Towerwall's InfoSec Blog

Content Type

See all

Securing Your Future with a Virtual CISO

Fractional Chief Information Security Officer (CIS , Compliance & Privacy , penetration testing , Compliance , cannabis , Enterprise

Michelle Drolet

The enterprise is facing a dangerous combination of mounting cybersecurity threats of increasing subtlety, and a widening gap in the skills required to identify and combat them. Having someone that knows how to lead the charge in identifying and analyzing threats, creating strategic security plans and ensuring compliance, requires the right level of expertise. Many businesses, especially small and medium businesses, simply don’t have it.

How to keep cybercriminals out of your apps

Application Security , penetration testing

Michelle Drolet

Four ways to implement and maintain security testing. Cybercriminals had a fantastic time in 2014 – breaching major retailers such as Home Depot and Kmart, major financial institutions (notably JPMorgan Chase), and a slew of smaller companies.

Towerwall Application Security Alert Vol 13.73

network security , passwords , Web Storage , Data Security , Security Regulations , Botnet , credit card security , Security Threat , bot-infected , two-factor authentification , Information Security , web server , Application Security , Security , Hackers , Cloud Security , Web Application Firewall , security policy , cybercriminals , penetration testing , Cryptolocker , Security Alert , Data Privacy , Web Browser , web users , cybersecurity , Enterprise , Data Breach

Michelle Drolet

1.2 billion logins scooped up by CyberVor hacking crew - what you need to do Hackers have amassed a vast collection of stolen data, including 1.2 billion unique username/password pairs, by compromising over 420,000 websites using SQL injection techniques. Researchers monitored the gang for over seven months, thought to be "fewer than a dozen men in their 20s who know one another personally" based in a small city in central Russia. They found that the group, working together since at least 2011,false

Cork That App or Face Attack

Cork That App or Face Attack

passwords , Data Security , Government Compliance Regulations , Assessment , Security Regulations , credit card security , Security Threat , Security Program , Information Security , Application Security , Mobile Apps , Hackers , endpoint security system , security policy , cybercriminals , penetration testing , information security tips , Compliance , Mobile Security , cybersecurity , Enterprise , Gap Assessment

Michelle Drolet

Despite all the news about hackers infiltrating major corporations, most businesses continue to leave themselves woefully unprotected. Some surveys estimate more than 70% of businesses perform vulnerability tests on less than 10% of their cloud, mobile and web applications. A majority also confess they have been hacked at least once in the last two years. While most large businesses have begun application vulnerability testing, there is still a long way to go. After all, you are only asfalse

Deciding Between Vulnerability Scanning And Penetration Testing

Security Services , security software , Data Security , Assessment , Security Regulations , Security Threat , Information Security , Application Security , Security , Hackers , security policy , cybercriminals , penetration testing , Big Data , Data Privacy , vulnerability management , cybersecurity , Enterprise , Data Breach , Gap Assessment

Michelle Drolet

My clients often confuse scanning and penetration testing. Organisations should be conducting both external vulnerability scans and penetration tests. If you are storing or transmitting data on the Internet, particularly sensitive data such as credit card details, then quarterly scanning is required to validate your PCI compliance. You also need to conduct a penetration test at least once a year. These are the minimum requirements to remain compliant; it is prudent to scan and test more often.false

Why security professionals need to get more creative with penetration testing (and how to do it)

network security , Security Services , security software , Data Security , Security Regulations , Social Engineering , Security Threat , Cloud Security , penetration testing , Big Data , Data Privacy , vulnerability management , Mobile Security , cybersecurity , Enterprise , Data Breach

Michelle Drolet

Criminals are evolving with their techniques for hacking and breaching corporate assets, so security managers need to as well. Here are some ways companies are going beyond standard pen testing in order to increase awareness By Maria Korolov Security professionals have long been running penetration tests against their firewalls and other security systems to find weaknesses that need to be addressed. The Common Vulnerability Scoring System is an industry standard, but has been around for afalse

Towerwall Heartbleed Vulnerability Alert

network security , Data Security , Security Regulations , Heartbleed , credit card security , Security Threat , Information Security , Security , security policy , cybercriminals , penetration testing , Security Alert , information security tips , Big Data , Data Privacy , vulnerability management , cybersecurity , Enterprise , Data Breach

Michelle Drolet

Good Afternoon: The IT infrastructure your organization may use for day-to-day business may be vulnerable because of the Heartbleed vulnerability. Sophos a Towerwall partner has prepared a podcast of the Heartbleed vulnerability, which addresses who is likely affected, workarounds and an offer to help determine if you are vulnerable. http://nakedsecurity.sophos.com/2014/04/10/sscc-142-heartbleed-explained-patches-evaluated-apple-chastised-podcast/ If you think you may be affected and don't knowfalse

Towerwall Information/Vulnerability Alert Vol 13.69: Cisco Security Notice

security software , Security Regulations , Security Threat , Security Program , Information Security , Security , security policy , penetration testing , Security Alert , information security tips , security research , cybersecurity , Enterprise

Michelle Drolet

Cisco Security Notice Cisco WebEx Business Suite HTTP GET Parameters Include Sensitive Information

Why wasn't healthcare.gov security properly tested?

security software , Security Regulations , credit card security , Security Threat , Security Program , Information Security , web server , Application Security , Security , software updates , Hackers , Web Application Firewall , HIPAA , security policy , cybercriminals , penetration testing , information security tips , web users , cybersecurity

Michelle Drolet

When the healthcare.gov website was launched on Oct. 1 it didn't take long for technical issues to hit the headlines. Americans trying to register for health care found the website unusable. There were glitches, extremely long loading times, and serious errors, but most worrying of all for anyone entrusting sensitive data to the system was the lack of security testing. Three white hat hackers, charged with exposing flaws in the security of online systems told a Congress hearing that thefalse

Introducing our Quarterly Newsletter: the Data Security Review

Security Partners , network security , Security Services , security software , Web Storage , Data Security , Government Compliance Regulations , Security Regulations , Heartbleed , credit card security , Mobile Devices , Security Threat , Security Program , Information Security , web server , Application Security , Security , malware , Mobile Apps , Hackers , endpoint security system , Cloud Security , T-Mobile , Web Application Firewall , Apple , Shockwave. Internet Explorer , security policy , cybercriminals , penetration testing , financial security , Security Alert , information security tips , Big Data , Mobile Protection , Data Privacy , Web Browser , security research , vulnerability management , Mobile Security , Third-party Vendor , web users , cybersecurity , Data Breach

Michelle Drolet

I am excited to announce the launch of our quarterly newsletter, the Data Security Review.