Towerwall's InfoSec Blog

Content Type

See all

Towerwall Information Security Alert Vol 14.07 - Watch out for April Fools scamming on Friday

Google , Fractional Chief Information Security Officer (CIS , Conficker , Phishing , Virus , ransomware , Amazon , scammers , April Fools , Starbucks , cannabis , Enterprise

Michelle Drolet

Watch out for April Fools scamming on Friday by Kevin Frey Annually, businesses and organizations often put up jokes or pranks for April Fools’ Day. Google, Starbucks, Amazon, etc. are frequent participants. E.g. Last year, Amazon revamped their site to look their old, original 1999 version... and Google (known for multiples) turned its "Maps" app into the classic arcade game "Pac-Man." However, it is important to remember to think twice before clicking on things you receive on email or see onfalse

Hundreds of cloud apps still vulnerable to DROWN

SSLv2 , CISO , DROWN vulnerability , FREAK , DROWN , HTTPS , cannabis , Enterprise

Michelle Drolet

Complacency in addressing known vulnerabilities puts users at risk If you have even a passing interest in security vulnerabilities, there’s no chance that you missed the news about the DROWN vulnerability. It’s one of the biggest vulnerabilities to hit since Heartbleed, potentially impacting a third of all HTTPS websites. By exploiting the obsolete SSLv2 protocol, this flaw makes it possible for an attacker to eavesdrop on a TLS session. Because we use SSL and TLS encryption to shop, sendfalse

Do you have the right person for the job?

Fractional Chief Information Security Officer (CIS , cannabis , Enterprise

Michelle Drolet

According to Cisco’s 2015 Annual Security Report, 91 percent of companies have an executive with direct responsibility for security, but only 29 percent of them have a Chief Information Security Officer.

Save the Date: Information Security Summit 2016

Security Partners , network security , Fractional Chief Information Security Officer (CIS , Phishing , GDPR , Information Security , Application Security , Security , ransomware , Information Security Summit , HIPAA , Compliance & Privacy , penetration testing , Events , Compliance , Mobile Security , cannabis , cybersecurity , Enterprise

Michelle Drolet

Click here for more information & to register! Please save the date and plan to join us for this timely forum on what you need to know about the latest security issues, threats, and technologies that will help you protect your business!

2015 International Compendium of Data Privacy Laws

GDPR , HIPAA , Compliance , cannabis , Enterprise

Michelle Drolet

Privacy and data protection issues confront all organizations—whether you handle employee information, credit card data, sensitive financial information, or trade secrets. Securing data is a daunting task that is further complicated by cross-border transfer issues and the differences in privacy laws around the world. The team at BakerHostetler has developed a prompt and practical PDF to assist and inform your data protection policies. Download the 2015 International Compendium of Data Privacyfalse

10 Things I Know About...Hiring a vCISO

breach , Virtual CISO , Fractional Chief Information Security Officer (CIS , Compliance & Privacy , 10 Things I Know , Compliance , cannabis , vCISO , Enterprise , small and midsize businesses

Michelle Drolet

10. A hedge against a breach A virtual chief information security officer can serve as security consul or as an interim CISO to fill the gaps during a planned information-technology security policy review. Better to be safe than sorry.

5 cybersecurity trends to watch for in 2016

5 cybersecurity trends to watch for in 2016

Phishing , malware , ransomware , Internet of Things , cloud services , Known vulnerabilities , cannabis , Enterprise

Michelle Drolet

As threats evolve and grow more sophisticated, securing IT systems is more important than ever. We may welcome in the New Year with open arms, but we must also prepare for the cybersecurity threats ahead of us. The 2015 Cost of Data Breach Study from IBM and the Ponemon Institute put the average cost of a data breach at $3.79 million, and that figure is expected to grow in the year ahead. With the right resolutions, you can drastically reduce your chances of falling prey to cybercriminals.

Ransomware is only getting worse. How do you prepare for it?

Counterintelligence Program , ransomware , ransomware-as-a-service , CryptoWall v3 , cannabis , Enterprise

Michelle Drolet

Ransomware-as-a-service, help desks, third parties -- all point to a mature yet illegal enterprise undergoing serious growth. Here are tips to protect yourself and your company. Ransomware is big business. Over the last few years we've observed the steady rise of ransomware, with some trepidation. It is fast becoming a multi-billion dollar business, and it's getting surprisingly sophisticated. The ransomware industry is continually innovating, offering cybercriminals new technology, variousfalse

Join us for Security BSides Boston 2016

Join us for Security BSides Boston 2016

Sophos , Security BSides Boston 2016 , Microsoft NERD , BSides Boston , Events , Microsoft , Enterprise

Michelle Drolet

Friday, May 20 2016 (Training) Saturday, May 21 2016 (Conference) Follow BSidesBoston on Twitter: #BSidesBOS @BsidesBoston @MicrosoftNERD Questions: help@bsidesboston.org

5 Information Security Trends for 2016

DRIDEX botnet , Darkode , China hack , EMV credit cards , SIMDA botnet , Application Security , Google Wallet , mobile malware , ransomware , Internet of Things , smart-connected , RFID credit cards , IoT , cannabis , EU Data Protection , Enterprise , Apple Pay

Michelle Drolet

Online security trends continue to evolve. This year, online extortion will become more prevalent. We also expect that at least one consumer-grade IoT smart device failure will be lethal. Ransomware will make further inroads, since the majority go unreported. China will drive mobile malware growth to 20M, and cybercrime legislation will take a significant step towards becoming a truly global movement. Here are five information security trends on track for the New Year: