<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
>

<channel>
	<title>Speaking of Security - The RSA Blog and Podcast &#187; Rashmi Knowles</title>
	<atom:link href="http://blogs.rsa.com/author/knowles/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.rsa.com</link>
	<description>The Security Blog for Security Professionals</description>
	<lastBuildDate>Fri, 17 May 2013 12:30:58 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5</generator>
<!-- podcast_generator="Blubrry PowerPress/4.0.7" -->
	<itunes:summary>The Speaking of Security podcast features lively discussion with industry experts on the latest issues and trends in the security industry.</itunes:summary>
	<itunes:author>RSA, The Security Division of EMC</itunes:author>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://blogs.rsa.com/wp-content/uploads/userphoto/sos.png" />
	<itunes:owner>
		<itunes:name>RSA, The Security Division of EMC</itunes:name>
		<itunes:email>podcast@rsa.com</itunes:email>
	</itunes:owner>
	<managingEditor>podcast@rsa.com (RSA, The Security Division of EMC)</managingEditor>
	<itunes:subtitle>The Security Blog for Security Professionals</itunes:subtitle>
	<itunes:keywords>Security, Cyber Crime, APTs, Sam Curry, RSA, EMC, Advanced Persistant Threats, Fraud</itunes:keywords>
	<image>
		<title>Speaking of Security - The RSA Blog and Podcast &#187; Rashmi Knowles</title>
		<url>http://blogs.rsa.com/wp-content/uploads/userphoto/sos.png</url>
		<link>http://blogs.rsa.com</link>
	</image>
	<itunes:category text="Technology">
		<itunes:category text="Tech News" />
		<itunes:category text="Podcasting" />
	</itunes:category>
		<item>
		<title>To Cybercriminals, The Size of a Company No Longer Matters</title>
		<link>http://blogs.rsa.com/to-cybercriminals-the-size-of-a-company-no-longer-matters/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=to-cybercriminals-the-size-of-a-company-no-longer-matters</link>
		<comments>http://blogs.rsa.com/to-cybercriminals-the-size-of-a-company-no-longer-matters/#comments</comments>
		<pubDate>Fri, 17 May 2013 12:30:58 +0000</pubDate>
		<dc:creator>Rashmi Knowles</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Cybercrime and Fraud]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[IT Security]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=9073</guid>
		<description><![CDATA[Gone are the days when it was thought that size of the company matters to the cybercriminals.  The latest PwC Information Security Breaches Survey 2013 shows that there has been a significant rise in the number of small businesses that were attacked by an unauthorized outsider in the last year – up by 22%.  Interestingly large organizations only went up by 5%.  The cybercriminal has moved on to stealing intellectual property or corporate secrets as that’s where the real money is and small companies become easy targets as many do not have the resources or budgets to fully protect their information.

It’s time to understand the differences between corporate secrets and custodial data.]]></description>
				<content:encoded><![CDATA[<p>Gone are the days when it was thought that size of the company matters to the cybercriminals.  The latest <a href="http://www.pwc.com/gx/en/consulting-services/information-security-survey/index.jhtml">PwC Information Security Breaches Survey 2013</a> shows that there has been a significant rise in the number of small businesses that were attacked by an unauthorized outsider in the last year – up by 22%.  Interestingly large organizations only went up by 5%.  The cybercriminal has moved on to stealing intellectual property or corporate secrets as that’s where the real money is and small companies become easy targets as many do not have the resources or budgets to fully protect their information.</p>
<p>It’s time to understand the differences between corporate secrets and custodial data.</p>
<p>S<i>ecrets </i>refer to information that the enterprise creates and wishes to keep under wraps. They tend to be messily and abstractly described in Word documents, embedded in presentations, and enshrined in application-specific formats like CAD. Secrets that have intrinsic value to the firm are  almost always specific to the enterprise’s business context &#8212; where an interested party could cause long-term competitive harm if this information is obtained. Keeping proprietary knowledge away from competitors is essential to maintaining market advantage.</p>
<p>Typically, companies in knowledge-intensive industries such as aerospace and defense, electronics, and consulting generate large amounts of confidential intellectual property that present barriers to entry for competitors. Unlike with toxic data spills, failures to protect secrets are almost never made public.</p>
<p>By contrast, legislation, regulation, and contracts compel enterprises to protect <i>custodial data</i>. Mandates that oblige enterprises to be good custodians include contractual obligations like the Payment Card Industry Data Security Standard (PCI-DSS) and data breach and privacy laws. Custodial data has little intrinsic value in and of itself, but  when it is obtained by an unauthorized party, misused, lost or stolen, it changes state.Data that is ordinarily benign transforms into something harmful.</p>
<p>When custodial data is spilled, it becomes “toxic” and poisons the enterprise’s air in terms of press headlines, fines, and customer complaints. Outsiders, such as organized criminals, value custodial data because they can make money with it. Custodial data also accrues indirect value to the enterprise based on the costs of fines, lawsuits, and adverse publicity. Examples of custodial data include customer personally identifiable information (PII) attributes like name, address, email, and phone number; government identifiers; payment card details like credit card numbers and expiry dates; and medical records and government identifiers like passport numbers. Many well-known companies have graced the front pages of major newspapers with toxic data spills.</p>
<p>Interestingly, enterprises in highly knowledge-intensive industries like manufacturing, information services, professional, scientific and technical services, and transportation have between 70-80% of their information portfolio value from secrets while healthcare firms and governmental entities are nearly exactly the opposite, most of the value of their information assets are custodial data assets.</p>
<p>Data security incidents related to accidental losses and mistakes are common but cause little quantifiable damage. By contrast, employee theft of sensitive information is costlier on a per-incident basis than any single incident caused by accidents.</p>
<p>Unfortunately, compliance drives spending on security for all companies and smaller ones have a difficult choice to make.  “Compliance” in all its forms has helped CISO’s buy more gear, but it has distracted IT security from its traditional focus, keeping company secrets secure. All companies, large and small really need to do a better job of understanding the value of their corporate secrets.</p>
<p>Read my next blog for some recommendations on achieving the right balance.</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fto-cybercriminals-the-size-of-a-company-no-longer-matters%2F&amp;t=To%20Cybercriminals%2C%20The%20Size%20of%20a%20Company%20No%20Longer%20Matters"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=To%20Cybercriminals%2C%20The%20Size%20of%20a%20Company%20No%20Longer%20Matters%20-%20http%3A%2F%2Fblogs.rsa.com%2Fto-cybercriminals-the-size-of-a-company-no-longer-matters%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fto-cybercriminals-the-size-of-a-company-no-longer-matters%2F&amp;title=To%20Cybercriminals%2C%20The%20Size%20of%20a%20Company%20No%20Longer%20Matters&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=Gone%20are%20the%20days%20when%20it%20was%20thought%20that%20size%20of%20the%20company%20matters%20to%20the%20cybercriminals.%20%20The%20latest%20PwC%20Information%20Security%20Breaches%20Survey%202013%20shows%20that%20there%20has%20been%20a%20significant%20rise%20in%20the%20number%20of%20small%20businesses%20that%20were%20attacked%20by%20an%20unauthorized%20outsider%20in%20the%20last%20year%20%E2%80%93%20up%20by%2022%25.%20%20Interestingly%20large%20organizations%20only%20went%20up%20by%205%25.%20%20The%20cybercriminal%20has%20moved%20on%20to%20stealing%20intellectual%20property%20or%20corporate%20secrets%20as%20that%E2%80%99s%20where%20the%20real%20money%20is%20and%20small%20companies%20become%20easy%20targets%20as%20many%20do%20not%20have%20the%20resources%20or%20budgets%20to%20fully%20protect%20their%20information.%0D%0A%0D%0AIt%E2%80%99s%20time%20to%20understand%20the%20differences%20between%20corporate%20secrets%20and%20custodial%20data."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=To%20Cybercriminals%2C%20The%20Size%20of%20a%20Company%20No%20Longer%20Matters&body=http%3A%2F%2Fblogs.rsa.com%2Fto-cybercriminals-the-size-of-a-company-no-longer-matters%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-9073')" id="sociable-post-9073" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fto-cybercriminals-the-size-of-a-company-no-longer-matters%2F&amp;t=To%20Cybercriminals%2C%20The%20Size%20of%20a%20Company%20No%20Longer%20Matters"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fto-cybercriminals-the-size-of-a-company-no-longer-matters%2F&amp;title=To%20Cybercriminals%2C%20The%20Size%20of%20a%20Company%20No%20Longer%20Matters&amp;notes=Gone%20are%20the%20days%20when%20it%20was%20thought%20that%20size%20of%20the%20company%20matters%20to%20the%20cybercriminals.%20%20The%20latest%20PwC%20Information%20Security%20Breaches%20Survey%202013%20shows%20that%20there%20has%20been%20a%20significant%20rise%20in%20the%20number%20of%20small%20businesses%20that%20were%20attacked%20by%20an%20unauthorized%20outsider%20in%20the%20last%20year%20%E2%80%93%20up%20by%2022%25.%20%20Interestingly%20large%20organizations%20only%20went%20up%20by%205%25.%20%20The%20cybercriminal%20has%20moved%20on%20to%20stealing%20intellectual%20property%20or%20corporate%20secrets%20as%20that%E2%80%99s%20where%20the%20real%20money%20is%20and%20small%20companies%20become%20easy%20targets%20as%20many%20do%20not%20have%20the%20resources%20or%20budgets%20to%20fully%20protect%20their%20information.%0D%0A%0D%0AIt%E2%80%99s%20time%20to%20understand%20the%20differences%20between%20corporate%20secrets%20and%20custodial%20data."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fto-cybercriminals-the-size-of-a-company-no-longer-matters%2F&amp;title=To%20Cybercriminals%2C%20The%20Size%20of%20a%20Company%20No%20Longer%20Matters&amp;bodytext=Gone%20are%20the%20days%20when%20it%20was%20thought%20that%20size%20of%20the%20company%20matters%20to%20the%20cybercriminals.%20%20The%20latest%20PwC%20Information%20Security%20Breaches%20Survey%202013%20shows%20that%20there%20has%20been%20a%20significant%20rise%20in%20the%20number%20of%20small%20businesses%20that%20were%20attacked%20by%20an%20unauthorized%20outsider%20in%20the%20last%20year%20%E2%80%93%20up%20by%2022%25.%20%20Interestingly%20large%20organizations%20only%20went%20up%20by%205%25.%20%20The%20cybercriminal%20has%20moved%20on%20to%20stealing%20intellectual%20property%20or%20corporate%20secrets%20as%20that%E2%80%99s%20where%20the%20real%20money%20is%20and%20small%20companies%20become%20easy%20targets%20as%20many%20do%20not%20have%20the%20resources%20or%20budgets%20to%20fully%20protect%20their%20information.%0D%0A%0D%0AIt%E2%80%99s%20time%20to%20understand%20the%20differences%20between%20corporate%20secrets%20and%20custodial%20data."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fto-cybercriminals-the-size-of-a-company-no-longer-matters%2F&amp;title=To%20Cybercriminals%2C%20The%20Size%20of%20a%20Company%20No%20Longer%20Matters"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fto-cybercriminals-the-size-of-a-company-no-longer-matters%2F&title=To%20Cybercriminals%2C%20The%20Size%20of%20a%20Company%20No%20Longer%20Matters"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fto-cybercriminals-the-size-of-a-company-no-longer-matters%2F&amp;title=To%20Cybercriminals%2C%20The%20Size%20of%20a%20Company%20No%20Longer%20Matters&amp;annotation=Gone%20are%20the%20days%20when%20it%20was%20thought%20that%20size%20of%20the%20company%20matters%20to%20the%20cybercriminals.%20%20The%20latest%20PwC%20Information%20Security%20Breaches%20Survey%202013%20shows%20that%20there%20has%20been%20a%20significant%20rise%20in%20the%20number%20of%20small%20businesses%20that%20were%20attacked%20by%20an%20unauthorized%20outsider%20in%20the%20last%20year%20%E2%80%93%20up%20by%2022%25.%20%20Interestingly%20large%20organizations%20only%20went%20up%20by%205%25.%20%20The%20cybercriminal%20has%20moved%20on%20to%20stealing%20intellectual%20property%20or%20corporate%20secrets%20as%20that%E2%80%99s%20where%20the%20real%20money%20is%20and%20small%20companies%20become%20easy%20targets%20as%20many%20do%20not%20have%20the%20resources%20or%20budgets%20to%20fully%20protect%20their%20information.%0D%0A%0D%0AIt%E2%80%99s%20time%20to%20understand%20the%20differences%20between%20corporate%20secrets%20and%20custodial%20data."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fto-cybercriminals-the-size-of-a-company-no-longer-matters%2F&amp;t=To%20Cybercriminals%2C%20The%20Size%20of%20a%20Company%20No%20Longer%20Matters"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=To%20Cybercriminals%2C%20The%20Size%20of%20a%20Company%20No%20Longer%20Matters&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fto-cybercriminals-the-size-of-a-company-no-longer-matters%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=Gone%20are%20the%20days%20when%20it%20was%20thought%20that%20size%20of%20the%20company%20matters%20to%20the%20cybercriminals.