Do I need a Web Application Firewall?
I have been recently confronted with a dilemma. If I was given a fresh start at building a secure DMZ environment, could I justify the cost of adding Web Application Firewalls into my DMZ? Would they...
View ArticleComparing Cloud Enterprise SSO
There are a few very strong players currently in the Enterprise Single Sign On practice: And there are some Up and Comers...(List of single-sign-on implementations) If you want a maintenance free -...
View ArticleSecurity Appliances: In-band or out-of-band?
Do we need to place our Security Appliances inline? In a typical Corporate DMZ, such as a Public Internet Landing Zone, where private internal network traffic and public Internet traffic meet, you...
View ArticleCDN: Content Delivery Networks in the Context of Security
In Information Security, we very frequently discuss the merits and challenges of Confidentiality and Integrity, but alas, Availability regularly takes the back seat... In today's world of Dynamic Web...
View ArticleHost Protection - Standards and Reference Controls
The Concept of Zero-TrustTo allow for near-future work models, where employees can bring their own mobile devices into the workplace, where “work from home” is standard practice, and where the Data...
View ArticleShould I be concerned about Heartbleed?
First: Here is the fixed OpenSSL HeartBleed Check Site: -> http://filippo.io/Heartbleed/If you are running HTTPS, SFTP, or any other SSL enabled service on the Internet, you *NEED* to know about...
View ArticleWhat if Target had followed a Zero Trust model?
Yes, I agree that I'm late to the table on yet another Target Breach Blog, but I want to throw a twist on the story.. A fantastic "WHAT IF?"I want to transport you momentarily, to a utopian world...
View ArticleAdvanced Persistent Threats, the Killchain, and FireEye...
Over the past several years, our Defence In Depth strategy has been working overtime to keep up with Advanced Persistent Threats and Zero Day Exploits. Firewalls, Intrusion Prevention, URL filtering,...
View ArticleFTP, SFTP, FTPS? What's the difference, and how the !@#$ do I secure them?
File Transfer (FTP) may be the single most insecure piece of infrastructure that any corporation has. It's roots date back to the early 70's before encryption and transport security were of great...
View ArticleDenial of Service? What is it, and how can we defend against it? - Executive...
I've been asked to write a higher level version of some of my blogs. Apparently my writing is too technical... According to Prolexic (now part of Akamai), DDoS, or Distributed Denial of Serviceattacks...
View ArticleWhat is DTLS or Datagram Transport Layer Security?
Otherwise known as Secure Real-time Transport Protocol, DTLS (Datagram Transport Layer Security) is used where low latency or "delay sensitive" data must be secured, such as Voice over IP, VPN, Video...
View ArticleProtecting Sensitive Data with Tokenization - Overview of Tokenization vs...
For the protection of sensitive data, Tokenization is every bit as important as data Encryption.This blog entry is also being hosted over on the ITWorldCanada site. Thank you...
View ArticleThe Demise of Excess Access - A eulogy for traditional VPN
(as published in Itworldcanada.ca) http://www.itworldcanada.com/blog/the-demise-of-excess-access-a-eulogy-for-traditional-vpn/96655 Once upon a time, in a world where mobile meant "laptop" or "remote...
View ArticleToronto based PCI Compliance upstart brings single solution to Voice-Web-POS
As published in ITWorldCanada.com(http://www.itworldcanada.com/blog/toronto-upstart-brings-tokenization-protection-to-uc-web-pos/98109)The standard Information Security mantra is to Protect Sensitive...
View ArticleKnow Your Threat Landscape - Standardized Security Threat Information (STIX &...
Over the years, many managed security service providers have been publishing variants of an external Threat Analysis in one form or another. Annual, Quarterly, Weekly, Daily, and live feeds are regular...
View ArticleCyberArk positioned to lead Industry in SSH key management practice
CyberArk, best known for it's Privileged Password Vault, and recent IPO success story has just announced a new product set. At the 2014 CyberArk Customer Event held in Boston this week, they announced...
View ArticleEliminate HTTP Man-In-The-Middle attacks with HSTS
The most prolific Internet Protocol (ok, maybe aside from mail) is HTTP, or common Web traffic, between end user browsers and web servers. However, it is also one of the most insecure. Setting up a...
View ArticleRisk reduction through Jump Servers
A common practice in today's data centers is to allow Systems Administrators Remote Desktop (RDP) or Secure Shell (SSH) access to the servers they are administrating, directly from their desktops....
View ArticleCyberArk Privileged Identity Vault - Enterprise Case Study
Cyber-Ark Enterprise Password Vault (EPV) Cyber-Ark EPV is a suite of applications to securely manage passwords and other related sensitive objects. While it typically is used to store and manage...
View ArticleJentu: Canadian Company aims to turn VDI upside down
For the past decade and a half, Citrix and then VMWare have promised to deliver Virtual Desktopseamlessly and efficiently to the corporate user... Maintenance and patching could be done on images on...
View Article