Towerwall's InfoSec Blog

Content Type

See all

Establishing Security Goals

network security , Security Services , security software , Data Security , Security Threat , Security Program , Information Security , Application Security , Security , Hackers , endpoint security system , Cloud Security , security policy , cybercriminals , penetration testing , information security tips , Compliance , security research , vulnerability management , Mobile Security , cybersecurity

Michelle Drolet

Implementing security practices in your organization’s employees’ daily work habits, and ensuring the integrity and confidentiality of information security, the goals of the Security Awareness Program are:

How Can you Expose Targeted Attacks and Combat APTs?

network security , Security Services , security software , Data Security , Towerwall , Security Regulations , Security Threat , Security Program , Information Security , Application Security , Security , malware , endpoint security system , Cloud Security , cyber-attack , cybercriminals , penetration testing , financial security , information security tips , Big Data , Data Privacy , APT , vulnerability management , cybersecurity , Data Breach

Michelle Drolet

Cybercriminals are employing more sophisticated techniques all the time and far too many companies and organizations still don’t have the protection they really need to safeguard their systems. The prevalence of targeted attacks and advanced persistent threats (APTs) is disturbing. The risk is that security is breached, typically through manipulation of employees using a technique such as spear phishing, and existing security systems are unable to detect the attack. Data can be harvested forfalse

Tips for testing your mobile app security

Security Partners , Security Services , Data Security , Towerwall , Security Regulations , Mobile Devices , Security Threat , Security Program , Information Security , Application Security , Security , Mobile Apps , Hackers , Cloud Security , cyber-attack , security policy , cybercriminals , penetration testing , information security tips , cloud services , Mobile Protection , vulnerability management , Mobile Security , cannabis , cybersecurity , Enterprise

Michelle Drolet

Wherever an app originates from, it is vital that you can vouch for its security before it is circulated The enterprise has gone mobile and there's no turning back. And while the BYOD movement has received plenty of attention, IT departments are getting a handle on the security risks of personal mobile devices in the workplace. The next challenge is " bring your own application" (BYOA), because many public app stores have serious malware problems. Enterprise app stores could be the answer. false

Towerwall and the Information Security Summit highlighted in SearchSecurity.com Article

Security Partners , network security , Security Services , security software , Data Security , Towerwall , Security Regulations , threat landscape , credit card security , Mobile Devices , Security Threat , Information Security , Application Security , Security , Mobile Apps , Information Security Summit , endpoint security system , Cloud Security , HIPAA , penetration testing , financial security , information security tips , Compliance , Mobile Protection , vulnerability management , Mobile Security

Michelle Drolet

Check out Search Security's article - "HIPAA Omnibus Rule, PPACA challenge enterprise compliance management", where our own Natalie Kmit and the Information Security Summit 2013 are highlighted:

Compliance Combines with Vulnerability Scanning to Create Aegify

network security , Security Services , security software , Data Security , GDPR , Security Program , Information Security , Application Security , vulnerability scanning , Hackers , cyber-attack , security policy , cybercriminals , penetration testing , information security tips , Compliance , vulnerability management , cannabis , cybersecurity , Enterprise

Michelle Drolet

Two security firms, the established Rapid7 vulnerability manager and eGestalt, a cloud-based compliance management provider, have signed an OEM deal that will do something for the IT security industry that hasn’t been done before: a combination security and compliance posture management offering called Aegify SPM. The SPM stands for Security Posture Management, and eGestalt of Santa Clara defines SPM as “the art and science of monitoring and managing business security status by orchestratingfalse

Top 10 PHP Security Vulnerabilities

Security Services , security software , Data Security , Security Regulations , threat landscape , Security Threat , Information Security , Application Security , Security , Hackers , cyber-attack , security policy , cybercriminals , penetration testing , Security Alert , information security tips , security research , cannabis , cybersecurity , Enterprise

Michelle Drolet

Security is not a list of things you do. Security is a way of thinking, a way of looking at things, a way of dealing with the world that says “I don’t know how they’ll do it, but I know they’re going to try to screw me” and then, rather than dissolving into an existential funk, being proactive to prevent the problem. But, you can’t buck statistics. Nobody is going to read an article entitled “Coding for Security.” Everyone wants an article with a number in it: “The 8 Most Common PHP Securityfalse

New Internet Explorer zero day being exploited in the wild

Security Services , security software , Web Storage , Data Security , Security Regulations , Security Threat , Information Security , web server , Security , Internet Explorer , Hackers , Web Application Firewall , cyber-attack , security policy , cybercriminals , penetration testing , information security tips , Web Browser , security research , Mobile Security , web users , cannabis , cybersecurity , Enterprise

Michelle Drolet

After the last zero day exploit on Java we reported some weeks ago it appears that a new 0day has been found in Internet Explorer by the same authors that created the Java one. Yesterday, Eric Romang reported the findings of a new exploit code on the same server that the Java 0day was found some weeks ago. The new vulnerability appears to affect Internet Explorer 7 and 8 and seems to be exploitable at least on Windows XP. The exploit code found in the server works as follow: - The filefalse

10 Things to Know Before Creating BYOD Policy

Security Services , Data Security , BYOD , Security Threat , Security Program , Security , software updates , Cloud Security , security policy , penetration testing , security research , cannabis , cybersecurity , Enterprise

Michelle Drolet

In recent years, the work place has become more mobile than ever, and the mobile worker revolution is, in large part, the reason for the rise in Bring Your Own Device (BYOD) policies. The big idea is that through the use of cloud computing-based collaboration platforms, enterprise-class companies can save a great deal of money in IT, security and overall operational costs. While this would seem like a no-brainer, more companies are learning that the opposite is true. Both executives andfalse

Apple iCloud breach proves Wozniak's point about cloud risks

network security , passwords , Mobile Devices , Application Security , software updates , cybercriminals , penetration testing , cloud services , cannabis , Enterprise

Michelle Drolet

In a great article by Ted Samson at InfoWorld, that not even a complex, 16-character password guarantees that your cloud-based data and devices are secure. Here is what Ted had to say: This past weekend, Apple co-founder Steve Wozniak predicted that cloud computing would yield "horrible problems" in coming years. By extraordinary coincidence, Wired reporter Mat Honan experienced firsthand a series of horrible, cloud-related problems, all of which reportedly started when an unnamed Applefalse

Malware attack spread as email from your office's HP scanner

network security , Phishing , Application Security , malware , software updates , penetration testing , cannabis , Enterprise

Michelle Drolet

For those on our Security Alert and Update list we just emailed an article by Graham Cluley on how a malware attack spread as email from your office's HP scanner, yes that's right a scanner! In these high-tech times, scanners and photocopiers aren't just dumb machines sitting in the corner of the office. They are usually connected to the corporate network, and - in some cases - can even email you at your desk to save you having to wear out your shoe leather. And it's precisely thisfalse