<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>Savid Technologies &#187; Savid Insights Blog</title> <atom:link href="http://www.savidtech.com/blog/feed/" rel="self" type="application/rss+xml" /><link>http://www.savidtech.com</link> <description></description> <lastBuildDate>Tue, 21 Feb 2012 19:56:55 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=</generator> <xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /> <item><title>Technology Capital Investors Acquires Savid Technologies</title><link>http://www.savidtech.com/blog/news/technology-capital-investors-acquires-savid-technologies/</link> <comments>http://www.savidtech.com/blog/news/technology-capital-investors-acquires-savid-technologies/#comments</comments> <pubDate>Mon, 13 Feb 2012 00:48:05 +0000</pubDate> <dc:creator>Michael A. Davis</dc:creator> <category><![CDATA[News]]></category> <guid
isPermaLink="false">http://www.savidtech.com/?p=1434</guid> <description><![CDATA[Technology Capital Investors Acquires IT Security Firm Savid Technologies MSP Investment Firm Expands IT Services Portfolio; Previews Plans to Launch New Cloud Security and Compliance Practice in North America  New York City, NY – Feb. 13, 2012 – Executing against its vision to successfully partner with, empower and profitably grow local and regional MSPs, Technology [...]]]></description> <content:encoded><![CDATA[<p
align="center"><strong>Technology Capital Investors Acquires IT Security Firm Savid Technologies</strong></p><p
align="center"><em>MSP Investment Firm Expands IT Services Portfolio; Previews Plans to Launch New Cloud Security and Compliance Practice in North America</em><em> </em></p><p><strong>New York City, NY – Feb. 13, 2012</strong> – Executing against its vision to successfully partner with, empower and profitably grow local and regional MSPs, <a
href="http://www.techcapinvestors.com/">Technology Capital Investors</a> (TCI), a specialized IT services investment firm, announced today it has acquired <a
href="http://www.savidtech.com/">Savid Technologies Inc</a>., a well established security consulting firm and managed service provider (MSP) with operations based out of Chicago.</p><p>Under the terms of the agreement, Savid Technologies will join TCI’s national portfolio of high-performance MSP partners. The successful MSP will keep its company brand, associates and executive leadership including industry renowned cloud security expert, author of <em>Hacking Exposed,</em> and CEO of Savid Technologies Michael A. Davis.</p><p>As part of TCI, Michael Davis will continue to run the day-to-day operations of the business, and serve as the leadership behind TCI’s new suite of managed security and compliance services which is scheduled to launch in Q1 2012.</p><p>“Savid Technologies is a strategic partner acquisition that will play an integral role in TCI’s growing family of MSP brands, and become the central hub for our new North America security and compliance practice,” says Sam Attias, managing partner, TCI.  “Working as a team, TCI and Savid Technologies will bring to market a fully integrated security offering that our partners can market and sell to their clients.”</p><p>“TCI is on the cutting edge of technology and fast becoming a driving force within the IT industry,” says Davis. “Sam and his team have a true understanding of client IT needs, and have the right vision and plan around the future of the marketplace.”</p><p>“We’re pleased to join the TCI family and extend our security and compliance skill set into a nationwide  team that will help shape the IT industry and accelerate adoption of cloud computing by offering proven security and compliance services to enterprise and SMB clients,” concludes Davis.</p><p>For more information on TCI, visit <a
href="http://www.techcapinvestors.com/">www.techcapinvestors.com</a>.</p><p><strong>About Savid Technologies, Inc. </strong></p><p>Savid Technologies, Inc. provides specialized IT consulting services nationwide. The firm’s expertise and experience runs broad and deep with clients ranging from small businesses consisting of no more than three people to Fortune 500 companies, as well as high-profile government and military agencies. Savid’s primary IT services include IT security audits, outsourced IT for small to midsize businesses and compliance services. <a
href="http://www.savidtech.com/">www.savidtech.com</a></p><p><strong>About Technology Capital Investors </strong></p><p>Technology Capital Investors (TCI) has helped MSPs and hosting companies successfully grow their businesses by partnering with them and establishing a profitable and scalable business model that includes cloud-based IT services and specialized market expertise. TCI also invests in cloud and</p><p>SaaS based solutions that enable the delivery of IT services to end clients. <a
href="http://www.techcapinvestors.com/">www.techcapinvestors.com</a> <strong></strong></p><p># # #</p><p><strong>Press contact:<br
/> </strong>Marie Rourke<br
/> WhiteFox Marketing<br
/> 714.292.2199<br
/> <a
href="mailto:marie@whitefoxpr.com">marie@whitefoxpr.com</a></p><p>&nbsp;</p> ]]></content:encoded> <wfw:commentRss>http://www.savidtech.com/blog/news/technology-capital-investors-acquires-savid-technologies/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Is the Security Industry a Fad?</title><link>http://www.savidtech.com/blog/it-security/security-industry-fad/</link> <comments>http://www.savidtech.com/blog/it-security/security-industry-fad/#comments</comments> <pubDate>Sat, 11 Feb 2012 22:04:30 +0000</pubDate> <dc:creator>Michael A. Davis</dc:creator> <category><![CDATA[IT Security]]></category> <category><![CDATA[newsletter]]></category> <guid
isPermaLink="false">http://www.savidtech.com/?p=1607</guid> <description><![CDATA[In 2007, world-renown security professional Bruce Schneier said in an interview that the convergence of security, where it’s built in vs. bolted on, could make our industry a fad. Has the adoption of the cloud and consumerization started to make this a reality in 2012? We think so, and while we don’t recommend you hang [...]]]></description> <content:encoded><![CDATA[<p><a
href="http://www.savidtech.com/blog/it-security/security-industry-fad/attachment/fads/" rel="attachment wp-att-1608"><img
