to  conclude it had been designed to sabotage Iranian nuclear power plants,  including the Bushehr nuclear reactor.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Because of the sophisticated way the worm operates once  'installed', it was also believed by many that Stuxnet could only have been  designed by a Western nation state or, at least with state support. Perhaps,  some speculated, this was a step towards cyber-warfare.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;How does it  work?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Computers and servers are primarily infected through the  attachment of USB devices since the types of systems targeted by Stuxnet are not  generally connected to the internet. Once installed it is capable of propagating  to other machines within a network and escalating its privileges so internet  access is possible. The worm does no harm to these Windows computers and  servers. It merely 'uses' them to help identify its real target, which is a  specific type of Programmable Logic Controller (PLC) made by Siemens, and access  the internet.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;What are  PLCs?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;PLCs are small devices that run all manner of automated  processes. They are used in factories, oil refineries, transport systems,  utilities provision, ATM networks and nuclear power plants, to give just a few  examples. A robotic arm in a car factory is a good example of something that's  controlled by PLCs.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Stuxnet can seek out PLCs controlled by a particular  type of Siemens software - SIMATIC WinCC/Step 7 – then embed itself and 'action'  changes by altering certain data. Whilst it's almost impossible to determine  their effect, the changes appear to be quite specific, leading many experts and  commentators to conclude that Stuxnet is aimed at gaining control of PLCs that  perform specific functions, perhaps even in a specific type of environment;  hence the conclusion that the targets were nuclear plants.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;It sounds  quite scary. Could things be worse?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;As we've already mentioned, it has been speculated that  Stuxnet's purpose was to sabotage the Iranian nuclear programme. Some might  actually argue that's no bad thing and, if it was aimed at reducing the  potential for nuclear proliferation in Iran, its purpose was for good. That's  questionable logic and it has to be pointed out there is no specific evidence to  suggest Stuxnet was intended for this purpose. Moreover, Iran denies its nuclear  programme is intended to develop weaponry.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Without wishing to scaremonger, the potential for  malicious use of Stuxnet is far greater if, as it is feared, criminal gangs have  gained access to the Stuxnet worm and are working on decrypting its  code.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;If they succeed in creating new variants of the worm,  who knows what systems they could attempt to gain control of? In theory, they  could gain access to ATM control systems and cause them to dispense all their  cash in one go. Great for passers-by, but not so good for the banks! At the  other extreme, they could bring a major manufacturer to its knees by sabotaging  its production lines, or hold a water company to ransom by blocking or diverting  supplies.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;But that would pale into insignificance if terrorist  groups were able to deploy Stuxnet. The impact and implications of a terrorist  gang gaining control of transport systems, particularly those that are fully  automated like the Docklands Light Railway in London, would be huge and could  result in mass fatalities. And what would be the outcome if they gained control  of a nuclear plant or weaponry systems?&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;That sounds  even scarier? Are we looking at Armageddon?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;It shouldn't come to that, but it does rely upon sense  prevailing.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;In terms of the way it works, Stuxnet is very  sophisticated and is likely to evolve, 'mutate' and proliferate. But the manner  in which it is deployed – the payload – is primitive by comparison. It primarily  relies upon connection of a USB device to a target computer, or a computer on  the same network, and is dependent upon being able to 'engineer' access to the  internet.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;So whilst its capacity for harm is great, its potential  could be greatly lessened by stringent and strictly enforced protocols. Indeed,  when it comes to the protection of key infrastructures like transport systems,  utilities provision and even systems underpinning financial institutions, it  could be argued that Governments should be laying down the law to the  organisations responsible for maintaining these infrastructures.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Given the manner in which Stuxnet is deployed and  functions, there are some basic preventative measures that should be  taken:&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpFirst align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Restrict or  block the use of USB devices on any critical control systems;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Ensure all  software patches are up-to-date;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Implement  regular monitoring for unusual network activity at user and access  levels;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Make sure IT  security applications are fully functioning and up-to-date; and&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpLast align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Do not allow  systems that control key processes to have access to the Internet, whether  directly or via gateways to other networks.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;We're not suggesting this will completely stop Stuxnet  in its tracks, but taking a common-sense approach to the problem should, at  least, limit its potential for harm and reduce its value to criminal gangs and  terrorist groups.&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-7135341162974099642?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/7135341162974099642/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/11/is-this-dawn-of-new-age-of-cyber.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/7135341162974099642'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/7135341162974099642'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/11/is-this-dawn-of-new-age-of-cyber.html' title='Is this the dawn of a new age of cyber-warfare, cyber-crime and cyber-terrorism?'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-2699338671975509359</id><published>2010-11-23T17:14:00.001Z</published><updated>2010-11-23T17:14:26.290Z</updated><title type='text'>Cutting costs, not corners?</title><content type='html'>&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Following on from the recent publication of its  forecasts for global IT expenditure, Gartner has released its predictions for  specific markets in 2011. It doesn't make particularly good reading for Europe,  the Middle East and Africa (EMEA).&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;The forecast for EMEA is a 1.3 per cent increase in  expenditure next year, but that comes off the back of an anticipated overall 2.1  per cent decrease this year. And for Western Europe, the story is even bleaker  with a 3.3 per cent decrease this year and only a compound annual growth of 0.8  per cent from 2010 to 2014.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;The biggest contributors to the decline in spending are,  not unexpectedly, local authorities and national Governments, which reduced  expenditure across the board by 2.8 per cent. Worst hit by this decrease was IT  services, which has suffered a 5.6 per cent drop. Conversely, hardware  expenditure increased by 4.6%. The applied logic is that businesses can justify  replacing out-dated and perhaps inefficient equipment but not expenditure on  outsourced services.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;In the short-term, it may make some sort of business  sense to invest in infrastructure, but over the years to come the money may have  been better spent on outsourced services. This could be particularly true for  local authorities and Government bodies. Indeed, if investment was focused upon  developing secure, reliable Cloud-based services for such organisations, costs  could be substantially reduced whilst delivering greater efficiency and a host  of benefits that 'stand alone' IT infrastructures simply could not  provide:&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpFirst align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Enhanced  security;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Ease of access  to information;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Specialist  support;&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpLast align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Opportunities  for platform independent collaboration.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Our recent blog, "&lt;I  style="mso-bidi-font-style: normal"&gt;What is The Cloud?" &lt;/I&gt;discusses the  benefits of Cloud-based services in more detail, as well as covering some points  to consider before entrusting your IT requirements to The Cloud. &lt;A  href="http://blog.securm.co.uk/2010/11/what-is-cloud.html"&gt;Read  more&lt;/A&gt;.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Whatever route public/Government bodies decide to take,  one has to hope that they do not lose focus on IT Security and ensure they have  made effective provision to protect data and infrastructure. Cutting costs is  one thing. Cutting corners is another!&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;No-one would wish to see a repeat of the problems faced  by the Royal Navy after its website was hacked. Nor would they want to see data  losses like that experienced by Stoke-on-Trent Council when an unencrypted USB  device, containing court reports and details of care proceedings relating to 40  children, was mislaid.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;In both cases, the simple things appear to have been  overlooked. We've said it before, and we'll say it again. Get the basics right  first, then enhance where appropriate.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;We've discussed these subjects before. If you've not had  an opportunity to read our blogs, why not click on the links below and take a  look?&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;I  style="mso-bidi-font-style: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;That Sinking  Feeling &lt;/FONT&gt;&lt;/I&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;– Royal Navy website hacked: &lt;A  href="http://blog.securm.co.uk/2010/11/that-sinking-feeling.html"&gt;Read  more&lt;/A&gt;.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;I  style="mso-bidi-font-style: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;To USB or not  to USB &lt;/FONT&gt;&lt;/I&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;– Sensitive data on USB devices:  &lt;A href="http://blog.securm.co.uk/2010/01/to-usb-or-to-not-usb.html"&gt;Read  more&lt;/A&gt;.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;I&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Data Security – Belt &amp;amp; Braces, not Bells &amp;amp;  Whistles&lt;/FONT&gt;&lt;/I&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;&lt;SPAN  style="mso-bidi-font-style: italic"&gt; – Getting the basics right first: &lt;/SPAN&gt;&lt;A  href="http://blog.securm.co.uk/2010/10/data-security-belt-braces-not-bells.html"&gt;&lt;SPAN  style="mso-bidi-font-style: italic"&gt;Read more&lt;/SPAN&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;SPAN  style="mso-bidi-font-style: italic"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-2699338671975509359?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/2699338671975509359/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/11/cutting-costs-not-corners.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/2699338671975509359'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/2699338671975509359'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/11/cutting-costs-not-corners.html' title='Cutting costs, not corners?'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-7697996057571415683</id><published>2010-11-19T11:19:00.001Z</published><updated>2010-11-19T11:19:57.618Z</updated><title type='text'>What is The Cloud?</title><content type='html'>&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Cloud computing is a new way of delivering IT services  over the Internet. It facilitates the sharing of resources, software and data,  and its biggest selling point is the fact it does away with the need for  businesses to invest heavily in IT infrastructure because everything can be  hosted off-site.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;The Cloud itself is made up of a vast array of  computers, servers and storage devices. This aspect is often referred to as 'the  back end'. 'The front end' is what the client or computer user sees –  network/PC/laptop and the applications used.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;More and more businesses are turning to The Cloud for  both data and infrastructure hosting. The primary drivers are:&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo2"  class=MsoListParagraphCxSpFirst align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Reduced costs;  and&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 36pt; mso-list: l1 level1 lfo2"  class=MsoListParagraphCxSpLast align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;The  simplification of IT as a service. &lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 12pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;But how could it benefit your business? What things  should you consider before becoming reliant upon The Cloud? And what does the  future hold for Cloud Computing?&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;How could it  benefit my business?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;As we've already mentioned, the primary benefit is  reduced expenditure on infrastructure and equipment. Not just in terms of  acquisition, but also on-going maintenance. In addition, businesses benefit from  the fact that applications and software can be accessed and utilised via The  Cloud, meaning no upfront purchase or high support costs. The only cost would be  a reduced licence fee.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Obviously every business is different, so you will need  to look at the possible short-term and long-term expenditure involved in a  Cloud-based solution against the cost of your own IT provision. But there are  other benefits that you simply will not get if you rely upon your own  infrastructure.&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Specialist support&lt;/FONT&gt;&lt;/B&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt; – when you sign up to services in The Cloud, whether  from a single provider or a series of providers, you should receive technical  support from IT technicians who are specialists in particular applications, as  opposed to generalists who have to spread their time and knowledge supporting  anything from SQL Server to specialised facets of an IT infrastructure. This too  can contribute to cost savings for businesses.&lt;/FONT&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Ease of access to information&lt;/FONT&gt;&lt;/B&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt; – You can get to your data wherever you are,  independently of the hardware used to host it. Additionally, because you will be  running applications and accessing data virtually, the devices you use to access  them will not need to be so highly specified, so you may find that that you will  not need to upgrade as frequently as technological advancement  dictates.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Security&lt;/FONT&gt;&lt;/B&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt; – Some  say you can't have secure data in the Cloud but, if you choose the right  provider with the right credentials, your data could be far more protected than  it would be on your own networks. Reputable providers use fully secure Data  Centres and employ high-level encryption for both the transfer and storage of  your data.