 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Business-Technology Weave &#187; cybersecurity</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/business-technology/tag/cybersecurity/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/business-technology</link>
	<description>Closing divides, directing purpose, and achieving results.</description>
	<lastBuildDate>Thu, 23 May 2013 17:30:17 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Cyber Awareness:  Personal Security</title>
		<link>http://itknowledgeexchange.techtarget.com/business-technology/cyber-awareness-personal-security/</link>
		<comments>http://itknowledgeexchange.techtarget.com/business-technology/cyber-awareness-personal-security/#comments</comments>
		<pubDate>Mon, 25 Feb 2013 17:50:52 +0000</pubDate>
		<dc:creator>David Scott</dc:creator>
				<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[cyber awareness]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[cyber espionage]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber threat]]></category>
		<category><![CDATA[cyber training]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cyberspying]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[acceptable use]]></category>
		<category><![CDATA[acceptable use policy]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[best business practice]]></category>
		<category><![CDATA[best practice]]></category>
		<category><![CDATA[bring your own device]]></category>
		<category><![CDATA[business and IT planning]]></category>
		<category><![CDATA[business and IT plans]]></category>
		<category><![CDATA[business continuity]]></category>
		<category><![CDATA[business management]]></category>
		<category><![CDATA[business-technology weave]]></category>
		<category><![CDATA[BYOD]]></category>
		<category><![CDATA[cellular]]></category>
		<category><![CDATA[change management]]></category>
		<category><![CDATA[CMS]]></category>
		<category><![CDATA[content management]]></category>
		<category><![CDATA[data access]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[information technology]]></category>
		<category><![CDATA[iPad]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[IT governance]]></category>
		<category><![CDATA[IT plans]]></category>
		<category><![CDATA[IT policy]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[mobile access]]></category>
		<category><![CDATA[mobile application]]></category>
		<category><![CDATA[mobile application development]]></category>
		<category><![CDATA[mobile challenge]]></category>
		<category><![CDATA[mobile development]]></category>
		<category><![CDATA[mobile enablement]]></category>
		<category><![CDATA[mobile enterprise]]></category>
		<category><![CDATA[mobile planning]]></category>
		<category><![CDATA[mobile policies]]></category>
		<category><![CDATA[mobile policy]]></category>
		<category><![CDATA[mobile programming]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[mobile technologies]]></category>
		<category><![CDATA[mobile technology]]></category>
		<category><![CDATA[mobile’s future]]></category>
		<category><![CDATA[project management]]></category>
		<category><![CDATA[security policy]]></category>
		<category><![CDATA[smartphone]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[tablet]]></category>
		<category><![CDATA[the cloud]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/business-technology/?p=1646</guid>
		<description><![CDATA[People have been asking me what they can do for their home environments, and related cyber security &#8211; some tips are provided below. First, recognize that social engineering is the biggest factor in personal breaches and matters of identity theft; the “grooming” of folks, getting them used to clicking on offers as distributed in e-mail, [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://itknowledgeexchange.techtarget.com/business-technology/files/2013/02/Cyber-Personal2.jpg"><img class="alignleft  wp-image-1650" src="http://itknowledgeexchange.techtarget.com/business-technology/files/2013/02/Cyber-Personal2.jpg" alt="" width="200" height="149" /></a>People have been asking me what they can do for their home environments, and related cyber security &#8211; some tips are provided below.</p>
<p>First, recognize that social engineering is the biggest factor in personal breaches and matters of identity theft; the “grooming” of folks, getting them used to clicking on offers as distributed in e-mail, and even through social networking sites.  Children can be especially vulnerable.</p>
<p>Oftentimes job offers, or “You’ve won!” scenarios, have templates for fill-in.  If you’re not careful you, or perhaps children in your household, may end up divulging name, address, date-of-birth, and other highly sensitive information.</p>
<p>Be wary too of targeting that meets areas of your interest, yet is unsolicited.  Scammers rake social media websites and glean all sorts of info.  Avoid following your curiosity when assessing any unsolicited electronic contact with you, or your household.</p>
<p>Here are some tips – share them with younger people too:</p>
<ol>
<li><strong>Encrypt</strong> your home wireless network, for those that have them, and pay attention to security setups on iPads; iPhones; Androids; laptops; desktops, etc.  There are innumerable cases where people use others’ networks for the propagation of crimes – especially within large apartment houses and condominiums.</li>
<li><strong>Generate </strong>strong passwords – forget pet’s names; tricks like reversal of D-o-B.  Use long passwords – consider 25 characters or more, as crazy as that sounds.  Many can be stored anyway.  The main liability with storage is, if you access an account on a device other than the one with stored password(s), you either may not remember it/them, or you’ll have quite a chore typing it/them in.  But the extra security is worth it – algorithms now can hack just about any password, but if a program takes too long trying to crack yours, it’s more efficient to move on to a more vulnerable one.  You can also use password generators/randomizers – just Google for that if you’re not familiar with the concept.</li>
<li><strong>Update</strong> your anti-virus/malware programs regularly; set these to do auto-updates in background where possible.</li>
<li><strong>Turn on</strong> personal firewalls.  Search Help for “personal firewall” – check to see what’s available in your operating system.</li>
<li><strong>Consider</strong> using an Identity Protection program.</li>
<li><strong>Seek recommendations</strong> from your workplace:  If you can check with your IT department, see if they have any suggestions for home protections.</li>
</ol>
<p>Of course, on that last one, a good IT department will survey the user population for personal/corporate tethers anyway, and will perform their due dililgence in sewing shut this area of liability.  But, it’s good to solicit advice and updates anyway, as things can get overlooked quite easily, even in these terms.</p>
<p><em>Stay safe out there.</em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/business-technology/cyber-awareness-personal-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyberwar Between Business Competitors – This blog’s prediction come true?</title>
		<link>http://itknowledgeexchange.techtarget.com/business-technology/cyberwar-between-business-competitors-this-blogs-prediction-come-true/</link>
		<comments>http://itknowledgeexchange.techtarget.com/business-technology/cyberwar-between-business-competitors-this-blogs-prediction-come-true/#comments</comments>
		<pubDate>Tue, 19 Feb 2013 16:33:10 +0000</pubDate>
		<dc:creator>David Scott</dc:creator>
				<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[cyber awareness]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[cyber espionage]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber war]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[cyberwarfare]]></category>