class="aligncenter size-medium wp-image-1608" title="Security Industry Fads" src="http://www.savidtech.com/wp-content/uploads/fads-300x79.jpg" alt="fads 300x79 Is the Security Industry a Fad?" width="300" height="79" /></a></p><p>In 2007, world-renown security professional Bruce Schneier said in an interview that the convergence of security, where it’s built in vs. bolted on, could make our industry a fad. Has the adoption of the cloud and consumerization started to make this a reality in 2012? We think so, and while we don’t recommend you hang up your security hat to become a Starbucks barista just yet, infosec pros must adapt or risk extinction.</p><p>“The primary reason the IT security industry exists is because IT products and services aren’t naturally secure,” wrote Schneier in his blog. “If computers were already secure against viruses, there wouldn’t be any need for antivirus products. If bad network traffic couldn’t be used to attack computers, no one would bother buying a firewall. If there were no more buffer overflows, no one would have to buy products to protect against their effects. If the IT products we purchased were secure out of the box, we wouldn’t have to spend billions every year making them secure.”</p><p>While Schneier may have been ahead of his time in 2007, the security industry has definitely changed in the past five years. In 2011, we saw executives starting to get involved, and security has become a topic on the tongues of consumers and enterprises alike thanks to hacker groups making headlines on the evening news. In the future Schneier envisions, product manufacturers “fold security into the underlying products, and the companies marketing those products will have an incentive to invest in security upfront, to avoid having to spend more cash obviating the problems later.”</p><p>Just look at the acquisitions: Intel bought McAfee, HP bought ArcSight, VMware bought PacketMotion. 2011 saw vendors begin to bake security into consumer and general IT products. The requirement for security in the cloud will accelerate this process. Here’s what you need to do to avoid extinction:<strong></strong></p><ol><li><strong>Take a communications class.</strong> The No. 1 issue we see with security professionals is an inability to communicate security risks and remediation to nontechnical people. How can you help marketing select a more secure cloud provider if you can’t explain to them the security risks and benefits?</li><li><strong>Less trust, more verify. </strong>Most security organizations don’t audit the systems, vendors or processes that ostensibly have security “built-in.” Just because a vendor passed your inspection when you bought it doesn’t mean it’s still doing a good job six months later. While security professionals normally don’t like IT auditors, the roles are merging; be prepared, and understand how to continually audit and assess whether a once-trusted component can still be trusted. <strong></strong></li><li><strong>Build in security yourself. </strong>The business has new projects coming online all the time. While it may seem like drinking from a fire hose, take the time to assemble a menu of services that your security team can implement consistently instead of looking at all projects as one-offs. Over time, you will identify trends and opportunities to build security into a whole range of processes, from system builds to HR practices to vendor selection. Building security in and letting your audit team verify frees you up to look out the front window with the business instead of always watching the rear-view mirror. If you haven’t read up on the “security as a service” concept, do it now.<strong></strong></li><li><strong>Realize that bolt-ons fall off. </strong>If you cannot build security in to an organizational process and need to bolt on controls—which is the current state of application security—don’t make the mistake of setting and forgetting. Put a system in place to let you know when those bolted on controls come flying off. We’ve seen faulty one-off <a
href="http://www.savidtech.com/blog/tag/security-controls/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Security controls">security controls</a> and processes bring down even the most automated security systems. Think of F1 racing teams; these guys have sensors for every small part on the car. If one piece falls off, it changes the entire aerodynamic profile of the vehicle and could cost them the race. Therefore, they put detective controls in place to perceive when preventive controls fail.<strong></strong></li></ol><p>The built-in vs. bolt-on debate will continue to rage. But the fact is, more vendors will be promising built-in security, and while this will make the business decision to use certain products and services easier for management, it doesn’t mean you can let your guard down. Never assume that these products are more secure or won’t introduce risk into the organization. Rather, the risk will simply move from technical vulnerabilities to process and management—which, unfortunately, are some of the weakest areas in risk programs.</p> ]]></content:encoded> <wfw:commentRss>http://www.savidtech.com/blog/it-security/security-industry-fad/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Savid CEO Discusses How Security Falls Short When It Comes To Dealing With Growing Cyber Attacks</title><link>http://www.savidtech.com/blog/news/savid-ceo-discusses-security-falling-short-dealing-growing-cyber-attacks/</link> <comments>http://www.savidtech.com/blog/news/savid-ceo-discusses-security-falling-short-dealing-growing-cyber-attacks/#comments</comments> <pubDate>Sat, 11 Feb 2012 08:19:32 +0000</pubDate> <dc:creator>Savid Technologies</dc:creator> <category><![CDATA[News]]></category> <guid
isPermaLink="false">http://www.savidtech.com/?p=1587</guid> <description><![CDATA[Savid CEO, Michael Davis, is quoted by NetworkComputing.com regarding how  total number of network breaches are on the rise, although data loss from cyber attacks has decreased significantly: According to Michael Davis, CEO of a Chicago-based security consulting firm, Savid Technologies, and author of the new InformationWeek Reports How to Pick Endpoint Protection, malware was by far [...]]]></description> <content:encoded><![CDATA[<p>Savid CEO, Michael Davis, is quoted by NetworkComputing.com regarding how  total number of network breaches are on the rise, although data loss from cyber attacks has decreased significantly:</p><blockquote><p>According to Michael Davis, CEO of a Chicago-based security consulting firm, Savid Technologies, and author of the new InformationWeek Reports <a
