Google searchers for news on Patrick Swayze's funeral may come across links that are loaded with malware.
Watch where you are going and what you are clicking on. More from SecurityFocus/F-Secure.
Saturday, September 19, 2009
Friday, September 18, 2009
Fool me once...
Hmm.. looks like this is not the first brush of data breach at Akron Children's Hospital. In our last post we wrote about how a misdirected spyware was installed on a computer there, and subsequently leaked financial and medical information.
In 2006, an intruder broke into their network and compromised a database. Here is what the FAQ says:
Typically, it takes a security breach to wake up a company--it is their "come to Jesus" moment. If after that 2006 breach they did not include simple things like educating employees to not open attachments and blocking outside email access, they were not doing a very good job.
In 2006, an intruder broke into their network and compromised a database. Here is what the FAQ says:
Akron Children's Hospital recently identified that during an expansion of its computer systems, there were unauthorized entries (breaches) into two separate computer databases. The first database contained personal information of our patients, and of the parents or guardians who provide their health insurance. This personal information included names, addresses, social security numbers and patient birth dates. We have found no evidence that any medical or financial patient information was exposed.There is a report from the local NBC affiliate that says pretty much the same thing, but adds that the intruders came in via a number of intermediate hops.
The second breach involved a server containing information about individuals who have made donations to the hospital. This breach may have exposed personal financial information, specifically some unencrypted bank account and routing numbers. Social security numbers were not included in this database, and credit card information was protected through the highest level of encryption.
Typically, it takes a security breach to wake up a company--it is their "come to Jesus" moment. If after that 2006 breach they did not include simple things like educating employees to not open attachments and blocking outside email access, they were not doing a very good job.
Spyware causes HIPAA violation at Ohio Hospital
Man emails spyware to ex girlfriend's Yahoo account. What could go wrong?
The woman happens to work at a hospital. She opened it at a work computer, and the spyware happily emailed out billing and healthcare information for 65 patients. As other people used that computer, it also emailed out their email and financial information (presumably they looked at their online accounts from there)
CIO Magazine reports:
The woman happens to work at a hospital. She opened it at a work computer, and the spyware happily emailed out billing and healthcare information for 65 patients. As other people used that computer, it also emailed out their email and financial information (presumably they looked at their online accounts from there)
CIO Magazine reports:
He allegedly sent the spyware to the woman's Yahoo e-mail address, hoping that it would give him a way to monitor what she was doing on her PC. But instead, she opened the spyware on a computer in the hospital's pediatric cardiac surgery department, creating a regulatory nightmare for the hospital.
The complaint does not explain how Graham managed to convince the woman to install the program, but clever attackers often trick their victims into clicking on files by saying that they are interesting videos or some kind of useful software.
Between March 19 and March 28 the spyware sent more than 1,000 screen captures to Graham via e-mail.
The hospital is also to blame. It is unclear if they provided any training to employees about not opening attachments from emails, but it is absolutely clear that they were not blocking 3rd party email access from work.
The article is also unclear about if the girlfriend is still employed at work or not.
Wednesday, September 16, 2009
In Oregon, a manual on Public Records is NOT Public
We just wrote about how some Boston City Hall employees were deleting emails so they would not be subject to Public Record Laws. But in Oregon, Public Record laws are taking an interesting turn.
The state attorney general publishes a manual for dealing with public record requests, and sell it for $25. He (not personally, his office) also claims copyright over this (public) manual
Oh, the irony.
But lets look at the mundane issue first. He claims the $25 is the cost of publishing the hard-copy version of the manual. Yeah? Hasn't he head of PDF files, and "click here to download"? I know Oregon has lots of trees, but shouldn't he at least pretend to care?
Next: if he can not claim an exemption from the public records law, then he is required to provide this to, hey presto, THE PUBLIC. How can he (or his office) claim copyright to something created with public funds?
So a professor at University of Oregon has challenged him by posting a scanned copy of the manual on his blog.
