Infosecurity Europe says US national cybersecurity plans should be supported

London UK 3rd April 2009 - Infosecurity Europe says a bill just presented to the US Congress - which seeks to introduce mandatory security standards to private and public sector companies that control the critical infrastructure of the US - should be actively supported.

"The proposal to create a National Cybersecurity Advisor (NCA) position with direct reporting to the President will allow one person and their team to act as a focal point in the event of an electronic attack on the US infrastructure," said Tamar Beck, Group Event Director, Infosecurity Europe, "This is an important step in securing the cybersecurity of the US and is in keeping with President Obama's stated aim of securing the IT infrastructure of the United States," she added.

According to Beck, the NCA will have the power to shut down any aspect of the US infrastructure, such as power, telephony or environmental supplies, if an electronic attack takes place.

In addition, she says, the NCA would be able to enforce common security standards - such as those from National Institute of Standards and Technology - across the national infrastructure.
The plan with the NCA program, she explained, is to create state and regional cybersecurity centres that will provide local advice to businesses, as well as working with universities to supply - and tap - their educational resources.

In parallel with the creation of the NCA position and team, Beck said that the bill seeks to create a Cybersecurity Advisory Panel made up of representatives from the private and public sector, with the eventual aim of licensing cybersecurity professionals.

"This really is excellent news, since it creates a private-public framework that will foster IT security education and professionalism at all levels," she said.

"In time, not only will the national US infrastructure be much better protected, but we could even see a better understanding of the need for cybersecurity amongst all Internet users. And that is no bad thing," she added.

For more on the US Cybersecurity bill: http://preview.tinyurl.com/dyeudq

Infosecurity Europe, running for its 14th year in 2009, is Europe’s number one Information Security event. Featuring over 300 exhibitors, the most diverse range of new products and services, an unrivalled education programme and visitors from every segment of the industry, it is the most important date in the calendar for Information Security professionals across Europe. Infosecurity Europe is one of five Infosecurity events around the world with events also running in Belgium, Netherlands, Russia, and France. Infosecurity Europe runs from the 28th – 30th April 2009, in its new venue Earls Court, London. To register to attend or for more information please visit www.infosec.co.uk

Neil Stinchcombe, Eskenzi PR
<>

OneClick IntelliPanel Desktop from Lakeland - Product Review

Standby To Save Money!

Review by Michael Smith

Desktop IntelliPanel Lakeland Ref 21306

We live in a digital age, but it’s still important to switch off from time to time – especially your electrical appliances. We’re told that leaving something on standby wastes a staggering £740 million a year, well waste no more!

These IntelliPanels are recommended by the Energy Saving Trust, and mean that you can say goodbye to standby on your desktop or home entertainment system. Simply plug all the equipment in and every time you turn the screen on or off, IntelliPanel will automatically take care of the rest.

The IntelliPanel Desktop for PCs has one master socket – that is the one that controls the system – and 7 sockets for peripherals and power supplies to run peripherals on a PC. When the PC is shut down a relay, for lack of a better word, is triggered and the other 7 sockets are switched off, thus turning off all appliances with nothing draing any phantom power.

The IntelliPanel Desktop, Lakeland Ref 21306, costs 32.29 GBP, and will be available from Lakeland until 31st May 2009 (so hurry), and is well worth it, especially considering that, would you go for the ByeBye Standby option you would pay that money for 3 plug in devices that are remote controlled, meaning you still have to remember to actually push the buttons on the remote. Here you don't have to think about it. Once the PC is powered down the rest follows. Bingo!

The information to this device states that it is compatible with PC, which normally always means just MS Windows, and Mac. The panel does, however, works on PC with Linux Operating Systems, that is to say, Open Source PC Operating Systems – something that has not been mentioned in the information, but that I think is worth mentioning.

I personally like the OneClick IntelliPanel and can but recommend it. Though I have only had it here for a very short time but I am sold on it already. It is the simplicity in that you do not have to think to turn this off and that and, especially, as with power supply plugs, one does not have to crawl under the desk to turn off the sockets.

Nice one.

Definitely a device to recommend, and the Planet will be thankful if we all would use such devices, especially the offices around, and not just businesses. Too many government offices leave computers and what not all all day and all night all the time. It is not just the money, taxpayer's money, that government offices waste, but the energy and with it the damage that does to the environment.