%20%20The%20latest%20PwC%20Information%20Security%20Breaches%20Survey%202013%20shows%20that%20there%20has%20been%20a%20significant%20rise%20in%20the%20number%20of%20small%20businesses%20that%20were%20attacked%20by%20an%20unauthorized%20outsider%20in%20the%20last%20year%20%E2%80%93%20up%20by%2022%25.%20%20Interestingly%20large%20organizations%20only%20went%20up%20by%205%25.%20%20The%20cybercriminal%20has%20moved%20on%20to%20stealing%20intellectual%20property%20or%20corporate%20secrets%20as%20that%E2%80%99s%20where%20the%20real%20money%20is%20and%20small%20companies%20become%20easy%20targets%20as%20many%20do%20not%20have%20the%20resources%20or%20budgets%20to%20fully%20protect%20their%20information.%0D%0A%0D%0AIt%E2%80%99s%20time%20to%20understand%20the%20differences%20between%20corporate%20secrets%20and%20custodial%20data."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fto-cybercriminals-the-size-of-a-company-no-longer-matters%2F&amp;Title=To%20Cybercriminals%2C%20The%20Size%20of%20a%20Company%20No%20Longer%20Matters"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fto-cybercriminals-the-size-of-a-company-no-longer-matters%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fto-cybercriminals-the-size-of-a-company-no-longer-matters%2F&amp;title=To%20Cybercriminals%2C%20The%20Size%20of%20a%20Company%20No%20Longer%20Matters&amp;selection=Gone%20are%20the%20days%20when%20it%20was%20thought%20that%20size%20of%20the%20company%20matters%20to%20the%20cybercriminals.%20%20The%20latest%20PwC%20Information%20Security%20Breaches%20Survey%202013%20shows%20that%20there%20has%20been%20a%20significant%20rise%20in%20the%20number%20of%20small%20businesses%20that%20were%20attacked%20by%20an%20unauthorized%20outsider%20in%20the%20last%20year%20%E2%80%93%20up%20by%2022%25.%20%20Interestingly%20large%20organizations%20only%20went%20up%20by%205%25.%20%20The%20cybercriminal%20has%20moved%20on%20to%20stealing%20intellectual%20property%20or%20corporate%20secrets%20as%20that%E2%80%99s%20where%20the%20real%20money%20is%20and%20small%20companies%20become%20easy%20targets%20as%20many%20do%20not%20have%20the%20resources%20or%20budgets%20to%20fully%20protect%20their%20information.%0D%0A%0D%0AIt%E2%80%99s%20time%20to%20understand%20the%20differences%20between%20corporate%20secrets%20and%20custodial%20data."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fto-cybercriminals-the-size-of-a-company-no-longer-matters%2F&amp;t=To%20Cybercriminals%2C%20The%20Size%20of%20a%20Company%20No%20Longer%20Matters&amp;s=Gone%20are%20the%20days%20when%20it%20was%20thought%20that%20size%20of%20the%20company%20matters%20to%20the%20cybercriminals.%20%20The%20latest%20PwC%20Information%20Security%20Breaches%20Survey%202013%20shows%20that%20there%20has%20been%20a%20significant%20rise%20in%20the%20number%20of%20small%20businesses%20that%20were%20attacked%20by%20an%20unauthorized%20outsider%20in%20the%20last%20year%20%E2%80%93%20up%20by%2022%25.%20%20Interestingly%20large%20organizations%20only%20went%20up%20by%205%25.%20%20The%20cybercriminal%20has%20moved%20on%20to%20stealing%20intellectual%20property%20or%20corporate%20secrets%20as%20that%E2%80%99s%20where%20the%20real%20money%20is%20and%20small%20companies%20become%20easy%20targets%20as%20many%20do%20not%20have%20the%20resources%20or%20budgets%20to%20fully%20protect%20their%20information.%0D%0A%0D%0AIt%E2%80%99s%20time%20to%20understand%20the%20differences%20between%20corporate%20secrets%20and%20custodial%20data."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fto-cybercriminals-the-size-of-a-company-no-longer-matters%2F&amp;title=To%20Cybercriminals%2C%20The%20Size%20of%20a%20Company%20No%20Longer%20Matters&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fto-cybercriminals-the-size-of-a-company-no-longer-matters%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-9073')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-9073',true)" class="close">

		  <img onclick="hide_sociable('post-9073',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/to-cybercriminals-the-size-of-a-company-no-longer-matters/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/to-cybercriminals-the-size-of-a-company-no-longer-matters/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Where has the £650 million gone?</title>
		<link>http://blogs.rsa.com/where-has-the-650-million-gone/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=where-has-the-650-million-gone</link>
		<comments>http://blogs.rsa.com/where-has-the-650-million-gone/#comments</comments>
		<pubDate>Fri, 26 Apr 2013 16:30:29 +0000</pubDate>
		<dc:creator>Rashmi Knowles</dc:creator>
				<category><![CDATA[Cybercrime and Fraud]]></category>
		<category><![CDATA[IT Security]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=8911</guid>
		<description><![CDATA[The UK government has identified cyber security as a key area of focus and new investment and in 2011 announced a budget of £650 million to shore up defenses in the UK.  So after two years, let's examine how it's been spent.]]></description>
				<content:encoded><![CDATA[<p>The UK government has identified cyber security as a key area of focus and new investment and in 2011 announced a budget of £650 million to shore up defenses in the UK.  So after two years, let&#8217;s examine how it&#8217;s been spent.</p>
<p>Here&#8217;s some of the good things that have resulted from the investment</p>
<ul>
<li>SOCA took down 36 website domains that sold credit card data –a small tip of the iceberg, but progress.</li>
<li>15,000 fraud websites were suspended</li>
<li>GCHQ announced a scheme to help companies deal with cyber attacks and give guidance on response to a compromise</li>
<li>8 universities have been given the Academic Centre for Excellence in Cyber Security and Research</li>
<li>CISP, the Cyber security Information Sharing Scheme</li>
</ul>
<p>However, there are still areas that need further investment</p>
<ul>
<li>60% of the budget was spent on ‘detect and defend’ – we hope that &#8216;response&#8217; is also a large portion of this investment although it’s not very clear</li>
<li>The government needs to do a lot more to collaborate with the security industry and ensure that skills and knowledge can be exchanged</li>
<li>According to the UK National Audit Office it will take the UK up to 20 years to meet the required skills in Cyber security.  The universities are a good start but a lot more will have to be done to educate the citizens and raise awareness on cyber security</li>
<li>Agility is a key factor on where and how this budget is spent.  A continuous challenge facing any government is how quickly they can invest with a cyber security landscape that is evolving every day.</li>
</ul>
<p>The threat to cyber security is persistent and continually evolving. Business, government and the public must constantly be alert to the level of risk if they are to succeed in detecting and resisting the threat of cyber attack.  It’s good that the Government has articulated their policy and published some results to date.  We’ll have to wait and see if the remainder of the funding is spent to meet the goals initially set out.</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fwhere-has-the-650-million-gone%2F&amp;t=Where%20has%20the%20%C2%A3650%20million%20gone%3F"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Where%20has%20the%20%C2%A3650%20million%20gone%3F%20-%20http%3A%2F%2Fblogs.rsa.com%2Fwhere-has-the-650-million-gone%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fwhere-has-the-650-million-gone%2F&amp;title=Where%20has%20the%20%C2%A3650%20million%20gone%3F&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=The%20UK%20government%20has%20identified%20cyber%20security%20as%20a%20key%20area%20of%20focus%20and%20new%20investment%20and%20in%202011%20announced%20a%20budget%20of%20%C2%A3650%20million%20to%20shore%20up%20defenses%20in%20the%20UK.%20%20So%20after%20two%20years%2C%20let%27s%20examine%20how%20it%27s%20been%20spent."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Where%20has%20the%20%C2%A3650%20million%20gone%3F&body=http%3A%2F%2Fblogs.rsa.com%2Fwhere-has-the-650-million-gone%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-8911')" id="sociable-post-8911" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fwhere-has-the-650-million-gone%2F&amp;t=Where%20has%20the%20%C2%A3650%20million%20gone%3F"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fwhere-has-the-650-million-gone%2F&amp;title=Where%20has%20the%20%C2%A3650%20million%20gone%3F&amp;notes=The%20UK%20government%20has%20identified%20cyber%20security%20as%20a%20key%20area%20of%20focus%20and%20new%20investment%20and%20in%202011%20announced%20a%20budget%20of%20%C2%A3650%20million%20to%20shore%20up%20defenses%20in%20the%20UK.%20%20So%20after%20two%20years%2C%20let%27s%20examine%20how%20it%27s%20been%20spent."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fwhere-has-the-650-million-gone%2F&amp;title=Where%20has%20the%20%C2%A3650%20million%20gone%3F&amp;bodytext=The%20UK%20government%20has%20identified%20cyber%20security%20as%20a%20key%20area%20of%20focus%20and%20new%20investment%20and%20in%202011%20announced%20a%20budget%20of%20%C2%A3650%20million%20to%20shore%20up%20defenses%20in%20the%20UK.%20%20So%20after%20two%20years%2C%20let%27s%20examine%20how%20it%27s%20been%20spent."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fwhere-has-the-650-million-gone%2F&amp;title=Where%20has%20the%20%C2%A3650%20million%20gone%3F"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fwhere-has-the-650-million-gone%2F&title=Where%20has%20the%20%C2%A3650%20million%20gone%3F"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fwhere-has-the-650-million-gone%2F&amp;title=Where%20has%20the%20%C2%A3650%20million%20gone%3F&amp;annotation=The%20UK%20government%20has%20identified%20cyber%20security%20as%20a%20key%20area%20of%20focus%20and%20new%20investment%20and%20in%202011%20announced%20a%20budget%20of%20%C2%A3650%20million%20to%20shore%20up%20defenses%20in%20the%20UK.%20%20So%20after%20two%20years%2C%20let%27s%20examine%20how%20it%27s%20been%20spent."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fwhere-has-the-650-million-gone%2F&amp;t=Where%20has%20the%20%C2%A3650%20million%20gone%3F"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Where%20has%20the%20%C2%A3650%20million%20gone%3F&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fwhere-has-the-650-million-gone%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=The%20UK%20government%20has%20identified%20cyber%20security%20as%20a%20key%20area%20of%20focus%20and%20new%20investment%20and%20in%202011%20announced%20a%20budget%20of%20%C2%A3650%20million%20to%20shore%20up%20defenses%20in%20the%20UK.%20%20So%20after%20two%20years%2C%20let%27s%20examine%20how%20it%27s%20been%20spent."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fwhere-has-the-650-million-gone%2F&amp;Title=Where%20has%20the%20%C2%A3650%20million%20gone%3F"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fwhere-has-the-650-million-gone%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fwhere-has-the-650-million-gone%2F&amp;title=Where%20has%20the%20%C2%A3650%20million%20gone%3F&amp;selection=The%20UK%20government%20has%20identified%20cyber%20security%20as%20a%20key%20area%20of%20focus%20and%20new%20investment%20and%20in%202011%20announced%20a%20budget%20of%20%C2%A3650%20million%20to%20shore%20up%20defenses%20in%20the%20UK.%20%20So%20after%20two%20years%2C%20let%27s%20examine%20how%20it%27s%20been%20spent."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fwhere-has-the-650-million-gone%2F&amp;t=Where%20has%20the%20%C2%A3650%20million%20gone%3F&amp;s=The%20UK%20government%20has%20identified%20cyber%20security%20as%20a%20key%20area%20of%20focus%20and%20new%20investment%20and%20in%202011%20announced%20a%20budget%20of%20%C2%A3650%20million%20to%20shore%20up%20defenses%20in%20the%20UK.%20%20So%20after%20two%20years%2C%20let%27s%20examine%20how%20it%27s%20been%20spent."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fwhere-has-the-650-million-gone%2F&amp;title=Where%20has%20the%20%C2%A3650%20million%20gone%3F&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fwhere-has-the-650-million-gone%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-8911')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-8911',true)" class="close">

		  <img onclick="hide_sociable('post-8911',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/where-has-the-650-million-gone/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/where-has-the-650-million-gone/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Must have Competencies for Securing Social Media in 2013</title>
		<link>http://blogs.rsa.com/must-have-competencies-for-securing-social-media-in-2013/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=must-have-competencies-for-securing-social-media-in-2013</link>
		<comments>http://blogs.rsa.com/must-have-competencies-for-securing-social-media-in-2013/#comments</comments>
		<pubDate>Wed, 06 Mar 2013 17:30:19 +0000</pubDate>
		<dc:creator>Rashmi Knowles</dc:creator>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Social Media]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=7900</guid>
		<description><![CDATA[Following on from my recent blog ‘Re-enforcing our doors in 2013’ solving all of the issues of disruptive innovations isn’t going to be possible in a year but we must take some strides towards making some of the changes. The four members of the disruptive family are Cloud computing, social media, big data and Mobile.
