How much should I spend on Cybersecurity?

I want to discuss 2 articles and then answer the question on the title. http://www.theguardian.com/small-business-network/2015/mar/24/hackers-cyberwar-businesses-cybercrime {Hackers are winning the cyberwar and businesses are all too often simply hoping for the best, according to many security experts. } Cost of Cybercrime in UK is £18-27bn … supposedly.  This could actually be low, since many people do not … Read more

Have You Been Hacked? How Do You Know?

The following news story highlights stolen Uber email accounts which are worth $1 on the dark net (the criminal bazaar on the Internet where criminals buy and sell their wares) http://www.nydailynews.com/news/national/stolen-uber-accounts-sale-1-dark-net-article-1.2167072 (Image from Nypost. {A user on AlphaBay is selling log in credentials for $1 and a user on ThinkingForward-another dark web marketplace-is selling them … Read more

GitHub DDoS Attack Meaning

https://status.github.com/messages The status messages from the weekend state the problems GitHub had. We discussed a feint DDoS attack last week on blogpost: http://oversitesentry.com/ddos-not-only-for-disruption/   There are cases of DDoS that PCI compliance asks you to place the risk in a low category: Risk  level: Severity is low for Denial-of-service attack, abnormal termination   So the low risks are … Read more

Windows2003 Servers Will Not be Patched After Jul

Support for  http://www.microsoft.com/en-us/server-cloud/products/windows-server-2003/ Microsoft Windows Server 2003 patches will not be created anymore after July of this year. So what if it will take more than April, May, and June to Migrate all of your windows 2003 servers? Sometimes a migration takes a lot longer than 3 months. If you are not thinking about the … Read more

33% of “Top” Websites Compromised

http://www.infosecurity-magazine.com/news/one-in-every-3-top-websites-are/ What it means is Forbes.com  has been used for a zero-day malware dissemination. The reason hackers are using top websites is that they are classified as “safe” sites in  sitecheck.sucuri.net for example. But a major site would be expected to have no malware. this is what is called a watering hole attack. Wikipedia explains in this … Read more