&lt;/FONT&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;BR  style="mso-special-character: line-break"&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;And since your data never needs to  be loaded on to any PC, laptop or other device, if equipment is ever lost or  stolen you won't face potentially embarrassing data losses. With the disclosure  earlier this year that encryption codes for certain 'secure' USB devices were  vulnerable to hacking and may actually have been cracked – devices upon which  many government and financial organisations rely – this is another notable  security benefit. Why not take a look at our blog about USB encryption? Click &lt;A  href="http://blog.securm.co.uk/2010/01/to-usb-or-to-not-usb.html"&gt;here&lt;/A&gt;.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -17.85pt; MARGIN: 0cm 0cm 12pt 35.7pt; mso-list: l2 level1 lfo3; mso-add-space: auto"  class=MsoListParagraphCxSpLast align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Collaboration&lt;/FONT&gt;&lt;/B&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt; -  In addition to the financial and security benefits, The Cloud can offer  businesses great scope for collaborative working, independent of disparate and  incompatible systems.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Are there any  other benefits?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;What we've covered are some of the key benefits to  businesses. Wider benefits include the positive impact upon the  environment.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;A recent study commissioned by Microsoft found that  businesses running email, customer relationship and content sharing applications  on their own infrastructure could cut their computing carbon footprint by 30 per  cent or more just by moving operations to The Cloud.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;According to Microsoft, large data centres &lt;I  style="mso-bidi-font-style: normal"&gt;"…benefit from economies of scale and  operational efficiencies beyond what corporate IT departments can achieve.  Benefits become even more significant for a small business moving to the cloud,  where the net energy and carbon savings can be more than 90 per  cent&lt;/I&gt;".&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 12pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;To read the Microsoft press release, click &lt;A  href="http://www.microsoft.com/Presspass/press/2010/nov10/11-04CloudBenefitsPR.mspx?rss_fdn=Press%20Releases"&gt;here&lt;/A&gt;.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;What sort of  things do I need to consider?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;It would be impossible to cover everything you need to  think about utilising The Cloud, but we've covered some of the things we think  most important. In essence, they all linked back to ensuring the security of  your data and infrastructure.&lt;/FONT&gt;&lt;/P&gt; &lt;UL style="MARGIN-TOP: 0cm; MARGIN-BOTTOM: 0cm" type=disc&gt;   &lt;LI style="TEXT-ALIGN: justify; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT    style="FONT-SIZE: 11pt"&gt;Can you see the Data Centre?&lt;/FONT&gt;&lt;/B&gt;&lt;FONT    style="FONT-SIZE: 11pt"&gt; - Some of the best value providers of Cloud services    have UK Data Centres, so it's worth going to take a look at them. You can tell    a lot just by seeing the setup. If it consists of a couple of servers in a    dusty old broom cupboard, you'll know to steer clear!&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: justify; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT    style="FONT-SIZE: 11pt"&gt;Accreditation&lt;/FONT&gt;&lt;/B&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;    - Is the provider and/or Data Centre accredited to ISO 270001, the    international standard for information security management? More importantly    does the scope of accreditation cover the provision of Cloud-based services?    If not, look elsewhere.&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: justify; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT    style="FONT-SIZE: 11pt"&gt;Replication&lt;/FONT&gt;&lt;/B&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt; –    Does the provider replicate your data at another Data Centre, whether in the    UK or off-shore? A fall-back setup is a must.&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: justify; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT    style="FONT-SIZE: 11pt"&gt;Data Protection&lt;/FONT&gt;&lt;/B&gt;&lt;FONT    style="FONT-SIZE: 11pt"&gt; – If your data is to be held off-shore, particularly    if it is outside of the European Union, make sure you are absolutely clear    where you stand as far as your obligations under the Data Protection Act 1998    are concerned.&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: justify; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT    style="FONT-SIZE: 11pt"&gt;Encryption&lt;/FONT&gt;&lt;/B&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt; –    Is the data encrypted at all stages? That is during transfer to and from your    own systems and at point of storage. If data is to be transferred off-shore,    are you sure that you will not be in breach of the laws governing    encryption/cryptography in any of the jurisdictions through which your data is    routed or in which it is stored? Who controls the keys and where are they    backed up?&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: justify; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Backups – Who is responsible for    ensuring your data is backed up? Where are backups held (refer back to data    protection and encryption)? If it's all included in the service, is it an    individual document and incremental change level backup or a simple snapshot    backup? What can you afford and what suits your needs?&lt;/FONT&gt;    &lt;LI style="TEXT-ALIGN: justify; MARGIN: 0cm 0cm 6pt; mso-list: l0 level1 lfo1"    class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT    style="FONT-SIZE: 11pt"&gt;Fully managed&lt;/FONT&gt;&lt;/B&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;    – If you migrate data, infrastructure and backups to The Cloud, who manages    day-to-day operation? A fully managed service from a Cloud Provider should    mean greater security and that every glitch, flaw and problem is quickly    identified and addressed. But there are obviously cost implications? Establish    a balance that suits your requirements and budget.&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt; &lt;P  style="TEXT-INDENT: -17.85pt; MARGIN: 0cm 0cm 12pt 35.7pt; mso-list: l0 level1 lfo1"  class=MsoNormal align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Internet connection&lt;/FONT&gt;&lt;/B&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt; – Can you ensure you and your employees have unfettered  access to the Internet at all times? This is fundamentally important since  access to your data is wholly dependent upon Internet access.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;So what does  the future hold for Cloud Computing?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;We obviously don't have a crystal ball, so we can't  accurately predict the future for Cloud computing. But we can see it has the  potential to become the de facto IT solution for business, and we wouldn't be  surprised to see Governments around the world advocating, incentivising and even  prescribing its use in years to come, if only on the basis that it's greener and  can provide for greater security of data.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Indeed, as Cloud computing becomes ubiquitous we can  foresee Governments taxing businesses that operate their own, energy inefficient  IT infrastructure, perhaps levied according to carbon footprint. Steps might  also be taken to ensure Data Centres are subjected to regular assessment and  certification to ensure they meet defined standards that could even be enshrined  in law – in effect a Data Centre MOT.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;We would certainly like to see some form of regulation  introduced, or an 'industry standard' imposed. To our mind, regulation of the  use of The Cloud by UK businesses, and of Data Centres, by a UK Government  appointed body, backed by an enhanced ISO accreditation would be  preferable.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;The fact is that The Cloud will continue to evolve and  the benefits it can offer to businesses will become harder to ignore. The future  is bright. The future is Cloud-shaped!&lt;/FONT&gt;&lt;/P&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;DIV class=Section1&gt;&lt;STRONG&gt;&lt;FONT  color=#808080&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-7697996057571415683?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/7697996057571415683/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/11/what-is-cloud.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/7697996057571415683'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/7697996057571415683'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/11/what-is-cloud.html' title='What is The Cloud?'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-1412204359000303391</id><published>2010-11-16T15:47:00.001Z</published><updated>2010-11-16T15:47:55.605Z</updated><title type='text'>China Crisis? Part 2</title><content type='html'>&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 10pt"&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;In our last blog, we talked about the problem of  substandard goods from China and the potential impact they could have upon your  IT Security. This time, as promised, we're going to give our thoughts on how to  spot the 'dodgy' traders and avoid purchasing items that at best are poor  quality and at worst pose a danger to you and your business.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Moreover, it's not just a problem of the quality of  goods but also of whose pockets are being lined by their sale. In a recent  statement, Crimestoppers in the UK warned shoppers against buying counterfeit  goods because their sale can help finance serious organised crime.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;The Crimestoppers Chairman, Lord Michael Ashcroft, said,  "Christmas is a time when many are trying to find ways to reduce costs. I would  urge the public not to be tempted to buy cheap fake goods. The consequences are  far wider than the simple transaction. It can fund serious crimes such as human  trafficking."&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;In this context, the goods in question range from  cigarettes to DVDs and electronic items.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;So is it easy  to spot these goods?&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;Not always, and as we said last time there's the  distinction between straight counterfeit goods and those that are 'look-alikes',  not that this necessarily makes a difference to the quality of goods or where  the money ends up.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;There really isn't a 'scientific' way to identify the  dodgy traders or the substandard goods. Gone are the days of spotting a shady  figure dealing CDs, DVDs and perfume out of suitcases at markets and on the high  street. Nowadays there's an international virtual marketplace open to everyone  and you are bombarded with what appear to be great deals from an array of  apparently genuine traders.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 12pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;First and foremost, remember the old adage, "If it seems  too good to be true, it probably is." If that doesn't sway you, look out for  what we think are some of the clever 'tricks of the trade' used in online  auction sites and marketplaces.&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpFirst align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Clever wording  – &lt;I style="mso-bidi-font-style: normal"&gt;Genuine Replacement Part&lt;B  style="mso-bidi-font-weight: normal"&gt; &lt;/B&gt;&lt;/I&gt;is something you see quite  regularly, often with a picture of a genuine item or a picture bearing a  manufacturer's logo. Laptop and mobile phone chargers are favourites for this.  The price is frequently less than half that of the cost of a genuine  manufacture's replacement item and you're unlikely to receive an item that is  branded or endorsed by the manufacturer. But you've bought a replacement part  that is, genuinely, a replacement part! Argue your way out of that!&lt;/FONT&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpFirst align=justify&gt;&amp;nbsp;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Volume sales  and high feedback scores – Based upon anecdotal evidence, there is much to  suggest that certain traders sell high quantities of low value goods to each  other (or even to fake accounts) to build up their feedback scores. The accounts  with high feedback are then used to sell on the higher value and volume goods.  Obviously, the difficulty here is that there will be a lot of reputable sellers  with genuinely high feedback and we don't want to tar them with the same brush.  It's a case of taking into account everything else about the particular item and  seller – where are they based? How is the item described? Is the price too good  to be true?&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;If you're not sure, it's worth  taking a look at the feedback a seller has received. Is it for the same type of  goods as you want to buy? Have they built up high feedback over a matter of  weeks or even days? Is feedback received on the same day an item ended? Does the  feedback actually correspond to a genuine sale? Is there exchange of feedback  between different accounts?&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;In some cases you'll see the sellers  gain their feedback buying 1 penny lists. Their positive feedback is actually as  a buyer, not as a seller.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;UK Seller –  Often the seller is at great pains to point out they are UK-based, sometimes  with words like &lt;I style="mso-bidi-font-style: normal"&gt;Genuine UK Seller &lt;/I&gt;or  a UK flag emblazoned across the photos of items for sale, but provides no  specific location in the item listing. On certain auction sites and online  marketplaces, you can check the seller's location in their profile. You'd be  surprised how many sellers featuring a UK flag are located in China!&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Another 'giveaway' is the inclusion  of UK in the seller's name, e.g. Cheap_Chargers_UK. It's definitely worth  checking their profile if you see something like that.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;8 letter/digit  seller names – one eBay user who was scammed identified that many of the sellers  of dodgy Chinese goods have random 8 character usernames – e.g.  dd8tywer.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Seller in one  location, goods in another – In some cases sellers appear to be based in one  country, but the items are dispatched from another, e.g. seller in the  Netherlands and item in Ireland. Ask yourself why that would be.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraphCxSpMiddle  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=MsoListParagraphCxSpMiddle align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Extremely low  &lt;I style="mso-bidi-font-style: normal"&gt;Buy Now&lt;/I&gt; price – If the item is  genuine, why would someone try to sell it at a ludicrously low price?&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt 36pt" class=MsoListParagraphCxSpLast  align=justify&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;B  style="mso-bidi-font-weight: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;It sounds  like hard work. Surely there's an easier way.&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;It's a minefield at the best of times. If you really  start to look into it you could spend hours trying to spot the good from the bad  and never be quite sure if you'd got it right.&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;As we said right at the end of the last blog, steer  clear of auction sites and online marketplaces, particularly when it comes to  buying electrical and IT equipment for your business. We cannot stress  enough:&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=MsoNormal align=justify&gt;&lt;I  style="mso-bidi-font-style: normal"&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;When it comes  to equipment upon which your business is effectively reliant for stability,  functionality and security, our best advice is to only buy through established  and reputable suppliers, whether on the high street or  online.&lt;/FONT&gt;&lt;/I&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-1412204359000303391?