Any bets on when the attorney general will blink? I am predicting around 4:55 PM local time in oregon on Friday, 18th September 2009.
The state attorney general publishes a manual for dealing with public record requests, and sell it for $25. He (not personally, his office) also claims copyright over this (public) manual
Oh, the irony.
But lets look at the mundane issue first. He claims the $25 is the cost of publishing the hard-copy version of the manual. Yeah? Hasn't he head of PDF files, and "click here to download"? I know Oregon has lots of trees, but shouldn't he at least pretend to care?
Next: if he can not claim an exemption from the public records law, then he is required to provide this to, hey presto, THE PUBLIC. How can he (or his office) claim copyright to something created with public funds?
So a professor at University of Oregon has challenged him by posting a scanned copy of the manual on his blog.
Every 2 years the Oregon DOJ publishes the "Oregon Attorney General's Public Records and Meetings Manual", a very useful guide to public records law. It's essential reading for people trying to use their right to get public records from Oregon government agencies. The DOJ has been trying to keep me from redistributing this manual, on the grounds that they own the copyright to it. Trying to use copyright law to keep the public from getting information about how to get public records strikes me as wrong, so I've posted the manual online at my official UO faculty website. As the email below explains, I am posting this despite the fact that the AG's office has explicitly warned me not to redistribute this manual. Here are the links. (now fixed)
Any bets on when the attorney general will blink? I am predicting around 4:55 PM local time in oregon on Friday, 18th September 2009.
Labels:
foia,
oregon,
public record law
Sunday, September 13, 2009
Records retention in local government, and Boston City Hall
I have a city-hall as my client. Last month I was teaching an awareness class there, and when I mentioned that they should not have any expectation of privacy when using their computers, there was not a single raised eyebrow. Being the employees of a city government, they all knew about public record laws and freedom of information act requests.
This is different from a private enterprise, where there is always someone who will argue that point.
(as an aside, I had to throw away most of my examples of what is "confidential". Individual's salary figures? Not confidential. Next year's budget numbers? Not confidential. Agh).
Looks like the City of Boston's senior management knew all about the "no expectation of privacy" too:
This is different from a private enterprise, where there is always someone who will argue that point.
(as an aside, I had to throw away most of my examples of what is "confidential". Individual's salary figures? Not confidential. Next year's budget numbers? Not confidential. Agh).
Looks like the City of Boston's senior management knew all about the "no expectation of privacy" too:
The acknowledgement came after the Globe filed several requests for e-mails sent and received by Menino’s Cabinet chief of policy and planning, Michael J. Kineavy. He is one of Menino’s most powerful and trusted advisers, intimately involved in nearly everything at City Hall, but a search of city computers found just 18 e-mails he had sent or received between Oct. 1, 2008, and March 31 of this year.
The unusually low figure prompted administration officials to question him about what happened to the rest of the e-mails he was presumably sending and receiving during that period. Kineavy, who is also one of the mayor’s chief political advisers and a strategist on Menino’s reelection campaigns since 1993, told them that he deletes all his e-mails on a daily basis, in such a way that they are not saved on city backup computers, administration officials said.
There are indications that Kineavy was not the only city employee who may have violated the law. In June, the Globe filed requests for copies of six months’ worth of e-mails sent or received by five other employees, including Transportation Commissioner Thomas Tinlin. City officials said that a search for Tinlin’s e-mails turned up only those he had received, none he had sent.
Sunday, October 26, 2008
How would you start a network/security consulting business?
If you the typical security person, sales is not your strong suite. Heck, you may actually be very bad as a sales person. And since without sales you are not going to earn any money from this consultancy, you need someone who can actually close sales.
So what are you going to sell? Services? Do you have any software or other solution you will be offering? Go ahead, write them down in bullets. I know you know them, but you will be surprised when you try to boil each down into a soundbite. If you don't know this already, it is called an 'elevator pitch' because sometimes you will have a 10 or 20-second opportunity to make your case to a client, and that will not be the time to think up something clever to say. So know what you are selling, and know how to condense that to an elevator pitch.