Let’s take Social Media this week and examine some competencies organizations must start to build.]]></description>
				<content:encoded><![CDATA[<p>Following on from my recent blog ‘<span style="text-decoration: underline"><strong><a href="http://blogs.rsa.com/reinforcing-our-doors-in-2013/" target="_blank">Re-enforcing our doors in 2013</a></strong></span>’ solving all of the issues of disruptive innovations isn’t going to be possible in a year but we must take some strides towards making some of the changes. The four members of the disruptive family are Cloud computing, social media, big data and Mobile.<br />
Let’s take Social Media this week and examine some competencies organizations must start to build.</p>
<p>Social Media is here to stay; it is not going to go away so organizations really must start to define a clear policy when it comes to Social Media. It should not be a standalone policy and must be integrated into the overall security policy and process. Companies often make the mistake of having a complete separate policy and the risk is that some controls fall by the wayside. It also must involve all the key stakeholders in the business on who owns what and define a clear incident management responsibility. For example, legal/compliance owns the liability issues, marketing owns sentiment management, and security owns technical monitoring solutions.<br />
Response plans that may have worked in the past don’t work for Social Media due to the massive audience outreach and the speed with which the information can propagate. So, it may be time to have a dummy run of a breach via Social Media. For most organizations the far reaching security issues in Social Media only come to light when it’s too late.</p>
<p>Onto my favorite topic – User training. Social media due to outreach and speed requires a completely different level of training. Users may not be aware of the fact that a damaging tweet can be re-tweeted thousands of times within seconds. So, set out clear training around the use of social media and some of the issues it can create for companies. Set clear boundaries via technical controls and training.</p>
<p>And finally organisations often forget to monitor the social media for threat management. Brand monitoring on social sites is used by organizations to address reputational risk and customer services can also be monitoring to see if customers are escalating unsolved issues. Social media monitoring could also highlight hacktivist group activity that may be a concern for the organization.</p>
<p>All of these controls raised here shouldn’t come as a big surprise to a security professional but it time to re-think them and ensure you have the controls in places to mitigate any risks via Social Media.<br />
Look out for my next blog on Must Have Competencies for Big Data in 2013.</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-securing-social-media-in-2013%2F&amp;t=Must%20have%20Competencies%20for%20Securing%20Social%20Media%20in%202013"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Must%20have%20Competencies%20for%20Securing%20Social%20Media%20in%202013%20-%20http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-securing-social-media-in-2013%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-securing-social-media-in-2013%2F&amp;title=Must%20have%20Competencies%20for%20Securing%20Social%20Media%20in%202013&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=Following%20on%20from%20my%20recent%20blog%20%E2%80%98Re-enforcing%20our%20doors%20in%202013%E2%80%99%20solving%20all%20of%20the%20issues%20of%20disruptive%20innovations%20isn%E2%80%99t%20going%20to%20be%20possible%20in%20a%20year%20but%20we%20must%20take%20some%20strides%20towards%20making%20some%20of%20the%20changes.%20The%20four%20members%20of%20the%20disruptive%20family%20are%20Cloud%20computing%2C%20social%20media%2C%20big%20data%20and%20Mobile.%0D%0ALet%E2%80%99s%20take%20Social%20Media%20this%20week%20and%20examine%20some%20competencies%20organizations%20must%20start%20to%20build."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Must%20have%20Competencies%20for%20Securing%20Social%20Media%20in%202013&body=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-securing-social-media-in-2013%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-7900')" id="sociable-post-7900" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-securing-social-media-in-2013%2F&amp;t=Must%20have%20Competencies%20for%20Securing%20Social%20Media%20in%202013"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-securing-social-media-in-2013%2F&amp;title=Must%20have%20Competencies%20for%20Securing%20Social%20Media%20in%202013&amp;notes=Following%20on%20from%20my%20recent%20blog%20%E2%80%98Re-enforcing%20our%20doors%20in%202013%E2%80%99%20solving%20all%20of%20the%20issues%20of%20disruptive%20innovations%20isn%E2%80%99t%20going%20to%20be%20possible%20in%20a%20year%20but%20we%20must%20take%20some%20strides%20towards%20making%20some%20of%20the%20changes.%20The%20four%20members%20of%20the%20disruptive%20family%20are%20Cloud%20computing%2C%20social%20media%2C%20big%20data%20and%20Mobile.%0D%0ALet%E2%80%99s%20take%20Social%20Media%20this%20week%20and%20examine%20some%20competencies%20organizations%20must%20start%20to%20build."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-securing-social-media-in-2013%2F&amp;title=Must%20have%20Competencies%20for%20Securing%20Social%20Media%20in%202013&amp;bodytext=Following%20on%20from%20my%20recent%20blog%20%E2%80%98Re-enforcing%20our%20doors%20in%202013%E2%80%99%20solving%20all%20of%20the%20issues%20of%20disruptive%20innovations%20isn%E2%80%99t%20going%20to%20be%20possible%20in%20a%20year%20but%20we%20must%20take%20some%20strides%20towards%20making%20some%20of%20the%20changes.%20The%20four%20members%20of%20the%20disruptive%20family%20are%20Cloud%20computing%2C%20social%20media%2C%20big%20data%20and%20Mobile.%0D%0ALet%E2%80%99s%20take%20Social%20Media%20this%20week%20and%20examine%20some%20competencies%20organizations%20must%20start%20to%20build."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-securing-social-media-in-2013%2F&amp;title=Must%20have%20Competencies%20for%20Securing%20Social%20Media%20in%202013"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-securing-social-media-in-2013%2F&title=Must%20have%20Competencies%20for%20Securing%20Social%20Media%20in%202013"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-securing-social-media-in-2013%2F&amp;title=Must%20have%20Competencies%20for%20Securing%20Social%20Media%20in%202013&amp;annotation=Following%20on%20from%20my%20recent%20blog%20%E2%80%98Re-enforcing%20our%20doors%20in%202013%E2%80%99%20solving%20all%20of%20the%20issues%20of%20disruptive%20innovations%20isn%E2%80%99t%20going%20to%20be%20possible%20in%20a%20year%20but%20we%20must%20take%20some%20strides%20towards%20making%20some%20of%20the%20changes.%20The%20four%20members%20of%20the%20disruptive%20family%20are%20Cloud%20computing%2C%20social%20media%2C%20big%20data%20and%20Mobile.%0D%0ALet%E2%80%99s%20take%20Social%20Media%20this%20week%20and%20examine%20some%20competencies%20organizations%20must%20start%20to%20build."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-securing-social-media-in-2013%2F&amp;t=Must%20have%20Competencies%20for%20Securing%20Social%20Media%20in%202013"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Must%20have%20Competencies%20for%20Securing%20Social%20Media%20in%202013&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-securing-social-media-in-2013%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=Following%20on%20from%20my%20recent%20blog%20%E2%80%98Re-enforcing%20our%20doors%20in%202013%E2%80%99%20solving%20all%20of%20the%20issues%20of%20disruptive%20innovations%20isn%E2%80%99t%20going%20to%20be%20possible%20in%20a%20year%20but%20we%20must%20take%20some%20strides%20towards%20making%20some%20of%20the%20changes.%20The%20four%20members%20of%20the%20disruptive%20family%20are%20Cloud%20computing%2C%20social%20media%2C%20big%20data%20and%20Mobile.%0D%0ALet%E2%80%99s%20take%20Social%20Media%20this%20week%20and%20examine%20some%20competencies%20organizations%20must%20start%20to%20build."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-securing-social-media-in-2013%2F&amp;Title=Must%20have%20Competencies%20for%20Securing%20Social%20Media%20in%202013"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-securing-social-media-in-2013%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-securing-social-media-in-2013%2F&amp;title=Must%20have%20Competencies%20for%20Securing%20Social%20Media%20in%202013&amp;selection=Following%20on%20from%20my%20recent%20blog%20%E2%80%98Re-enforcing%20our%20doors%20in%202013%E2%80%99%20solving%20all%20of%20the%20issues%20of%20disruptive%20innovations%20isn%E2%80%99t%20going%20to%20be%20possible%20in%20a%20year%20but%20we%20must%20take%20some%20strides%20towards%20making%20some%20of%20the%20changes.%20The%20four%20members%20of%20the%20disruptive%20family%20are%20Cloud%20computing%2C%20social%20media%2C%20big%20data%20and%20Mobile.%0D%0ALet%E2%80%99s%20take%20Social%20Media%20this%20week%20and%20examine%20some%20competencies%20organizations%20must%20start%20to%20build."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-securing-social-media-in-2013%2F&amp;t=Must%20have%20Competencies%20for%20Securing%20Social%20Media%20in%202013&amp;s=Following%20on%20from%20my%20recent%20blog%20%E2%80%98Re-enforcing%20our%20doors%20in%202013%E2%80%99%20solving%20all%20of%20the%20issues%20of%20disruptive%20innovations%20isn%E2%80%99t%20going%20to%20be%20possible%20in%20a%20year%20but%20we%20must%20take%20some%20strides%20towards%20making%20some%20of%20the%20changes.%20The%20four%20members%20of%20the%20disruptive%20family%20are%20Cloud%20computing%2C%20social%20media%2C%20big%20data%20and%20Mobile.%0D%0ALet%E2%80%99s%20take%20Social%20Media%20this%20week%20and%20examine%20some%20competencies%20organizations%20must%20start%20to%20build."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-securing-social-media-in-2013%2F&amp;title=Must%20have%20Competencies%20for%20Securing%20Social%20Media%20in%202013&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-securing-social-media-in-2013%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-7900')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-7900',true)" class="close">

		  <img onclick="hide_sociable('post-7900',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/must-have-competencies-for-securing-social-media-in-2013/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/must-have-competencies-for-securing-social-media-in-2013/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Must Have Competencies for Mobile in 2013</title>
		<link>http://blogs.rsa.com/must-have-competencies-for-mobile-in-2013/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=must-have-competencies-for-mobile-in-2013</link>
		<comments>http://blogs.rsa.com/must-have-competencies-for-mobile-in-2013/#comments</comments>
		<pubDate>Mon, 04 Mar 2013 17:30:35 +0000</pubDate>
		<dc:creator>Rashmi Knowles</dc:creator>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[BYOD]]></category>
		<category><![CDATA[mobile]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=7967</guid>
		<description><![CDATA[It’s no surprise that Mobile is one of the four competencies which will need to be addressed in 2013. I addressed the mobile competencies in some detail sin one of my blogs last year so for the sake of completeness I will revisit to ensure my recommendations are still valid.]]></description>
				<content:encoded><![CDATA[<p>It’s no surprise that Mobile is one of the four competencies which will need to be addressed in 2013. I addressed the mobile competencies in some detail in one of my blogs last year so for the sake of completeness I will revisit to ensure my recommendations are still valid.</p>
<p>Many information-security and IT teams are under pressure to rapidly support mobility. Although time is of the essence, successfully managing risks requires coordinating stakeholders, creating policy and processes and integrating security into mobile plans and educating users. A basic checklist for a BYOD program must include terms and conditions, including enterprise and end-user rights and responsibilities for using a personal mobile device for work. Here are a few recommendations to get you started:</p>
<ol>
<li>Make signing a legal agreement a prerequisite to using a personal mobile device in fact; a lot of organizations include mandatory training at this stage so the user understands the risks.</li>
<li>Stolen or lost devices must be reported within a specific period of time</li>
<li>Ensure employees understand the company’s rights with respect to monitoring and wiping devices. Also, users must understand that their personal data may also be wiped.</li>
<li>Include specific provisions on how the company will monitor the device, retain the device or wipe the device (complete wipe or just the corporate container)</li>
<li>Require the use of an organizations corporate account for storing data in the cloud.</li>
<li>Ensure end-users are responsible for backing up personal data</li>
<li>Clarify lines of responsibility for device maintenance, support and costs</li>
<li>Require employees to remove apps at the request of the organization</li>
<li>Establish that the company will disable a device’s access to the network if a blacklisted app is installed or if the device has been jail-broken or tampered with in any way</li>
<li>Specify the consequences for any violations to the policy</li>
</ol>
<p>It seems to me that a lot of these recommendations should be common practice for a good security program as a lot of these actually apply to a corporate issued laptop anyway and let’s face it; most of us have personal information on our corporate laptops anyway&#8230;</p>