href="http://pro.networkcomputing.com/asset/8660/strategy-how-to-pick-endpoint-protection.html">How to Pick Endpoint Protection</a>, malware was by far the most common reason for security breaches suffered by respondents to the InformationWeek 2011 Strategic Security Survey. He says they routinely see users dismiss a security prompt or choose to execute a program (which turns out to be malicious) because they are irritated at being interrupted or don&#8217;t understand the consequences of their actions.</p></blockquote><p><a
title="Security Falling Short When It Comes To Dealing With Growing Cyber Attacks" href="http://www.networkcomputing.com/security/232600665" target="_blank">Read the entire article &gt;&gt;</a></p> ]]></content:encoded> <wfw:commentRss>http://www.savidtech.com/blog/news/savid-ceo-discusses-security-falling-short-dealing-growing-cyber-attacks/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Phishing Scams: Don’t Take the Bait</title><link>http://www.savidtech.com/blog/it-security/phishing-scams-dont-take-the-bait/</link> <comments>http://www.savidtech.com/blog/it-security/phishing-scams-dont-take-the-bait/#comments</comments> <pubDate>Fri, 10 Feb 2012 14:50:04 +0000</pubDate> <dc:creator>Michael A. Davis</dc:creator> <category><![CDATA[IT Security]]></category> <category><![CDATA[newsletter]]></category> <guid
isPermaLink="false">http://www.savidtech.com/?p=1598</guid> <description><![CDATA[We all do it—open our email accounts and quickly fly through and delete the spam before settling in to sift through messages that have some value to us. But before you start clicking links or downloading files, are you certain that none of those seemingly valued emails is actually from a cybercriminal posing as someone [...]]]></description> <content:encoded><![CDATA[<p><img
class="aligncenter size-medium wp-image-1599" title="e-wolf-phishing" src="http://www.savidtech.com/wp-content/uploads/e-wolf-phishing-300x174.jpg" alt="e wolf phishing 300x174 Phishing Scams: Don’t Take the Bait" width="300" height="174" /></p><p>We all do it—open our email accounts and quickly fly through and delete the spam before settling in to sift through messages that have some value to us. But before you start clicking links or downloading files, are you certain that none of those seemingly valued emails is actually from a cybercriminal posing as someone else in a bid to install malicious software on your computer and steal your data and personal information?</p><p>There are some red flags that can help determine if an email is legitimate. Pass these tips on to others, so they can defend their information against cybercriminals, too.</p><p><strong>Spelling and bad grammar:</strong> Legitimate companies employ copy editors to review content before circulation, so there should be no spelling or grammatical errors. Cybercriminals, on the other hand, tend not to worry about such niceties. Beware when you see misspellings or other grammatical inaccuracies.</p><p><strong>Links in emails: </strong>Look before you click. Whenever an email contains a link that you want to access, before you click to open it, hover your cursor over the link to see if the addresses match. If not, refrain from clicking the link.</p><p><strong>Threats: </strong>One sign that may indicate a phishing scheme is receiving a threat, such as, “Your account will be closed if you don’t respond by clicking the link below.” Another red flag is alerts that your security has been compromised.</p><p><strong>Spoofing companies and websites:</strong> These are e-wolves in sheep’s clothing. Often, cybercriminals will place logos and other imagery belonging to the companies they’re impersonating into the message body, then link those images to their malicious scam sites. If you do click on an image and are brought to the supposed site, look closely at the URL. Some scammers will use an address that closely resembles the URL of the company they’re looking to imitate; an example would be http://www.applle.com. You can also use the hovering maneuver with images.</p><p>So now that you know what to be aware of, the next hurdle is determining what to do if you have been subjected to a scam. First, report it. If you’re a Microsoft Office Outlook user, attach a copy of the email to a new email and send it to <a
href="mailto:reportphishing@antiphishing.org">reportphishing@antiphishing.org</a>. Most importantly if you have been a victim, change all PIN numbers and passwords on any accounts that may have been compromised. Contact your bank or online merchant if threats were issued saying your account has been compromised. Call your financial institution and have a <a
href="http://www.savidtech.com/blog/tag/fraud/" class="st_tag internal_tag" rel="tag" title="Posts tagged with fraud">fraud</a> alert placed on your credit reports. If your accounts have in fact been accessed, cancel those accounts and open new ones. Continue to closely monitor your account statements for unexplained transactions.</p> ]]></content:encoded> <wfw:commentRss>http://www.savidtech.com/blog/it-security/phishing-scams-dont-take-the-bait/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>The Future of Authentication? Not Passwords</title><link>http://www.savidtech.com/blog/it-security/future-authentication-passwords/</link> <comments>http://www.savidtech.com/blog/it-security/future-authentication-passwords/#comments</comments> <pubDate>Thu, 09 Feb 2012 12:59:24 +0000</pubDate> <dc:creator>Michael A. Davis</dc:creator> <category><![CDATA[IT Security]]></category> <category><![CDATA[newsletter]]></category> <guid
isPermaLink="false">http://www.savidtech.com/?p=1602</guid> <description><![CDATA[Passwords are a pain. The helpdesk hates resetting them. Security hates managing them. And users just plain hate them. The very term “password” reveals the fundamental flaw—we should be using pass phrases. Most modern operating systems, including Windows, OS X and Unix, support phrases with over 200 characters. Uncle Sam has a better idea, which [...]]]></description> <content:encoded><![CDATA[<p><a
href="http://www.savidtech.com/blog/it-security/future-authentication-passwords/attachment/password-secret-joke/" rel="attachment wp-att-1603"><img
class="alignleft size-medium wp-image-1603" title="The Truth About Passwords" src="http://www.savidtech.com/wp-content/uploads/password-secret-joke-300x183.png" alt="password secret joke 300x183 The Future of Authentication? Not Passwords" width="300" height="183" /></a></p><p>Passwords are a pain. The helpdesk hates resetting them. Security hates managing them. And users just plain hate them. The very term “password” reveals the fundamental flaw—we should be using pass phrases. Most modern operating systems, including Windows, OS X and Unix, support phrases with over 200 characters.</p><p>Uncle Sam has a better idea, which we’ll discuss. For now, let’s admit that security awareness trainers’ attempts to promote better passwords and our fancy policies to ensure complexity have failed. Part of the problem is that, to most organizations, a password of “Winter12” qualifies as complex. An analysis of the breached Sony accounts showed that while 93% of passwords were between six and 10 characters in length, only 1% contained an alphanumeric, and less than 1% were longer than 14 characters. The Top 3 passwords used: “seinfeld,” “password” and “winner.” Further analysis showed that 82% of passwords were found within rainbow tables.</p><p>So users make bad password decisions. We know this. But that isn’t the only reason they need to go. A problem just as significant as strength is that passwords and, for that matter, pass phrases provide authentication only once, when typed in or provided. There’s no mechanism for continuous re-authentication without interrupting user workflow. Think about the way attacks happen in the real world: ATM skimmers record PINs and reuse them later. The ATM has no way to know it was a fraudster who typed in the PIN. If a user walks away from a mobile device or PC, an attacker can jump on and take control of the session. Even metasploit, the open source exploit framework, has the ability to take control of RDP and VNC sessions from legitimate users.</p><p>This leads us to the requirement for continuous authentication in future system designs. Fortunately for enterprises, the U.S. government is putting our tax dollars behind R&amp;D for just such a cause. The Defense Advanced Research Projects Agency (DARPA) has released a grant to promote development of “active authentication.” DARPA states: “The current standard method for validating a user’s identity for authentication on an information system requires humans to do something that is inherently difficult: create, remember and manage long, complex passwords. Moreover, as long as the session remains active, typical systems incorporate no mechanisms to verify that the user originally authenticated is the user still in control of the keyboard. Thus, unauthorized individuals may improperly obtain extended access to information system resources if a password is compromised or if a user does not exercise adequate vigilance after initially authenticating at the console.”</p><p>DARPA’s recommendation solution is to develop a “cognitive fingerprint,” which is government speak for biometric tests that will include keystroke-latency analysis, eye scans, how a user searches for information, eye tracking and the speed with which a person reads content. The key is to develop a profile of an individual so that once an authorized user is authenticated, each move can reauthenticate the person, at a frequency as great as every second. With this technique, even if someone’s password is “seinfield” and an attacker takes over a session, the cognitive fingerprint won’t match and the session can be shut down. If an action requires administrative privileges, the cognitive fingerprint can provide the authentication system with additional statistical confidence that the user is actually who he’s supposed to be.</p><p>While passwords may not be gone completely in our lifetimes, the way we use them will change dramatically as additional metrics are brought online to authenticate and then continually reauthenticate users as they access a system. As technology like that behind Microsoft’s Kinect makes it into laptops, desktops and even smartphones, be prepared for new behavioral biometric authentication frameworks to make a strong introduction.</p> ]]></content:encoded> <wfw:commentRss>http://www.savidtech.com/blog/it-security/future-authentication-passwords/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Savid finds 21% of IT Pros Think Their Encryption Initiatives Are Falling Behind Peers</title><link>http://www.savidtech.com/blog/news/savid-finds-21-pros-encryption-initiatives-falling-peers/</link> <comments>http://www.savidtech.com/blog/news/savid-finds-21-pros-encryption-initiatives-falling-peers/#comments</comments> <pubDate>Wed, 08 Feb 2012 01:25:27 +0000</pubDate> <dc:creator>Savid Technologies</dc:creator> <category><![CDATA[News]]></category> <guid
isPermaLink="false">http://www.savidtech.com/?p=1590</guid> <description><![CDATA[New InformationWeek Reports Research Finds 21% of IT Pros Think Their Encryption Initiatives Are Falling Behind Peers At 94%, SSL or IPSec VPNs most common encryption deployed; TPM and cloud encryption least used By UBM TechWeb Published: Tuesday, Feb. 7, 2012 &#8211; 9:07 am SAN FRANCISCO,  Feb. 7, 2012 &#8211; /PRNewswire/ &#8211; InformationWeek Reports (www.reports.informationweek.com ), a service provider for [...]]]></description> <content:encoded><![CDATA[<div
id="story_header"><h3 id="story_headline">New InformationWeek Reports Research Finds 21% of IT Pros Think Their Encryption Initiatives Are Falling Behind Peers</h3><h4 id="story_subheadline"><strong>At 94%, SSL or IPSec VPNs most common encryption deployed; TPM and cloud encryption least used</strong></h4><div><div>By <a
title="Read more articles by UBM TechWeb" href="http://www.sacbee.com/search_results/?sf_pubsys_story_byline=UBM%20TechWeb&amp;link_location=top">UBM TechWeb</a></div></div><div><div
title="2012-02-07T09:07:48-0800">Published: Tuesday, Feb. 7, 2012 &#8211; 9:07 am</div></div></div><div
id="articlebody"><p><a
href="http://topics.sacbee.com/SAN+FRANCISCO/" rel="nofollow">SAN FRANCISCO,</a>  Feb. 7, 2012 &#8211; /PRNewswire/ &#8211; InformationWeek Reports (<a
href="http://www.reports.informationweek.com/" target="_blank">www.reports.informationweek.com</a> ), a service provider for peer-based IT research and analysis, announced the release of its latest research report. <strong>Data Encryption: Ushering In a New Era </strong>encompasses analysis of results from InformationWeek&#8217;s recent 2012 data encryption survey and guides readers in choosing and deploying encryption to support a data-centric <a
href="http://topics.sacbee.com/security+policy/" rel="nofollow">security policy.</a> More than 500 business technology professionals responded to this poll.</p><p><strong>Research Summary:</strong></p><p>As longstanding protocols come under attack and sensitive data moves to mobile devices and offsite cloud providers&#8217; systems, encryption adoption is growing, albeit modestly. In our 2012 survey, 91% of respondents are using some encryption vs. 86% in our July 2009 poll.</p><p><strong>Findings: </strong></p><ul
type="disc"><li>67% of our survey respondents encrypt <a
href="http://topics.sacbee.com/Social+Security+numbers/" rel="nofollow">Social Security numbers.</a></li><li>49% currently use mobile device encryption for smartphones and tablets.</li><li>33% have implemented encryption at the database level.</li><li>19% categorize their encryption use as pervasive, with widespread use across the enterprise.</li></ul><p>The report author, Michael A. Davis, serves as CEO of Chicago-based technology and security consultancy Savid Technologies.</p><p><strong>For full access to the research data, members can download now</strong>:<a
href="http://reports.informationweek.com/abstract/21/8628/Security/research-data-encryption.html" target="_blank">http://reports.informationweek.com/abstract/21/8628/Security/research-data-encryption.html</a></p><p>&#8220;Despite media attention, Zappos actually is a poster child for proper encryption of <a
href="http://topics.sacbee.com/credit+card/" rel="nofollow">credit card</a> data,&#8221; says report author Michael A. Davis. &#8220;They tokenized the data, so nothing was actually breached. The last four digits of a <a
href="http://www.savidtech.com/blog/tag/credit-card/" class="st_tag internal_tag" rel="tag" title="Posts tagged with credit card">credit card</a> are useless to an attacker. And, Zappos obfuscated passwords. In contrast, only 52% of respondents encrypt <a
href="http://www.savidtech.com/blog/tag/credit-card/" class="st_tag internal_tag" rel="tag" title="Posts tagged with credit card">credit card</a> numbers, and 35% encrypt data archived on tape.&#8221;</p><p><strong>For more information:<br
/> </strong>Art Wittmann     VP &amp; Managing Director, InformationWeek Reports415-947-6361<a
href="mailto:awittmann@techweb.com" target="_blank">awittmann@techweb.com</a></p><p><strong>About InformationWeek Business Technology Network </strong>(<a
href="http://www.informationweek.com/" target="_blank">www.informationweek.com</a> )</p><p>The InformationWeek Business Technology Network provides IT executives with unique analysis and tools that parallel their work flow—from defining and framing objectives through to the evaluation and recommendation of solutions. Anchored by InformationWeek, the multimedia powerhouse that looks across the enterprise, the network scales across the most critical technology categories with online properties like DarkReading.com (security), NetworkComputing.com (networking and communications) and BYTE (consumer technology). The network also provides focused content for key IT targets, such as CIOs, developers, and SMBs via InformationWeek Global CIO, Dr. Dobb&#8217;s and InformationWeek SMB, as well as vital vertical industries with InformationWeek Financial Services, Government and Healthcare sites. Content is at the nucleus of our information distribution strategy—IT professionals turn to our experts and communities to stay informed, get advice and research technologies to make strategic business decisions.</p><p><strong>About UBM TechWeb</strong> (<a
href="http://www.ubmtechweb.com/" target="_blank">www.ubmtechweb.com</a> )</p><p>UBM TechWeb, the global leader in technology media and professional information, enables people and organizations to harness the transformative power of technology. Through its three core businesses – media solutions, marketing services and paid content – UBM TechWeb produces the most respected and consumed brands and media applications in the technology market. More than 14.5 million business and technology professionals (CIOs and IT managers, Web &amp; Digital professionals, <a
href="http://topics.sacbee.com/Software+Developers/" rel="nofollow">Software Developers,</a>  Government decision makers, and Telecom providers) actively engage in UBM TechWeb&#8217;s communities and information resources monthly. UBM TechWeb brands include: global face-to-face events such as Interop, <a
href="http://topics.sacbee.com/Web+2.0/" rel="nofollow">Web 2.0,</a>  <a
href="http://topics.sacbee.com/Black+Hat/" rel="nofollow">Black Hat</a>  and Enterprise Connect; award-winning online resources such as InformationWeek, Light Reading, and Network Computing; and market-leading magazines InformationWeek, Wall Street &amp; Technology, and Advanced Trading. UBM TechWeb is a UBM plc company, a global provider of news distribution and specialist information services with a market capitalization of more than $2.5 billion.</p><p>SOURCE UBM TechWeb</p></div> ]]></content:encoded> <wfw:commentRss>http://www.savidtech.com/blog/news/savid-finds-21-pros-encryption-initiatives-falling-peers/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Savid Research &#8211; Encryption Key To Evolving Data-Centric Security Model</title><link>http://www.savidtech.com/blog/news/savid-research-encryption-key-evolving-datacentric-security-model/</link> <comments>http://www.savidtech.com/blog/news/savid-research-encryption-key-evolving-datacentric-security-model/#comments</comments> <pubDate>Tue, 07 Feb 2012 19:28:38 +0000</pubDate> <dc:creator>Savid Technologies</dc:creator> <category><![CDATA[News]]></category> <guid
isPermaLink="false">http://www.savidtech.com/?p=1593</guid> <description><![CDATA[Savid&#8217;s CEO, Michael Davis, talks with Chris Talbot regarding Savid&#8217;s latest research report, &#8220;Data Encryption: Ushering In a New Era&#8221; &#8220;Furthermore, the determination of what is encrypted or not is based on the data itself,&#8221; Davis said. &#8220;Depending on the classification schemes of the organization, it could mean credit card data, PII (personally identifiable information), [...]]]></description> <content:encoded><![CDATA[<p>Savid&#8217;s CEO, Michael Davis, talks with Chris Talbot regarding Savid&#8217;s latest research report, &#8220;Data Encryption: Ushering In a New Era&#8221;</p><blockquote><p>&#8220;Furthermore, the determination of what is encrypted or not is based on the data itself,&#8221; Davis said. &#8220;Depending on the classification schemes of the organization, it could mean <a