Other things:
1. Now that you know what you are going to offer, and what your pitch is, get a good sales guy. Seriously. Your team may be extremely talented, but they need the contacts and they need the personality to 'close' sales. Not something techies are good at.
2. Create proposal, report and assessment templates (and get website/email/phones the usual logistics stuff)
3. More than one person? Think about the corporate structure. LLC, S-corp, C-corp? (Google for the differences and how each may effect you). Don't put this off--no matter how good friends you all are.
3. Land your first customer. Make sure s/he is willing to be a reference. Start looking for this customer now, even before the business is fully formed. The first customer is the hardest to get. Start by talking to people who are in a position to buy your offering. If you are currently working for someone else, you need to have a very clear idea about who is going to be your customer. Talk to every consulting firm, software company and VAR in your region.
4. Speak at places/seminars/conferences where potential customers show up. Stay longer and listen to them, talk to them, solve problems for them or give them pointers. People like nice people.
5. Did I say you need a sales person with a rolodex full of contacts that s/he already knows from previous jobs? You can hire someone on commission. Make a deal with a hardware sales-guy (so there is no conflict of interest)--when s/he visits a customer s/he can mention your company, make an introduction, etc.
6. Prepare for an initial dry spell. If the people can not handle no income, no health insurance, etc. for 6 months (just to be safe) then they are not ready for this. If you do hit the doldrums, look into opportunities for potential part-time contract work. It may sound strange, but this may help provide sustenance during lean periods. (for this, check out DICE, which lets you search for contract work based on W-2, corp-to-corp, etc). And don't forget, once you are at a contract gig, you are meeting a potential client who may hire your company for the next job.
Misc:
Any decent-sized clients will ask you about your workman's compensation, liability and errors/omissions insurance. This will set you back a few thousand dollars--talk to an insurance agent and find out.
Good luck.
So what are you going to sell? Services? Do you have any software or other solution you will be offering? Go ahead, write them down in bullets. I know you know them, but you will be surprised when you try to boil each down into a soundbite. If you don't know this already, it is called an 'elevator pitch' because sometimes you will have a 10 or 20-second opportunity to make your case to a client, and that will not be the time to think up something clever to say. So know what you are selling, and know how to condense that to an elevator pitch.
Other things:
1. Now that you know what you are going to offer, and what your pitch is, get a good sales guy. Seriously. Your team may be extremely talented, but they need the contacts and they need the personality to 'close' sales. Not something techies are good at.
2. Create proposal, report and assessment templates (and get website/email/phones the usual logistics stuff)
3. More than one person? Think about the corporate structure. LLC, S-corp, C-corp? (Google for the differences and how each may effect you). Don't put this off--no matter how good friends you all are.
3. Land your first customer. Make sure s/he is willing to be a reference. Start looking for this customer now, even before the business is fully formed. The first customer is the hardest to get. Start by talking to people who are in a position to buy your offering. If you are currently working for someone else, you need to have a very clear idea about who is going to be your customer. Talk to every consulting firm, software company and VAR in your region.
4. Speak at places/seminars/conferences where potential customers show up. Stay longer and listen to them, talk to them, solve problems for them or give them pointers. People like nice people.
5. Did I say you need a sales person with a rolodex full of contacts that s/he already knows from previous jobs? You can hire someone on commission. Make a deal with a hardware sales-guy (so there is no conflict of interest)--when s/he visits a customer s/he can mention your company, make an introduction, etc.
6. Prepare for an initial dry spell. If the people can not handle no income, no health insurance, etc. for 6 months (just to be safe) then they are not ready for this. If you do hit the doldrums, look into opportunities for potential part-time contract work. It may sound strange, but this may help provide sustenance during lean periods. (for this, check out DICE, which lets you search for contract work based on W-2, corp-to-corp, etc). And don't forget, once you are at a contract gig, you are meeting a potential client who may hire your company for the next job.