		<category><![CDATA[acceptable use]]></category>
		<category><![CDATA[acceptable use policy]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[best business practice]]></category>
		<category><![CDATA[best practice]]></category>
		<category><![CDATA[bring your own device]]></category>
		<category><![CDATA[business and IT planning]]></category>
		<category><![CDATA[business and IT plans]]></category>
		<category><![CDATA[business continuity]]></category>
		<category><![CDATA[business management]]></category>
		<category><![CDATA[business-technology weave]]></category>
		<category><![CDATA[BYOD]]></category>
		<category><![CDATA[cellular]]></category>
		<category><![CDATA[change management]]></category>
		<category><![CDATA[CMS]]></category>
		<category><![CDATA[content management]]></category>
		<category><![CDATA[data access]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[information technology]]></category>
		<category><![CDATA[iPad]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[IT governance]]></category>
		<category><![CDATA[IT plans]]></category>
		<category><![CDATA[IT policy]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[mobile access]]></category>
		<category><![CDATA[mobile application]]></category>
		<category><![CDATA[mobile application development]]></category>
		<category><![CDATA[mobile challenge]]></category>
		<category><![CDATA[mobile development]]></category>
		<category><![CDATA[mobile enablement]]></category>
		<category><![CDATA[mobile enterprise]]></category>
		<category><![CDATA[mobile planning]]></category>
		<category><![CDATA[mobile policies]]></category>
		<category><![CDATA[mobile policy]]></category>
		<category><![CDATA[mobile programming]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[mobile technologies]]></category>
		<category><![CDATA[mobile technology]]></category>
		<category><![CDATA[mobile’s future]]></category>
		<category><![CDATA[project management]]></category>
		<category><![CDATA[security policy]]></category>
		<category><![CDATA[smartphone]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[tablet]]></category>
		<category><![CDATA[the cloud]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/business-technology/?p=1607</guid>
		<description><![CDATA[It’s just been reported that Burger King’s Twitter feed was hacked.  The Burger King logo was replaced with McDonald’s golden arches logo. Further, a tweet indicated that “the whopper flopped” and that BK had thus been sold to McDonald’s.  Several other tweets contained obscenities. It’s not clear who hacked BK’s account, and I am not [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://itknowledgeexchange.techtarget.com/business-technology/files/2013/02/BK.jpg"><img class=" wp-image-1608 alignleft" src="http://itknowledgeexchange.techtarget.com/business-technology/files/2013/02/BK.jpg" alt="" width="190" height="147" /></a>It’s just been reported that Burger King’s Twitter feed was hacked.  The Burger King logo was replaced with McDonald’s golden arches logo.</p>
<p>Further, a tweet indicated that “the whopper flopped” and that BK had thus been sold to McDonald’s.  Several other tweets contained obscenities.</p>
<p>It’s not clear who hacked BK’s account, and I am not implying that it was a “competitor hack” (that is, it was not likely initiated by McDonald’s, or any potential rogue employee of that firm – although the Hamburglar’s criminal tendencies are well-established).</p>
<p>However, this hack has to fit squarely into one of two realms, and it provides a nice entrée to some new definitions for an evolving threat landscape.  Let’s create the concept of a “branded hack” that is unique to this forum – branded hacks that will be handles for discussion, and which will hopefully propagate for ease-of-discussion at orgs, with vendors, with media, etc.:  1)  Competitor-Hack (CH), and  2) Hack-at-Random (HaR).  This is a good opportunity to define these two types of hacks, for purpose of establishing exactly “where we are” in 2013, in getting to where we need to go – these definitions will likely evolve a bit:</p>
<p align="center"><strong><span style="text-decoration: underline">New Definitions for New Realities</span></strong></p>
<p><strong>Competitor-Hack (CH)</strong>:  This is a directed hack by a business competitor, with a business motivation:  The purpose of disrupting the competition’s ability to conduct competing business through harm to enablements (data, infrastructure, apps, etc.), or to cause damage to any specific competitor’s reputation (such as false Tweets, implanting of false content, false business positions, etc.).  These CHs can include political motivations, and political targets – they include <em>any</em> orgs and/or individuals who <span style="text-decoration: underline">compete</span> on some plane.</p>
<p><strong>Hack-at-Random (HaR)</strong>:  This is an attack that has more of a mischievous spirit as motivator.  Motivators can include humor, bragging rights, or even the preference of Big Macs over Whoppers, or Whoppers over Big Macs – but generally speaking, the people mounting these are not employees or formal representatives of the organizations in question – they are people who mount trouble for sport and fun.</p>
<p><span style="text-decoration: underline">Recognize this</span>:  In discussing cybersecurity a few articles ago, as contained in <a href="http://itknowledgeexchange.techtarget.com/business-technology/cyberwar-a-consideration-for-business-protections/">this post</a>, and as indicated in another post’s <a href="http://itknowledgeexchange.techtarget.com/business-technology/cybersecurity-the-local-impact-inside-and-out/">matrix</a>, I mentioned that organizations would have to guard against CHs from business competitors.  I also debuted the concept of HaR.  It is easy enough for me to envision these things coming, as immodest as that may sound:  <em>In the realm of risk, unmanaged possibilities become probabilities.</em></p>
<p>It is easy enough to see that risk is being compounded by three fundamental things that are being driven to everyone:</p>
<p>1)       Power</p>
<p>2)      Affordability</p>
<p>3)      Capability</p>
<p>Ever-more power, affordability, and capability are being driven to very modest “players” and devices.</p>
<p><em>Ever-more robust hacking tools will be available on rogue “gaming” sites, and the business and sport of hacking is going to explode.  Watch for it – and be positioned to guard against it.</em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/business-technology/cyberwar-between-business-competitors-this-blogs-prediction-come-true/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Business Protections:  New thinking for new realities</title>
		<link>http://itknowledgeexchange.techtarget.com/business-technology/business-protections-new-thinking-for-new-realities/</link>
		<comments>http://itknowledgeexchange.techtarget.com/business-technology/business-protections-new-thinking-for-new-realities/#comments</comments>
		<pubDate>Sun, 17 Feb 2013 21:17:23 +0000</pubDate>
		<dc:creator>David Scott</dc:creator>
				<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[cyber espionage]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber terror]]></category>
		<category><![CDATA[cyber threat]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[acceptable use]]></category>
		<category><![CDATA[acceptable use policy]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[best business practice]]></category>
		<category><![CDATA[best practice]]></category>
		<category><![CDATA[bring your own device]]></category>
		<category><![CDATA[business and IT planning]]></category>
		<category><![CDATA[business and IT plans]]></category>
		<category><![CDATA[business continuity]]></category>
		<category><![CDATA[business management]]></category>
		<category><![CDATA[business-technology weave]]></category>
		<category><![CDATA[BYOD]]></category>