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/1412204359000303391/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/11/china-crisis-part-2.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/1412204359000303391'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/1412204359000303391'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/11/china-crisis-part-2.html' title='China Crisis? Part 2'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-4914828218119880064</id><published>2010-11-12T20:29:00.002Z</published><updated>2010-11-12T20:41:32.596Z</updated><title type='text'>China Crisis?</title><content type='html'>&lt;div dir="ltr"&gt;&lt;div style="color: black; font-family: 'Trebuchet MS'; font-size: 10pt;"&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;With the Prime Minister and a 'UK trade delegation'  having recently paid a visit to China to forge economic and business links, we  thought we'd take a look at some of the pros &amp;amp; cons of Chinese trade. Not a  topic that has an obvious link to IT security, you would think, but you might be  surprised.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;a href="http://1.bp.blogspot.com/_QqJuA7XTtKA/TN2mYR2POtI/AAAAAAAAACQ/-5oIIGrUWdc/s1600/china_flag.JPG" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="149" src="http://1.bp.blogspot.com/_QqJuA7XTtKA/TN2mYR2POtI/AAAAAAAAACQ/-5oIIGrUWdc/s200/china_flag.JPG" width="200" /&gt;&lt;/a&gt;&lt;span style="font-size: 11pt;"&gt;China is now recognised as the second largest economy in  the world and it is still growing. As a manufacturing nation it is very much in  its infancy, but the proliferation of factories producing anything from clothing  to 'high-end' electrical and computer equipment is phenomenal.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;The plus side is that, for UK companies seeking quality  goods at rock-bottom prices, China can often prove to be a land of opportunity;  and consumers benefit from cheaper goods on the High Street.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Most of us can probably list the negatives that are  widely reported and discussed. These include:&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpFirst" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Difficulties  faced by many companies when doing business in China - often as a result of  ignorance of the languages, laws and customs of the land; but sometimes through  falling prey to conmen capitalising on China's new world status;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Loss of UK  manufacturing jobs; and&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpLast" style="margin: 0cm 0cm 6pt 35.7pt; text-indent: -17.85pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;Reported poor,  even inhuman, working conditions in many of the factories.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;We're not going to dwell on these issues. They're for  another discussion. However, regarding the latter, the Chinese Government spoke  out on 8&lt;sup&gt;th&lt;/sup&gt; November saying that China should not be judged by Western  standards. Arguably it has a point.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;What we really want to talk about is the huge growth in  sales of grey and black market goods, particularly electrical items and computer  equipment. These items are usually either look-alike items (grey market) or  straight counterfeits (black-market).&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Take a look at any auction site or online marketplace  and you will see all manner of goods, all at a fraction of the cost of what you  might pay for a branded item. From MP3 players that look like iPods (and  purportedly function like them) to mobile phone &amp;amp; laptop chargers; and from  computer memory to residual current devices (RCDs). It's tempting to opt for  these items because they are so cheap. They seem like a real bargain. And they  would be…if you were getting an item of equivalent quality and functionality as  the branded item.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;What makes things worse is that the accompanying blurb  often says all the right things and the items may carry applicable mandatory  'safety marks' for the jurisdiction in which they are sold, like the CE mark in  Europe. Unfortunately the marks are often not genuine.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;These are generally grey market goods and, sadly, you  will often regret your decision to purchase. Hopefully this regret will only be  born out of disappointment that the item doesn't work quite as well as you'd  hoped.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;But spare a thought for those who come to regret their  decision as a result of a spectacular failure of the item purchased.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpFirst" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;The exploding  RCDs that were featured on TV. RCDs being the very devices you are reliant upon  to protect from electrical surge and electric shock;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;The laptop  charger that produced an amperage three times higher than its stated rating,  thus damaging the charging circuit and battery of the laptop;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;The 4GB MP3  players that when tested could cope with little more than 300MB of data and  contained malware to boot; and&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpLast" style="margin: 0cm 0cm 6pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;The computer  memory that caused a BIOS failure and the shutdown of a key server on a  network.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;The really worrying thing is that IT technicians and  electricians are just as capable of being duped as the rest of us. The  opportunity to keep costs down by purchasing items that appear genuine branded  products, or just as good as them, at knockdown prices is not one to be sniffed  at. It's just that the goods aren't necessarily always what they seem. So you  could be unwittingly purchasing substandard and unsafe items from somebody who  purchased them in good faith.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Add to this the fact there are numerous reports and much  anecdotal evidence to suggest the sale of such goods supports organised crime,  perhaps even terrorism, and the problem is compounded even further. Action  really needs to be taken to stamp out this insidious trade. The most effective  action would be to stop it at source and close down the factories producing  these goods, which is something that should fall to the Chinese  Authorities.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 12pt;"&gt;&lt;span style="font-size: 11pt;"&gt;If they fail to act, maybe then they should expect to be  judged by Western standards.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;So where does  IT security feature in all of this?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;If you buy and install substandard IT equipment and  electrical items for your business systems, the savings you make at point of  purchase could be written off multi-fold if systems fail and data is lost as a  result of their use.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Earlier in this blog we touched upon some examples of  how shoddy goods had caused problems for unwitting buyers. Imagine them in the  context of your business for a moment; and consider the potentially devastating  outcomes.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpFirst" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;What would  happen if the RCDs in your server/communications room failed or, worse still,  exploded?&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;What sort of  damage could be caused if replacement mains chargers for laptops either surged  or caught fire?&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpMiddle" style="margin: 0cm 0cm 0pt 36pt; text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;If a USB device  containing sophisticated malware, viruses and key-loggers was connected to a  laptop, PC or server on your network, would you and/or your business's IT  security features be able to respond quickly enough to stop any harm to your  systems? Even if you could, you'd be spending valuable time dealing with  something that should never have been allowed to happen in the first  place.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoListParagraphCxSpLast" style="margin: 0cm 0cm 6pt 35.7pt; text-indent: -17.85pt;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font-size: 11pt;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 11pt;"&gt;You've just  installed RAM to speed up your server. The online merchant described it as top  quality and based upon a recognised brand name, but it's actually poorly  manufactured, unstable and its capacity is less than a quarter of what was  claimed. At best your server will operate less efficiently than you had hoped.  At worst?&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 12pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Any of the disasters resulting from such situations  could have a major impact upon your IT systems and thus upon your IT security.  It's really not our intention to scaremonger, but this is a real and present  threat.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;How do I  avoid substandard electrical and IT equipment?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 12pt;"&gt;&lt;span style="font-size: 11pt;"&gt;It's not always easy to identify the good from the bad,  especially when shopping online. The bottom line is that online auction sites  and marketplaces might serve a purpose if you just want cheap and cheerful items  for personal use. But when it comes to equipment upon which your business is  effectively reliant for stability, functionality and security, our best advice  is to only buy through established and reputable suppliers, whether on the high  street or online.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Is there a  way of spotting the 'dodgy' suppliers?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Yes, but we'll cover that in the next blog…&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;To be continued.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-4914828218119880064?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/4914828218119880064/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/11/china-crisis.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/4914828218119880064'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/4914828218119880064'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/11/china-crisis.html' title='China Crisis?'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_QqJuA7XTtKA/TN2mYR2POtI/AAAAAAAAACQ/-5oIIGrUWdc/s72-c/china_flag.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-3480122298374412499</id><published>2010-11-09T19:47:00.003Z</published><updated>2010-11-12T17:15:42.307Z</updated><title type='text'>That sinking feeling?</title><content type='html'>&lt;div dir="ltr"&gt;&lt;div style="color: black; font-family: 'Trebuchet MS'; font-size: 10pt;"&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;On Friday 5&lt;sup&gt;th&lt;/sup&gt; November 2010, the Royal Navy  shut down its website after it was compromised by a Romanian hacker. As at 19:00  today, 9&lt;sup&gt;th&lt;/sup&gt; November, the website is still unavailable and is  displaying a message about essential maintenance.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;What exactly  happened?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Unsurprisingly, the Royal Navy is staying tight-lipped,  but it seems a hacker, known as TinKode, identified a vulnerability in the  website and used a method known as SQL injection to compromise it. The hacker  reportedly gained access to the login details of site administrators and users  and published them via a link posted on Twitter.&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_QqJuA7XTtKA/TNpxyfti-NI/AAAAAAAAACM/QX-wQrUZOHA/s1600/Navy+Site.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="268" src="http://1.bp.blogspot.com/_QqJuA7XTtKA/TNpxyfti-NI/AAAAAAAAACM/QX-wQrUZOHA/s320/Navy+Site.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 12pt;"&gt;&lt;span style="font-size: 11pt;"&gt;The Royal Navy has strongly refuted any assertion that  classified information has been accessed and stated there has been no malicious  damage.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;That's a bit  worrying, isn't it?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;It is a concern, particularly given the type of  vulnerability believed to have been exploited – a known flaw in an internet  bulletin board site identified in July, which the software provider is said to  have since patched.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 12pt;"&gt;&lt;span style="font-size: 11pt;"&gt;It appears TinKode may have realised the Royal Navy had  been remiss in not ensuring the most up-to-date bulletin board software was  installed and took advantage of this fact.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;So what  should the Royal Navy have done?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 12pt;"&gt;&lt;span style="font-size: 11pt;"&gt;It is essential that any methods by which a site user  can enter information are checked for vulnerabilities before going live and any  updates applied as soon as they are available. Rigorous testing and a patch  management program (as a minimum) enforced by dedicated IT security specialists  would have helped guard against this attack.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Will this  have significant ramifications?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;The Royal Navy may have got off lightly. At this stage,  there does not appear to have been any major harm inflicted upon the site.  Perhaps it's lucky that the hacker in question is a "self-confessed security  enthusiast" whose motive was mischief and not malice. If malice had been behind  the attack things could have been far worse.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;What should also be borne in mind is that the site in  question is essentially a marketing vehicle for the Royal Navy and not a  critical operational site. It still doesn't excuse the situation  though.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 12pt;"&gt;&lt;span style="font-size: 11pt;"&gt;The most notable result of this attack is the  embarrassment caused. Not just to the Royal Navy but also to the Government,  which recently announced it was treating cyber defence as key element of  national security and would make an additional £500 million available to bolster  it.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;b&gt;&lt;span style="font-size: 11pt;"&gt;Additional  funding! That's good, isn't it?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Yes and no.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Arguably, the Royal Navy got the basics wrong. It goes  back to the opinion we put forward in our blog entitled &lt;i&gt;Data Security – Belt &amp;amp; Braces, not Bells  &amp;amp; Whistles&lt;/i&gt;; you have to get the basics right before you build upon them.  There's no point throwing money at something that is fundamentally flawed. It  would be a waste of valuable funding and, in this case, could potentially just  serve to fill the coffers of the larger technology consulting  companies.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify" class="MsoNormal" style="margin: 0cm 0cm 6pt;"&gt;&lt;span style="font-size: 11pt;"&gt;Focusing upon improving security of key technologies and  websites 'from the ground up' is the best approach and would be the most  effective use of the additional funding.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-3480122298374412499?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/3480122298374412499/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/11/that-sinking-feeling.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/3480122298374412499'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/3480122298374412499'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/11/that-sinking-feeling.html' title='That sinking feeling?'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_QqJuA7XTtKA/TNpxyfti-NI/AAAAAAAAACM/QX-wQrUZOHA/s72-c/Navy+Site.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-7853411226783182196</id><published>2010-11-03T20:58:00.003Z</published><updated>2010-11-03T21:14:25.772Z</updated><title type='text'>Is the ICO’s bark worse than its bite?</title><content type='html'>&lt;div dir="ltr"&gt;&lt;div style="color: black; font-family: 'Calibri'; font-size: 12pt;"&gt;&lt;div&gt;In April of this year, the Information Commissioner's Office (ICO) was  empowered to impose fines of up to £500,000 for serious breaches of data  security and the Data Protection Act (DPA) 1998. It seemed that data security  was going to have a real champion at last.