<p>All of these recommendations will require an enterprise to truly understand the nature of their BYOD estate. I fear a lot of organizations are under so much time pressure that BYOD has been implemented by stealth and not as part of the overall Security program. But the quicker you can gain control of the reigns puts you in a much stronger position to implement a comprehensive BYOD program.</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-mobile-in-2013%2F&amp;t=Must%20Have%20Competencies%20for%20Mobile%20in%202013"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Must%20Have%20Competencies%20for%20Mobile%20in%202013%20-%20http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-mobile-in-2013%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-mobile-in-2013%2F&amp;title=Must%20Have%20Competencies%20for%20Mobile%20in%202013&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=It%E2%80%99s%20no%20surprise%20that%20Mobile%20is%20one%20of%20the%20four%20competencies%20which%20will%20need%20to%20be%20addressed%20in%202013.%20I%20addressed%20the%20mobile%20competencies%20in%20some%20detail%20sin%20one%20of%20my%20blogs%20last%20year%20so%20for%20the%20sake%20of%20completeness%20I%20will%20revisit%20to%20ensure%20my%20recommendations%20are%20still%20valid."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Must%20Have%20Competencies%20for%20Mobile%20in%202013&body=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-mobile-in-2013%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-7967')" id="sociable-post-7967" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-mobile-in-2013%2F&amp;t=Must%20Have%20Competencies%20for%20Mobile%20in%202013"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-mobile-in-2013%2F&amp;title=Must%20Have%20Competencies%20for%20Mobile%20in%202013&amp;notes=It%E2%80%99s%20no%20surprise%20that%20Mobile%20is%20one%20of%20the%20four%20competencies%20which%20will%20need%20to%20be%20addressed%20in%202013.%20I%20addressed%20the%20mobile%20competencies%20in%20some%20detail%20sin%20one%20of%20my%20blogs%20last%20year%20so%20for%20the%20sake%20of%20completeness%20I%20will%20revisit%20to%20ensure%20my%20recommendations%20are%20still%20valid."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-mobile-in-2013%2F&amp;title=Must%20Have%20Competencies%20for%20Mobile%20in%202013&amp;bodytext=It%E2%80%99s%20no%20surprise%20that%20Mobile%20is%20one%20of%20the%20four%20competencies%20which%20will%20need%20to%20be%20addressed%20in%202013.%20I%20addressed%20the%20mobile%20competencies%20in%20some%20detail%20sin%20one%20of%20my%20blogs%20last%20year%20so%20for%20the%20sake%20of%20completeness%20I%20will%20revisit%20to%20ensure%20my%20recommendations%20are%20still%20valid."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-mobile-in-2013%2F&amp;title=Must%20Have%20Competencies%20for%20Mobile%20in%202013"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-mobile-in-2013%2F&title=Must%20Have%20Competencies%20for%20Mobile%20in%202013"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-mobile-in-2013%2F&amp;title=Must%20Have%20Competencies%20for%20Mobile%20in%202013&amp;annotation=It%E2%80%99s%20no%20surprise%20that%20Mobile%20is%20one%20of%20the%20four%20competencies%20which%20will%20need%20to%20be%20addressed%20in%202013.%20I%20addressed%20the%20mobile%20competencies%20in%20some%20detail%20sin%20one%20of%20my%20blogs%20last%20year%20so%20for%20the%20sake%20of%20completeness%20I%20will%20revisit%20to%20ensure%20my%20recommendations%20are%20still%20valid."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-mobile-in-2013%2F&amp;t=Must%20Have%20Competencies%20for%20Mobile%20in%202013"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Must%20Have%20Competencies%20for%20Mobile%20in%202013&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-mobile-in-2013%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=It%E2%80%99s%20no%20surprise%20that%20Mobile%20is%20one%20of%20the%20four%20competencies%20which%20will%20need%20to%20be%20addressed%20in%202013.%20I%20addressed%20the%20mobile%20competencies%20in%20some%20detail%20sin%20one%20of%20my%20blogs%20last%20year%20so%20for%20the%20sake%20of%20completeness%20I%20will%20revisit%20to%20ensure%20my%20recommendations%20are%20still%20valid."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-mobile-in-2013%2F&amp;Title=Must%20Have%20Competencies%20for%20Mobile%20in%202013"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-mobile-in-2013%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-mobile-in-2013%2F&amp;title=Must%20Have%20Competencies%20for%20Mobile%20in%202013&amp;selection=It%E2%80%99s%20no%20surprise%20that%20Mobile%20is%20one%20of%20the%20four%20competencies%20which%20will%20need%20to%20be%20addressed%20in%202013.%20I%20addressed%20the%20mobile%20competencies%20in%20some%20detail%20sin%20one%20of%20my%20blogs%20last%20year%20so%20for%20the%20sake%20of%20completeness%20I%20will%20revisit%20to%20ensure%20my%20recommendations%20are%20still%20valid."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-mobile-in-2013%2F&amp;t=Must%20Have%20Competencies%20for%20Mobile%20in%202013&amp;s=It%E2%80%99s%20no%20surprise%20that%20Mobile%20is%20one%20of%20the%20four%20competencies%20which%20will%20need%20to%20be%20addressed%20in%202013.%20I%20addressed%20the%20mobile%20competencies%20in%20some%20detail%20sin%20one%20of%20my%20blogs%20last%20year%20so%20for%20the%20sake%20of%20completeness%20I%20will%20revisit%20to%20ensure%20my%20recommendations%20are%20still%20valid."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-mobile-in-2013%2F&amp;title=Must%20Have%20Competencies%20for%20Mobile%20in%202013&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-mobile-in-2013%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-7967')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-7967',true)" class="close">

		  <img onclick="hide_sociable('post-7967',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/must-have-competencies-for-mobile-in-2013/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/must-have-competencies-for-mobile-in-2013/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Calling IT Professionals: Addressing the Security Skills Gap</title>
		<link>http://blogs.rsa.com/calling-it-professionals-addressing-the-security-skills-gap/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=calling-it-professionals-addressing-the-security-skills-gap</link>
		<comments>http://blogs.rsa.com/calling-it-professionals-addressing-the-security-skills-gap/#comments</comments>
		<pubDate>Thu, 28 Feb 2013 12:00:21 +0000</pubDate>
		<dc:creator>Rashmi Knowles</dc:creator>
				<category><![CDATA[Cyber Security Training]]></category>
		<category><![CDATA[cybercrime]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=8227</guid>
		<description><![CDATA[Art Coviello at RSA often refers to the skills gap in the number of Cyber security professionals in his keynotes. A UK National Audit Office report out today quotes it could take "up to 20 years to address the skills gap." The truth is the number of IT and cyber security professionals in the UK has not increased in line with the growth of the internet and the NAO warns that the UK faced a current and future cyber security skills gap, with "the current pipeline of graduates and practitioners" unable to meet demand.]]></description>
				<content:encoded><![CDATA[<p>Art Coviello at RSA often refers to the skills gap in the number of Cyber security professionals in his keynotes. A UK National Audit Office report out today quotes it could take &#8220;up to 20 years to address the skills gap”.</p>
<p>The truth is the number of IT and cyber security professionals in the UK has not increased in line with the growth of the internet and the NAO warns that the UK faced a current and future cyber security skills gap, with &#8220;the current pipeline of graduates and practitioners&#8221; unable to meet demand.</p>
<p>It warned that the cost of cyber crime is estimated to be between £18bn and £27bn a year. In 2011, ministers announced funding of £650m to implement the UK&#8217;s <span style="text-decoration: underline"><strong><a href="http://www.cabinetoffice.gov.uk/sites/default/files/resources/uk-cyber-security-strategy-final.pdf">Cyber Security Strategy</a></strong></span>, which set out the risks of the UK&#8217;s growing reliance on cyber space.</p>
<p>The strategy identified criminals, terrorists, foreign intelligence services, foreign militaries and politically motivated &#8220;hacktivists&#8221; as potential enemies who might choose to attack vulnerabilities in British cyber-defences. To date both <span style="text-decoration: underline"><strong><a href="http://www.soca.gov.uk/" target="_blank">SOCA</a></strong></span> (Serious Organised Crime Agency) and <span style="text-decoration: underline"><strong><a href="http://actionfraud.org.uk/" target="_blank">Action Fraud</a></strong></span>, the UK’s national fraud reporting centre have both been very active in thwarting threats.</p>
<p>How can this skills gap be addresses? It needs investment by the government but also by education authorities and indeed the Cyber security profession.  Many years ago studying IT at a University was very attractive, but it seems to have lost its appeal.  Moreover, how many IT related degree courses actually teach security as part of its curriculum.</p>
<p>I think the industry needs to do its part to ensure that the Cyber security profession is seen as an attractive career choice and start early by evangelizing in schools and colleges.</p>
<p>The TV series CSI did wonders for enrolment into Forensics courses so I wonder if we need an equivalent Cyber security TV series to get individuals signed up.  Whatever, we do we are still going to be faced with a huge skills gap in this sector.</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fcalling-it-professionals-addressing-the-security-skills-gap%2F&amp;t=Calling%20IT%20Professionals%3A%20Addressing%20the%20Security%20Skills%20Gap"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Calling%20IT%20Professionals%3A%20Addressing%20the%20Security%20Skills%20Gap%20-%20http%3A%2F%2Fblogs.rsa.com%2Fcalling-it-professionals-addressing-the-security-skills-gap%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fcalling-it-professionals-addressing-the-security-skills-gap%2F&amp;title=Calling%20IT%20Professionals%3A%20Addressing%20the%20Security%20Skills%20Gap&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=Art%20Coviello%20at%20RSA%20often%20refers%20to%20the%20skills%20gap%20in%20the%20number%20of%20Cyber%20security%20professionals%20in%20his%20keynotes.%20A%20UK%20National%20Audit%20Office%20report%20out%20today%20quotes%20it%20could%20take%20%22up%20to%2020%20years%20to%20address%20the%20skills%20gap.%22%20The%20truth%20is%20the%20number%20of%20IT%20and%20cyber%20security%20professionals%20in%20the%20UK%20has%20not%20increased%20in%20line%20with%20the%20growth%20of%20the%20internet%20and%20the%20NAO%20warns%20that%20the%20UK%20faced%20a%20current%20and%20future%20cyber%20security%20skills%20gap%2C%20with%20%22the%20current%20pipeline%20of%20graduates%20and%20practitioners%22%20unable%20to%20meet%20demand."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Calling%20IT%20Professionals%3A%20Addressing%20the%20Security%20Skills%20Gap&body=http%3A%2F%2Fblogs.rsa.com%2Fcalling-it-professionals-addressing-the-security-skills-gap%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-8227')" id="sociable-post-8227" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fcalling-it-professionals-addressing-the-security-skills-gap%2F&amp;t=Calling%20IT%20Professionals%3A%20Addressing%20the%20Security%20Skills%20Gap"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fcalling-it-professionals-addressing-the-security-skills-gap%2F&amp;title=Calling%20IT%20Professionals%3A%20Addressing%20the%20Security%20Skills%20Gap&amp;notes=Art%20Coviello%20at%20RSA%20often%20refers%20to%20the%20skills%20gap%20in%20the%20number%20of%20Cyber%20security%20professionals%20in%20his%20keynotes.%20A%20UK%20National%20Audit%20Office%20report%20out%20today%20quotes%20it%20could%20take%20%22up%20to%2020%20years%20to%20address%20the%20skills%20gap.%22%20The%20truth%20is%20the%20number%20of%20IT%20and%20cyber%20security%20professionals%20in%20the%20UK%20has%20not%20increased%20in%20line%20with%20the%20growth%20of%20the%20internet%20and%20the%20NAO%20warns%20that%20the%20UK%20faced%20a%20current%20and%20future%20cyber%20security%20skills%20gap%2C%20with%20%22the%20current%20pipeline%20of%20graduates%20and%20practitioners%22%20unable%20to%20meet%20demand."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fcalling-it-professionals-addressing-the-security-skills-gap%2F&amp;title=Calling%20IT%20Professionals%3A%20Addressing%20the%20Security%20Skills%20Gap&amp;bodytext=Art%20Coviello%20at%20RSA%20often%20refers%20to%20the%20skills%20gap%20in%20the%20number%20of%20Cyber%20security%20professionals%20in%20his%20keynotes.%20A%20UK%20National%20Audit%20Office%20report%20out%20today%20quotes%20it%20could%20take%20%22up%20to%2020%20years%20to%20address%20the%20skills%20gap.%22%20The%20truth%20is%20the%20number%20of%20IT%20and%20cyber%20security%20professionals%20in%20the%20UK%20has%20not%20increased%20in%20line%20with%20the%20growth%20of%20the%20internet%20and%20the%20NAO%20warns%20that%20the%20UK%20faced%20a%20current%20and%20future%20cyber%20security%20skills%20gap%2C%20with%20%22the%20current%20pipeline%20of%20graduates%20and%20practitioners%22%20unable%20to%20meet%20demand."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fcalling-it-professionals-addressing-the-security-skills-gap%2F&amp;title=Calling%20IT%20Professionals%3A%20Addressing%20the%20Security%20Skills%20Gap"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fcalling-it-professionals-addressing-the-security-skills-gap%2F&title=Calling%20IT%20Professionals%3A%20Addressing%20the%20Security%20Skills%20Gap"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fcalling-it-professionals-addressing-the-security-skills-gap%2F&amp;title=Calling%20IT%20Professionals%3A%20Addressing%20the%20Security%20Skills%20Gap&amp;annotation=Art%20Coviello%20at%20RSA%20often%20refers%20to%20the%20skills%20gap%20in%20the%20number%20of%20Cyber%20security%20professionals%20in%20his%20keynotes.%20A%20UK%20National%20Audit%20Office%20report%20out%20today%20quotes%20it%20could%20take%20%22up%20to%2020%20years%20to%20address%20the%20skills%20gap.%22%20The%20truth%20is%20the%20number%20of%20IT%20and%20cyber%20security%20professionals%20in%20the%20UK%20has%20not%20increased%20in%20line%20with%20the%20growth%20of%20the%20internet%20and%20the%20NAO%20warns%20that%20the%20UK%20faced%20a%20current%20and%20future%20cyber%20security%20skills%20gap%2C%20with%20%22the%20current%20pipeline%20of%20graduates%20and%20practitioners%22%20unable%20to%20meet%20demand."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fcalling-it-professionals-addressing-the-security-skills-gap%2F&amp;t=Calling%20IT%20Professionals%3A%20Addressing%20the%20Security%20Skills%20Gap"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Calling%20IT%20Professionals%3A%20Addressing%20the%20Security%20Skills%20Gap&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fcalling-it-professionals-addressing-the-security-skills-gap%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=Art%20Coviello%20at%20RSA%20often%20refers%20to%20the%20skills%20gap%20in%20the%20number%20of%20Cyber%20security%20professionals%20in%20his%20keynotes.