2018: How to make it better. Seriously.

Continuing a topic that we've discussed, ad nauseam.  Dealing with attacks and threats in 2018 will be much of a continuation of 2017.  We can expect that need to address both the continual advancement and innovation of attackers ways to compromise devices and exfiltrate data, but also the need to cover the "basics" of network security. With the systemic and ongoing resource and skills deficiencies, this issue isn't likely to be resolved in the near term. In order to get ahead of the curve, we have to approach these problems from a more deliberate course and action. In short, it's now a requirement to understand that we can't secure, "all the things".  We have to focus on what truly matters, develop actionable and automated processes of getting to that data, and letting that which truly doesn't matter... slide. With the focus adjusted to what is actually attainable, the following skills and…

0 Comments

Spectre and Meltdown

Spectre and Meltdown are the names given to variations on a vulnerability that affects nearly every computer chip manufactured in the last 20 or so years. Unfortunately, the flaws can only be described as catastrophic in nature.In the first days of 2018, published research revealed that flaws arise from features built into chips that help them run faster, and while software patches are available, they have had impacts on system performance. In fact, it seems that the cure has been far more devastating than the actual vulnerability.Supporting this argument, SolarWinds has created other visualizations of its cloud post Meltdown/Spectre and most of the results are ugly. Throughput was down as much as 40 per cent on its Kafka rig, while CPUs spiked by around 25 per cent on Cassandra. In large environments, such as AWS, this is significant.Spectre and Meltdown are the names given to different variants of the underlying…

0 Comments

GDPR – Breach Notification and Artificial Intelligence

  The GDPR is directly applicable in each member state and will lead to a greater degree of data protection harmonization across EU nations, but there is application to US and Canadian organizations as well. Read the actual articles here - https://gdpr-info.eu GDPR contains a number of new protections for EU data subjects and threatens significant fines and penalties for non-compliant data controllers and processors once it comes into force in the spring of 2018. One of the biggest challenges is Data Security and Breach Notification. With new obligations on such matters as data subject consent, data privacy, breach notification, trans-border data transfers, and designation of data protection officers, the GDPR requires organizations handling EU citizens’ data to undertake major operational changes. New Data Processing Standards The GDRP separates responsibilities and duties of data controllers and processors. Which means, Controllers are only obligated to engage those processors that provide “sufficient guarantees…

0 Comments

Executive Round table – 2 Bits and Gigabits

  Join Sentinel Benefits & Critical Path Security in NY City on Wednesday January 17th 2018 for an executive round-table covering two important topics. Samuel Mitchell, President & CEO of Sentinel Benefits and Financial Group will be tackling a discussion to increase your 2 Bits, financial well being, what it is and how to achieve it by seizing today's opportunities. Patrick Kelley, Principal Security Engineer for Critical Path Security will lead the group discussion effective ways to protect your Gigabits of digital assets from insider threats by raising awareness about the most overlooked threats, disgruntled employees and their remote access from a myriad of mobile devices. If you are interested in attending please RSVP to Daria Oterin by email Daria.Oterin@sentinelgroup.com or by phone at (212)  655-0511. We hope to see you there.  .

0 Comments