&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://4.bp.blogspot.com/_QqJuA7XTtKA/TNHO5VUsVSI/AAAAAAAAACE/CYQvE-_dmgc/s1600/ico_logo.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="110" src="http://4.bp.blogspot.com/_QqJuA7XTtKA/TNHO5VUsVSI/AAAAAAAAACE/CYQvE-_dmgc/s200/ico_logo.gif" width="200" /&gt;&lt;/a&gt;Fast forward to 3rd November 2010 and one wonders whether the ICO has  simply been posturing since it was given these powers.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Why, what's happened?&lt;/b&gt;&lt;/div&gt;&lt;div&gt;You may have read that Google was brought to task earlier this year over  the interception of Wi-Fi data as it recorded images for Street View. In June it  faced questions from US congress about allegations it had carried out such  actions in over 30 countries! In August, it was cleared by the ICO in the UK  because initial investigations revealed that only fragments of data had been  'harvested'.&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://2.bp.blogspot.com/_QqJuA7XTtKA/TNHPojvhicI/AAAAAAAAACI/yew99kXI8Ts/s1600/google.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="100" src="http://2.bp.blogspot.com/_QqJuA7XTtKA/TNHPojvhicI/AAAAAAAAACI/yew99kXI8Ts/s200/google.jpg" width="200" /&gt;&lt;/a&gt;Well, subsequent investigations by 'various international privacy bodies'  established that the data acquired was, in some cases, far more detailed than  first thought. In fact, evidence was found that the data captured actually  contained complete emails, URLs visited and passwords. So, not the 'fragmentary  data' first described.&lt;/div&gt;&lt;div&gt;As a result, the ICO announced a further investigation, which was widely  reported on 2nd and 25th October. Authorities in some of the other 30 countries  also launched new investigations.&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Well that's good, isn't it?&lt;/b&gt;&lt;/div&gt;&lt;div&gt;It's good that the ICO decided to revisit the matter, but the speed and  outcome of this new investigation are rather disappointing. On 3rd November it  was reported that Google had effectively received a slap on the wrist from the  ICO and will avoid a fine simply by apologising and signing an undertaking that  it won't happen again.&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;At least Google has accepted responsibility.&lt;/b&gt;&lt;/div&gt;&lt;div&gt;Yes, but here was an ideal opportunity for the ICO to flex its muscle and  demonstrate it really does have teeth. Whilst there is no doubt the organisation  has worked hard to put data security breaches under the spotlight in the past  few months, it has yet to hand down a fine for such a breach since being given  its new powers in April. Hence the title of this blog!&lt;/div&gt;&lt;div&gt;There's also the fact it again raises concerns for businesses about the use  of unsecured Wi-Fi networks.&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;What concerns?&lt;/b&gt;&lt;/div&gt;&lt;div&gt;It might be argued that at least it was Google that captured the data and  not a criminal gang. But of course, we only know about the Google issue because  the company was forced to disclose it. Who knows the extent of data that could  be being captured with malicious intent?&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;If your employees use laptops or handheld devices over Wi-Fi networks that  are not secured, they could be inadvertently making business sensitive data  available to unauthorised individuals. It's well worth reviewing the security of  such devices and your organisations' policies and procedures for ensuring the  security of data held on them.&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-7853411226783182196?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/7853411226783182196/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/11/is-icos-bark-worse-than-its-bite.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/7853411226783182196'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/7853411226783182196'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/11/is-icos-bark-worse-than-its-bite.html' title='Is the ICO’s bark worse than its bite?'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_QqJuA7XTtKA/TNHO5VUsVSI/AAAAAAAAACE/CYQvE-_dmgc/s72-c/ico_logo.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-8259967748166586713</id><published>2010-11-02T13:41:00.002Z</published><updated>2010-11-02T14:55:20.870Z</updated><title type='text'>Latest Facebook privacy issues – a concern for businesses?</title><content type='html'>&lt;div dir="ltr"&gt;&lt;div style="color: black; font-family: 'Trebuchet MS'; font-size: 12pt;"&gt;&lt;div&gt;&lt;span style="font-family: Calibri;"&gt;Yet again, Facebook has been found wanting when it comes  to ensuring the privacy of its users. In short, settings intended to allow users  to limit or block access to their profiles can be easily bypassed.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_QqJuA7XTtKA/TNAmHWotInI/AAAAAAAAAB8/1cubGDg6c9k/s1600/facebook-logo.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://1.bp.blogspot.com/_QqJuA7XTtKA/TNAmHWotInI/AAAAAAAAAB8/1cubGDg6c9k/s200/facebook-logo.png" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family: Calibri;"&gt;Amongst other things, it means that even 'private  profiles' are viewable by someone browsing lists of friends that include these  profiles. So all the information intended only for the eyes of a selected group  of friends is suddenly available to any visitor to Facebook.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b&gt;So what has this got to do with the security of  data in my organisation?&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family: Calibri;"&gt;On the face of it, you might argue it is of more concern  to the individuals who have profiles on Facebook that they thought were only  viewable by people they had accepted as friends.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family: Calibri;"&gt;The trouble for businesses is that Facebook (and many of  the other online networking resources) can be an ideal resource for socially  engineering ways around data security measures. The more personal information  that's available about an organisation's employees online, the less work the  'cybercriminals' often have to do.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b&gt;My organisation blocks the use of social  networking sites at work, so there's no problem is there?&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family: Calibri;"&gt;Blocking social networking sites helps but,  unfortunately, it's no guarantee of protection from attack. Your employees will  still use them at home and possibly on their mobile phones. They may provide  information about their families, their jobs, their birthdays and lots more. And  even if they've taken steps to make their profiles private, the latest reports  tell us these steps don't actually guarantee privacy!&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family: Calibri;"&gt;This means that somebody looking to penetrate your IT  systems may simply have to set up a fake user profile on Facebook, perhaps  saying they once worked for your organisation or, if your organisation is large  enough, that they still do! They'll then start trying to identify people who  work for your organisation and start "friending" and building up the trust of  their new found friends.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b&gt;What will these hackers  do?&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family: Calibri;"&gt;They may simply harvest data that gives clues as to  passwords or security questions and then attempt to gain access to your systems.  But the more sophisticated hackers could employ cross-scripting bugs on your  website and generate a secured web page that looks as if it is a legitimate part  of your site.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family: Calibri;"&gt;In one stated case, a link to such a web page was posted  on a fake user profile after only three days of "friending". The comment with  the link stated the organisation's systems may have been hacked and that  employees should log on to the secure page to verify and reactivate their  credentials.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family: Calibri;"&gt;The hackers gained credentials that could have given  them access to all network systems. Luckily for the organisation in question,  the hackers were IT security experts and the activity was all part of an  authorised penetration test.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b&gt;So what steps can I take to avoid these  problems?&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family: Calibri;"&gt;An authorised penetration test, including social  engineering, is something you should at least consider. It will help to scope  any problems your organisation may face and make recommendations about how to  address them. You can then review your policies and procedures.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family: Calibri;"&gt;But essentially it's a training and awareness issue. You  need &lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;to educate your employees and emphasise their  responsibilities. Through focused training – short courses, online training,  etc. - you can explain the importance of IT and data security and heighten  awareness. Above all, whilst &lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;social networking is an  obvious threat, the greatest imperative is to ensure your employees understand  why they should never give up security credentials or business sensitive  information to any 'unauthorised' person, in &lt;b&gt;any&lt;/b&gt;  circumstances.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family: Calibri;"&gt;If you can engender a culture of IT and data security  amongst your employees, with systems &amp;amp; policies in place that they  understand and "buy in to" you'll have won the biggest part of your  battle.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-8259967748166586713?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/8259967748166586713/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/11/latest-facebook-privacy-issues-concern.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/8259967748166586713'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/8259967748166586713'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/11/latest-facebook-privacy-issues-concern.html' title='Latest Facebook privacy issues – a concern for businesses?'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_QqJuA7XTtKA/TNAmHWotInI/AAAAAAAAAB8/1cubGDg6c9k/s72-c/facebook-logo.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-5526168236583227229</id><published>2010-10-30T08:50:00.001+01:00</published><updated>2010-10-30T08:50:58.492+01:00</updated><title type='text'>An extra hour in bed?</title><content type='html'>&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 12pt"&gt; &lt;P style="LINE-HEIGHT: 14pt"&gt;&lt;FONT color=#333333&gt;&lt;FONT face=Calibri&gt;Yes, we know  it has nothing to do with Security but we thought we'd remind you  anyway.&lt;BR&gt;&lt;BR&gt;As of tomorrow, Sunday 31st of October, at 2 a.m. all clocks in  the UK go back one hour.&lt;BR&gt;&lt;BR&gt;Also, have a great Halloween.&lt;BR&gt;&lt;BR&gt;The Securm  Team&lt;BR&gt;&lt;BR&gt;0800 612 4074&lt;/FONT&gt;&lt;/FONT&gt;&lt;BR&gt;&lt;A  href="http://www.securm.co.uk"&gt;&lt;FONT color=#2c68a6&gt;&lt;FONT  face=Calibri&gt;http://www.securm.co.uk&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;BR&gt;&lt;/P&gt;&lt;IMG border=0  alt=""  src="http://gallery.mailchimp.com/19dd068224a6e0b03fe6a607b/images/clock.png"  width=273 height=263&gt;&lt;BR&gt;&lt;IMG border=0 alt=""  src="http://gallery.mailchimp.com/19dd068224a6e0b03fe6a607b/images/loggo.jpg"  width=285 height=89&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-5526168236583227229?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/5526168236583227229/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/10/extra-hour-in-bed.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/5526168236583227229'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/5526168236583227229'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/10/extra-hour-in-bed.html' title='An extra hour in bed?'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-5696148523669581317</id><published>2010-10-28T12:10:00.002+01:00</published><updated>2010-10-29T17:15:11.467+01:00</updated><title type='text'>Data Security – belt &amp; braces, not bells &amp; whistles.</title><content type='html'>&lt;div dir=ltr&gt;&lt;div style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 12pt"&gt;&lt;div  style="FONT-STYLE: normal; DISPLAY: inline; FONT-FAMILY: 'Calibri'; COLOR: #000000; FONT-SIZE: small; FONT-WEIGHT: normal; TEXT-DECORATION: none"&gt;&lt;div  style="FONT-STYLE: normal; DISPLAY: inline; FONT-FAMILY: 'Calibri'; COLOR: #000000; FONT-SIZE: small; FONT-WEIGHT: normal; TEXT-DECORATION: none"&gt;&lt;div dir=ltr&gt;&lt;div style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 12pt"&gt;&lt;div dir=ltr&gt;&lt;div style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 12pt"&gt;&lt;div&gt;&lt;font face=Calibri&gt;There is a lot written about data security these days.  It's a hot topic and it will remain so as long as data breaches and resulting  fines continue. An example is the recently publicised Zurich Insurance data  loss.&lt;strong&gt;&lt;font size=4&gt;*&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;div&gt;&lt;font face=Calibri&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;&lt;div&gt;&lt;font face=Calibri&gt;The Information Commissioner's Office is responsible for  enforcing the Data Protection Act 1998 and has the power to fine companies up to  £500,000 for serious data security breaches. It can also pursue criminal action  against directors of companies responsible for such breaches. Whilst either is  bad enough in itself, the damage to reputation and integrity could ultimately  harm your company more. And for regulated financial companies, like Zurich,  there is also the prospect of fines and censure by the Financial Services  Authority (FSA).&lt;/FONT&gt;&lt;/DIV&gt;&lt;div&gt;&lt;font face=Calibri&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;&lt;div&gt;&lt;font face=Calibri&gt;Data security is paramount, but it needn't be  complicated or unnecessarily expensive. It's primarily about adopting a common  sense approach and implementing robust policies and procedures. Most  importantly, you need to ensure all members of staff are aware of these policies  and procedures and understand the importance of keeping data secure. After all,  of the recently reported data security breaches the majority have resulted from  some form of human error and / or the failure to implement even the most  rudimentary protective measures.&lt;/FONT&gt;&lt;/DIV&gt;&lt;div&gt;&lt;font face=Calibri&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;&lt;div&gt;&lt;font face=Calibri&gt;Once you have the basics in place, you can reinforce  your systems with other measures. But just make sure what you are buying into is  really what you need, and don't overcomplicate things. Identify what works for  your company and look for 'belt &amp;amp; braces', not 'bells &amp;amp;  whistles'.&lt;/FONT&gt;&lt;/DIV&gt;&lt;div&gt;&lt;font face=Calibri&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;&lt;div&gt;&lt;font face=Calibri&gt;If you're not sure where to start, it would be worth  engaging the services of an expert information security consultancy company.  They can identify where your current systems and processes are vulnerable; provide  advice and guidance about how to test your systems; help you implement enhanced  security solutions; and even handle the secure destruction of data and the  disposal of old IT equipment.&lt;/FONT&gt;&lt;/DIV&gt;&lt;div&gt;&lt;font face=Calibri&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;&lt;div&gt;&lt;font face=Calibri&gt;Although many see the latter as a minor concern in  comparison to other data security issues, the point at which data is no longer  required and/or is held on obsolete IT equipment can be one of the most  vulnerable stages of its lifecycle within an organisation. Many companies simply  stockpile obsolete IT equipment because they know the risks of insecure disposal  but are not aware of methods for secure destruction of data.&lt;/FONT&gt;&lt;/DIV&gt;&lt;div&gt;&lt;font face=Calibri&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;&lt;div&gt;&lt;font face=Calibri&gt;Whilst taking a hammer to hard drives or memory sticks  may seem like a good idea, it simply isn't a viable solution to the problem and  carries with it other implications, not least a potential failure to comply with  the prevailing Waste Electrical and Electronic Equipment (WEEE) regulations.  