		<category><![CDATA[cellular]]></category>
		<category><![CDATA[change management]]></category>
		<category><![CDATA[CMS]]></category>
		<category><![CDATA[content management]]></category>
		<category><![CDATA[data access]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[information technology]]></category>
		<category><![CDATA[iPad]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[IT governance]]></category>
		<category><![CDATA[IT plans]]></category>
		<category><![CDATA[IT policy]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[mobile access]]></category>
		<category><![CDATA[mobile application]]></category>
		<category><![CDATA[mobile application development]]></category>
		<category><![CDATA[mobile challenge]]></category>
		<category><![CDATA[mobile development]]></category>
		<category><![CDATA[mobile enablement]]></category>
		<category><![CDATA[mobile enterprise]]></category>
		<category><![CDATA[mobile planning]]></category>
		<category><![CDATA[mobile policies]]></category>
		<category><![CDATA[mobile policy]]></category>
		<category><![CDATA[mobile programming]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[mobile technologies]]></category>
		<category><![CDATA[mobile technology]]></category>
		<category><![CDATA[mobile’s future]]></category>
		<category><![CDATA[project management]]></category>
		<category><![CDATA[security policy]]></category>
		<category><![CDATA[smartphone]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[tablet]]></category>
		<category><![CDATA[the cloud]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/business-technology/?p=1603</guid>
		<description><![CDATA[In the next 2 to 10 years, the securing of business will take on a whole new dimension from the perspective of “whole view” considerations.  In my book, I.T. Wars, I spoke throughout of regional business security teams – BizSec – that would be comprised of business and government representatives.  Orgs would partner with outside [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://itknowledgeexchange.techtarget.com/business-technology/files/2013/02/Untitled.jpg"><img class="wp-image-1604 alignleft" src="http://itknowledgeexchange.techtarget.com/business-technology/files/2013/02/Untitled.jpg" alt="" width="224" height="219" /></a>In the next 2 to 10 years, the securing of business will take on a whole new dimension from the perspective of “whole view” considerations.  In my book, <a href="http://www.amazon.com/I-T-Wars-Managing-Business-Technology-Millennium/dp/1419627635">I.T. Wars</a>, I spoke throughout of regional business security teams – BizSec – that would be comprised of business and government representatives.  Orgs would partner with outside agencies, local government, and Federal government, in order to plan larger-scale securities to business enabling things, such as infrastructure, the power grid, utilities, etc.</p>
<p>The various BizSecs will have their work cut out for them.  Hacks-at-Random (HAR) will become a nuisance at minimum; a business-ender at maximum.  Nefarious mischief makers will take down organizations for sport.  Those orgs that do not maintain the most forward-edge, vigilant, protections will be victims:  That is simply how it will be.  Organizations will also openly discuss potential cyber attack from larger forces, for sized and proportioned positionings (We’ll be discussing these, and how to get positioned, in upcoming posts).</p>
<p><strong>Perhaps an early sign of new awarenesses and realities concerning cyber and related securities will be the end of above ground electrical grid considerations.  Watch for “telephone poles” to disappear in the coming decade &#8211; at least in certain areas, particularly Washington, DC.</strong></p>
<p>Wires and related infrastructure will go into underground, hopefully EMP-proof, conduits.</p>
<p>A corresponding example is potent:  After recent hurricanes, there were calls for the burying of electrical lines and cables – when you think about it, above-ground lines, poles and towers seem positively archaic – they’re so “last century.”  In fact, above ground infrastructure <em>does</em> date back to the very beginning of the last century – and it is quite plainly woefully out-of-date.</p>
<p>Placing this infrastructure underground removes the liability of damage and disablement from weather; such as hurricanes, or just high winds (any corresponding consideration of risk from earthquakes is offset by the fact that above-ground poles would likely fall anyway – and earthquake damage will simply require cleanup and reconstitution of infrastructure as normally performed).</p>
<p>A comprehensive plan to protect lines through a grid of underground conduits should be a national plan, much like the <a href="http://en.wikipedia.org/wiki/Interstate_Highway_System">interstate highway system</a> was.</p>
<p>This project and progression is already being discussed within the Federal government.</p>
<p><strong>NP</strong>:  <em>Talk is Cheap</em>, Keith Richards, original LP</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/business-technology/business-protections-new-thinking-for-new-realities/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Cybersecurity – The local impact… inside and out</title>
		<link>http://itknowledgeexchange.techtarget.com/business-technology/cybersecurity-the-local-impact-inside-and-out/</link>
		<comments>http://itknowledgeexchange.techtarget.com/business-technology/cybersecurity-the-local-impact-inside-and-out/#comments</comments>
		<pubDate>Tue, 12 Feb 2013 16:35:40 +0000</pubDate>
		<dc:creator>David Scott</dc:creator>
				<category><![CDATA[computer virus]]></category>
		<category><![CDATA[computer vulnerabilities]]></category>
		<category><![CDATA[computer vulnerability]]></category>
		<category><![CDATA[computer war]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[cyber awareness]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[cyber espionage]]></category>
		<category><![CDATA[cyber monday]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security and government]]></category>
		<category><![CDATA[cyber shopping]]></category>
		<category><![CDATA[cyber terror]]></category>
		<category><![CDATA[cyber terrorism]]></category>
		<category><![CDATA[cyber threat]]></category>
		<category><![CDATA[cyber training]]></category>
		<category><![CDATA[cyber war]]></category>
		<category><![CDATA[cyber warfare]]></category>
		<category><![CDATA[cyber-cop]]></category>
		<category><![CDATA[cyber-spying]]></category>
		<category><![CDATA[cybercop]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cyberspying]]></category>
		<category><![CDATA[cyberterror]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[cyberwarfare]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[acceptable use]]></category>
		<category><![CDATA[acceptable use policy]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[best business practice]]></category>
		<category><![CDATA[best practice]]></category>
		<category><![CDATA[bring your own device]]></category>
		<category><![CDATA[business and IT planning]]></category>
		<category><![CDATA[business and IT plans]]></category>
		<category><![CDATA[business continuity]]></category>
		<category><![CDATA[business management]]></category>
		<category><![CDATA[business-technology weave]]></category>
		<category><![CDATA[BYOD]]></category>
		<category><![CDATA[cellular]]></category>
		<category><![CDATA[change management]]></category>
		<category><![CDATA[CMS]]></category>
		<category><![CDATA[content management]]></category>
		<category><![CDATA[data access]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[information technology]]></category>
		<category><![CDATA[iPad]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[IT governance]]></category>
		<category><![CDATA[IT plans]]></category>
		<category><![CDATA[IT policy]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[mobile access]]></category>