%20A%20UK%20National%20Audit%20Office%20report%20out%20today%20quotes%20it%20could%20take%20%22up%20to%2020%20years%20to%20address%20the%20skills%20gap.%22%20The%20truth%20is%20the%20number%20of%20IT%20and%20cyber%20security%20professionals%20in%20the%20UK%20has%20not%20increased%20in%20line%20with%20the%20growth%20of%20the%20internet%20and%20the%20NAO%20warns%20that%20the%20UK%20faced%20a%20current%20and%20future%20cyber%20security%20skills%20gap%2C%20with%20%22the%20current%20pipeline%20of%20graduates%20and%20practitioners%22%20unable%20to%20meet%20demand."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fcalling-it-professionals-addressing-the-security-skills-gap%2F&amp;Title=Calling%20IT%20Professionals%3A%20Addressing%20the%20Security%20Skills%20Gap"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fcalling-it-professionals-addressing-the-security-skills-gap%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fcalling-it-professionals-addressing-the-security-skills-gap%2F&amp;title=Calling%20IT%20Professionals%3A%20Addressing%20the%20Security%20Skills%20Gap&amp;selection=Art%20Coviello%20at%20RSA%20often%20refers%20to%20the%20skills%20gap%20in%20the%20number%20of%20Cyber%20security%20professionals%20in%20his%20keynotes.%20A%20UK%20National%20Audit%20Office%20report%20out%20today%20quotes%20it%20could%20take%20%22up%20to%2020%20years%20to%20address%20the%20skills%20gap.%22%20The%20truth%20is%20the%20number%20of%20IT%20and%20cyber%20security%20professionals%20in%20the%20UK%20has%20not%20increased%20in%20line%20with%20the%20growth%20of%20the%20internet%20and%20the%20NAO%20warns%20that%20the%20UK%20faced%20a%20current%20and%20future%20cyber%20security%20skills%20gap%2C%20with%20%22the%20current%20pipeline%20of%20graduates%20and%20practitioners%22%20unable%20to%20meet%20demand."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fcalling-it-professionals-addressing-the-security-skills-gap%2F&amp;t=Calling%20IT%20Professionals%3A%20Addressing%20the%20Security%20Skills%20Gap&amp;s=Art%20Coviello%20at%20RSA%20often%20refers%20to%20the%20skills%20gap%20in%20the%20number%20of%20Cyber%20security%20professionals%20in%20his%20keynotes.%20A%20UK%20National%20Audit%20Office%20report%20out%20today%20quotes%20it%20could%20take%20%22up%20to%2020%20years%20to%20address%20the%20skills%20gap.%22%20The%20truth%20is%20the%20number%20of%20IT%20and%20cyber%20security%20professionals%20in%20the%20UK%20has%20not%20increased%20in%20line%20with%20the%20growth%20of%20the%20internet%20and%20the%20NAO%20warns%20that%20the%20UK%20faced%20a%20current%20and%20future%20cyber%20security%20skills%20gap%2C%20with%20%22the%20current%20pipeline%20of%20graduates%20and%20practitioners%22%20unable%20to%20meet%20demand."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fcalling-it-professionals-addressing-the-security-skills-gap%2F&amp;title=Calling%20IT%20Professionals%3A%20Addressing%20the%20Security%20Skills%20Gap&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fcalling-it-professionals-addressing-the-security-skills-gap%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-8227')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-8227',true)" class="close">

		  <img onclick="hide_sociable('post-8227',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/calling-it-professionals-addressing-the-security-skills-gap/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/calling-it-professionals-addressing-the-security-skills-gap/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How broken is security?</title>
		<link>http://blogs.rsa.com/how-broken-is-security/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=how-broken-is-security</link>
		<comments>http://blogs.rsa.com/how-broken-is-security/#comments</comments>
		<pubDate>Tue, 26 Feb 2013 21:35:35 +0000</pubDate>
		<dc:creator>Rashmi Knowles</dc:creator>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[advanced threats]]></category>
		<category><![CDATA[APT]]></category>
		<category><![CDATA[cyber espionage]]></category>

		<guid isPermaLink="false">https://blogs.rsa.com/?p=8186</guid>
		<description><![CDATA[Last week Mandiant produced their report entitled ‘Mandiant APT1 report’ that was widely covered by global media and essentially exposed a ring in China allegedly responsible for APT attacks. To many, this in itself is startling news and there have been many stories pointing the finger at hackers in China. However, on reading the report [...]]]></description>
				<content:encoded><![CDATA[<p>Last week Mandiant produced their report entitled ‘<a href="http://intelreport.mandiant.com/?gclid=COzT_rD31LUCFQLhQgodR0kANw">Mandiant APT1 report</a>’ that was widely covered by global media and essentially exposed a ring in China allegedly responsible for APT attacks.  To many, this in itself is startling news and there have been many stories pointing the finger at hackers in China.</p>
<p>However, on reading the report an interesting statistic about how long APT1 were in organizations stands out. We know from the <a href="http://www.verizonenterprise.com/resources/reports/rp_data-breach-investigations-report-2012_en_xg.pdf?__ct_return=1">2012 Verizon Data Breach Report</a> that breaches lead to compromise much faster than companies can discover them.  Security tools are slow, lack visibility and are too often perimeter and signature-based to detect the presence of cyber activity.  Here’s a quote from the report:</p>
<blockquote><p>“APT1 maintained access to victim networks for an average of 356 days. The longest time period APT1 maintained access to a victim’s network was 1,764 days, or four years and ten months.”</p></blockquote>
<p>The challenge for all organizations is that they rely on obsolete technology or signature-based detection systems which are really not adequate for these types of attacks.</p>
<p>Disparate security tools are unable to identify and investigate advanced attacks in a timely manner and SIEM tools have either speed or smarts, but never both. Furthermore, large amounts of blind spots combined with a large window of risk from an attack allows attackers too much free time on the network. Organizations must have a target to reduce the ‘free time’ or ‘dwell time’ in an APT attack, early detection and remediation will minimize the damage. Proving compliance also costs too much and takes resources away from improving security against targeted attacks and we all know that being compliant doesn’t translate to being secure.</p>
<p>Until companies change the status quo and implement Intelligence-Driven security models we will continue to see compromises over long periods of time without companies even realizing they are hosting cybercriminals in their infrastructures.  Final thought &#8211; Did the company that had APT1 in their network for 4 years and 10 months actually find the attack and stop it? Or did the attackers just get bored?  My money is on the latter.</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fhow-broken-is-security%2F&amp;t=How%20broken%20is%20security%3F"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=How%20broken%20is%20security%3F%20-%20http%3A%2F%2Fblogs.rsa.com%2Fhow-broken-is-security%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fhow-broken-is-security%2F&amp;title=How%20broken%20is%20security%3F&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=Last%20week%20Mandiant%20produced%20their%20report%20entitled%20%E2%80%98Mandiant%20APT1%20report%E2%80%99%20that%20was%20widely%20covered%20by%20global%20media%20and%20essentially%20exposed%20a%20ring%20in%20China%20allegedly%20responsible%20for%20APT%20attacks.%20%20To%20many%2C%20this%20in%20itself%20is%20startling%20news%20and%20there%20h"></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=How%20broken%20is%20security%3F&body=http%3A%2F%2Fblogs.rsa.com%2Fhow-broken-is-security%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-8186')" id="sociable-post-8186" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fhow-broken-is-security%2F&amp;t=How%20broken%20is%20security%3F"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fhow-broken-is-security%2F&amp;title=How%20broken%20is%20security%3F&amp;notes=Last%20week%20Mandiant%20produced%20their%20report%20entitled%20%E2%80%98Mandiant%20APT1%20report%E2%80%99%20that%20was%20widely%20covered%20by%20global%20media%20and%20essentially%20exposed%20a%20ring%20in%20China%20allegedly%20responsible%20for%20APT%20attacks.%20%20To%20many%2C%20this%20in%20itself%20is%20startling%20news%20and%20there%20h"></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fhow-broken-is-security%2F&amp;title=How%20broken%20is%20security%3F&amp;bodytext=Last%20week%20Mandiant%20produced%20their%20report%20entitled%20%E2%80%98Mandiant%20APT1%20report%E2%80%99%20that%20was%20widely%20covered%20by%20global%20media%20and%20essentially%20exposed%20a%20ring%20in%20China%20allegedly%20responsible%20for%20APT%20attacks.%20%20To%20many%2C%20this%20in%20itself%20is%20startling%20news%20and%20there%20h"></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fhow-broken-is-security%2F&amp;title=How%20broken%20is%20security%3F"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fhow-broken-is-security%2F&title=How%20broken%20is%20security%3F"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fhow-broken-is-security%2F&amp;title=How%20broken%20is%20security%3F&amp;annotation=Last%20week%20Mandiant%20produced%20their%20report%20entitled%20%E2%80%98Mandiant%20APT1%20report%E2%80%99%20that%20was%20widely%20covered%20by%20global%20media%20and%20essentially%20exposed%20a%20ring%20in%20China%20allegedly%20responsible%20for%20APT%20attacks.%20%20To%20many%2C%20this%20in%20itself%20is%20startling%20news%20and%20there%20h"></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fhow-broken-is-security%2F&amp;t=How%20broken%20is%20security%3F"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=How%20broken%20is%20security%3F&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fhow-broken-is-security%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=Last%20week%20Mandiant%20produced%20their%20report%20entitled%20%E2%80%98Mandiant%20APT1%20report%E2%80%99%20that%20was%20widely%20covered%20by%20global%20media%20and%20essentially%20exposed%20a%20ring%20in%20China%20allegedly%20responsible%20for%20APT%20attacks.%20%20To%20many%2C%20this%20in%20itself%20is%20startling%20news%20and%20there%20h"></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fhow-broken-is-security%2F&amp;Title=How%20broken%20is%20security%3F"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fhow-broken-is-security%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fhow-broken-is-security%2F&amp;title=How%20broken%20is%20security%3F&amp;selection=Last%20week%20Mandiant%20produced%20their%20report%20entitled%20%E2%80%98Mandiant%20APT1%20report%E2%80%99%20that%20was%20widely%20covered%20by%20global%20media%20and%20essentially%20exposed%20a%20ring%20in%20China%20allegedly%20responsible%20for%20APT%20attacks.%20%20To%20many%2C%20this%20in%20itself%20is%20startling%20news%20and%20there%20h"></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fhow-broken-is-security%2F&amp;t=How%20broken%20is%20security%3F&amp;s=Last%20week%20Mandiant%20produced%20their%20report%20entitled%20%E2%80%98Mandiant%20APT1%20report%E2%80%99%20that%20was%20widely%20covered%20by%20global%20media%20and%20essentially%20exposed%20a%20ring%20in%20China%20allegedly%20responsible%20for%20APT%20attacks.%20%20To%20many%2C%20this%20in%20itself%20is%20startling%20news%20and%20there%20h"></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fhow-broken-is-security%2F&amp;title=How%20broken%20is%20security%3F&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fhow-broken-is-security%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-8186')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-8186',true)" class="close">

		  <img onclick="hide_sociable('post-8186',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/how-broken-is-security/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/how-broken-is-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Prevent and Predict Attacks</title>
		<link>http://blogs.rsa.com/prevent-and-predict-attacks/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=prevent-and-predict-attacks</link>
		<comments>http://blogs.rsa.com/prevent-and-predict-attacks/#comments</comments>
		<pubDate>Mon, 04 Feb 2013 10:30:00 +0000</pubDate>
		<dc:creator>Rashmi Knowles</dc:creator>
				<category><![CDATA[Intelligence-driven security]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Security Information and Event Management (SIEM)]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[security analytics]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=8011</guid>
		<description><![CDATA[When it comes to defending our networks we have to be right 100% of the time but a cybercriminal has to be right just once. We must shift this balance if we are ever going to be in a position to truly protect and defend our networks. In fact, defence is probably no longer appropriate [...]]]></description>
				<content:encoded><![CDATA[<p>When it comes to defending our networks we have to be right 100% of the time but a cybercriminal has to be right just once. We must shift this balance if we are ever going to be in a position to truly protect and defend our networks. In fact, defence is probably no longer appropriate because it is not enough we need to be in a position to stop the attacks and even predict attacks. Predict attacks you say? How?<br />
Those of you familiar with the Lockheed Martin Kill Chain methodology will know that ultimately the goal is to analyze persistent intrusions for patterns and trends and then use this data to stop attacks or even predict attacks. Breaking the chain in one place means that you may have been successful in stopping that one attack however to be truly resilient you really need to break the chain in several places. How can you do that and what tools would you need? There is an answer….</p>
<p>RSA launched <a href="http://www.emc.com/about/news/press/2013/20130130-01.htm">Security Analytics</a> on the 30th January. It is a security monitoring system that brings together technologies from the existing technology categories, including network security monitoring, log-oriented SIEM, malware analytics, forensics, compliance reporting, and Big Data management &amp; analytics, to better address the security needs of organizations. In particular the RSA Security Analytics solution provides capabilities that improve the effectiveness and efficiency of security analysts in their discovery (or detection) and investigation of security vulnerabilities and attacks which are underway. In addition, with RSA Security Analytics, proving compliance becomes an outcome of effective security controls as opposed the main driver of them.</p>