Yes, even hard drives and portable media devices are covered by these  regulations!&lt;/FONT&gt;&lt;/DIV&gt;&lt;div&gt;&lt;font face=Calibri&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;&lt;div&gt;&lt;font face=Calibri&gt;As mentioned earlier, an expert company will guide you  through the data security maze and help you to identify and implement the right  solutions for your company. &lt;/FONT&gt;&lt;/DIV&gt;&lt;div&gt;&lt;font face=Calibri&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;&lt;div&gt;&lt;font face=Calibri&gt;In summary:&lt;/FONT&gt;&lt;/DIV&gt;&lt;ul&gt;&lt;li&gt;&lt;font face=Calibri&gt;Take care of the basics of data security first;&lt;/FONT&gt;&lt;br /&gt;&lt;li&gt;&lt;font face=Calibri&gt;Implement robust policies and procedures;&lt;/FONT&gt;&lt;br /&gt;&lt;li&gt;&lt;font face=Calibri&gt;Educate members of staff and ensure they understand the    importance of data security;&lt;/FONT&gt;&lt;br /&gt;&lt;li&gt;&lt;font face=Calibri&gt;Be selective about what technical solutions you    implement;&lt;/FONT&gt;&lt;br /&gt;&lt;li&gt;&lt;font face=Calibri&gt;If you are unsure, seek the help of information    security experts; and&lt;/FONT&gt;&lt;br /&gt;&lt;li&gt;&lt;font face=Calibri&gt;Never forget, you are responsible for your company data    from acquisition to destruction.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;div&gt;&lt;font size=4 face=Calibri&gt;* &lt;span  style="LINE-HEIGHT: 13pt; FONT-FAMILY: ; mso-bidi-font-family: 'Times New Roman'; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi; mso-fareast-language: en-us; mso-ansi-language: en-gb; mso-bidi-language: ar-sa"&gt;&lt;font  style="FONT-SIZE: 11pt"&gt;In August 2010 the Financial Services Authority found  Zurich Insurance had failed to ensure the security of customers' confidential  information, held on an unencrypted backup tape that was lost. The FSA decided  that whilst there was nothing to suggest any data had been compromised or  misused, the loss of 46,000 confidential records warranted a fine of  £2.275m.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-5696148523669581317?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/5696148523669581317/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/10/data-security-belt-braces-not-bells.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/5696148523669581317'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/5696148523669581317'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/10/data-security-belt-braces-not-bells.html' title='Data Security – belt &amp; braces, not bells &amp; whistles.'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-141942185117526941</id><published>2010-10-26T16:30:00.001+01:00</published><updated>2010-10-26T16:39:45.245+01:00</updated><title type='text'>It’s the FSA’s loss…</title><content type='html'>&lt;div dir="ltr"&gt;&lt;div&gt;On 18th October 2010, &lt;i&gt;Citywire&lt;/i&gt; reported that in the past three  years the Financial Services Authority (FSA) has lost 41 hardware items,  including laptops, Blackberries and memory sticks. Of these, only 11 were  reported as stolen. The rest were lost by FSA staff. This all came to light as  the result of a Freedom of Information request by  &lt;i&gt;Citywire&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;Drilling down further into the figures reveals that in  2010 alone, the FSA has reported 10 laptops, 7 Blackberries and 2 USB memory  sticks lost or stolen. In 2009, 8 laptops and 10 Blackberries were lost, whilst  in 2008 it was 2 laptops and 2 Blackberries.&lt;br /&gt;&lt;br /&gt;It should be pointed out  that the FSA did have generally effective security measures in place. All the  laptops and memory sticks were encrypted and the Blackberries were password  protected. As an additional measure, the FSA claimed, it had remotely disabled  the hardware in order to block further access to secure  information.&lt;br /&gt;&lt;br /&gt;There has been nothing so far to suggest any data has been  compromised or misused, but if the FSA is judged by its own standards it should  face some form of censure. Here are two examples of hefty fines it handed down  for failure to ensure data security:&lt;/div&gt;&lt;ol&gt;&lt;li&gt;In 2007, Nationwide Building Society was fined £980,000 when it was    discovered that a laptop, stolen from an employee's home, held confidential    customer information. The Society was not initially aware that such data was    held on the laptop and did not investigate the matter until three weeks after    the theft. The FSA found that Nationwide had failed to put in place "…adequate    information security procedures and controls…"&lt;br /&gt;&lt;/li&gt;&lt;li&gt;In August 2010 the FSA found Zurich Insurance had failed to ensure the    security of customers' confidential information, held on an unencrypted backup    tape that was lost. The FSA decided that whilst there was &lt;u&gt;nothing to    suggest any data had been compromised or misused&lt;/u&gt;, the loss of 46,000    confidential records warranted a fine of £2.275m.&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;Maybe it's too soon after the disclosure, but nothing has yet been said  about potential action against the FSA for these losses, which raises the  obvious question of who is policing the regulator. Perhaps the task will fall to  The Information Commissioner's Office, the body responsible for enforcing the  Data Protection Act 1998. It has the power to impose fines of up to £500,000 for  serious data security breaches.  Only time will tell what, if anything,  will be done.  NB: It is worthy of note that however bad the FSA losses  sound, they pale into insignificance when compared to the Ministry of Defence  losses for the last two years – 220 laptops lost and 120 stolen. Worst of all,  less than half of the lost laptops were encrypted according to a Freedom of  Information request by a firm of technology  consultants.&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-141942185117526941?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/141942185117526941/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/10/its-fsas-loss.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/141942185117526941'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/141942185117526941'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/10/its-fsas-loss.html' title='It’s the FSA’s loss…'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-2774296910848315715</id><published>2010-10-22T10:50:00.001+01:00</published><updated>2010-10-22T10:50:45.906+01:00</updated><title type='text'>Cloud computing - just how secure is your data?</title><content type='html'>&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 12pt"&gt; &lt;P style="LINE-HEIGHT: 13pt; MARGIN: 0cm 0cm 6pt" class=MsoNormal  align=justify&gt;&lt;FONT face=Calibri&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;The growth of  cloud computing services over the past 12 months has been phenomenal and it's  easy to understand why.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Companies  can have access to a huge variety of productivity resources, share software  online and take advantage of incredible storage space, all at a fraction of the  cost of investing in their own infrastructure.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt; &lt;P style="LINE-HEIGHT: 13pt; MARGIN: 0cm 0cm 6pt" class=MsoNormal  align=justify&gt;&lt;FONT face=Calibri&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;It's what might  technically be referred to as a "no brainer". But what about security and what  control would you have if you gave your data up to 'The  Cloud'?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=Default align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT  face=Calibri&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;There is growing disquiet about the  security of Cloud-based services amongst increasing numbers of IT professionals.  Not least that what appears to be a single provider service will generally rely  upon a number of third parties, and the number of third parties can grow  exponentially as the primary provider grows its business.  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=Default align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT  face=Calibri&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;This can mean passwords and other  security information are shared amongst numerous providers, possibly without a  client organisation's knowledge. Whilst the service providers will, of course,  tell you that security is paramount, your data is entirely safe and their  systems are protected, it cannot be ignored that any system that has ever been  breached was once considered impenetrable.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=Default align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT  face=Calibri&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;The fact that huge amounts of data  from a multitude of different organisation can often be held in one place makes  The Cloud increasingly attractive to cyber-criminals. If they could obtain data,  or the security credentials, of these organisations through a single attack on a  Cloud-based provider their return against investment would be  huge.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=Default align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT  face=Calibri&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;One shouldn't overlook the fact that  there are currently no recognised standards or measures of accountability to  which Cloud-based service provider must adhere. This is primarily because the  'industry' is very much in its infancy. Standards usually come with  maturity.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=Default align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT  face=Calibri&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;And perhaps it's worth asking  yourself what the response of the Information Commissioner's Office or a  regulatory body such as the Financial Services Authority would be if your data  fell into the wrong hands and you tried to place the blame at the door of your  service provider?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="LINE-HEIGHT: normal; MARGIN: 0cm 0cm 6pt" class=MsoNormal  align=justify&gt;&lt;FONT face=Calibri&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;This is not  intended to suggest that such services don't have their place, but the bottom  line is that relying upon Cloud-based providers is no substitute for an  organisation's own robust security measures.  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-2774296910848315715?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/2774296910848315715/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/10/cloud-computing-just-how-secure-is-your.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/2774296910848315715'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/2774296910848315715'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/10/cloud-computing-just-how-secure-is-your.html' title='Cloud computing - just how secure is your data?'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-7215211010363337704</id><published>2010-10-20T17:37:00.000+01:00</published><updated>2010-10-20T17:38:00.725+01:00</updated><title type='text'>Testing Times</title><content type='html'>&lt;DIV dir=ltr&gt; &lt;DIV style="FONT-FAMILY: 'Trebuchet MS'; COLOR: #000000; FONT-SIZE: 12pt"&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=Default align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT  face=Calibri&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Organisations naturally rely upon the  numerous systems and controls they put in place for their data security and  integrity. But however well they appear to operate, there are times when the  only way of knowing that they are functioning correctly is to rigorously test  them and push them to their limits.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=Default align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT  face=Calibri&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Many organisations wrongly believe  that if they have secure passwords, a firewall and anti-virus software they are  unlikely to be troubled by a data breach or information theft. But oversights  such as failure to fully validate an input form on a website, or simply  installing a patch to a server without checking the effect it might have on port  settings, can undermine even the best security systems.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="MARGIN: 0cm 0cm 6pt" class=Default align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT  face=Calibri&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;You cannot implement systems and  processes then just leave them to run unchecked. Without a strict testing regime  - a general rule of thumb is that Penetration Testing should be carried out at  least quarterly in most organisations - your networks could be open to misuse  and abuse, ultimately leading to loss of data through such circumstances  as:&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=Default align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT  face=Calibri&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Inappropriate access controls  allowing unauthorised use; &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=Default align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT  face=Calibri&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Human error, through ignorance or  disregard of processes; &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1"  class=Default align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT  face=Calibri&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;Hacking attacks; or  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P  style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 6pt 36pt; mso-list: l0 level1 lfo1"  class=Default align=justify&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;SPAN  style="mso-list: ignore"&gt;&lt;FONT face=Symbol&gt;&lt;FONT  style="FONT-SIZE: 11pt"&gt;·&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN  style="LINE-HEIGHT: normal; FONT-FAMILY: "&gt;&lt;FONT face="Times New Roman"&gt;&lt;FONT  style="FONT-SIZE: 7pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN  style="FONT-FAMILY: ; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT  face=Calibri&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;'Blagging offences', where  information is obtained by deceit. &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="LINE-HEIGHT: normal; MARGIN: 0cm 0cm 6pt" class=MsoNormal&gt;&lt;FONT  face=Calibri&gt;&lt;FONT style="FONT-SIZE: 11pt"&gt;It's a common misconception that  Penetration Testing and other information security services are extremely  expensive. Whilst there will be providers who try to charge everything at a  premium, most will charge a fair rate for a high quality service - a service  that ultimately helps you to ensure the security of your networks and data.  &lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-7215211010363337704?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/7215211010363337704/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/10/testing-times.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/7215211010363337704'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/7215211010363337704'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/10/testing-times.html' title='Testing Times'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-7942029350805757229</id><published>2010-09-07T13:36:00.000+01:00</published><updated>2010-09-07T13:36:46.823+01:00</updated><title type='text'>Securm becomes a Microsoft Refurbisher - Press release</title><content type='html'>For Immediate Release&lt;br /&gt;11:00hrs 7th September 2010 &lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_QqJuA7XTtKA/TIYxwGTTC_I/AAAAAAAAAB0/3cgomhNU4yQ/s1600/ms-Registered-Refurb_cL.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="110" src="http://4.bp.blogspot.com/_QqJuA7XTtKA/TIYxwGTTC_I/AAAAAAAAAB0/3cgomhNU4yQ/s200/ms-Registered-Refurb_cL.png" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Securm Ltd has been accepted on to the Microsoft Registered Refurbisher Program&lt;br /&gt;&lt;br /&gt;Milton Keynes, 13:30 7th September 2010 – Securm, the specialist IT security company, is pleased to announce it has been accepted on to the Microsoft Registered Refurbisher Program. This means it can now deliver genuine preinstalled Microsoft software licences to its customers on the computer equipment it refurbishes.&lt;br /&gt;&lt;br /&gt;Securm’s services include data destruction, WEEE compliant disposal of IT equipment – which includes refurbishment of serviceable units - highly specialised Penetration Testing and Business Continuity Planning.