		<category><![CDATA[mobile application]]></category>
		<category><![CDATA[mobile application development]]></category>
		<category><![CDATA[mobile challenge]]></category>
		<category><![CDATA[mobile development]]></category>
		<category><![CDATA[mobile enablement]]></category>
		<category><![CDATA[mobile enterprise]]></category>
		<category><![CDATA[mobile planning]]></category>
		<category><![CDATA[mobile policies]]></category>
		<category><![CDATA[mobile policy]]></category>
		<category><![CDATA[mobile programming]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[mobile technologies]]></category>
		<category><![CDATA[mobile technology]]></category>
		<category><![CDATA[mobile’s future]]></category>
		<category><![CDATA[project management]]></category>
		<category><![CDATA[security policy]]></category>
		<category><![CDATA[smartphone]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[tablet]]></category>
		<category><![CDATA[the cloud]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/business-technology/?p=1591</guid>
		<description><![CDATA[The other day, in the article Cyberwar:  A consideration for business protections?, we asked a few questions vis-à-vis cyberwarfare: Outside:  What are the modern organization’s possible contributions to surrounding outside public enablements and related security there?  [Think:  electrical grid; communications; infrastructure such as roads, etc.] Inside:  What are your new requirements concerning internal controls and [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://itknowledgeexchange.techtarget.com/business-technology/files/2013/02/CyberThreat-corner-article-pic.jpg"><img class="alignleft  wp-image-1593" src="http://itknowledgeexchange.techtarget.com/business-technology/files/2013/02/CyberThreat-corner-article-pic.jpg" alt="" width="172" height="155" /></a>The other day, in the article <em><a href="http://itknowledgeexchange.techtarget.com/business-technology/cyberwar-a-consideration-for-business-protections/">Cyberwar:  A consideration for business protections?</a></em>, we asked a few questions vis-à-vis cyberwarfare:</p>
<p><strong>Outside</strong>:  What are the modern organization’s possible contributions to surrounding outside public enablements and related security there?  [Think:  electrical grid; communications; infrastructure such as roads, etc.]</p>
<p><strong>Inside</strong>:  What are your new requirements concerning internal controls and security measures?  [Think:  Malware comprehensiveness and timeliness; firewalls; education, etc.]</p>
<p>In advancing the discussion, recognize that any modern organization with reliance on electronic enablements, applications, processing, content, and the dynamic flow of information, is vulnerable due to <span style="text-decoration: underline">both</span> outside liabilities, and inside liabilities.  But further, the organization will face threat with two other distinct characteristics.  There will be <strong>national</strong> threats (originating outside) that impact inside &#8211; and there will be <em>local</em> threats, also with corresponding inside impacts.  Further, there will be your own inside perils, due to deficiencies, deliberate harm, or human error.  We can evolve the following matrix over time for a more comprehensive understanding… and for the taking of appropriate (affordable) action:</p>
<p style="text-align: center"><a href="http://itknowledgeexchange.techtarget.com/business-technology/files/2013/02/CyberThreat-Matrix2.jpg"><img class="aligncenter  wp-image-1600" src="http://itknowledgeexchange.techtarget.com/business-technology/files/2013/02/CyberThreat-Matrix2.jpg" alt="" width="576" height="338" /></a></p>
<p>Nation-states:  The organization is vulnerable to national threats, as delivered by outside nation-states, both formal ones such as China, as well as virtual “nations” of thought or philosophy or action, such as al-Qaeda.</p>
<p>If you believe the “local” organization – that is, yours – is not susceptible to large cyber threats… read on…</p>
<p>It’s been reported recently that the President of the United States could order a pre-emptive cyber strike if a major cyber plot was detected and deemed credible.  We’re talking about a cyber plot as mounted against the U.S. by a foreign and hostile country or entity.  (In fact, tonight’s (2-12-13) State of the Union address is going to contain mention of cyberwar as a national threat).</p>
<p>This reportage is <em>not</em> in the context of President Obama potentially ordering, or considering, such a strike:  Rather, this was a discussion for the legalities of any president, now or future, for ordering such a strike.  In other words, a general legal and Constitutional question, and potentials for action.  In this regard, The National Intelligence Estimate, considered the intelligence community’s most authoritative document, has been updated and is commissioned to focus on cyber security, with special focus on Iran, North Korea, and China.</p>
<p><strong><span style="text-decoration: underline">Orgs close for inclement weather – will they close for inclement cyber conditions?</span></strong></p>
<p>So, we’re plowing new ground – and, like it or not, considerations of large-scale cyberwarfare will come to the organization much as considerations of weather do (such as when to close early, when to close entirely, who makes those determinations, etc.)  Consider:  Will there come a day when a specific national or regional CyberThreat is deemed so high <em>that specific geographic areas are advised to shut down computer systems, in order to take them offline and to remove their vulnerability until the threat is successfully resolved?</em>  Computers, critical content, access to apps, and the dynamic flow of information, are necessary to virtually everything we do today:  Banking, commerce, travel, education.  Technical enablements sustain our power grid; any damage to that cascades to critical areas mentioned in the last few articles here.  If national or regional authorities believe some measure of systems supporting the power grid are in a window of vulnerability, might local power “go out” for a period of time?  (Much as it does following a bad storm).</p>
<p>So what are the boundaries by which we can execute cyber operations?  How “preemptive” are we permitted to be?  Former CIA deputy director John McLaughlin says that this is a “new arena, a new frontier, where people can move with stealth, agility, and invisibly.”</p>
<p>The difficult part of “invisibility” is that an enemy can attack, cause great harm, and escape liability or penalty, which in-turn makes it difficult for the attackee to respond, and to mount protection from continued attacks.  See how the removal of a MAD scenario exacerbates the threat (one article down, or <a title="here." href="http://itknowledgeexchange.techtarget.com/business-technology/cyberwar-a-consideration-for-business-protections/" target="_blank">here</a>).</p>
<p>As to perils to the local organization, we’re already seeing large, private, high-profile targets being hit:  The New York Times said Chinese hackers had compromised their computers, stealing employee passwords a few weeks ago.  Same for the Washington Post and Wall Street Journal, as they reported similar incidents.</p>
<p>Twitter recently said that 250,000 accounts may have been compromised.  A breach at the Department of Energy came to light when employees were notified that servers had been compromised at their headquarters.  There have been numerous denial-of-service attacks on U.S. banks.</p>
<p>Large, high-profile, organizations and their associated vulnerabilities are pretty well understood inside of those orgs.  But what of small-to-medium business?  SMB is particularly vulnerable.  But beyond nation-states wreaking large-scale harm, SMB faces both inside and outside threats.  Where are their meager resources best-leveraged?</p>