href="http://www.savidtech.com/blog/tag/credit-card/" class="st_tag internal_tag" rel="tag" title="Posts tagged with credit card">credit card</a> data, PII (personally identifiable information), or PHI (protected health information). Using this approach reduces the risk of having to manage and detect when data leaves the organization because you can be assured it is encrypted no matter where it is.&#8221;</p></blockquote><p>Read the Entire Article,<a
title="Encryption Key To Evolving Data-Centric Security Model" href="http://www.networkcomputing.com/security/232600361" target="_blank"> Encryption Key To Evolving Data-Centric Security Model</a></p> ]]></content:encoded> <wfw:commentRss>http://www.savidtech.com/blog/news/savid-research-encryption-key-evolving-datacentric-security-model/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Davis provides clashing opinion on physical and logical security convergence</title><link>http://www.savidtech.com/blog/news/davis-clashing-opinion-physical-logical-security-convergence/</link> <comments>http://www.savidtech.com/blog/news/davis-clashing-opinion-physical-logical-security-convergence/#comments</comments> <pubDate>Fri, 20 Jan 2012 08:34:18 +0000</pubDate> <dc:creator>Savid Technologies</dc:creator> <category><![CDATA[News]]></category> <guid
isPermaLink="false">http://www.savidtech.com/?p=1596</guid> <description><![CDATA[Secuirity Director News quotes Savid Technologies, CEO, Michael Davis, opinion on physical and logical convergence: The results from the InformationWeek survey prompted its author, Michael Davis, CEO of Savid Technologies, to begin the report with the declaration: &#8220;The wheels have officially come off the security convergence bandwagon.&#8221; Read the rest of the article and learn [...]]]></description> <content:encoded><![CDATA[<p>Secuirity Director News quotes Savid Technologies, CEO, Michael Davis, opinion on physical and logical convergence:</p><blockquote><p>The results from the InformationWeek survey prompted its author, Michael Davis, CEO of Savid Technologies, to begin the report with the declaration: &#8220;The wheels have officially come off the security convergence bandwagon.&#8221;</p></blockquote><p>Read the rest of the article and learn what Savid believes is the future of physical and logical security.</p><p>Security Director News, <a
title="Two surveys expose clashing opinions on physical and logical security convergence" href="http://www.securitydirectornews.com/?p=article&amp;id=sd2012015L5kXA" target="_blank">Two surveys expose clashing opinions on physical and logical security convergence</a></p> ]]></content:encoded> <wfw:commentRss>http://www.savidtech.com/blog/news/davis-clashing-opinion-physical-logical-security-convergence/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>If You Cannot Prevent It, Detect It: Why Defense In Depth Works</title><link>http://www.savidtech.com/blog/application-security/if-you-cannot-prevent-it-detect-it-why-defense-in-depth-works/</link> <comments>http://www.savidtech.com/blog/application-security/if-you-cannot-prevent-it-detect-it-why-defense-in-depth-works/#comments</comments> <pubDate>Sun, 08 Jan 2012 22:25:09 +0000</pubDate> <dc:creator>Michael A. Davis</dc:creator> <category><![CDATA[Application Security]]></category> <category><![CDATA[HIPAA]]></category> <category><![CDATA[IT Security]]></category> <category><![CDATA[PCI]]></category> <category><![CDATA[application security defense in depth]]></category> <category><![CDATA[Data Breach]]></category> <category><![CDATA[defense in depth]]></category> <category><![CDATA[ethical hackers]]></category> <category><![CDATA[ethical hacking]]></category> <category><![CDATA[GLBA]]></category> <category><![CDATA[honeytokens]]></category> <category><![CDATA[prevent breach]]></category> <category><![CDATA[Security controls]]></category> <category><![CDATA[SQL]]></category> <category><![CDATA[SQL injection]]></category> <guid
isPermaLink="false">http://www.savidtech.com/blog/?p=759</guid> <description><![CDATA[As audit season is finally over, (over 65% of all our assessments and audits happen in Q4) we finally have a chance to grab a cup of coffee and look back at a couple trends in 2011 that we think separate the best security teams from the worst. First, we need to discuss how we [...]]]></description> <content:encoded><![CDATA[<p><img
class="alignleft size-thumbnail wp-image-760" style="text-decoration: line-through; padding: 0px 5px 5px 0px;" title="If You Cannot Prevent It, Detect It" src="http://www.savidtech.com/wp-content/uploads/2012/01/prevention-150x150.jpg" alt="prevention 150x150 If You Cannot Prevent It, Detect It: Why Defense In Depth Works" width="150" height="150" /> As audit season is finally over, (over 65% of all our assessments and audits happen in Q4) we finally have a chance to grab a cup of coffee and look back at a couple trends in 2011 that we think separate the best security teams from the worst.</p><p>First, we need to discuss how we measure the quality of a security team. At Savid, it is pretty simple. Since we perform <a
href="http://www.savidtech.com/blog/tag/ethical-hacking/" class="st_tag internal_tag" rel="tag" title="Posts tagged with ethical hacking">ethical hacking</a> to assess security programs at organizations, if we got access to something we shouldn’t have, it counts as an intrusion in our books.</p><p>Most reviews of <a
href="http://www.savidtech.com/blog/tag/security-controls/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Security controls">security controls</a> look at what went wrong because it’s harder to learn from the successes. So let’s get the major failures of 2011 out of the way and then let’s talk about what our best clients did to prevent us from breaking in. Overall, most of the security programs we assessed had application security issues. However, 2011 was the worst we have ever seen in terms of the depth and breadth of application security issues &#8211; even though the majority of the security programs we tested were in compliance with regulations such as <a
href="http://www.savidtech.com/blog/tag/hipaa/" class="st_tag internal_tag" rel="tag" title="Posts tagged with HIPAA">HIPAA</a>, <a
href="http://www.savidtech.com/blog/tag/pci/" class="st_tag internal_tag" rel="tag" title="Posts tagged with PCI">PCI</a>, and <a
href="http://www.savidtech.com/blog/tag/glba/" class="st_tag internal_tag" rel="tag" title="Posts tagged with GLBA">GLBA</a>.</p><p>Ok, so with that out of the way, what did the best security teams do to prevent our <a