&lt;br /&gt;&lt;br /&gt;Lee Barney, founder and Director of Securm, says, “We are delighted to have been accepted on to Microsoft’s Refurbisher Program. The Program will allow us to provide genuine Microsoft software on good quality, low cost equipment to a range of different customers, from individual consumers to small business and charitable organisations. Having genuine Microsoft software installed gives confidence to our customers because they know they will have legitimate access to all the updates and support that Microsoft provides.&lt;br /&gt;&lt;br /&gt;We will be able to refurbish and sell more IT equipment so there will be less to be destroyed and disposed of, which is better for the environment, and this in turn will help us reduce costs to the customers from whom we collect. So it’s a win-win situation all round.”&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-7942029350805757229?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/7942029350805757229/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/09/securm-becomes-microsoft-refurbisher.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/7942029350805757229'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/7942029350805757229'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/09/securm-becomes-microsoft-refurbisher.html' title='Securm becomes a Microsoft Refurbisher - Press release'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_QqJuA7XTtKA/TIYxwGTTC_I/AAAAAAAAAB0/3cgomhNU4yQ/s72-c/ms-Registered-Refurb_cL.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-4038363570846874051</id><published>2010-05-05T09:07:00.002+01:00</published><updated>2010-05-05T09:07:19.505+01:00</updated><title type='text'>InfoSec 2010 pictures</title><content type='html'>&lt;style&gt;&lt;!-- /* Font Definitions */ @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4; mso-font-charset:1; mso-generic-font-family:roman; mso-font-format:other; mso-font-pitch:variable; mso-font-signature:0 0 0 0 0 0;}@font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4; mso-font-charset:0; mso-generic-font-family:swiss; mso-font-pitch:variable; mso-font-signature:-1610611985 1073750139 0 0 159 0;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {mso-style-unhide:no; mso-style-qformat:yes; mso-style-parent:""; margin:0cm; margin-bottom:.0001pt; mso-pagination:widow-orphan; font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-ascii-font-family:Calibri; mso-ascii-theme-font:minor-latin; mso-fareast-font-family:Calibri; mso-fareast-theme-font:minor-latin; mso-hansi-font-family:Calibri; mso-hansi-theme-font:minor-latin; mso-bidi-font-family:"Times New Roman"; mso-bidi-theme-font:minor-bidi; mso-fareast-language:EN-US;}span.EmailStyle15 {mso-style-type:personal; mso-style-noshow:yes; mso-style-unhide:no; mso-ansi-font-size:11.0pt; mso-bidi-font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-ascii-font-family:Calibri; mso-ascii-theme-font:minor-latin; mso-fareast-font-family:Calibri; mso-fareast-theme-font:minor-latin; mso-hansi-font-family:Calibri; mso-hansi-theme-font:minor-latin; mso-bidi-font-family:"Times New Roman"; mso-bidi-theme-font:minor-bidi; color:windowtext;}.MsoChpDefault {mso-style-type:export-only; mso-default-props:yes; mso-ascii-font-family:Calibri; mso-ascii-theme-font:minor-latin; mso-fareast-font-family:Calibri; mso-fareast-theme-font:minor-latin; mso-hansi-font-family:Calibri; mso-hansi-theme-font:minor-latin; mso-bidi-font-family:"Times New Roman"; mso-bidi-theme-font:minor-bidi; mso-fareast-language:EN-US;}@page Section1 {size:612.0pt 792.0pt; margin:72.0pt 72.0pt 72.0pt 72.0pt; mso-header-margin:36.0pt; mso-footer-margin:36.0pt; mso-paper-source:0;}div.Section1 {page:Section1;}--&gt;&lt;/style&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;It has been a while since our last post and we thought we should update you on what we have been up to.&lt;br /&gt;&lt;br /&gt;Last week Chris Brunning and Lee Barney went to InfoSec 2010 as Exhibitors. This was the first time that Securm had Exhibited at InfoSec so for those of you who met us there please do accept our apologies for our terrible sales pitches :)&lt;br /&gt;&lt;br /&gt;Below are a couple of pictures of ourselves and the stand at InfoSec 2010... see you there next year :)&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_QqJuA7XTtKA/S-EmFMKY0QI/AAAAAAAAABc/crFVLTgD3nA/s1600/chris3.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_QqJuA7XTtKA/S-EmFMKY0QI/AAAAAAAAABc/crFVLTgD3nA/s320/chris3.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&amp;nbsp;&lt;a href="http://3.bp.blogspot.com/_QqJuA7XTtKA/S-El4PczEQI/AAAAAAAAABE/aYJaj_SPyu8/s1600/lee1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_QqJuA7XTtKA/S-El4PczEQI/AAAAAAAAABE/aYJaj_SPyu8/s320/lee1.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_QqJuA7XTtKA/S-El-putjUI/AAAAAAAAABM/nGnrEqjaNAQ/s1600/chris1.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_QqJuA7XTtKA/S-El-putjUI/AAAAAAAAABM/nGnrEqjaNAQ/s320/chris1.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_QqJuA7XTtKA/S-EmB-Xk2xI/AAAAAAAAABU/a31YxXVceqc/s1600/chris2.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_QqJuA7XTtKA/S-EmB-Xk2xI/AAAAAAAAABU/a31YxXVceqc/s320/chris2.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_QqJuA7XTtKA/S-EmF92WShI/AAAAAAAAABk/oV1ip5vBgxI/s1600/lee2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_QqJuA7XTtKA/S-EmF92WShI/AAAAAAAAABk/oV1ip5vBgxI/s320/lee2.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&amp;nbsp;Clearly we could only take the photo's when we weren't busy :) At least you can see our stand...&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-4038363570846874051?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/4038363570846874051/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/05/infosec-2010-pictures.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/4038363570846874051'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/4038363570846874051'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/05/infosec-2010-pictures.html' title='InfoSec 2010 pictures'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_QqJuA7XTtKA/S-EmFMKY0QI/AAAAAAAAABc/crFVLTgD3nA/s72-c/chris3.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-2726916246189132838</id><published>2010-03-19T12:06:00.002Z</published><updated>2010-03-19T14:22:33.538Z</updated><title type='text'>Political Warfare</title><content type='html'>Hacking. It is a word that inspires fear into the hearts of literally thousands of Administrators every day. You may ask how they sleep at night, knowing that prying fingers are playing with their sites, looking for that one mistake that was made, ready to pounce and do something nasty? They sleep because they probably don't consider themselves a target, they will say something like, there are bigger and better companies out there who should be more worried about it than me... To an extent they are right, of course I am not saying that smaller companies should neglect their security or stop having regular pen tests etc, but what I am saying is that they need to look at the risk involved...&lt;br /&gt;&lt;br /&gt;So let’s talk politics... In the UK we have an election at least every 4 years. So what does that mean to the average MP? Well it means that they should be dusting off their posters, flyers and campaign plans&amp;nbsp; at about the 3 years 6 months mark. They know that putting posters up will properly get a few defaced (See below)&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_QqJuA7XTtKA/S6NnGnmfueI/AAAAAAAAAA8/9WQn6BM8LIo/s1600-h/tory+poster.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_QqJuA7XTtKA/S6NnGnmfueI/AAAAAAAAAA8/9WQn6BM8LIo/s320/tory+poster.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Generally though they know that most will be safe from prying fingers and aerosol cans of bored teenagers, political activists. Stop there though, what if there was a way to get around every leaflet, every poster and every calling card and change them to Anti Party messages? Well don't worry there is no way to literally do that, but with 66.3% of the population under the age of 64, (according to Wiki) you can be sure that most of them have access to the internet and you can be sure that running up to an election they will be taking another look at their candidates websites... So it is a surprise to see that Security on these sites is not taken at all seriously. Recently we have seen a number of attacks against the Conservative Party and The Labour Party political websites:&lt;br /&gt;&lt;a href="http://www.blogger.com/goog_1269008559684"&gt;&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://bit.ly/a5WVje"&gt;Tory Site Defaced&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bit.ly/cq9JYN"&gt;Harriet Harman Twitter account hacked (BBC)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bit.ly/d8dlXu"&gt;Climategate&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Why does this happen? Imagine you’re a candidate or sitting MP, for 3 out of 4 years, your website hasn't really been used or looked at. Least not forget that 4 years ago we didn't use the net as much as we do now. essentially Politicians aren't moving with the times, their sites have had their content updated but the security and coding has stayed the same. 4 years to a politician is a long time... it is the span of their political office... 4 years to a hacker is more than a lifetime!&lt;br /&gt;&lt;br /&gt;My message to all the politicians out there. Stop. Look. Listen and get your Websites Scanned, Fixed and updated!&lt;br /&gt;&lt;br /&gt;BTW, if you or anyone you know has been affected by the issues mentioned above then call the Securm confidential hotline on 0800 612 4074 – We can help&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-2726916246189132838?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/2726916246189132838/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/03/political-warefare.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/2726916246189132838'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/2726916246189132838'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/03/political-warefare.html' title='Political Warfare'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_QqJuA7XTtKA/S6NnGnmfueI/AAAAAAAAAA8/9WQn6BM8LIo/s72-c/tory+poster.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-4645329328203475745</id><published>2010-03-12T16:38:00.000Z</published><updated>2010-03-12T16:38:41.013Z</updated><title type='text'>Facebook or Faceplant</title><content type='html'>In recent years Facebook has emerged as the top social networking site, surpassing competitors such as MySpace and Friends Reunited. With over 200 million users, and everyone asking: ‘Are you on Facebook?’ – this website has become a pervasive part of our lives.&amp;nbsp; This raises cause for concern with regards to the use of the social networking and the need for security within the workplace.&lt;br /&gt;&lt;br /&gt;Certainly one issue falls under the category of privacy. We’ve all heard the taboos about keeping our profiles private, in order to protect our personal data.&amp;nbsp; That’s right. Your sensitive, private information is there; indefinitely stored on their servers. And all Facebook employees have access to it.&amp;nbsp;&amp;nbsp; And if they decided to move their servers to house them somewhere with less scrupulous data regulations, who would then have access to ALL of our personal information?&lt;br /&gt;&lt;br /&gt;The availability of personal information such as passwords, birthdays, and names of family members can pose a very big problem. For instance – such information as ‘place of birth’ and ‘mother’s maiden name’ are required when logging onto secure websites such as online banking systems – these are readily available via Facebook, whether hidden or not. Also, because most of us tend to use the same or similar passwords for all our online accounts – it means that if someone gains access to our Facebook password, they potentially have access to our workplace computing systems. &lt;br /&gt;&lt;br /&gt;Facebook (and most social networking sites) are also a breeding ground for the spread of computer viruses. A recent outbreak, spread via the automated posting of links on users’ walls, direct the user to a virus download called ‘Koobface’. The link in question is supposed to appear to be a post from a trusted friend – misleading the user into clicking and downloading malware which infiltrates your system, stealing your personal information and at times, reporting keyboard tracking to the mother site. Presenting another very serious problem for the use of Facebook within a business/ work environment.&lt;br /&gt;&lt;br /&gt;So is the solution to ban all your employees from using Facebook? Not at all.&amp;nbsp; Ensure&lt;br /&gt;that your organisation develops a policy for the use of social networking sites in the workplace and encourage your employees to be security conscious.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;Let them use it at work, but rigorously test your information security systems to ensure that they are ISO27001 compliant, then you can ensure that you meet the latest legislation on data protection compliance.&amp;nbsp; After all, regardless of Facebook, if your data is lost or stolen, you could face a fine of up to £500,000 from the Ministry of Justice.&lt;br /&gt;&lt;br /&gt;Seek out an experienced and qualified information security specialist to debunk the myths and fully secure your electronic perimeter.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-4645329328203475745?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/4645329328203475745/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/03/facebook-or-faceplant.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/4645329328203475745'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/4645329328203475745'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/03/facebook-or-faceplant.html' title='Facebook or Faceplant'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-113277106057157372</id><published>2010-03-04T10:13:00.000Z</published><updated>2010-03-04T10:13:49.535Z</updated><title type='text'>Top Gun - Information security quotes</title><content type='html'>Before we begin let me start by saying this. Occasionally our sales guys like to have a little fun on the phone and we have this bug board at work where they try and get quotes or puns in whilst speaking to clients. The trick is to do it so well that you wouldn't know that they were doing it... On the flipside it is hilarious to listen to. So I have picked seven quotes from the greatest movie of all time... &lt;b&gt;TOP GUN&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span id="goog_1267697207194"&gt;&lt;/span&gt;&lt;span id="goog_1267697207195"&gt;&lt;/span&gt;&lt;a href="http://www.blogger.com/"&gt;&lt;/a&gt;&lt;a href="http://4.bp.blogspot.com/_QqJuA7XTtKA/S4-HbAceCSI/AAAAAAAAAA0/YOBIefnn2X4/s1600/topgun-logo_empatch.jpg" imageanchor="1"&gt;&lt;img border="0" height="200" src="http://4.bp.blogspot.com/_QqJuA7XTtKA/S4-HbAceCSI/AAAAAAAAAA0/YOBIefnn2X4/s200/topgun-logo_empatch.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;The trick in our case is that they have to somehow relate to Information Security... If you think it's easy then try it when you’re on the phone.&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;It's classified. I could tell you, but then I'd have to kill you. &lt;/li&gt;&lt;li&gt;Yes ma'am, the data on the ***Insert product here*** is inaccurate. &lt;/li&gt;&lt;li&gt;That son of a b**** cut me off! ***Usually used when someone hangs up the phone ***&lt;/li&gt;&lt;li&gt;This is what I call a target-rich environment. &lt;/li&gt;&lt;li&gt;That's a negative, Ghost Rider.&lt;/li&gt;&lt;li&gt;I can see it's dangerous for you, but if the government trusts me, maybe you could.&lt;/li&gt;&lt;li&gt;Had the shot there was no danger so I took it...&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Finally - the most inappropiate top gun quote to use on the phone... ever&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8. Goose you big sssssstttttuuuuuud, take me to bed or lose me forever. &lt;br /&gt;If you have any better quotes please leave a comment below, or&lt;a href="http://www.twitter.com/securm"&gt; tweet us here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-113277106057157372?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/113277106057157372/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/03/top-gun-information-security-quotes.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/113277106057157372'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/113277106057157372'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/03/top-gun-information-security-quotes.html' title='Top Gun - Information security quotes'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_QqJuA7XTtKA/S4-HbAceCSI/AAAAAAAAAA0/YOBIefnn2X4/s72-c/topgun-logo_empatch.