<p>Understanding the problem will advance our discussion in the coming days…</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/business-technology/cybersecurity-the-local-impact-inside-and-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyberwar:  A consideration for business protections?</title>
		<link>http://itknowledgeexchange.techtarget.com/business-technology/cyberwar-a-consideration-for-business-protections/</link>
		<comments>http://itknowledgeexchange.techtarget.com/business-technology/cyberwar-a-consideration-for-business-protections/#comments</comments>
		<pubDate>Wed, 06 Feb 2013 15:24:25 +0000</pubDate>
		<dc:creator>David Scott</dc:creator>
				<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[cyber awareness]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[cyber espionage]]></category>
		<category><![CDATA[cyber monday]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security and government]]></category>
		<category><![CDATA[cyber terror]]></category>
		<category><![CDATA[cyber terrorism]]></category>
		<category><![CDATA[cyber threat]]></category>
		<category><![CDATA[cyber training]]></category>
		<category><![CDATA[cyber war]]></category>
		<category><![CDATA[cyber warfare]]></category>
		<category><![CDATA[cyber-cop]]></category>
		<category><![CDATA[cyber-spying]]></category>
		<category><![CDATA[cybercop]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cyberspying]]></category>
		<category><![CDATA[cyberterror]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[cyberwarfare]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/business-technology/?p=1548</guid>
		<description><![CDATA[Hey, don’t blame me; no fan of war, I.  But people are actually speculating on the nature of the next big war. Of course, there’s the nuclear component, and concomitant fear.  But hopefully the MAD policy still provides some measure of protection:  Mutually Assured Destruction.  In MAD, the theory is that if the U.S. or [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://itknowledgeexchange.techtarget.com/business-technology/files/2013/02/Security-Plans-Cyberwar.jpg"><img class="alignleft  wp-image-1585" src="http://itknowledgeexchange.techtarget.com/business-technology/files/2013/02/Security-Plans-Cyberwar.jpg" alt="" width="178" height="205" /></a>Hey, don’t blame me; no fan of war, I.  But people are actually speculating on the nature of the next big war.</p>
<p>Of course, there’s the nuclear component, and concomitant fear.  But hopefully the MAD policy still provides some measure of protection:  <em>Mutually Assured Destruction</em>.  In MAD, the theory is that if the U.S. or any country and its allies find that their forward-sensing intelligence probes have noted a missile launch, they could then launch their own volley toward the aggressor – each’s missiles traversing and crossing to their respective destinations and  -</p>
<p>BOOM! &#8211;  both countries would lose – so why start?</p>
<p><strong><em>But things aren’t quite so clear with cyberwarfare</em></strong>.  Malware can wreak its destructive vengeance, <em>and then clean up after itself!</em> – hiding its originating trail.  Removed is a certain MAD component, opening the way for all sorts of attacks – perhaps&#8230; and it&#8217;s not just peril from large-scale wars between countries:  Let’s not forget or discount another cyberwar possibility:  In the future, who’s to say that simple business competitors might not unleash a cyberattack against companies in their market?  <em>It is foolish to discount this possibility</em>.  It may already have happened.</p>
<p>Let&#8217;s also consider a recent event:  One minute you’re enjoying a game, the next, half the stadium is dark.  Ok, I’m not a conspiracy theorist, but I couldn’t resist a poke at the recent Super Bowl lighting problem.  Now that many of us have thought about it, though, it well could have been a (relatively harmless) test-hack performed by a country.  For that matter, it could have been a kid in his bedroom.   <em>Nah</em>.  Still…</p>
<p>Here in America over the past couple decades, the Pentagon and a few intelligence agencies have shared power in deploying cyberweapons.  I believe the actual “trigger” for this deployment required Presidential authorization.  The highest profile cyber attack was, perhaps, the strike on Iran’s computer systems that run their nuclear enrichment facilities.  However, we ain’t seen nothin’ yet as far as cyberwarfare’s actual potential.  Potentials of cyberwarfare cannot be ignored &#8211; countries not only must safeguard against it; they must envision their use of it (sadly), in staying competitive on the modern, virtual, battlefield – in tandem with the physical one.  And, cyberwar’s yield is hardly just virtual:  For example, removing any measure of a country’s electrical grid would yield catastrophic “real-world” results -</p>
<p>Imagine:  disrupting computers controlling train travel; resultant derailments, to include not only direct crash-related deaths, but the release of toxic chemicals due to crashes.  Attacks on water treatment plants, causing illness and death.  Crashing of the power grid; homes and businesses without power; rotting food, lack of potable water.  Entire industries idle.  Disruption of major media, and critical denial of wartime information, and what to do in terms of safety.  Removal of power would also inhibit basic 911-type emergency response –prioritizations of emergency activity would revert to “line of sight.”   The list can go on and on…</p>
<p>Let this be a call to government and private sector/innovator alike:  We need hardening of critical key infrastructure, and the securing of all electronic enablements.  We must begin building to “cyberproof” standards… or at least, make the best attempt.</p>
<p>In the coming days, we’ll examine what the emerging responsibilities are for organizations:  Your “local” scope of responsibilities and duties is fairly clear, and hopefully covered in your Security, Acceptable Use, and related policies and plans…</p>
<p>So, vis-a-vis cyberwarfare:</p>
<p><strong>Outside</strong>:  What are the modern organization’s possible contributions to surrounding public enablements and related security there?</p>
<p><strong>Inside</strong>:  What are your new requirements concerning internal controls and security measures?  <em>Stay tuned…</em></p>
<p><strong>NP</strong>:  <em>Gerry Mulligan Meets Stan Getz</em>, original LP, Verve, MG V &#8211; 8249</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/business-technology/cyberwar-a-consideration-for-business-protections/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware:  Insertion and Types</title>
		<link>http://itknowledgeexchange.techtarget.com/business-technology/malware-insertion-and-types/</link>
		<comments>http://itknowledgeexchange.techtarget.com/business-technology/malware-insertion-and-types/#comments</comments>
		<pubDate>Tue, 15 Jan 2013 21:25:03 +0000</pubDate>
		<dc:creator>David Scott</dc:creator>
				<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[cyber awareness]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cyberspying]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[acceptable use]]></category>
		<category><![CDATA[acceptable use policy]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[best business practice]]></category>
		<category><![CDATA[best practice]]></category>
		<category><![CDATA[bring your own device]]></category>
		<category><![CDATA[business and IT planning]]></category>
		<category><![CDATA[business and IT plans]]></category>
		<category><![CDATA[business continuity]]></category>
		<category><![CDATA[business management]]></category>
		<category><![CDATA[business-technology weave]]></category>
		<category><![CDATA[BYOD]]></category>
		<category><![CDATA[cellular]]></category>
		<category><![CDATA[change management]]></category>
		<category><![CDATA[CMS]]></category>
		<category><![CDATA[content management]]></category>