<p>&nbsp;</p>
<p>In most companies’ protection and analysis is done by an army of people relying on point tools and manual or labour intensive processes. According to ESG research, 44% of enterprise organizations believe that their security data collection, processing and analysis qualify as “big data” today. This is simply not good enough to thwart our adversaries. We need real-time security intelligence and situational awareness to give them visibility into their security status at all layers of the technology stack and across their enterprise. This unprecedented view was not possible until now. This level of intelligence will help security executives prioritize actions adjust security controls accelerate incident detections and improve workflows around incident response. All of these can advances can not only improve security but can also lower the overall operational costs of doing so. RSA Security Analytics may just have the tools to help with breaking the kill chain. Read more on <a href="http://www.emc.com/security/security-analytics/security-analytics.htm">RSA Security Analytics</a></p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fprevent-and-predict-attacks%2F&amp;t=Prevent%20and%20Predict%20Attacks"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Prevent%20and%20Predict%20Attacks%20-%20http%3A%2F%2Fblogs.rsa.com%2Fprevent-and-predict-attacks%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fprevent-and-predict-attacks%2F&amp;title=Prevent%20and%20Predict%20Attacks&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=When%20it%20comes%20to%20defending%20our%20networks%20we%20have%20to%20be%20right%20100%25%20of%20the%20time%20but%20a%20cybercriminal%20has%20to%20be%20right%20just%20once.%20We%20must%20shift%20this%20balance%20if%20we%20are%20ever%20going%20to%20be%20in%20a%20position%20to%20truly%20protect%20and%20defend%20our%20networks.%20In%20fact%2C%20defence"></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Prevent%20and%20Predict%20Attacks&body=http%3A%2F%2Fblogs.rsa.com%2Fprevent-and-predict-attacks%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-8011')" id="sociable-post-8011" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fprevent-and-predict-attacks%2F&amp;t=Prevent%20and%20Predict%20Attacks"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fprevent-and-predict-attacks%2F&amp;title=Prevent%20and%20Predict%20Attacks&amp;notes=When%20it%20comes%20to%20defending%20our%20networks%20we%20have%20to%20be%20right%20100%25%20of%20the%20time%20but%20a%20cybercriminal%20has%20to%20be%20right%20just%20once.%20We%20must%20shift%20this%20balance%20if%20we%20are%20ever%20going%20to%20be%20in%20a%20position%20to%20truly%20protect%20and%20defend%20our%20networks.%20In%20fact%2C%20defence"></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fprevent-and-predict-attacks%2F&amp;title=Prevent%20and%20Predict%20Attacks&amp;bodytext=When%20it%20comes%20to%20defending%20our%20networks%20we%20have%20to%20be%20right%20100%25%20of%20the%20time%20but%20a%20cybercriminal%20has%20to%20be%20right%20just%20once.%20We%20must%20shift%20this%20balance%20if%20we%20are%20ever%20going%20to%20be%20in%20a%20position%20to%20truly%20protect%20and%20defend%20our%20networks.%20In%20fact%2C%20defence"></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fprevent-and-predict-attacks%2F&amp;title=Prevent%20and%20Predict%20Attacks"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fprevent-and-predict-attacks%2F&title=Prevent%20and%20Predict%20Attacks"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fprevent-and-predict-attacks%2F&amp;title=Prevent%20and%20Predict%20Attacks&amp;annotation=When%20it%20comes%20to%20defending%20our%20networks%20we%20have%20to%20be%20right%20100%25%20of%20the%20time%20but%20a%20cybercriminal%20has%20to%20be%20right%20just%20once.%20We%20must%20shift%20this%20balance%20if%20we%20are%20ever%20going%20to%20be%20in%20a%20position%20to%20truly%20protect%20and%20defend%20our%20networks.%20In%20fact%2C%20defence"></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fprevent-and-predict-attacks%2F&amp;t=Prevent%20and%20Predict%20Attacks"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Prevent%20and%20Predict%20Attacks&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fprevent-and-predict-attacks%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=When%20it%20comes%20to%20defending%20our%20networks%20we%20have%20to%20be%20right%20100%25%20of%20the%20time%20but%20a%20cybercriminal%20has%20to%20be%20right%20just%20once.%20We%20must%20shift%20this%20balance%20if%20we%20are%20ever%20going%20to%20be%20in%20a%20position%20to%20truly%20protect%20and%20defend%20our%20networks.%20In%20fact%2C%20defence"></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fprevent-and-predict-attacks%2F&amp;Title=Prevent%20and%20Predict%20Attacks"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fprevent-and-predict-attacks%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fprevent-and-predict-attacks%2F&amp;title=Prevent%20and%20Predict%20Attacks&amp;selection=When%20it%20comes%20to%20defending%20our%20networks%20we%20have%20to%20be%20right%20100%25%20of%20the%20time%20but%20a%20cybercriminal%20has%20to%20be%20right%20just%20once.%20We%20must%20shift%20this%20balance%20if%20we%20are%20ever%20going%20to%20be%20in%20a%20position%20to%20truly%20protect%20and%20defend%20our%20networks.%20In%20fact%2C%20defence"></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fprevent-and-predict-attacks%2F&amp;t=Prevent%20and%20Predict%20Attacks&amp;s=When%20it%20comes%20to%20defending%20our%20networks%20we%20have%20to%20be%20right%20100%25%20of%20the%20time%20but%20a%20cybercriminal%20has%20to%20be%20right%20just%20once.%20We%20must%20shift%20this%20balance%20if%20we%20are%20ever%20going%20to%20be%20in%20a%20position%20to%20truly%20protect%20and%20defend%20our%20networks.%20In%20fact%2C%20defence"></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fprevent-and-predict-attacks%2F&amp;title=Prevent%20and%20Predict%20Attacks&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fprevent-and-predict-attacks%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-8011')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-8011',true)" class="close">

		  <img onclick="hide_sociable('post-8011',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/prevent-and-predict-attacks/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/prevent-and-predict-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Must-have Competencies for the Cloud in 2013</title>
		<link>http://blogs.rsa.com/must-have-competencies-for-the-cloud-in-2013/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=must-have-competencies-for-the-cloud-in-2013</link>
		<comments>http://blogs.rsa.com/must-have-competencies-for-the-cloud-in-2013/#comments</comments>
		<pubDate>Tue, 29 Jan 2013 13:00:50 +0000</pubDate>
		<dc:creator>Rashmi Knowles</dc:creator>
				<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[cloud assurance standards]]></category>
		<category><![CDATA[Cloud Security Alliance]]></category>
		<category><![CDATA[cloud service providers]]></category>
		<category><![CDATA[risk]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=7773</guid>
		<description><![CDATA[Following on from my last blog ‘Re-enforcing our doors in 2013’ solving all of the issues of disruptive innovations isn’t going to be possible in a year but we must take some strides towards making some of the changes. The four members of the disruptive family are Cloud Computing, Social Media, Big Data and Mobile. Let’s take Cloud Computing this week and examine some competencies organizations must start to build.]]></description>
				<content:encoded><![CDATA[<p>Following on from my last blog ‘<a href="http://blogs.rsa.com/reinforcing-our-doors-in-2013/">Re-enforcing our doors in 2013</a>’ solving all of the issues of disruptive innovations isn’t going to be possible in a year but we must take strides towards making some of the changes. The four members of the disruptive family are Cloud Computing, Social Media, Big Data and Mobile. Let’s take Cloud Computing this week and examine some competencies organizations must start to build.</p>
<p>Cloud vendor management has been on our list for a long time but how effective are we at doing this? Ultimately, organizations are responsible for the information that’s held by the Cloud service provider (CSP).  Information security teams must now switch their focus from implementing controls internally to controls implemented by third parties and asking themselves ‘how can we ensure that cloud services providers are meeting our trust levels?’ Are they are attuned to our particular threats?</p>
<p>The conventional controls assurance model is not sustainable the cloud. Client organizations cannot visit every cloud service provider to examine their security controls. Today, CSP’s provide assurance by using questionnaires. This is a wholly inefficient process as all organizations ask the same questions and it turns out to be a box ticking exercise. There are also no standards for these, apart from guidelines issued by the <a href="https://cloudsecurityalliance.org/">Cloud Security Alliance</a>. A better approach would be third party assessment or certification like the AIPCA’s SOC 2 Report on Controls or the imminent ISO 27017 Standards for Security in Cloud Computing. In the meantime, organizations must find a happy medium to effectively measure controls and detect failures. The basic building blocks of an effective GRC implementations has some of the elements but while these need to mature companies will have to find their own way to measure assurance. Automated and transparent controls together with continuous monitoring will be an important part of the solution.</p>
<p>&nbsp;<br />
If mismanaged, this assurance process can add cost for sides, companies and service providers so it is important to ensure that overall budgets can be realigned. Companies have to realize that when moving to the cloud a larger portion of their budget is going to be needed to address cloud security. Budget realignment means reinvesting a portion of IT savings the organization achieves by moving to the cloud into managing risks. In the short term this realignment may not prove to be any more cost effective.</p>
<p>&nbsp;<br />
And finally, organizations must invest in technical proficiency for virtual and cloud environments. We know security controls change in the cloud e.g. the hypervisor in a virtual environment becomes a powerful software security control. Security teams must invest in these skills and ensure they have the knowledge to secure virtual environments within their own data centers and extend that knowledge to both private and public cloud models.</p>
<p>Look out my next blog on &#8211; Must have competencies for Social Media in 2013.</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-the-cloud-in-2013%2F&amp;t=Must-have%20Competencies%20for%20the%20Cloud%20in%202013"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Must-have%20Competencies%20for%20the%20Cloud%20in%202013%20-%20http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-the-cloud-in-2013%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-the-cloud-in-2013%2F&amp;title=Must-have%20Competencies%20for%20the%20Cloud%20in%202013&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=Following%20on%20from%20my%20last%20blog%20%E2%80%98Re-enforcing%20our%20doors%20in%202013%E2%80%99%20solving%20all%20of%20the%20issues%20of%20disruptive%20innovations%20isn%E2%80%99t%20going%20to%20be%20possible%20in%20a%20year%20but%20we%20must%20take%20some%20strides%20towards%20making%20some%20of%20the%20changes.%20The%20four%20members%20of%20the%20disruptive%20family%20are%20Cloud%20Computing%2C%20Social%20Media%2C%20Big%20Data%20and%20Mobile.%20Let%E2%80%99s%20take%20Cloud%20Computing%20this%20week%20and%20examine%20some%20competencies%20organizations%20must%20start%20to%20build."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Must-have%20Competencies%20for%20the%20Cloud%20in%202013&body=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-the-cloud-in-2013%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-7773')" id="sociable-post-7773" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-the-cloud-in-2013%2F&amp;t=Must-have%20Competencies%20for%20the%20Cloud%20in%202013"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-the-cloud-in-2013%2F&amp;title=Must-have%20Competencies%20for%20the%20Cloud%20in%202013&amp;notes=Following%20on%20from%20my%20last%20blog%20%E2%80%98Re-enforcing%20our%20doors%20in%202013%E2%80%99%20solving%20all%20of%20the%20issues%20of%20disruptive%20innovations%20isn%E2%80%99t%20going%20to%20be%20possible%20in%20a%20year%20but%20we%20must%20take%20some%20strides%20towards%20making%20some%20of%20the%20changes.%20The%20four%20members%20of%20the%20disruptive%20family%20are%20Cloud%20Computing%2C%20Social%20Media%2C%20Big%20Data%20and%20Mobile.%20Let%E2%80%99s%20take%20Cloud%20Computing%20this%20week%20and%20examine%20some%20competencies%20organizations%20must%20start%20to%20build."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-the-cloud-in-2013%2F&amp;title=Must-have%20Competencies%20for%20the%20Cloud%20in%202013&amp;bodytext=Following%20on%20from%20my%20last%20blog%20%E2%80%98Re-enforcing%20our%20doors%20in%202013%E2%80%99%20solving%20all%20of%20the%20issues%20of%20disruptive%20innovations%20isn%E2%80%99t%20going%20to%20be%20possible%20in%20a%20year%20but%20we%20must%20take%20some%20strides%20towards%20making%20some%20of%20the%20changes.%20The%20four%20members%20of%20the%20disruptive%20family%20are%20Cloud%20Computing%2C%20Social%20Media%2C%20Big%20Data%20and%20Mobile.%20Let%E2%80%99s%20take%20Cloud%20Computing%20this%20week%20and%20examine%20some%20competencies%20organizations%20must%20start%20to%20build."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-the-cloud-in-2013%2F&amp;title=Must-have%20Competencies%20for%20the%20Cloud%20in%202013"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-the-cloud-in-2013%2F&title=Must-have%20Competencies%20for%20the%20Cloud%20in%202013"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-the-cloud-in-2013%2F&amp;title=Must-have%20Competencies%20for%20the%20Cloud%20in%202013&amp;annotation=Following%20on%20from%20my%20last%20blog%20%E2%80%98Re-enforcing%20our%20doors%20in%202013%E2%80%99%20solving%20all%20of%20the%20issues%20of%20disruptive%20innovations%20isn%E2%80%99t%20going%20to%20be%20possible%20in%20a%20year%20but%20we%20must%20take%20some%20strides%20towards%20making%20some%20of%20the%20changes.