href="http://www.savidtech.com/blog/tag/ethical-hackers/" class="st_tag internal_tag" rel="tag" title="Posts tagged with ethical hackers">ethical hackers</a> from breaking in?  One Thing: <a
href="http://www.savidtech.com/blog/tag/defense-in-depth/" class="st_tag internal_tag" rel="tag" title="Posts tagged with defense in depth">Defense In Depth</a>. 2011 was the first year where we saw significant advancements in <a
href="http://www.savidtech.com/blog/tag/defense-in-depth/" class="st_tag internal_tag" rel="tag" title="Posts tagged with defense in depth">defense in depth</a> deployments among our clients. For example, we saw a noticeable increase in proper system hardening (using standards such as CIS and NIST) and reduction of excessive permissions that stopped our attacks cold.</p><p>Properly deploying <a
href="http://www.savidtech.com/blog/tag/defense-in-depth/" class="st_tag internal_tag" rel="tag" title="Posts tagged with defense in depth">defense in depth</a> can be the distinction between a <a
href="http://www.savidtech.com/blog/tag/data-breach/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Data Breach">data breach</a> requiring notification or a simple documented incident. The difference between the two for some organizations could be millions of dollars. Oh, and it also has a side effect of making most malware non-functional by preventing the malware from creating temporary files, accessing DLLs, etc. Remember, an attacker can’t exfiltrate data if the exfiltration tools won’t run!</p><p>So, how did the <a
href="http://www.savidtech.com/blog/tag/defense-in-depth/" class="st_tag internal_tag" rel="tag" title="Posts tagged with defense in depth">defense in depth</a> stop our hacking? Most of the time we were able to get entry into a server or application but because of <a
href="http://www.savidtech.com/blog/tag/defense-in-depth/" class="st_tag internal_tag" rel="tag" title="Posts tagged with defense in depth">defense in depth</a> we weren’t able to leverage that entry for any gain (such as privilege escalation, intellectual property, or personally identifiable information). For example, if we got access to an application via <a
href="http://www.savidtech.com/blog/tag/sql-injection/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SQL injection">SQL injection</a>, we weren’t able to execute any commands on the server because the <a
href="http://www.savidtech.com/blog/tag/sql/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SQL">SQL</a> server was hardened to prevent usage of xp_cmd and the <a
href="http://www.savidtech.com/blog/tag/sql/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SQL">SQL</a> service account had no local permissions on the box to do anything other than access the database files and folders. Another example is when we got access to a Linux system running a custom PHP login system via an upload vulnerable and a PHP Shell script. The hardening of Apache and the file system prevented our low privileged web server service account from reading local files, creating files, etc. Essentially, the account we got control of was useless and the attack vector wasted our time and effort.</p><p>Wasting an attacker’s time and effort is exactly what you as the defender want to do. Every minute an attacker is stalled or delayed is more time for your detective controls such as IDS/IPS, Logging, or even Tripwire like defenses to detect an attack. We recommend that every security program have a simple theme: If You Cannot Prevent It, Detect It. Leveraging defense in depth provides additional detection points along the attack path. Every time a low privileged user attempts to access the Accounting Share – detect it. Every time a server in your DMZ attempts to connect to a server in the internal network (which should be blocked by the firewall) detect it and respond to it. These are all indicators that the server is doing something it shouldn’t.</p><p>Our number one recommendation when deploying defense in depth with proper detection controls is the use of fake records &#8211; commonly called “<a
href="http://www.savidtech.com/blog/tag/honeytokens/" class="st_tag internal_tag" rel="tag" title="Posts tagged with honeytokens">honeytokens</a>”. For example, if you have a public web application that has access to an internal database server through a firewall, place a fake record in the database using a randomly generated 30-64 character value. This record has no value and should never be accessed via normal web application use. If your firewall, web filter, or DLP system ever sees this traffic move across the network – something went wrong and you need to find out why.</p><p>Every year Verizon releases their Data Breach investigations Report and year after year they mention the same problem: The time between a breach occurring and detection of the breach is too long, sometimes it takes years! So this year, add some more defense in depth controls to your security program and watch how quickly it helps reduce the impact of a vulnerability.</p> Tags: <a
href="http://www.savidtech.com/blog/tag/application-security-defense-in-depth/" title="application security defense in depth" rel="tag">application security defense in depth</a>, <a
href="http://www.savidtech.com/blog/tag/data-breach/" title="Data Breach" rel="tag">Data Breach</a>, <a
href="http://www.savidtech.com/blog/tag/defense-in-depth/" title="defense in depth" rel="tag">defense in depth</a>, <a
href="http://www.savidtech.com/blog/tag/ethical-hackers/" title="ethical hackers" rel="tag">ethical hackers</a>, <a
href="http://www.savidtech.com/blog/tag/ethical-hacking/" title="ethical hacking" rel="tag">ethical hacking</a>, <a
href="http://www.savidtech.com/blog/tag/glba/" title="GLBA" rel="tag">GLBA</a>, <a
href="http://www.savidtech.com/blog/tag/hipaa/" title="HIPAA" rel="tag">HIPAA</a>, <a
href="http://www.savidtech.com/blog/tag/honeytokens/" title="honeytokens" rel="tag">honeytokens</a>, <a
href="http://www.savidtech.com/blog/tag/pci/" title="PCI" rel="tag">PCI</a>, <a
href="http://www.savidtech.com/blog/tag/prevent-breach/" title="prevent breach" rel="tag">prevent breach</a>, <a
href="http://www.savidtech.com/blog/tag/security-controls/" title="Security controls" rel="tag">Security controls</a>, <a
href="http://www.savidtech.com/blog/tag/sql/" title="SQL" rel="tag">SQL</a>, <a
href="http://www.savidtech.com/blog/tag/sql-injection/" title="SQL injection" rel="tag">SQL injection</a><br