		<category><![CDATA[data access]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[information technology]]></category>
		<category><![CDATA[iPad]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[IT governance]]></category>
		<category><![CDATA[IT plans]]></category>
		<category><![CDATA[IT policy]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[mobile access]]></category>
		<category><![CDATA[mobile application]]></category>
		<category><![CDATA[mobile application development]]></category>
		<category><![CDATA[mobile challenge]]></category>
		<category><![CDATA[mobile development]]></category>
		<category><![CDATA[mobile enablement]]></category>
		<category><![CDATA[mobile enterprise]]></category>
		<category><![CDATA[mobile planning]]></category>
		<category><![CDATA[mobile policies]]></category>
		<category><![CDATA[mobile policy]]></category>
		<category><![CDATA[mobile programming]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[mobile technologies]]></category>
		<category><![CDATA[mobile technology]]></category>
		<category><![CDATA[mobile’s future]]></category>
		<category><![CDATA[project management]]></category>
		<category><![CDATA[security policy]]></category>
		<category><![CDATA[smartphone]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[tablet]]></category>
		<category><![CDATA[the cloud]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/business-technology/?p=1514</guid>
		<description><![CDATA[In continuing our awareness for cyber-crime, recognize that after an entity penetrates a network for access, far more than an episodic outcome can occur (such as a one-time theft of data or money, for example). Beyond the sole-harming event type of experience, the insertion and ongoing residency of malware has to be considered.  This represents [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://itknowledgeexchange.techtarget.com/business-technology/files/2013/01/Malware.jpg"><img class="alignleft  wp-image-1515" src="http://itknowledgeexchange.techtarget.com/business-technology/files/2013/01/Malware.jpg" alt="" width="188" height="163" /></a>In continuing our awareness for cyber-crime, recognize that after an entity penetrates a network for access, far more than an episodic outcome can occur (such as a one-time theft of data or money, for example).</p>
<p>Beyond the sole-harming event type of experience, the insertion and ongoing residency of malware has to be considered.  This represents a particularly gnarly problem, because ongoing control regarding systems can be manifested – and it may continue in the absence of an organization’s knowledge for quite some time – until various harming incidents stack up, or an accrual of thefts occur, until they gain a profile that bites hard enough to be noticed.</p>
<p>Resident malware can execute its code for particular outcomes, and recognition of these helps to monitor for them.  In the next days, we’ll take a look at three basic types of malware:</p>
<p>Nuisance (perhaps delivering marketing-oriented spam, or provide for spying, etc.)</p>
<p>Controlling (to provide “back door” access, or takeover of systems by remote control)</p>
<p>Destructive (perhaps to destroy data, or plant false content, to harm reputation of the host.  Destruction can also be used to remove evidence of intrusion).</p>
<p><strong>NP</strong>:  Joshua Redmond; <em>Freedom in the Groove</em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/business-technology/malware-insertion-and-types/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber-crime Continued:  Attacks’ methodology</title>
		<link>http://itknowledgeexchange.techtarget.com/business-technology/cyber-crime-continued-attacks-methodology/</link>
		<comments>http://itknowledgeexchange.techtarget.com/business-technology/cyber-crime-continued-attacks-methodology/#comments</comments>
		<pubDate>Tue, 08 Jan 2013 18:34:59 +0000</pubDate>
		<dc:creator>David Scott</dc:creator>
				<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[cyber awareness]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber-spying]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cyberspying]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[denial-of-service]]></category>
		<category><![CDATA[DoS]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[network penetration]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spoofing]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/business-technology/?p=1467</guid>
		<description><![CDATA[No matter the nefarious goal of attack, subsequent entry, and exploitation, (such as those mentioned in articles below), there are basic steps for breaking your defenses, and taking advantage of the breach, that are common to all attacks. - Exploration, or scouting, for potential targets: Breaching entities here are searching for networks and systems that [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://itknowledgeexchange.techtarget.com/business-technology/files/2013/01/cybercrime-1-8.jpg"><img class="alignleft  wp-image-1511" src="http://itknowledgeexchange.techtarget.com/business-technology/files/2013/01/cybercrime-1-8.jpg" alt="" width="159" height="112" /></a>No matter the nefarious goal of attack, subsequent entry, and exploitation, (such as those mentioned in articles below), there are basic steps for breaking your defenses, and taking advantage of the breach, that are common to all attacks.</p>
<p>- <strong>Exploration</strong>, or scouting, for potential targets: Breaching entities here are searching for networks and systems that have vulnerabilities. These vulnerabilities can include easily breached or guessed authenticating credentials, outdated and susceptible software, and missing or misconfigurated settings for both software and hardware. Recognize that in addition to hard, empirical, soft spots – such as easily hacked firewalls or default/too-simple login credentials, there is the liability of simple human failing. This is going to include an exploration for naiveté regarding phishing; that is, fraudulent e-mails that solicit sensitive data by posing as legitimate enterprise e-mail/authority. Also pharming, whereby fraudulent websites that pose as legitimate partnering/enhancing entities can glean registration, and thus make solicitation of sensitive data. Be aware too that once an outside entity establishes a relationship, any manner of “legitimate” download can be recommended and thus penetration made.</p>
<p>- <strong>Taking stock</strong> goes hand-in-hand with exploration, in expanding the knowledge gained regarding vulnerabilities. Correlation of known bugs regarding the software surveyed during exploration happens. Human error can be paired with what that person has access to, and breaching entities can then reference other people and specific knowledge in looking legitimate to others… climbing a ladder of access, into ever more rarified and sensitive circles…</p>
<p>- <strong>Penetration</strong> can be for any of the purposes mentioned in the day’s prior article, but also it can be to perpetrate simple Denial-of-Service (DoS) attacks, which will not only render networks and sites inoperable, but can also crash business reputation.</p>
<p><em>Next: The introduction of malware to the environment…</em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/business-technology/cyber-crime-continued-attacks-methodology/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Cyber-crime:  Awareness for 2013… and beyond…</title>
		<link>http://itknowledgeexchange.techtarget.com/business-technology/cyber-crime-awareness-for-2013-and-beyond/</link>
		<comments>http://itknowledgeexchange.techtarget.com/business-technology/cyber-crime-awareness-for-2013-and-beyond/#comments</comments>
		<pubDate>Sat, 05 Jan 2013 18:59:09 +0000</pubDate>
		<dc:creator>David Scott</dc:creator>