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-2393415602048320246</id><published>2010-03-02T16:07:00.001Z</published><updated>2010-03-02T16:12:19.058Z</updated><title type='text'>Need to keep your data safe?.... Just Encrypt it</title><content type='html'>As of today (March 1st 2010) the state of Massachusetts in the USA has put in place the most comprehensive set of information security regulations across America.  The regulations include Physical Security Controls, Administrative Security Controls and Technical Security Controls.  It looks to be an impressive attempt by authorities to curb the threat to personal and private data and lead the way for the rest of the country.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_QqJuA7XTtKA/S404tJ6PFbI/AAAAAAAAAAs/HrZafNWCnBA/s1600-h/binary+lock.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_QqJuA7XTtKA/S404tJ6PFbI/AAAAAAAAAAs/HrZafNWCnBA/s320/binary+lock.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;But what about the UK? No such controls exist.  Certainly there are some legislative requirements for certain industries, but instead of forcing companies to do things the old way, using firewalls and encryption, we should be insisting upon them taking the risk of security penetration seriously.  &lt;br /&gt;&lt;br /&gt;For instance, in Hong Kong, the banks are all obliged by law to adopt ISO27001.  This ensures that they analyse and assess their risk and that correct measures and controls are put into place to address the issues raised.  It doesn’t force them down a particular technological path, but it allows companies to see where things have gone wrong (or could), rather than simply blaming the systems.&lt;br /&gt;&lt;br /&gt;This month, the annual RSA Conference meets in California to discuss data security measures. Both Government agencies and private companies will gather to share and debate the latest advances in information security and look at ways to implement more effective solutions.&lt;br /&gt;&lt;br /&gt;But in the UK, we need to pressure government to insist that companies address the security threat to their information use and storage.  Government agencies are already required to adopt ISO27001, why shouldn’t everyone else comply too?  We might not be able to stop all information security attacks occurring, but we’d be better prepared to deal with things when a breach occurs and to learn from that experience.&lt;br /&gt;&lt;br /&gt;As more and more businesses across the UK depend upon the Internet and Information Technology to run their business, the issue of information security has become increasingly vital.  Even if the Government does not force your business to meet the latest ISO27001 standards, take a leaf out of Hong Kong’s book and get in ahead of the curve.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-2393415602048320246?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/2393415602048320246/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/03/need-to-keep-your-data-safe-just.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/2393415602048320246'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/2393415602048320246'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/03/need-to-keep-your-data-safe-just.html' title='Need to keep your data safe?.... Just Encrypt it'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_QqJuA7XTtKA/S404tJ6PFbI/AAAAAAAAAAs/HrZafNWCnBA/s72-c/binary+lock.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-2278886161428932456</id><published>2010-03-02T12:05:00.001Z</published><updated>2010-03-02T12:07:32.528Z</updated><title type='text'>Open Source, to saucy for the enterprise?</title><content type='html'>Only a few years ago many companies would have shuddered at the thought of using Open Source software, but times are changing.&amp;nbsp; Mozilla’s Firefox, which according to web analysis firm Net Applications is second only to Internet Explorer as the world’s most popular Internet browser, is actually a very successful piece of open source secure software.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Open Source software is no longer a thing to be afraid of, in fact, I often find that much of the open source software now available is taking great leaps in providing user-friendly, secure tools, with a surprisingly decent amount of support!&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img border="0" height="197" src="http://3.bp.blogspot.com/_QqJuA7XTtKA/S4z-ylPuXMI/AAAAAAAAAAk/dRnXPf4FXcY/s200/firefox-logo.png" width="200" /&gt;&lt;/div&gt;But I must add a word of caution here though. Not all open source software is going to be as secure as the next, so there is still a matter of Risk Assessment involved. There will be glitches and security issues that may cause vulnerabilities, but as long as you keep up-to-date with any software updates and patches, and report any issues that you have, and then open source software can be trusted as much as private source software. Actually open source software is usually more readily patched than something like Internet Explorer, for example.&lt;br /&gt;&lt;br /&gt;Equally, private source software is also open to security issues. Most recently you will have heard of the Google hack in China that was only possible through a vulnerability in Microsoft’s Internet Explorer.&amp;nbsp; Yet the Open Source Firefox and its many useful add-ons (like Firebug) was not compromised and are now being increasingly recommended by professionals in many industries for its security, stability, compatibility and ease of use.&lt;br /&gt;&lt;br /&gt;One of the major shifts in the last few years is also the ‘general’ computing and software knowledge of your staff. People are savvier when it comes to software, they are clued in on potential threats and they don’t tend to panic as much when something goes wrong. &lt;br /&gt;&lt;br /&gt;So yes, open source software can (with certain security caveats) be trusted. It may not be perfect (plenty of private source software is far worse) but if you can commit to checking and updating the software regularly (which you should be doing anyway), and give the developers useful feedback, then you will find that it should grow to meet your needs and keep you safe online.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-2278886161428932456?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/2278886161428932456/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/03/open-source-to-saucy-for-enterprise.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/2278886161428932456'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/2278886161428932456'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/03/open-source-to-saucy-for-enterprise.html' title='Open Source, to saucy for the enterprise?'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_QqJuA7XTtKA/S4z-ylPuXMI/AAAAAAAAAAk/dRnXPf4FXcY/s72-c/firefox-logo.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-2691945911364412497</id><published>2010-02-25T10:44:00.000Z</published><updated>2010-02-25T10:44:07.173Z</updated><title type='text'>Social Media Scams</title><content type='html'>This isn’t a news flash, I think by now most people know about the Twitter Scam that is going around at the moment. If you are reading this then &lt;b&gt;CHANGE YOUR PASSWORD NOW&lt;/b&gt;. This goes for your myspace and facebook accounts and even your Computer passwords if they are similar (I imagine that they are....).&lt;br /&gt;The scam is quite a simple one, essentially a group of Chinese scammers have set up login pages for popular social networking sites with the aim of collecting passwords.&amp;nbsp; They trick you to following a link using URL shortening services such as tr.im (which doesn’t allow you to expand the url like bit.ly) with a message similar to&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_QqJuA7XTtKA/S4ZURAlscSI/AAAAAAAAAAU/CSthAP10wgY/s1600-h/Hacked.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_QqJuA7XTtKA/S4ZURAlscSI/AAAAAAAAAAU/CSthAP10wgY/s320/Hacked.bmp" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Of course because it’s one of your followers (a genuine real person) and you are curious you follow the link. You are now prompted to re-authenticate to twitter. The page that you are asked to authenticate on is actually hosted in China, the one for the above attack was at this URL:&lt;br /&gt;&lt;br /&gt;http://twitter.login.kevanshome.org/login/?k9u2b&lt;br /&gt;&lt;br /&gt;This clearly isn’t twitter or myspace. Of course, if wasn’t for the helpful people at Mozilla Firefox why would you think to look at the URL.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_QqJuA7XTtKA/S4ZUYWdiihI/AAAAAAAAAAc/oMuNEQjXFWM/s1600-h/Blocked.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_QqJuA7XTtKA/S4ZUYWdiihI/AAAAAAAAAAc/oMuNEQjXFWM/s320/Blocked.bmp" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Note that Windows Internet Explorer doesn’t pick up on this....&lt;br /&gt;&lt;br /&gt;Or course you should but not many people do... and thus a number or people are attempting to re-authenticate themselves and therefore giving your details away.&lt;br /&gt;&lt;br /&gt;So check your DM’s that you have sent out, check you’re sent items in your network accounts and if you see any messages that you don’t recognise then &lt;b&gt;CHANGE YOUR PASSWORDS&lt;/b&gt;. In fact, &lt;b&gt;CHANGE YOUR PASSWORDS ANYWAY&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Lessons to learn?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;As I am always telling anyone who will listen, don’t click on links sent to you in whatever form they come in, be it DM’s or emails, especially if they are from a “trusted” source. Always cut and past the URL into the address bar and if it has been shortened, expand it first. Look at the URL before you enter it or attempt to traverse to it, then STOP. Don’t hit enter, take it to a web proxy services such as http://www.daveproxy.co.uk and enter it there. View the page and only then if you trust it, visit it.&lt;br /&gt;When it comes to using the internet, be very, very careful. Don’t take things at face value and don’t click on links.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Network Admins &lt;/b&gt;&lt;br /&gt;&lt;br /&gt;I know a lot of you out there already know this stuff, but remember as responsible netizens we should be continuously warning people of these things. A simple password hack like this can lead to a corporate network being compromised just because the user used the same password... If you’re a network admin reading this, are you sure that no one in your organisation uses the same password for their corporate VPN access as they do for their twitter, facebook account?&lt;br /&gt;&lt;br /&gt;On a final note, push out internet explorer and get in FireFox...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-2691945911364412497?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/2691945911364412497/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/02/social-media-scams.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/2691945911364412497'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/2691945911364412497'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/02/social-media-scams.html' title='Social Media Scams'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_QqJuA7XTtKA/S4ZURAlscSI/AAAAAAAAAAU/CSthAP10wgY/s72-c/Hacked.bmp' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-1238668387100225462</id><published>2010-02-16T15:04:00.000Z</published><updated>2010-02-16T15:04:47.941Z</updated><title type='text'>Top 20 Cloud Puns... we never said that they were funny</title><content type='html'>After a couple of minutes talking about puns to use when calling cloud based companies we came up with the following. Any of you got any others out there, please let us know on &lt;a href="http://twitter.com/securm"&gt;Twitter&lt;/a&gt; or &lt;a href="mailto:info@securm.co.uk"&gt;email&amp;nbsp;&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Some of your policies are a too high level&lt;/li&gt;&lt;li&gt;Do you want to reign above the competition&lt;/li&gt;&lt;li&gt;Using our service will help you see the blue sky beyond&lt;/li&gt;&lt;li&gt;We think that your security vision is a little foggy&lt;/li&gt;&lt;li&gt;Perhaps your perimeter is blurred&lt;/li&gt;&lt;li&gt;With securm.co.uk the sky is the limit&lt;/li&gt;&lt;li&gt;Are you worried that data leaks could dry up your business&lt;/li&gt;&lt;li&gt;We can help your business soar above the rest&lt;/li&gt;&lt;li&gt;Just turn on the fog lights to see the road ahead&lt;/li&gt;&lt;li&gt;We can steer your way through cloud cuckoo land&lt;/li&gt;&lt;li&gt;(in relation to security breaches) it never rains but it pours&lt;/li&gt;&lt;li&gt;Where will my data be stored in the clouds? Heaven knows&lt;/li&gt;&lt;li&gt;What’s the weather like where you are&lt;/li&gt;&lt;li&gt;Securm.co.uk the service with the silver lining&lt;/li&gt;&lt;li&gt;We leave you walking on cloud 9&lt;/li&gt;&lt;li&gt;Don't leave your head in the clouds&lt;/li&gt;&lt;li&gt;Being on the leaking edge of the cloud&lt;/li&gt;&lt;li&gt;In the midst of opportunity you appear&lt;/li&gt;&lt;li&gt;SaaS providers thinking is sometimes clouded&lt;/li&gt;&lt;li&gt;Cloud companies are always thinking blue sky but it often wanes&lt;/li&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-1238668387100225462?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/1238668387100225462/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/02/top-20-cloud-puns-we-never-said-that.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/1238668387100225462'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/1238668387100225462'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/02/top-20-cloud-puns-we-never-said-that.html' title='Top 20 Cloud Puns... we never said that they were funny'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-5996881570122753612</id><published>2010-01-25T11:50:00.001Z</published><updated>2010-01-25T11:50:08.629Z</updated><title type='text'>To USB or to not USB</title><content type='html'>&lt;div class=Section1&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;span lang=EN-US&gt;Do you remember in 2008, when a British Government contractor lost a USB device containing the details of the UK prison population?&amp;nbsp; Of course, they encrypted all the data so they didn&amp;#8217;t reveal this sensitive information to anyone that found it, didn&amp;#8217;t they? &lt;b&gt;No.&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;span lang=EN-US&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;span lang=EN-US&gt;Or perhaps you recall that last year the Scottish NHS admitted losing a USB data stick with the personal medical records of 137 individuals on it?&amp;nbsp; Of course, because information security is a priority for the data held by the NHS, they surely found a way to make device unreadable to those without security clearance? &lt;b&gt;No.&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;b&gt;&lt;span lang=EN-US&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;span lang=EN-US&gt;What about...2008, when a Leicestershire nurse lost a USB drive containing the names, addresses, date of birth and phone number of 80 young children.&amp;nbsp; &lt;b&gt;All unencrypted data&lt;/b&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;span lang=EN-US&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;span lang=EN-US&gt;Okay, you get the point.&amp;nbsp; Using unencrypted USBs for your business or organisation is an information security nightmare.&amp;nbsp; So what&amp;#8217;s the solution?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;span lang=EN-US&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;span lang=EN-US&gt;The first is not to store sensitive data on removable or portable drives.&amp;nbsp; That may be easier said than done, but it is the common sense approach.&amp;nbsp; Some government agencies have made it a sackable offense for staff to possess USB devices at work, and that immediately reduces the risk.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;span lang=EN-US&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;span lang=EN-US&gt;But surely, you can just invest in encryption technology? Software or the latest built-in encryption should be a workable solution. On the surface, that sounds like a sensible strategy, but let&amp;#8217;s look at how this may be an even more disastrous decision:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;span lang=EN-US&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;span lang=EN-US&gt;You&amp;#8217;ve bought your organisation 10,000 encrypted USB devices and you now tell your staff that it&amp;#8217;s okay to take them home or work on them outside the office because it&amp;#8217;s safe.