/> ]]></content:encoded> <wfw:commentRss>http://www.savidtech.com/blog/application-security/if-you-cannot-prevent-it-detect-it-why-defense-in-depth-works/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>How to Stay Safe While Shopping Online</title><link>http://www.savidtech.com/blog/general/how-to-stay-safe-while-shopping-online/</link> <comments>http://www.savidtech.com/blog/general/how-to-stay-safe-while-shopping-online/#comments</comments> <pubDate>Sun, 08 Jan 2012 22:11:52 +0000</pubDate> <dc:creator>Michael A. Davis</dc:creator> <category><![CDATA[General]]></category> <category><![CDATA[bbb]]></category> <category><![CDATA[credit card]]></category> <category><![CDATA[credit card data]]></category> <category><![CDATA[ebay]]></category> <category><![CDATA[Electronic commerce]]></category> <category><![CDATA[fraud]]></category> <category><![CDATA[online shopping]]></category> <category><![CDATA[paypal]]></category> <category><![CDATA[TRUSTe]]></category> <guid
isPermaLink="false">http://www.savidtech.com/blog/?p=755</guid> <description><![CDATA[As we all know, online shopping is nothing new but as its popularity continues to grow so does the malicious threats that can occur during your shopping experience.  That is why we want to provide you with some reminders and tips on how to make you’re online shopping a safer experience.  We also encourage you [...]]]></description> <content:encoded><![CDATA[<p><a
href="http://www.savidtech.com/wp-content/uploads/2012/01/online_shopping.jpg"><img
class="alignleft size-thumbnail wp-image-756" title="Stay Secure When Shopping Online" src="http://www.savidtech.com/wp-content/uploads/2012/01/online_shopping-150x150.jpg" alt="online shopping 150x150 How to Stay Safe While Shopping Online" width="150" height="150" /></a>As we all know, <a
href="http://www.savidtech.com/blog/tag/online-shopping/" class="st_tag internal_tag" rel="tag" title="Posts tagged with online shopping">online shopping</a> is nothing new but as its popularity continues to grow so does the malicious threats that can occur during your shopping experience.  That is why we want to provide you with some reminders and tips on how to make you’re <a
href="http://www.savidtech.com/blog/tag/online-shopping/" class="st_tag internal_tag" rel="tag" title="Posts tagged with online shopping">online shopping</a> a safer experience.  We also encourage you to share these tips with your family who may make online purchases too.</p><p>There are a few simple precautions you can take to further secure yourself before you make your online purchases.  First make sure you have a web filter in place that will warn you of suspicious websites. Keep your web browsers up to date too. Often times the site you are shopping on is legitimate but if your computer is infected with keyloggers and other malicious viruses you can run the risk of your <a
href="http://www.savidtech.com/blog/tag/credit-card/" class="st_tag internal_tag" rel="tag" title="Posts tagged with credit card">credit card</a> data being stolen.</p><p>It is always best to shop at familiar websites but if you are looking at products or services from an unfamiliar sight do a little research before you begin; find out what other consumers have to say about the store or seller.  Epinions.com and BizRate.com give customer evaluations that may help you determine the legitimacy of the company.  It is also a good idea to review the website for the <a
href="http://www.savidtech.com/blog/tag/bbb/" class="st_tag internal_tag" rel="tag" title="Posts tagged with bbb">BBB</a> and or <a
href="http://www.savidtech.com/blog/tag/truste/" class="st_tag internal_tag" rel="tag" title="Posts tagged with TRUSTe">TRUSTe</a> approval icons.  Be sure to click those icons to ensure that they take you to those accredited sites and that you can find the companies name within their listings. Often times harmful sights will display the graphic with no link so be aware.</p><p>Remember, before entering your personal data and credit card information check the connection of the website out to make sure it is encrypted. The URL will start with (http<strong>“s”</strong>) and also look for the padlock icon in the address bar or right corner of the window.  Be aware of any warnings that your computer gives you regarding the security certificate of the site, when in doubt find somewhere else to shop.</p><p>Keep in mind when choosing a payment method it is always best to use <a
href="http://www.savidtech.com/blog/tag/paypal/" class="st_tag internal_tag" rel="tag" title="Posts tagged with paypal">PayPal</a> if it is an option, that way your credit card and bank account information will not be shared with the merchants and sellers. <a
href="http://www.savidtech.com/blog/tag/paypal/" class="st_tag internal_tag" rel="tag" title="Posts tagged with paypal">PayPal</a> will also protect you against fraudulent charges and if there are problems with your purchases. Once your purchases are made it’s always a good idea to check your bank accounts and credit card statements to ensure the proper amount was charged; if the charges are wrong contact the website where your purchases were made immediately along with calling your  Credit Card Company to inquire about a “charge back”.</p><p>We hope that by keeping these tips in mind that you will continue to enjoy shopping online and are more secure in doing so.</p> Tags: <a
href="http://www.savidtech.com/blog/tag/bbb/" title="bbb" rel="tag">bbb</a>, <a
href="http://www.savidtech.com/blog/tag/credit-card/" title="credit card" rel="tag">credit card</a>, <a
href="http://www.savidtech.com/blog/tag/credit-card-data/" title="credit card data" rel="tag">credit card data</a>, <a
href="http://www.savidtech.com/blog/tag/ebay/" title="ebay" rel="tag">ebay</a>, <a
href="http://www.savidtech.com/blog/tag/electronic-commerce/" title="Electronic commerce" rel="tag">Electronic commerce</a>, <a
href="http://www.savidtech.com/blog/tag/fraud/" title="fraud" rel="tag">fraud</a>, <a
href="http://www.savidtech.com/blog/tag/online-shopping/" title="online shopping" rel="tag">online shopping</a>, <a
href="http://www.savidtech.com/blog/tag/paypal/" title="paypal" rel="tag">paypal</a>, <a
href="http://www.savidtech.com/blog/tag/truste/" title="TRUSTe" rel="tag">TRUSTe</a><br
/> ]]></content:encoded> <wfw:commentRss>http://www.savidtech.com/blog/general/how-to-stay-safe-while-shopping-online/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