				<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[cyber awareness]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[cyber terrorism]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[credit card fraud]]></category>
		<category><![CDATA[cyber-crime]]></category>
		<category><![CDATA[denial-of-service attack]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[spoofing]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/business-technology/?p=1505</guid>
		<description><![CDATA[In continuing from yesterday, let’s examine cyber-crime in a bit more detail.  Before we get into the actual mechanics of intrusions and rip-offs, let’s fully understand the true perils inherent in 2013’s modern environment &#8211; some important cyber awareness. Most people think of cyber crime as identity theft, for purpose of stealing money from online [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://itknowledgeexchange.techtarget.com/business-technology/files/2013/01/cybercrime2.jpg"><img class="alignleft  wp-image-1506" src="http://itknowledgeexchange.techtarget.com/business-technology/files/2013/01/cybercrime2.jpg" alt="" width="200" height="174" /></a>In continuing from yesterday, let’s examine cyber-crime in a bit more detail.  Before we get into the actual mechanics of intrusions and rip-offs, let’s fully understand the true perils inherent in 2013’s modern environment &#8211; some important cyber awareness.</p>
<p>Most people think of cyber crime as identity theft, for purpose of stealing money from online accounts, or perhaps in order to pose as someone else online for whatever reason.  Cyber bullying comes to many people’s minds  That, and outright “hacks” into systems by breaching electronic perimeter defenses, and then exploiting whatever resources are within for the taking.</p>
<p>But there are a number of other nuances.  Routine “<strong><span style="text-decoration: underline">spam</span></strong>” is bothersome, but spam also incentivizes other cyber-crime.  Disseminators of spam aren’t particularly interested in paying for their own processing, broadband, and propagation means and infrastructures – and that’s where you (the individual or organization) comes in.  If you’re insecure enough (from a systems and security perspective) to host, automate, and blast spam, then there are plenty of entities out there surveying for <em>you</em> and your associated vulnerabilities.</p>
<p><strong>Credit fraud</strong> is big.  A simple keystroke monitor can glean your, or an organization’s, credit card number and authenticating credentials – and away they go.  Recognize that your SSN, address, bank account numbers, and all manner of other info and online accounts can be breached.  Ouch.</p>
<p>There’s also the use of networks and resources for <strong>piracy</strong>, and the <strong>illegal transfer of data and information</strong>.  You don’t want your company’s resources used for illegally passing <strong>music transfers</strong>, or other copyrighted material, for example.  Nor do you or your organization want to be in the middle of <strong>electronic</strong> <strong>money laundering operations or tax evasion schemes</strong>.</p>
<p>Certainly government agencies are aware of <strong>cyber-terrorism</strong>, which can involve access for theft of secrets, flooding and disabling of critical systems, and breakage of systems through intrusion of malware.  Too, false-information can replace legitimate content, confusing those people who rely on these sites for best information, best practices, and  thus there is the subsequent hindering of allied cooperation between supporting/reinforcing agencies.</p>
<p>In 2013 and beyond, the stakes are too high to ignore the first step toward best-security postures:  <span style="text-decoration: underline">Modern Awareness</span>.</p>
<p>For our first take-away in this series, recognize that <em><span style="text-decoration: underline">Everyone with online presence should be a Security Officer</span></em> of sorts.  So, next, we’ll get to an awareness for both individuals and orgs.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/business-technology/cyber-crime-awareness-for-2013-and-beyond/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Year, New Tricks…  Old Standby:  Cyber-crime</title>
		<link>http://itknowledgeexchange.techtarget.com/business-technology/new-year-new-tricks-old-standby-cyber-crime/</link>
		<comments>http://itknowledgeexchange.techtarget.com/business-technology/new-year-new-tricks-old-standby-cyber-crime/#comments</comments>
		<pubDate>Wed, 02 Jan 2013 19:52:36 +0000</pubDate>
		<dc:creator>David Scott</dc:creator>
				<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[cyber awareness]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[cyber espionage]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber threat]]></category>
		<category><![CDATA[cyber training]]></category>
		<category><![CDATA[cyber war]]></category>
		<category><![CDATA[cyber-spying]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[acceptable use]]></category>
		<category><![CDATA[acceptable use policy]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[best business practice]]></category>
		<category><![CDATA[best practice]]></category>
		<category><![CDATA[bring your own device]]></category>
		<category><![CDATA[business and IT planning]]></category>
		<category><![CDATA[business and IT plans]]></category>
		<category><![CDATA[business continuity]]></category>
		<category><![CDATA[business management]]></category>
		<category><![CDATA[business-technology weave]]></category>
		<category><![CDATA[BYOD]]></category>
		<category><![CDATA[cellular]]></category>
		<category><![CDATA[change management]]></category>
		<category><![CDATA[CMS]]></category>
		<category><![CDATA[content management]]></category>
		<category><![CDATA[data access]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[information technology]]></category>
		<category><![CDATA[iPad]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[IT governance]]></category>
		<category><![CDATA[IT plans]]></category>
		<category><![CDATA[IT policy]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[mobile access]]></category>
		<category><![CDATA[mobile application]]></category>
		<category><![CDATA[mobile application development]]></category>
		<category><![CDATA[mobile challenge]]></category>
		<category><![CDATA[mobile development]]></category>
		<category><![CDATA[mobile enablement]]></category>
		<category><![CDATA[mobile enterprise]]></category>
		<category><![CDATA[mobile planning]]></category>
		<category><![CDATA[mobile policies]]></category>
		<category><![CDATA[mobile policy]]></category>
		<category><![CDATA[mobile programming]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[mobile technologies]]></category>
		<category><![CDATA[mobile technology]]></category>
		<category><![CDATA[mobile’s future]]></category>
		<category><![CDATA[project management]]></category>
		<category><![CDATA[security policy]]></category>
		<category><![CDATA[smartphone]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[tablet]]></category>
		<category><![CDATA[the cloud]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/business-technology/?p=1498</guid>
		<description><![CDATA[As we enter 2013, many of us are excited by new projects, new enablements, and an expansion of systems and related capabilities.  I always feel a sunny optimism when embarking on projects, and I anticipate the deliveries and related empowerments. But there’s a corresponding dark side for every positive pursuit, and the tech realm is [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://itknowledgeexchange.techtarget.com/business-technology/files/2013/01/cybercrime1.jpg"><img class="alignleft  wp-image-1501" src="http://itknowledgeexchange.techtarget.com/business-technology/files/2013/01/cybercrime1.jpg" alt="" width="186" height="143" /></a>As we enter 2013, many of us are excited by new projects, new enablements, and an expansion of systems and related capabilities.  I always feel a sunny optimism when embarking on projects, and I anticipate the deliveries and related empowerments.</p>
