Insider Knowledge Threats and Action

We know Insider trading is bad – even though we all want the money, the info to know that there will be good news before the news becomes public is sometimes draws a certain person like a moth to a flame.   image from slide: http://www.slideshare.net/Identacor/8-nastiest-data-breaches-in-2015 7. Morgan Stanley insider theft: Morgan Stanley fired an employee … Read more

How Can You Test Your Network? Safely-Legally?

Let’s assume that you agree that some sort of testing of your computers/network is required or should be done.   How should you test your network? There are daily scans coming onto all ip addresses on the Internet. This is a fact of life.  What is going on? We have talked about this before: http://oversitesentry.com/how-many-scans-are-attacking-the-internet/ {Most … Read more

How much should I spend on Cybersecurity?

I want to discuss 2 articles and then answer the question on the title. http://www.theguardian.com/small-business-network/2015/mar/24/hackers-cyberwar-businesses-cybercrime {Hackers are winning the cyberwar and businesses are all too often simply hoping for the best, according to many security experts. } Cost of Cybercrime in UK is £18-27bn … supposedly.  This could actually be low, since many people do not … Read more

Have You Been Hacked? How Do You Know?

The following news story highlights stolen Uber email accounts which are worth $1 on the dark net (the criminal bazaar on the Internet where criminals buy and sell their wares) http://www.nydailynews.com/news/national/stolen-uber-accounts-sale-1-dark-net-article-1.2167072 (Image from Nypost. {A user on AlphaBay is selling log in credentials for $1 and a user on ThinkingForward-another dark web marketplace-is selling them … Read more

GitHub DDoS Attack Meaning

https://status.github.com/messages The status messages from the weekend state the problems GitHub had. We discussed a feint DDoS attack last week on blogpost: http://oversitesentry.com/ddos-not-only-for-disruption/   There are cases of DDoS that PCI compliance asks you to place the risk in a low category: Risk  level: Severity is low for Denial-of-service attack, abnormal termination   So the low risks are … Read more