Devices such as the IntelliPanels do not cost a fortune but sure could save one and, maybe, our Planet too.

© M Smith (Veshengro), 2009
<>

VisionRacer VR3 – Launch Afternoon

by Michael Smith
London, March 31 at the Aston Martin Garage, Mayfair, the UK launch took place of the VisionRacer VR3 took place and I had the privilege to be among the invited guests.

While I am not normally a gamer of any sort – well, bar playing Solitaire and Frozen Bubble and Tetris on the PC – I must say that this is one heck of a gaming device that, with all its components really offers the closest thing to actually physically sitting in a race car and doing the circuits.

What makes it especially, I should think, such a good piece of kit is the quality of the human interface devices, the steering wheel system, the gear changer and the pedals, from Logitech. Logitech is one of the world's leading, if not indeed the world's leading, maker of computer human interface devices, from simple rodents – though there is nothing simple on them – to such as used in the VisionRacer VR3. It is those interface devices from Logitech that make the VR3 such a strong product.

Aside from the use for gaming and the training of future F1 drivers the VR3, I am sure, could also find uses as a driver's training tool for the ordinary drivers as well and especially for police pursuit drivers.

In the simulator setting a lot of things could be done and tested as far as driver's reactions and such that would not, necessarily, safe to so on the roads. Also, if there is a crash nothing gets damaged and no one injured or killed.

Even though, as said, I am not normally someone who indulges too much in computer games and such I would love to, if I just had the space here, to have one of them VisionRacer VR3s at home. And that says a lot for what I think of it.

Brilliant piece of kit and well worth the money.

© M Smith (Veshengro), 2009
<>

Microsoft MEA Director's comments on security shows the need for branch office protection says Finjan

Farnborough, United Kingdom, 1st April 2009 - Comments on the need to stay protected by Microsoft's Commercial Market Strategy Director in the Middle East and Africa highlight the need not to overlook the security requirements of branch offices, says Yuval Ben-Itzhak, Finjan's Chief Technology Officer.

"The comments of Microsoft's Mark Chaban, which came after Chinese cyber spies had been found to have infiltrated into the online networks of companies around the world are very relevant to the needs of branch offices," he said.

"When news reports like this there is a tendency to overlook the fact that we live and work in a global village, and that many companies have branch offices in the Middle East or, of course, that Middle Eastern firms have operations elsewhere in the world," he added.
According to Ben-Itzhak, Chaban's revelations that Microsoft's security software detected malware and similarly unwanted applications on 42.6 per cent more PCs in the Gulf States last year than in 2007 makes for very interesting reading.

Whilst many major companies install unified Web security on their head office systems, he says, the security needs of branch offices and operations are often overlooked, with the result that these branch IT systems are usually the weakest link in the IT security defence chain.
Hackers, he explained, are now sufficiently criminally-driven (and minded) to research their victim companies and, as a result, target branch offices, knowing full well that this is their best chance of gaining unauthorised access to the organisation concerned.

Ben-Itzhak went on to say that, in its latest quarterly cybercrime report (http://preview.tinyurl.com/cajblt), Finjan identified that criminal hackers are injecting search engine optimisation targeted pages to include repetitive popular search keywords with minor typos.

By targeting regional pages of major companies, which have lesser page visitors, but whose page accesses are still measured in the tens of thousands, he says, it is far easier to get these injected pages to the top of the search engine lists.

"This means that, when someone searches for XYZ Corporation Middle East, they have a greater chance of ending up on the compromised pages of XYZ Corp's pages than if they searched for the company name alone," he said.

"And this is where weaker defences on branch office IT systems really come into play, as their weaknesses can be exploited by hackers wanting to route innocent Internet users over to their compromised sites," he added.

It's against this backdrop that Ben-Itzhak is urging IT managers to spend just as much time and resources on securing their branch offices as their head office.

"Only by doing this can they hope to equally protect all aspects of their organisation's IT operations against criminals," he said.

Finjan MCRC specializes in the detection, analysis and research of web threats, including Crimeware, Web 2.0 attacks, Trojans and other forms of malware. Our goal is to be steps ahead of hackers and cybercriminals, who are attempting to exploit flaws in computer platforms and applications for their profit. In order to protect our customers from the next Crimeware wave and emerging malware and attack vectors, Finjan MCRC is a driving force behind the development of Finjan's next generation of security technologies used in our unified Secure Web Gateway solutions. For more information please also visit our info center and blog.

Secure Gateway provides organizations with a unified web security solution combining productivity, liability and bandwidth control via URL categorization, content caching and applications control technologies. Crimeware, malware and data leakage are proactively prevented via patented active real-time content inspection technologies and optional anti-virus modules. Powerful central management enables intuitive task-based policy management, excellent drill-down reporting capabilities and easy directory integration for all network implementation options. By integrating several security engines in a single dedicated appliance, Finjan’s comprehensive and integrated web security solution enables quick deployment, simplified management and reduction of costs. Business benefits include real-time web security (no patches or updates needed), lower total cost of ownership (TCO), cost savings in administration efforts, lower maintenance costs, and reduction in loss of productivity. Finjan's security solutions have received industry awards and recognition from leading analyst houses and publications, including Gartner, IDC, Butler Group, SC Magazine, eWEEK, CRN, ITPro, PCPro, ITWeek, Network Computing, and Information Security. With Finjan’s award-winning and widely used solutions, businesses can focus on implementing web strategies to realize their full organizational and commercial potential. For more information about Finjan, please visit: www.finjan.com.

For more on Mark Chaban's comments: http://preview.tinyurl.com/dan3xd

Neil Stinchcombe, Eskenzi PR
<>

Tufin Technologies Names Michael Hamelin as its Chief Security Architect

Renowned Technologist Tapped to Maintain Tufin’s Technical Leadership as it Accelerates Global Operations

Ramat Gan, Israel, March 31, 2009 – Tufin Technologies, the market leading provider of Security Lifecycle Management solutions, today announced Michael Hamelin as the company’s Chief Security Architect. Hamelin, a well known security expert, will work closely with Tufin CTO, Reuven Harrison to guide the technical evolution of Tufin’s growing solution set and ensure best practices are integrated into all aspects of design and development. Hamelin will support Tufin’s ability to innovate and extend its recognized technical leadership in the Security Lifecycle Management market.

“All too often, security is an afterthought - end user organizations roll out new technologies for the benefits without properly evaluating the risks, and security vendors scramble to help eliminate those risks without fully vetting their products. It’s an extremely inefficient cycle that is very difficult to get ahead of,” said Hamelin. “What is so exceptional about Tufin is that everyone in the company is committed to delivering superior products that get it right the first time -- an attitude that really shapes the corporate culture and enables me to be successful in my charter.”

As Chief Security Architect, Hamelin will identify and champion the security standards and processes for Tufin’s solution set and provide leadership on strategies and technologies that further Tufin’s market position, extend its technical leadership, and ensure Tufin solutions are optimized to solve business problems. Bringing more than 15 years of deep security domain expertise to Tufin, Hamelin is an authority on security practices who has deep hands-on technical knowledge in security architecture, penetration testing, intrusion detection, and anomalous detection of rouge traffic. He has authored numerous courses in information security and worked as a consultant, security analyst, forensics lead, and security practice manager. He is also a featured security speaker around the world widely regarded as a leading technical thinker in information security.

Hamelin previously held technical leadership positions at VeriSign, Cox Communications, and Resilience. Prior to joining Tufin he was the Principal Network and Security Architect for ChoicePoint, a LexisNexis Company, where he was responsible for re-architecting the Company’s network and re-engineering its operational security processes. Hamelin’s efforts contributed to Gartner Inc. analyst Avivah Litan’s assessment in an April 2007 USA Today article that "ChoicePoint transformed itself from a poster child of data breaches to a role model for data security and privacy practices.".[1]

Hamelin received Bachelor of Science degrees in Chemistry and Physics from Norwich University , and did his graduate work at Texas A&M University.

“One of the main reasons Tufin is growing while other companies are either downsizing or struggling to hang on is because we have hired the right people at the right time,” said Reuven Harrison , CTO, Tufin Technologies. “Our commitment to technical excellence has enabled us to deliver products that very simply and elegantly help our customers streamline network security operations. Michael is one of the most technically astute people I’ve met. His experience and skill set is a perfect addition to our team, and we couldn't be happier to have him.”