<p>But there’s a corresponding dark side for every positive pursuit, and the tech realm is not sheltered from nefarious activities:  The number of cyber-crimes grows with each passing month – we don’t have to wait for the turn of a year – and the result of bad outcomes is ever-more severe.</p>
<p>The beginning of the year is a nice time to focus and position ourselves in understanding some important things, so as to take effective action:  The steps that cyber-criminals use to attack networks; basic types of malware utilized; and the things you need to use and do in order to stop attacks from being successful.</p>
<p>As we’ll see, we have to guard against reconnaissance (nefarious entities cruising around looking for vulnerabilities and easy marks to exploit), penetration (intrusion into the network/assets), insertion of malware (with resultant theft, corruption, exploitation, etc.), and in most instances, a protection of bad-activity by hiding the exploitation as it is going on, and covering tracks once done.</p>
<p>Stay tuned…</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/business-technology/new-year-new-tricks-old-standby-cyber-crime/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Help Propagate “The Business-Technology Weave” – and a bonus!</title>
		<link>http://itknowledgeexchange.techtarget.com/business-technology/help-propagate-%e2%80%9cthe-business-technology-weave%e2%80%9d-%e2%80%93-and-a-bonus/</link>
		<comments>http://itknowledgeexchange.techtarget.com/business-technology/help-propagate-%e2%80%9cthe-business-technology-weave%e2%80%9d-%e2%80%93-and-a-bonus/#comments</comments>
		<pubDate>Wed, 16 Nov 2011 18:45:42 +0000</pubDate>
		<dc:creator>David Scott</dc:creator>
				<category><![CDATA[BTW]]></category>
		<category><![CDATA[CMS]]></category>
		<category><![CDATA[content management]]></category>
		<category><![CDATA[cyber terror]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cyberterror]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[futilitycloset.com]]></category>
		<category><![CDATA[IT governance]]></category>
		<category><![CDATA[the business-technology weave]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/business-technology/help-propagate-%e2%80%9cthe-business-technology-weave%e2%80%9d-%e2%80%93-and-a-bonus/</guid>
		<description><![CDATA[“Human history becomes more and more a race between education and catastrophe.”      — H.G. Wells   Dear Readers:  The Business-Technology Weave blog has 800+ readers at present.  I’d like to increase readership and thought I’d ask if you’d be willing to forward BTW’s URL –   (http://itknowledgeexchange.techtarget.com/business-technology/)   - to a few colleagues and [...]]]></description>
				<content:encoded><![CDATA[<p><span style="font-family: Times New Roman"><span style="font-size: small"><em><a href="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/161/files/2011/11/btw.jpg"></a><a href="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/161/files/2011/11/btw1.jpg"><img class="alignleft size-medium wp-image-1016" src="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/161/files/2011/11/btw1.jpg" alt="" width="219" height="76" /></a>“Human history becomes more and more a race between education and catastrophe</em>.” </span></span></p>
<p><span style="font-family: Times New Roman"><span style="font-size: small"><span>     </span>— H.G. Wells</span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">Dear Readers:<span>  </span><em>The Business-Technology Weave</em> blog has 800+ readers at present.<span>  </span>I’d like to increase readership and thought I’d ask if you’d be willing to forward BTW’s </span><a href="http://itknowledgeexchange.techtarget.com/business-technology/"><span style="font-family: Calibri;font-size: small">URL</span></a><span style="font-family: Calibri;font-size: small"> –</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">(</span><a href="http://itknowledgeexchange.techtarget.com/business-technology/"><span style="font-family: Calibri;font-size: small">http://itknowledgeexchange.techtarget.com/business-technology/</span></a><span style="font-family: Calibri;font-size: small">) </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">- to a few colleagues and friends.  They can also simply Google &#8220;The Business-Technology Weave.&#8221;</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-size: small"><span style="font-family: Calibri">As thanks, I’d like to recommend one of the coolest sites I’ve stumbled upon in a long time:<span>  </span></span></span><a href="http://www.futilitycloset.com/"><span style="font-family: Calibri;font-size: small">FutilityCloset.com</span></a><span style="font-family: Calibri;font-size: small">.<span>  </span>This site is a treasure trove of fun and interesting things. In their own words, “<em>…a collection of entertaining curiosities in history, literature, mathematics, language, art, and philosophy. Each item is self-contained and written as concisely as possible…</em>”.<span>  </span>Their database has almost 6,000 items. </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">Check out the video “</span><a href="http://www.futilitycloset.com/category/technology/"><span style="font-family: Calibri;font-size: small">Both Sides Now</span></a><span style="font-family: Calibri;font-size: small">,” (scroll down to it) where a Bach piece is rendered as a <span lang="EN">Möbius </span>strip. It’s just over 3 minutes – let it get to the 1:45 minute mark – here’s where it gets really interesting.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">The </span><a href="http://www.futilitycloset.com/"><span style="font-family: Calibri;font-size: small">Quotations</span></a><span style="font-family: Calibri;font-size: small"> page is fun too.<span>  </span>I’ve poked through </span><a href="http://www.futilitycloset.com/category/technology/"><span style="font-family: Calibri;font-size: small">Technology</span></a><span style="font-family: Calibri;font-size: small">, and there are more than a dozen other sections.<span>  </span>There’s plenty of Archives too.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-size: small"><span style="font-family: Calibri">Have fun!<span>  </span><strong>And… if you could blast out a recommendation for <a href="http://itknowledgeexchange.techtarget.com/business-technology/">The Business-Technology Weave</a> (only to those you’d feel would benefit, of course), I would much appreciate it – </strong>how about to 10 of your closest friends and associates?<strong></strong></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-size: small"><span style="font-family: Calibri"><em>Tomorrow</em>:<span>  </span>Back to business with an article regarding a top security expert’s warning about cyber-terror.<span>  </span>To close, here’s a great quote I picked up from FutilityCloset:</span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><em><span style="font-size: small"><span style="font-family: Calibri">“I have never thought much of the courage of a lion tamer. Inside the cage he is at least safe from other men. There is not much harm in a lion. He has no ideals, no religion, no politics, no chivalry, no gentility; in short, no reason for destroying anything that he does not want to eat.”</span></span></em></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><em><span style="font-size: 10pt"><span style="font-family: Calibri"> </span></span></em></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-size: small"><span style="font-family: Calibri"><span> </span><span>    </span><span>  </span>— George Bernard Shaw</span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/business-technology/help-propagate-%e2%80%9cthe-business-technology-weave%e2%80%9d-%e2%80%93-and-a-bonus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
