I love cupcakes. I love baking them and I love eating them...
I also love finding analogies trying to explain relatively complex (or simple but little understood) concepts using everyday situations. And
today was my cupcake day, and a few friends last week asked me to explain how "The Cloud" works, so I just put two and two together and
came up with a simple picture...
A blog about information security, payments, risk, fraud, digital innovation and social media... Connect on LinkedIn?
Showing posts with label Cloud. Show all posts
Showing posts with label Cloud. Show all posts
6 August 2014
11 August 2013
I AM WHO I AM... OR AM I?
Google
I have spent the last 18 months pondering on the whole sphere of identity and authentication and a number of things have happened:
The analysts continue to tell us that lax password management and policies continue to put individuals and organisations at risk (according to the Trustwave Global Security Report 2013, Welcome1 is the most commonly used password by count - followed closely by STORE123 and Password1 - whereas Password1 is still most widely used when looking at % of unique active directory samples, followed closely by password1 and Welcome1)
I have spent the last 18 months pondering on the whole sphere of identity and authentication and a number of things have happened:
The analysts continue to tell us that lax password management and policies continue to put individuals and organisations at risk (according to the Trustwave Global Security Report 2013, Welcome1 is the most commonly used password by count - followed closely by STORE123 and Password1 - whereas Password1 is still most widely used when looking at % of unique active directory samples, followed closely by password1 and Welcome1)
15 July 2012
FAILING GRACEFULLY...
Google
Sometimes, despite our best endeavours, things just don't work out the way we planned...
You know the feeling: you think you have it all under control, you think you've engaged with the right people, you have buy in from those who matter, the right culture is in place, you're not struggling for investment and bang! you get hacked. Overwhelming sense of failure ensues. Where did it all go wrong?...
You know the feeling: you think you have it all under control, you think you've engaged with the right people, you have buy in from those who matter, the right culture is in place, you're not struggling for investment and bang! you get hacked. Overwhelming sense of failure ensues. Where did it all go wrong?...
9 May 2012
CLOSE ENCOUNTERS OF THE THIRD (PARTY) KIND...
Google
Phew... The last month was absolutely hectic, with all those conferences falling within the same short period of time! With all that, I was privileged enough to have been asked to speak at both Internet World and Infosecurity Europe. Two very different experiences... Whilst it is expected to be talking about security at an infosec conference, it is always welcome to be asked to present about security matters at an event with a different focus - in this instance, everything digital... (see my previous post on the subject). It was nevertheless surprising, walking the show floor at Internet World, talking to vendors and poring over the agendas in the various theatres, how little security featured. With everything about the show related to "cyber", not many had made the obvious leap to "cybercrime"... So, on the way to our Devil's Tower, our quest is still to find our curwen hand signs to communicate with the third (party) kind...
Phew... The last month was absolutely hectic, with all those conferences falling within the same short period of time! With all that, I was privileged enough to have been asked to speak at both Internet World and Infosecurity Europe. Two very different experiences... Whilst it is expected to be talking about security at an infosec conference, it is always welcome to be asked to present about security matters at an event with a different focus - in this instance, everything digital... (see my previous post on the subject). It was nevertheless surprising, walking the show floor at Internet World, talking to vendors and poring over the agendas in the various theatres, how little security featured. With everything about the show related to "cyber", not many had made the obvious leap to "cybercrime"... So, on the way to our Devil's Tower, our quest is still to find our curwen hand signs to communicate with the third (party) kind...
26 March 2012
VERIZON DBIR 2012 - some context...
Google
The Verizon
DBIR 2012 was released last week and I am sure you have seen a lot of blog
posts, articles and tweets on the subject... So let me try and put a different
perspective on it: many of you will have heard me say that the DBIR is the
“gift that keeps on giving”, and yes, it is! But as with every report,
statistics and opinions always have to be put into the right context... The conclusions are not surprising, but there are quite a few little
nuggets in the report that are worth examining...
To start with, I am glad to see that the analysis now offers
some separate insights in relation to SMEs and larger organisations, as some of
the issues can be different depending on size. The case load is also bigger
this year (855 incidents compared to 761 in 2010) and known compromised records
studied were also greater (3.8 million in 2010 compared to 174 million in 2011
- mostly due to the return of the “mega breaches” in 2011 after a relatively
quiet 2010).
Labels:
Cloud,
cybercrime,
Data Breach,
DBIR,
infosec,
PCI DSS,
security,
Verizon
21 February 2012
UNDERSTANDING CLOUD SECURITY: PART TWO...
Google
I
thank you for your attention on the previous
post where we had a look at security considerations for the three main
cloud service models commonly referred to as SPI (SaaS, PaaS, IaaS). As promised
here’s part two looking at other cloud implementation considerations, namely:
- Cloud deployment model: public vs. private vs community vs hybrid deployments,
- Cloud location: internal vs. external hosting or combined,
19 February 2012
UNDERSTANDING CLOUD SECURITY: FINDING THE BOUNDARIES...
Google
It
seems that my previous
post on compliance and third parties struck a chord with a few of you... So
I guess it’s about time I dedicated some time to “The Cloud” specifically! Over
the past couple of years, we have seen a lot of hype and confusion as to what
The Cloud really means and what it can do for you. I think we have now reached
the stage where there is perhaps a bit of disappointment that The Cloud, due to
inflated expectations, is perhaps not a miracle...
Subscribe to:
Posts (Atom)