%20The%20four%20members%20of%20the%20disruptive%20family%20are%20Cloud%20Computing%2C%20Social%20Media%2C%20Big%20Data%20and%20Mobile.%20Let%E2%80%99s%20take%20Cloud%20Computing%20this%20week%20and%20examine%20some%20competencies%20organizations%20must%20start%20to%20build."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-the-cloud-in-2013%2F&amp;t=Must-have%20Competencies%20for%20the%20Cloud%20in%202013"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Must-have%20Competencies%20for%20the%20Cloud%20in%202013&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-the-cloud-in-2013%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=Following%20on%20from%20my%20last%20blog%20%E2%80%98Re-enforcing%20our%20doors%20in%202013%E2%80%99%20solving%20all%20of%20the%20issues%20of%20disruptive%20innovations%20isn%E2%80%99t%20going%20to%20be%20possible%20in%20a%20year%20but%20we%20must%20take%20some%20strides%20towards%20making%20some%20of%20the%20changes.%20The%20four%20members%20of%20the%20disruptive%20family%20are%20Cloud%20Computing%2C%20Social%20Media%2C%20Big%20Data%20and%20Mobile.%20Let%E2%80%99s%20take%20Cloud%20Computing%20this%20week%20and%20examine%20some%20competencies%20organizations%20must%20start%20to%20build."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-the-cloud-in-2013%2F&amp;Title=Must-have%20Competencies%20for%20the%20Cloud%20in%202013"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-the-cloud-in-2013%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-the-cloud-in-2013%2F&amp;title=Must-have%20Competencies%20for%20the%20Cloud%20in%202013&amp;selection=Following%20on%20from%20my%20last%20blog%20%E2%80%98Re-enforcing%20our%20doors%20in%202013%E2%80%99%20solving%20all%20of%20the%20issues%20of%20disruptive%20innovations%20isn%E2%80%99t%20going%20to%20be%20possible%20in%20a%20year%20but%20we%20must%20take%20some%20strides%20towards%20making%20some%20of%20the%20changes.%20The%20four%20members%20of%20the%20disruptive%20family%20are%20Cloud%20Computing%2C%20Social%20Media%2C%20Big%20Data%20and%20Mobile.%20Let%E2%80%99s%20take%20Cloud%20Computing%20this%20week%20and%20examine%20some%20competencies%20organizations%20must%20start%20to%20build."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-the-cloud-in-2013%2F&amp;t=Must-have%20Competencies%20for%20the%20Cloud%20in%202013&amp;s=Following%20on%20from%20my%20last%20blog%20%E2%80%98Re-enforcing%20our%20doors%20in%202013%E2%80%99%20solving%20all%20of%20the%20issues%20of%20disruptive%20innovations%20isn%E2%80%99t%20going%20to%20be%20possible%20in%20a%20year%20but%20we%20must%20take%20some%20strides%20towards%20making%20some%20of%20the%20changes.%20The%20four%20members%20of%20the%20disruptive%20family%20are%20Cloud%20Computing%2C%20Social%20Media%2C%20Big%20Data%20and%20Mobile.%20Let%E2%80%99s%20take%20Cloud%20Computing%20this%20week%20and%20examine%20some%20competencies%20organizations%20must%20start%20to%20build."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-the-cloud-in-2013%2F&amp;title=Must-have%20Competencies%20for%20the%20Cloud%20in%202013&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fmust-have-competencies-for-the-cloud-in-2013%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-7773')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-7773',true)" class="close">

		  <img onclick="hide_sociable('post-7773',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/must-have-competencies-for-the-cloud-in-2013/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/must-have-competencies-for-the-cloud-in-2013/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Europe’s new Cybercrime Centre (EC3) opens for business</title>
		<link>http://blogs.rsa.com/europes-new-cybercrime-centre-ec3-opens-for-business/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=europes-new-cybercrime-centre-ec3-opens-for-business</link>
		<comments>http://blogs.rsa.com/europes-new-cybercrime-centre-ec3-opens-for-business/#comments</comments>
		<pubDate>Wed, 23 Jan 2013 13:30:52 +0000</pubDate>
		<dc:creator>Rashmi Knowles</dc:creator>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[cybercrime]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=7762</guid>
		<description><![CDATA[The European Cybercrime Centre officially opened its doors this month based at the European Police Office in the Netherlands. According to a BBC report cybercrime in europe is estimated to cost €1.5 billion. The EC3′s focus is on illegal online activities carried out by organized crime groups — especially attacks targeting e-banking and other online financial activities, online child sexual exploitation and crimes that affect the critical infrastructure and information systems in the European Union.]]></description>
				<content:encoded><![CDATA[<p>The <strong><span style="text-decoration: underline"><a href="https://www.europol.europa.eu/ec3" target="_blank">European Cybercrime Centre</a></span></strong> officially opened its doors this month based at the European Police Office in the Netherlands. According to a BBC report cybercrime in europe is estimated to cost €1.5 billion. The EC3′s focus is on illegal online activities carried out by organized crime groups — especially attacks targeting e-banking and other online financial activities, online child sexual exploitation and crimes that affect the critical infrastructure and information systems in the European Union.</p>
<p><strong>Its five main functions are:</strong></p>
<ul>
<li><em>Data Fusion</em> – collecting and processing information on cybercrime</li>
<li><em>Operations</em> – Supporting investigations and facilitating law enforcement across the EU member states</li>
<li><em>Strategy</em> – Producing threat analysis, trends, forecasting etc.</li>
<li><em>R&amp;D/training</em> – working with European police (CEPOL), raising awareness and developing new forensic tools</li>
<li><em>Outreach</em> – working with the private sector and relevant industry bodies to share information</li>
</ul>
<p><a href="http://blogs.rsa.com/wp-content/uploads/EC3.jpg"><img class="alignnone size-full wp-image-7858" alt="EC3" src="http://blogs.rsa.com/wp-content/uploads/EC3.jpg" width="333" height="187" /></a></p>
<p>I see this as a really good initiative particularly as individual countries in Europe are often left to their own devices to fight cybercrime which may have its roots elsewhere. In addition, a common centre will also increase collaboration between all the countries and allow them to share information. Information sharing has become one of the key weapons against cybercrime.</p>
<p>Of the five functions listed, I believe the last one on outreach is going to be the most significant. Information sharing between government agencies may happen to an extent, but we all need to share information including the private sector. And, although this is something that many countries in Europe including the UK have tried to put in place, a central unit in Europe that works closely with the private sector to understand the threat landscape and share data is definitely a big step in the right direction.</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Feuropes-new-cybercrime-centre-ec3-opens-for-business%2F&amp;t=Europe%E2%80%99s%20new%20Cybercrime%20Centre%20%28EC3%29%20opens%20for%20business"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Europe%E2%80%99s%20new%20Cybercrime%20Centre%20%28EC3%29%20opens%20for%20business%20-%20http%3A%2F%2Fblogs.rsa.com%2Feuropes-new-cybercrime-centre-ec3-opens-for-business%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Feuropes-new-cybercrime-centre-ec3-opens-for-business%2F&amp;title=Europe%E2%80%99s%20new%20Cybercrime%20Centre%20%28EC3%29%20opens%20for%20business&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=The%20European%20Cybercrime%20Centre%20officially%20opened%20its%20doors%20this%20month%20based%20at%20the%20European%20Police%20Office%20in%20the%20Netherlands.%20According%20to%20a%20BBC%20report%20cybercrime%20in%20europe%20is%20estimated%20to%20cost%20%E2%82%AC1.5%20billion.%20The%20EC3%E2%80%B2s%20focus%20is%20on%20illegal%20online%20activities%20carried%20out%20by%20organized%20crime%20groups%20%E2%80%94%20especially%20attacks%20targeting%20e-banking%20and%20other%20online%20financial%20activities%2C%20online%20child%20sexual%20exploitation%20and%20crimes%20that%20affect%20the%20critical%20infrastructure%20and%20information%20systems%20in%20the%20European%20Union."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Europe%E2%80%99s%20new%20Cybercrime%20Centre%20%28EC3%29%20opens%20for%20business&body=http%3A%2F%2Fblogs.rsa.com%2Feuropes-new-cybercrime-centre-ec3-opens-for-business%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-7762')" id="sociable-post-7762" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Feuropes-new-cybercrime-centre-ec3-opens-for-business%2F&amp;t=Europe%E2%80%99s%20new%20Cybercrime%20Centre%20%28EC3%29%20opens%20for%20business"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Feuropes-new-cybercrime-centre-ec3-opens-for-business%2F&amp;title=Europe%E2%80%99s%20new%20Cybercrime%20Centre%20%28EC3%29%20opens%20for%20business&amp;notes=The%20European%20Cybercrime%20Centre%20officially%20opened%20its%20doors%20this%20month%20based%20at%20the%20European%20Police%20Office%20in%20the%20Netherlands.%20According%20to%20a%20BBC%20report%20cybercrime%20in%20europe%20is%20estimated%20to%20cost%20%E2%82%AC1.5%20billion.%20The%20EC3%E2%80%B2s%20focus%20is%20on%20illegal%20online%20activities%20carried%20out%20by%20organized%20crime%20groups%20%E2%80%94%20especially%20attacks%20targeting%20e-banking%20and%20other%20online%20financial%20activities%2C%20online%20child%20sexual%20exploitation%20and%20crimes%20that%20affect%20the%20critical%20infrastructure%20and%20information%20systems%20in%20the%20European%20Union."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Feuropes-new-cybercrime-centre-ec3-opens-for-business%2F&amp;title=Europe%E2%80%99s%20new%20Cybercrime%20Centre%20%28EC3%29%20opens%20for%20business&amp;bodytext=The%20European%20Cybercrime%20Centre%20officially%20opened%20its%20doors%20this%20month%20based%20at%20the%20European%20Police%20Office%20in%20the%20Netherlands.%20According%20to%20a%20BBC%20report%20cybercrime%20in%20europe%20is%20estimated%20to%20cost%20%E2%82%AC1.5%20billion.%20The%20EC3%E2%80%B2s%20focus%20is%20on%20illegal%20online%20activities%20carried%20out%20by%20organized%20crime%20groups%20%E2%80%94%20especially%20attacks%20targeting%20e-banking%20and%20other%20online%20financial%20activities%2C%20online%20child%20sexual%20exploitation%20and%20crimes%20that%20affect%20the%20critical%20infrastructure%20and%20information%20systems%20in%20the%20European%20Union."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Feuropes-new-cybercrime-centre-ec3-opens-for-business%2F&amp;title=Europe%E2%80%99s%20new%20Cybercrime%20Centre%20%28EC3%29%20opens%20for%20business"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Feuropes-new-cybercrime-centre-ec3-opens-for-business%2F&title=Europe%E2%80%99s%20new%20Cybercrime%20Centre%20%28EC3%29%20opens%20for%20business"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Feuropes-new-cybercrime-centre-ec3-opens-for-business%2F&amp;title=Europe%E2%80%99s%20new%20Cybercrime%20Centre%20%28EC3%29%20opens%20for%20business&amp;annotation=The%20European%20Cybercrime%20Centre%20officially%20opened%20its%20doors%20this%20month%20based%20at%20the%20European%20Police%20Office%20in%20the%20Netherlands.%20According%20to%20a%20BBC%20report%20cybercrime%20in%20europe%20is%20estimated%20to%20cost%20%E2%82%AC1.5%20billion.%20The%20EC3%E2%80%B2s%20focus%20is%20on%20illegal%20online%20activities%20carried%20out%20by%20organized%20crime%20groups%20%E2%80%94%20especially%20attacks%20targeting%20e-banking%20and%20other%20online%20financial%20activities%2C%20online%20child%20sexual%20exploitation%20and%20crimes%20that%20affect%20the%20critical%20infrastructure%20and%20information%20systems%20in%20the%20European%20Union."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Feuropes-new-cybercrime-centre-ec3-opens-for-business%2F&amp;t=Europe%E2%80%99s%20new%20Cybercrime%20Centre%20%28EC3%29%20opens%20for%20business"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Europe%E2%80%99s%20new%20Cybercrime%20Centre%20%28EC3%29%20opens%20for%20business&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Feuropes-new-cybercrime-centre-ec3-opens-for-business%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=The%20European%20Cybercrime%20Centre%20officially%20opened%20its%20doors%20this%20month%20based%20at%20the%20European%20Police%20Office%20in%20the%20Netherlands.%20According%20to%20a%20BBC%20report%20cybercrime%20in%20europe%20is%20estimated%20to%20cost%20%E2%82%AC1.5%20billion.%20The%20EC3%E2%80%B2s%20focus%20is%20on%20illegal%20online%20activities%20carried%20out%20by%20organized%20crime%20groups%20%E2%80%94%20especially%20attacks%20targeting%20e-banking%20and%20other%20online%20financial%20activities%2C%20online%20child%20sexual%20exploitation%20and%20crimes%20that%20affect%20the%20critical%20infrastructure%20and%20information%20systems%20in%20the%20European%20Union."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Feuropes-new-cybercrime-centre-ec3-opens-for-business%2F&amp;Title=Europe%E2%80%99s%20new%20Cybercrime%20Centre%20%28EC3%29%20opens%20for%20business"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Feuropes-new-cybercrime-centre-ec3-opens-for-business%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Feuropes-new-cybercrime-centre-ec3-opens-for-business%2F&amp;title=Europe%E2%80%99s%20new%20Cybercrime%20Centre%20%28EC3%29%20opens%20for%20business&amp;selection=The%20European%20Cybercrime%20Centre%20officially%20opened%20its%20doors%20this%20month%20based%20at%20the%20European%20Police%20Office%20in%20the%20Netherlands.%20According%20to%20a%20BBC%20report%20cybercrime%20in%20europe%20is%20estimated%20to%20cost%20%E2%82%AC1.5%20billion.%20The%20EC3%E2%80%B2s%20focus%20is%20on%20illegal%20online%20activities%20carried%20out%20by%20organized%20crime%20groups%20%E2%80%94%20especially%20attacks%20targeting%20e-banking%20and%20other%20online%20financial%20activities%2C%20online%20child%20sexual%20exploitation%20and%20crimes%20that%20affect%20the%20critical%20infrastructure%20and%20information%20systems%20in%20the%20European%20Union."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Feuropes-new-cybercrime-centre-ec3-opens-for-business%2F&amp;t=Europe%E2%80%99s%20new%20Cybercrime%20Centre%20%28EC3%29%20opens%20for%20business&amp;s=The%20European%20Cybercrime%20Centre%20officially%20opened%20its%20doors%20this%20month%20based%20at%20the%20European%20Police%20Office%20in%20the%20Netherlands.%20According%20to%20a%20BBC%20report%20cybercrime%20in%20europe%20is%20estimated%20to%20cost%20%E2%82%AC1.5%20billion.%20The%20EC3%E2%80%B2s%20focus%20is%20on%20illegal%20online%20activities%20carried%20out%20by%20organized%20crime%20groups%20%E2%80%94%20especially%20attacks%20targeting%20e-banking%20and%20other%20online%20financial%20activities%2C%20online%20child%20sexual%20exploitation%20and%20crimes%20that%20affect%20the%20critical%20infrastructure%20and%20information%20systems%20in%20the%20European%20Union."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Feuropes-new-cybercrime-centre-ec3-opens-for-business%2F&amp;title=Europe%E2%80%99s%20new%20Cybercrime%20Centre%20%28EC3%29%20opens%20for%20business&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Feuropes-new-cybercrime-centre-ec3-opens-for-business%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-7762')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-7762',true)" class="close">