&amp;nbsp; Of course, now you&amp;#8217;ve told them that they&amp;#8217;re &amp;#8216;securely encrypted&amp;#8217;, they aren&amp;#8217;t quite as careful with them as they should be.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;span lang=EN-US&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;span lang=EN-US&gt;Over the course of a few years, they lose 1% of them.&amp;nbsp; That&amp;#8217;s 100 devices.&amp;nbsp; 25% of those devices contain highly sensitive or secret information.&amp;nbsp; In the third year, a vulnerability is exposed that allows completely open access to this important data.&amp;nbsp; Now all of your devices are compromised and the 25 devices with sensitive or secret data can now be read by anyone. If you want to do anything about this vulnerability, you&amp;#8217;ll have to recall all the USBs, but how will you cope with those that have been lost? &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;span lang=EN-US&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;span lang=EN-US&gt;Giving your employees encrypted USB devices is simply storing a problem for the future.&amp;nbsp; It may be a cheap solution, but in the long run it&amp;#8217;s the most damaging. Of course nothing like this could ever happen surely? &lt;b&gt;&lt;a href="http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html"&gt;It already did&lt;/a&gt;!&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;span lang=EN-US&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;span lang=EN-US&gt;So what&amp;#8217;s the solution?&amp;nbsp; The solution that offers the most protection (there is no perfect solution) is remote access and security in a private cloud.&amp;nbsp; With upsurge in mobile Internet, it allows the same anywhere/anytime access as a USB, but it provides a great deal more security through a secure TLS connection between the host and the remote server. It&amp;#8217;s not infallible, but it&amp;#8217;s a lot easier to change any of the encryption settings or security details on your server or hard drives if a vulnerability is released or a breach is discovered.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;span lang=EN-US&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=BodyA style='text-align:justify'&gt;&lt;span lang=EN-US&gt;If you want to keep your data protected, then USBs - even with encryption, are not a secure solution, so speak to an Information Security specialist about secure access to your own private cloud.&lt;/span&gt;&lt;span style='font-size:10.0pt;font-family:"Times New Roman","serif"; color:windowtext'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-5996881570122753612?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/5996881570122753612/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2010/01/to-usb-or-to-not-usb.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/5996881570122753612'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/5996881570122753612'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2010/01/to-usb-or-to-not-usb.html' title='To USB or to not USB'/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-768985831479828418</id><published>2009-11-23T09:26:00.000Z</published><updated>2009-11-23T09:27:54.747Z</updated><title type='text'></title><content type='html'>&lt;div class=Section1&gt;  &lt;p class=FreeForm style='text-align:justify'&gt;&lt;b&gt;&lt;span lang=EN-US&gt;PLAY.COM AND T-MOBILE ADMIT DATA LEAKS...&lt;/span&gt;&lt;/b&gt;&lt;span lang=EN-US&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=FreeForm style='text-align:justify'&gt;&lt;span lang=EN-US&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=FreeForm style='text-align:justify'&gt;&lt;span lang=EN-US style='font-family: "Calibri","sans-serif"'&gt;With the Christmas season upon us already, it was bad timing that the online entertainment e-tailer Play.com recently reported a breach in its information security protocols.&amp;nbsp; Who was the culprit? A team of North Koreans, trained and funded by their government? Chinese spies? Malicious Hackers? No.&amp;nbsp; This data leak was caused, created and carried out by Play.com themselves, in a moment of accidental commercial self-sabotage.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=FreeForm style='text-align:justify'&gt;&lt;span lang=EN-US style='font-family: "Calibri","sans-serif"'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=FreeForm style='text-align:justify'&gt;&lt;span lang=EN-US style='font-family: "Calibri","sans-serif"'&gt;At the time of the year when most people are wondering whether to save money by buying on the Internet, Play.com injured their own credibility by emailing their customers with other customer&amp;#8217;s order details.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=FreeForm style='text-align:justify'&gt;&lt;span lang=EN-US style='font-family: "Calibri","sans-serif"'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=FreeForm style='text-align:justify'&gt;&lt;span lang=EN-US style='font-family: "Calibri","sans-serif"'&gt;Not only did Play.com badly damage their reputation at an important time, but they are now being investigated by the Information Commissioner&amp;#8217;s Office for a possible breach of the Data Protection Act (DPA).&amp;nbsp; Whilst Play.com quickly assured customers that no sensitive information was accidentally leaked, they are still at risk of prosecution under the DPA.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=FreeForm style='text-align:justify'&gt;&lt;span lang=EN-US style='font-family: "Calibri","sans-serif"'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=FreeForm style='text-align:justify'&gt;&lt;span lang=EN-US style='font-family: "Calibri","sans-serif"'&gt;This comes in the same month that it was announced that staff at mobile phone company T-Mobile had sold millions of customer records to third party brokers.&amp;nbsp; This sensitive information is highly valuable in the right hands and was sold for substantial amounts of money.&amp;nbsp; T-Mobile are working with the Information Commissioner&amp;#8217;s Office to investigate the theft and prosecute the offenders.&amp;nbsp; However, it is unlikely that this will reassure those customers whose details have already been sold on.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=FreeForm style='text-align:justify'&gt;&lt;span lang=EN-US style='font-family: "Calibri","sans-serif"'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=FreeForm style='text-align:justify'&gt;&lt;span lang=EN-US style='font-family: "Calibri","sans-serif"'&gt;In terms of information security, most people only think of protecting their data from outside intrusion.&amp;nbsp; However, insider theft and accidental data leaks can be just as damaging to your organisation&amp;#8217;s reputation and success, as external attacks.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=FreeForm style='text-align:justify'&gt;&lt;span lang=EN-US style='font-family: "Calibri","sans-serif"'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;span lang=EN-US style='font-family:"Calibri","sans-serif"; color:black'&gt;To ensure that this doesn&amp;#8217;t happen, these companies should implement information security safeguards that prevent data theft and the accidental exposure of data within their own information systems.&amp;nbsp; The electronic perimeter of your data storage systems must be as closely guarded as the physical perimeter.&lt;/span&gt;&lt;span lang=EN-US style='font-size:11.0pt; font-family:"Calibri","sans-serif"'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-768985831479828418?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/768985831479828418/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2009/11/play.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/768985831479828418'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/768985831479828418'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2009/11/play.html' title=''/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8603369206500400146.post-8579315410210860927</id><published>2009-10-29T21:38:00.001Z</published><updated>2009-10-29T21:38:31.324Z</updated><title type='text'></title><content type='html'>&lt;div&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Times; font-size: 16px; -webkit-tap-highlight-color: rgba(26, 26, 26, 0.296875); -webkit-composition-fill-color: rgba(175, 192, 227, 0.230469); -webkit-composition-frame-color: rgba(77, 128, 180, 0.230469); "&gt;&lt;div style="font-size: 18px; -webkit-text-size-adjust: none; background-image: initial; background-repeat: initial; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: rgb(255, 255, 255); background-position: initial initial; "&gt;&lt;p class="s2" style="margin-top: 0px; margin-bottom: 0px; line-height: 1; margin-right: 0px; text-align: left; margin-left: 0px; text-indent: 0px; "&gt;&lt;span style="line-height: 18px; "&gt;&lt;span class="Apple-style-span" style="font-family: Helvetica; -webkit-tap-highlight-color: rgba(26, 26, 26, 0.289062); -webkit-composition-fill-color: rgba(175, 192, 227, 0.222656); -webkit-composition-frame-color: rgba(77, 128, 180, 0.222656); font-weight: bold; "&gt;Hacking: We Can Learn Something from Gary McKinnon...&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="s2" style="margin-top: 0px; margin-bottom: 0px; line-height: 1; margin-right: 0px; text-align: left; margin-left: 0px; text-indent: 0px; "&gt;&lt;span style="line-height: 18px; "&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class="s5" style="margin-top: 0px; margin-bottom: 0px; line-height: 1; margin-right: 0px; text-align: justify; margin-left: 0px; text-indent: 0px; "&gt;&lt;span class="s4" style="line-height: 18px; color: rgb(0, 0, 0); font-weight: normal; font-size: 18px; font-family: Helvetica; "&gt;The United States of America takes defending its borders very seriously. &amp;nbsp;Yet between 2001-02, a British hacker called Gary McKinnon was able to breach its digital boundaries on a regular basis, looking for evidence of little green men.&lt;/span&gt;&lt;/p&gt;&lt;p class="s5" style="margin-top: 0px; margin-bottom: 0px; line-height: 1; margin-right: 0px; text-align: justify; margin-left: 0px; text-indent: 0px; "&gt;&lt;span style="line-height: 18px; "&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class="s5" style="margin-top: 0px; margin-bottom: 0px; line-height: 1; margin-right: 0px; text-align: justify; margin-left: 0px; text-indent: 0px; "&gt;&lt;span class="s4" style="line-height: 18px; color: rgb(0, 0, 0); font-weight: normal; font-size: 18px; font-family: Helvetica; "&gt;McKinnon, a self-confessed UFO-nut with Aspergers' Syndrome managed to by-pass &amp;nbsp;some of America's top information security systems, hacking into computers at NASA, the DOD, the US Army, Navy and Air Force, in what American prosecutors are calling the "biggest military computer hack of all time."&lt;/span&gt;&lt;/p&gt;&lt;p class="s5" style="margin-top: 0px; margin-bottom: 0px; line-height: 1; margin-right: 0px; text-align: justify; margin-left: 0px; text-indent: 0px; "&gt;&lt;span style="line-height: 18px; "&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class="s5" style="margin-top: 0px; margin-bottom: 0px; line-height: 1; margin-right: 0px; text-align: justify; margin-left: 0px; text-indent: 0px; "&gt;&lt;span class="s4" style="line-height: 18px; color: rgb(0, 0, 0); font-weight: normal; font-size: 18px; font-family: Helvetica; "&gt;McKinnon freely admits that he hacked into US government computers by exploiting various security loopholes in the Windows operating system using commercially available software. But he denies causing millions of dollars of damage whilst hacking those systems. &amp;nbsp;McKinnon is currently fighting extradition for trial in the United States, which could result in a 70-year sentence.&lt;/span&gt;&lt;/p&gt;&lt;p class="s5" style="margin-top: 0px; margin-bottom: 0px; line-height: 1; margin-right: 0px; text-align: justify; margin-left: 0px; text-indent: 0px; "&gt;&lt;span style="line-height: 18px; "&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class="s5" style="margin-top: 0px; margin-bottom: 0px; line-height: 1; margin-right: 0px; text-align: justify; margin-left: 0px; text-indent: 0px; "&gt;&lt;span class="s4" style="line-height: 18px; color: rgb(0, 0, 0); font-weight: normal; font-size: 18px; font-family: Helvetica; "&gt;Regardless of the specifics of the case and the subsequent protracted extradition fight, this hacking story has some insights for both the US Military and all of us. &amp;nbsp;To me, what this highlights is the potential weaknesses in even the most robust information security systems. &amp;nbsp;If one guy, a 'bumbling computer nerd' in his own words, can compromise the information security infrastructure of NASA and the US Military, just how secure from hacking are the information networks we all use on a daily basis?&lt;/span&gt;&lt;/p&gt;&lt;p class="s5" style="margin-top: 0px; margin-bottom: 0px; line-height: 1; margin-right: 0px; text-align: justify; margin-left: 0px; text-indent: 0px; "&gt;&lt;span style="line-height: 18px; "&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class="s5" style="margin-top: 0px; margin-bottom: 0px; line-height: 1; margin-right: 0px; text-align: justify; margin-left: 0px; text-indent: 0px; "&gt;&lt;span class="s4" style="line-height: 18px; color: rgb(0, 0, 0); font-weight: normal; font-size: 18px; font-family: Helvetica; "&gt;Sources claim that teams of organised hackers working for foreign government agencies are constantly probing financial, industrial and government information systems for flaws, weaknesses and potential breaches in the digital perimeter.&lt;/span&gt;&lt;/p&gt;&lt;p class="s5" style="margin-top: 0px; margin-bottom: 0px; line-height: 1; margin-right: 0px; text-align: justify; margin-left: 0px; text-indent: 0px; "&gt;&lt;span style="line-height: 18px; "&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class="s5" style="margin-top: 0px; margin-bottom: 0px; line-height: 1; margin-right: 0px; text-align: justify; margin-left: 0px; text-indent: 0px; "&gt;&lt;span class="s4" style="line-height: 18px; color: rgb(0, 0, 0); font-weight: normal; font-size: 18px; font-family: Helvetica; "&gt;The US Administration must commit a serious amount of money to ensuring that their information systems are properly secured. &amp;nbsp;If the information systems of the most powerful country in the world can be breached by an amateur, isn't it time we all had a good long look at the integrity of our own information security systems? &amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class="s5" style="margin-top: 0px; margin-bottom: 0px; line-height: 1; margin-right: 0px; text-align: justify; margin-left: 0px; text-indent: 0px; "&gt;&lt;span style="line-height: 18px; "&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class="s5" style="margin-top: 0px; margin-bottom: 0px; line-height: 1; margin-right: 0px; text-align: justify; margin-left: 0px; text-indent: 0px; "&gt;&lt;span style="line-height: 18px; "&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class="s5" style="margin-top: 0px; margin-bottom: 0px; line-height: 1; margin-right: 0px; text-align: justify; margin-left: 0px; text-indent: 0px; "&gt;&lt;span style="line-height: 18px; "&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class="s5" style="margin-top: 0px; margin-bottom: 0px; line-height: 1; margin-right: 0px; text-align: justify; margin-left: 0px; text-indent: 0px; "&gt;&lt;span style="line-height: 18px; "&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class="s6" style="margin-top: 0px; margin-bottom: 16px; line-height: 1; margin-right: 0px; text-align: left; margin-left: 0px; text-indent: 0px; "&gt;&lt;span style="line-height: 18px; "&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class="s6" style="margin-top: 0px; margin-bottom: 16px; line-height: 1; margin-right: 0px; text-align: left; margin-left: 0px; text-indent: 0px; "&gt;&lt;span style="line-height: 18px; "&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class="s2" style="margin-top: 0px; margin-bottom: 0px; line-height: 1; margin-right: 0px; text-align: left; margin-left: 0px; text-indent: 0px; "&gt;&lt;span style="line-height: 18px; "&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8603369206500400146-8579315410210860927?l=blog.securm.co.uk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.securm.co.uk/feeds/8579315410210860927/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.securm.co.uk/2009/10/hacking-we-can-learn-something-from.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/8579315410210860927'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8603369206500400146/posts/default/8579315410210860927'/><link rel='alternate' type='text/html' href='http://blog.securm.co.uk/2009/10/hacking-we-can-learn-something-from.html' title=''/><author><name>Securm</name><uri>http://www.blogger.com/profile/06518888852150267237</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