Misc:
Any decent-sized clients will ask you about your workman's compensation, liability and errors/omissions insurance. This will set you back a few thousand dollars--talk to an insurance agent and find out.
Good luck.
Labels:
Consultancy,
Consultant,
FAQ,
Startup
Thursday, October 23, 2008
Career Progression: How to become a CISO
I am often asked about this--to the degree that this is now a frequently asked question. Sorry, there is no magic formula.
There are two parts to the answer: How to 'get' the job and How to be 'good at it' that are intermixed.
My first CISO job was through applying directly. I was a director at a financial industry giant, and became the first CISO at a 500-million-dollar financial services company.
My next CISO gig was for a company with about $1B in revenue, and I was recruited by a retained search firm.
Here is the summary of my experience:
If you can show most or all of the above in your resume and during the interview, that would be a huge help.
Networking definitely helps, but we all can't know the CEO, so working with recruiters is the next best thing. If it is a retained search, that is great. If it is a contingency, that is fine, too--but before you send a resume, talk to the recruiter and make sure they don't submit you before asking your permission first.
How about certifications? It is expected that the CISO will have at least one major certification. If the CISO position is asking for just A+ or Security+ certifications, see number 6 above. ISACA designed the CISM for the CISO-level professionals, but not many employers are making this the primary certification requirement. CISSP is still the certification to have for any senior security job, although it really does not cover the management of an information security program. The CISA is not directly needed, but helpful because as a true CISO you will have to deal with internal and external auditors. It is my opinion that the certifications do not indicate how good a candidate will be as a strategic leader, but they certainly show relevant job skills. On the other hand, it is easy to establish your business-friendliness if you have an MBA.
Good luck.
There are two parts to the answer: How to 'get' the job and How to be 'good at it' that are intermixed.
My first CISO job was through applying directly. I was a director at a financial industry giant, and became the first CISO at a 500-million-dollar financial services company.
My next CISO gig was for a company with about $1B in revenue, and I was recruited by a retained search firm.
Here is the summary of my experience:
- Relevant industry sector experience: going from financial services to healthcare (or vice versa is very rare)
- CISO/CSOs are typically director or above positions. If you already have a director or VP title, that helps
- If you are already a CISO, that also helps. A lot.
- If you are not being promoted from within, having a bachelors degree is absolutely required.
- Soft skills like communication is absolutely important. So is a demonstrated business skills, budgeting, people management, etc.
- If a CISO job description says you need hands-on experience configuring firewalls (or some other specific technology), tread carefully. Either the job description is wrong, or it is not a CISO job. There are exceptions, of course, but this is a good indicator.
- If other C-level officers are not in the interview team, you are not getting a 'real' CISO job, regardless of what the title is
- As a CISO, your job will be to make people who you have no direct influence over do things for you.
- You have to have direct reports and budget experience
- At the interview, you have to make them understand that [a] security will help business and [b] you understand and care about the business--you are not just a security-nazi.
If you can show most or all of the above in your resume and during the interview, that would be a huge help.
Networking definitely helps, but we all can't know the CEO, so working with recruiters is the next best thing. If it is a retained search, that is great. If it is a contingency, that is fine, too--but before you send a resume, talk to the recruiter and make sure they don't submit you before asking your permission first.
How about certifications? It is expected that the CISO will have at least one major certification. If the CISO position is asking for just A+ or Security+ certifications, see number 6 above. ISACA designed the CISM for the CISO-level professionals, but not many employers are making this the primary certification requirement. CISSP is still the certification to have for any senior security job, although it really does not cover the management of an information security program. The CISA is not directly needed, but helpful because as a true CISO you will have to deal with internal and external auditors. It is my opinion that the certifications do not indicate how good a candidate will be as a strategic leader, but they certainly show relevant job skills. On the other hand, it is easy to establish your business-friendliness if you have an MBA.
Good luck.