		  <img onclick="hide_sociable('post-7762',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/europes-new-cybercrime-centre-ec3-opens-for-business/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/europes-new-cybercrime-centre-ec3-opens-for-business/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Reinforcing our doors in 2013</title>
		<link>http://blogs.rsa.com/reinforcing-our-doors-in-2013/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=reinforcing-our-doors-in-2013</link>
		<comments>http://blogs.rsa.com/reinforcing-our-doors-in-2013/#comments</comments>
		<pubDate>Tue, 22 Jan 2013 17:30:11 +0000</pubDate>
		<dc:creator>Rashmi Knowles</dc:creator>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Big Data]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[Social Media]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=7763</guid>
		<description><![CDATA[In my last blog I talked about the key technologies breaking down our doors in 2013. The four key areas were Cloud Computing, Social Media, Big Data and Mobile Devices. None of these should have come as a surprise to anyone in the industry today. These are all topics that are discussed and debated around tables of security teams in most enterprises. So, what can we do today to ensure we are prepared for these challenges and how do we start reinforcing our doors so that we allow these new technologies but have greater control and visibility and provide transparency for the user?]]></description>
				<content:encoded><![CDATA[<p><span style="text-decoration: underline"><strong><a href="http://blogs.rsa.com/?p=7761" target="_blank">In my last blog </a></strong></span>I talked about the key technologies breaking down our doors in 2013. The four key areas were <em>Cloud Computing, Social Media, Big Data and Mobile Devices</em>. None of these should have come as a surprise to anyone in the industry today. These are all topics that are discussed and debated around tables of security teams in most enterprises. So, what can we do today to ensure we are prepared for these challenges and how do we start reinforcing our doors so that we allow these new technologies but have greater control and visibility and provide transparency for the user?</p>
<p>There are three gaps that will help with this reinforcement. Addressing these gaps will require organizations to act now!</p>
<ol>
<li>Security teams have always been seen as business inhibitors and it’s fair to say that this view has been changing. But as organization embraces the new technologies in 2013 they will have to up their skills quickly not only in understanding the security implications of these technologies but more importantly the impact on the overall business. The security team must work with the business to understand the risk and develop protection strategies to mitigate them to an acceptable level. 2013 is the year that information security migrates from being IT-focused to a <em>business-focused</em> problem. The success of security teams will be measured on their ability to enable business which will ultimately require tying security programs to business outcomes.</li>
<li>The security industry has <span style="text-decoration: underline"><strong><a href="http://www.emc.com/collateral/industry-overview/ciso-rpt-6.pdf" target="_blank">lobbied the C-level suite </a></strong></span>in recent years to elevate the security message and to an extent this campaign has been successful with most CISO’s meeting regularly with the board. This has also been driven by more stringent regulatory requirements. However, it seems the gap is lower down the chain. Middle management seems to be measured on deadlines, revenues or timeframes for delivery and therefore is reluctant to spend any time or resources on security, and typically this doesn’t fit into their objectives. Security teams will have to build relationships with these middle managers to help them understand the value of security. This is not going to be easy…</li>
<li>The supply chain in most organizations has been transformed in recent years. We need to focus on each element of the chain. Last year PC’s that were manufactured in China were found to be shipping with malware pre-installed, exposing flaws in the global supply chain. It’s not only hardware but software and applications have moved on dramatically with the ability for a user to download an app in seconds on his mobile device and use it to access corporate resources. So, it’s time to re-visit the entire supply chain and identify the gaps.</li>
</ol>
<p>Look out for my next blog on Action Plans for each of the four disruptive technologies.</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Freinforcing-our-doors-in-2013%2F&amp;t=Reinforcing%20our%20doors%20in%202013"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Reinforcing%20our%20doors%20in%202013%20-%20http%3A%2F%2Fblogs.rsa.com%2Freinforcing-our-doors-in-2013%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Freinforcing-our-doors-in-2013%2F&amp;title=Reinforcing%20our%20doors%20in%202013&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=In%20my%20last%20blog%20I%20talked%20about%20the%20key%20technologies%20breaking%20down%20our%20doors%20in%202013.%20The%20four%20key%20areas%20were%20Cloud%20Computing%2C%20Social%20Media%2C%20Big%20Data%20and%20Mobile%20Devices.%20None%20of%20these%20should%20have%20come%20as%20a%20surprise%20to%20anyone%20in%20the%20industry%20today.%20These%20are%20all%20topics%20that%20are%20discussed%20and%20debated%20around%20tables%20of%20security%20teams%20in%20most%20enterprises.%20So%2C%20what%20can%20we%20do%20today%20to%20ensure%20we%20are%20prepared%20for%20these%20challenges%20and%20how%20do%20we%20start%20reinforcing%20our%20doors%20so%20that%20we%20allow%20these%20new%20technologies%20but%20have%20greater%20control%20and%20visibility%20and%20provide%20transparency%20for%20the%20user%3F"></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Reinforcing%20our%20doors%20in%202013&body=http%3A%2F%2Fblogs.rsa.com%2Freinforcing-our-doors-in-2013%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-7763')" id="sociable-post-7763" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Freinforcing-our-doors-in-2013%2F&amp;t=Reinforcing%20our%20doors%20in%202013"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Freinforcing-our-doors-in-2013%2F&amp;title=Reinforcing%20our%20doors%20in%202013&amp;notes=In%20my%20last%20blog%20I%20talked%20about%20the%20key%20technologies%20breaking%20down%20our%20doors%20in%202013.%20The%20four%20key%20areas%20were%20Cloud%20Computing%2C%20Social%20Media%2C%20Big%20Data%20and%20Mobile%20Devices.%20None%20of%20these%20should%20have%20come%20as%20a%20surprise%20to%20anyone%20in%20the%20industry%20today.%20These%20are%20all%20topics%20that%20are%20discussed%20and%20debated%20around%20tables%20of%20security%20teams%20in%20most%20enterprises.%20So%2C%20what%20can%20we%20do%20today%20to%20ensure%20we%20are%20prepared%20for%20these%20challenges%20and%20how%20do%20we%20start%20reinforcing%20our%20doors%20so%20that%20we%20allow%20these%20new%20technologies%20but%20have%20greater%20control%20and%20visibility%20and%20provide%20transparency%20for%20the%20user%3F"></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Freinforcing-our-doors-in-2013%2F&amp;title=Reinforcing%20our%20doors%20in%202013&amp;bodytext=In%20my%20last%20blog%20I%20talked%20about%20the%20key%20technologies%20breaking%20down%20our%20doors%20in%202013.%20The%20four%20key%20areas%20were%20Cloud%20Computing%2C%20Social%20Media%2C%20Big%20Data%20and%20Mobile%20Devices.%20None%20of%20these%20should%20have%20come%20as%20a%20surprise%20to%20anyone%20in%20the%20industry%20today.%20These%20are%20all%20topics%20that%20are%20discussed%20and%20debated%20around%20tables%20of%20security%20teams%20in%20most%20enterprises.%20So%2C%20what%20can%20we%20do%20today%20to%20ensure%20we%20are%20prepared%20for%20these%20challenges%20and%20how%20do%20we%20start%20reinforcing%20our%20doors%20so%20that%20we%20allow%20these%20new%20technologies%20but%20have%20greater%20control%20and%20visibility%20and%20provide%20transparency%20for%20the%20user%3F"></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Freinforcing-our-doors-in-2013%2F&amp;title=Reinforcing%20our%20doors%20in%202013"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Freinforcing-our-doors-in-2013%2F&title=Reinforcing%20our%20doors%20in%202013"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Freinforcing-our-doors-in-2013%2F&amp;title=Reinforcing%20our%20doors%20in%202013&amp;annotation=In%20my%20last%20blog%20I%20talked%20about%20the%20key%20technologies%20breaking%20down%20our%20doors%20in%202013.%20The%20four%20key%20areas%20were%20Cloud%20Computing%2C%20Social%20Media%2C%20Big%20Data%20and%20Mobile%20Devices.%20None%20of%20these%20should%20have%20come%20as%20a%20surprise%20to%20anyone%20in%20the%20industry%20today.%20These%20are%20all%20topics%20that%20are%20discussed%20and%20debated%20around%20tables%20of%20security%20teams%20in%20most%20enterprises.%20So%2C%20what%20can%20we%20do%20today%20to%20ensure%20we%20are%20prepared%20for%20these%20challenges%20and%20how%20do%20we%20start%20reinforcing%20our%20doors%20so%20that%20we%20allow%20these%20new%20technologies%20but%20have%20greater%20control%20and%20visibility%20and%20provide%20transparency%20for%20the%20user%3F"></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Freinforcing-our-doors-in-2013%2F&amp;t=Reinforcing%20our%20doors%20in%202013"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Reinforcing%20our%20doors%20in%202013&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Freinforcing-our-doors-in-2013%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=In%20my%20last%20blog%20I%20talked%20about%20the%20key%20technologies%20breaking%20down%20our%20doors%20in%202013.%20The%20four%20key%20areas%20were%20Cloud%20Computing%2C%20Social%20Media%2C%20Big%20Data%20and%20Mobile%20Devices.%20None%20of%20these%20should%20have%20come%20as%20a%20surprise%20to%20anyone%20in%20the%20industry%20today.%20These%20are%20all%20topics%20that%20are%20discussed%20and%20debated%20around%20tables%20of%20security%20teams%20in%20most%20enterprises.%20So%2C%20what%20can%20we%20do%20today%20to%20ensure%20we%20are%20prepared%20for%20these%20challenges%20and%20how%20do%20we%20start%20reinforcing%20our%20doors%20so%20that%20we%20allow%20these%20new%20technologies%20but%20have%20greater%20control%20and%20visibility%20and%20provide%20transparency%20for%20the%20user%3F"></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Freinforcing-our-doors-in-2013%2F&amp;Title=Reinforcing%20our%20doors%20in%202013"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Freinforcing-our-doors-in-2013%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Freinforcing-our-doors-in-2013%2F&amp;title=Reinforcing%20our%20doors%20in%202013&amp;selection=In%20my%20last%20blog%20I%20talked%20about%20the%20key%20technologies%20breaking%20down%20our%20doors%20in%202013.%20The%20four%20key%20areas%20were%20Cloud%20Computing%2C%20Social%20Media%2C%20Big%20Data%20and%20Mobile%20Devices.%20None%20of%20these%20should%20have%20come%20as%20a%20surprise%20to%20anyone%20in%20the%20industry%20today.%20These%20are%20all%20topics%20that%20are%20discussed%20and%20debated%20around%20tables%20of%20security%20teams%20in%20most%20enterprises.%20So%2C%20what%20can%20we%20do%20today%20to%20ensure%20we%20are%20prepared%20for%20these%20challenges%20and%20how%20do%20we%20start%20reinforcing%20our%20doors%20so%20that%20we%20allow%20these%20new%20technologies%20but%20have%20greater%20control%20and%20visibility%20and%20provide%20transparency%20for%20the%20user%3F"></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Freinforcing-our-doors-in-2013%2F&amp;t=Reinforcing%20our%20doors%20in%202013&amp;s=In%20my%20last%20blog%20I%20talked%20about%20the%20key%20technologies%20breaking%20down%20our%20doors%20in%202013.%20The%20four%20key%20areas%20were%20Cloud%20Computing%2C%20Social%20Media%2C%20Big%20Data%20and%20Mobile%20Devices.%20None%20of%20these%20should%20have%20come%20as%20a%20surprise%20to%20anyone%20in%20the%20industry%20today.%20These%20are%20all%20topics%20that%20are%20discussed%20and%20debated%20around%20tables%20of%20security%20teams%20in%20most%20enterprises.%20So%2C%20what%20can%20we%20do%20today%20to%20ensure%20we%20are%20prepared%20for%20these%20challenges%20and%20how%20do%20we%20start%20reinforcing%20our%20doors%20so%20that%20we%20allow%20these%20new%20technologies%20but%20have%20greater%20control%20and%20visibility%20and%20provide%20transparency%20for%20the%20user%3F"></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Freinforcing-our-doors-in-2013%2F&amp;title=Reinforcing%20our%20doors%20in%202013&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Freinforcing-our-doors-in-2013%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-7763')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-7763',true)" class="close">

		  <img onclick="hide_sociable('post-7763',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/reinforcing-our-doors-in-2013/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/reinforcing-our-doors-in-2013/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