Tufin Technologies is the leading provider of Security Lifecycle Management solutions that enable large organizations to enhance security, ensure business continuity and increase operational efficiency. Tufin's products SecureTrack™ and SecureChange™ Workflow help security operations teams to manage change, minimize risks and dramatically reduce manual, repetitive tasks through automation. With a combination of accuracy and simplicity, Tufin empowers security officers to perform reliable audits and demonstrate compliance with corporate and government standards. Founded in 2005 by leading firewall and business systems experts, Tufin now serves 300 customers around the world, including leading financial institutions, telecom service providers, transportation, energy and pharmaceutical companies. For more information visit www.tufin.com or follow Tufin on Twitter at TufinTech http://twitter.com/TufinTech.

Elizabeth Safran,
Looking Glass Public Relations for Tufin Technologies

[1] USA Today, “Who's guarding your data in the cybervault?” Byron Acohido and Jon Swartz, April 22, 2007

<>

VisionRacer VR3 offers ultimate gaming experience with new driving rig

- Combines full-adjustable, ergonomic race chassis and seat with Logitech force-feedback wheels, gear changers and pedals

London, England – 31 March 2009: VRI Technology Ltd is set to offer the ultimate immersive gaming experience with the introduction (today) of VisionRacer VR3. In partnership with Logitech force feedback wheels and pedals, the innovative VR3 will thrill and inspire a new generation of drivers, offering the perfect ergonomics for long sessions of lap-time and race wins.

Available from today, the VisionRacer VR3 smart seat chassis brings together the latest console or PC gaming platforms and high-end gaming peripherals, such as the Logitec GT25 and the Logitech Driving Force GT wheels, and software such as Gran Turismo. Made from polished stainless steel, with anodised aluminium fittings and a fully adjustable seat, the VR3 includes cabling ducts.

VisionRacer VR3 combines the heritage of Engish race car design from the company founder and design chief, Geoff Turton, and New Zealand-based marketing and IT business expertise from CEO David Harvey. They are passionate about driving, racing, race car development, and the VisionRacer project.

VisionRacer grew out of an understanding that as a new, technology-based generation moves forward, virtual simulation has become a household reality through products such as PlayStation, Xbox, and PC. The one missing elements was how to bring all of these elements together.

Geoff Turton, comments, “the problem we found was that while all the components for high-def immersive racing are in place, the experience was just not complete. This is when I started thinking how we could complete the experience. Three years ago I started designing my first VisionRacer in my work shop”. Turton has gone on to develop the third-generation VR3, a professionally manufactured, fully adjustable racing rig for consumers.

Consumers today are hungry for better products, and actively seek real competition and visual communities. VisionRacer is, “the glue”, that brings together all of those components. VisionRacer is aimed at gamers that want to bring their driving to the next level.

Other groups include race car drivers who will be the future Lewis Hamiltons who want to hone their driving skills and become accustomed to high speed racing on global race circuits. In addition there will be those that are actively involved in virtual communities and will want to join the Formula VTTM virtual online racing competition.

Harvey continues “We are really proud that we have created a product and a system that facilitates low-cost entry into competitive virtual motorsport for a huge market. Today we are launching a world class product and racing experience that will be admired and loved by all”.

“VisionRacer have created the ultimate driving simulator platform and Logitech is delighted to be the supplier of choice for its force-feedback racing wheels,” commented Yehia Oweiss, Logitech's Regional Director, UK & Ireland. “The combination of our award-winning wheels and the VR3's perfect driving ergonomics gives gamers total immersion in the driving experience and the opportunity to post ever faster laps. You can't get more real than this without actually being on the race track”.

VisionRacer is a global company with operations in New Zealand and in the UK. The VR3 rig sells for 699 GBP incl. VAT, the VR3 Gearshift Mount if 59 GBP incl. VAT, and the VR3 LCD Stand is 99 GBP incl. VAT. VisionRacer sells its products via its website on www.visionracer.com

Logitech's flagship G25 Racing Wheel features simulator-grade force feedback, six-speed gear shift, leather-wrapped stainless steel frame wheel, and full metal pedal set with accelerator, clutch, and brake. SRP of this combination is 279.99 GBP incl. VAT.

The Logitech Driving Force GT is the official wheel of Gran Turismo, designed from the ground up to provide an exceptionally realistic PLAYSTATION 3 racing experience. It features force-feedback technology, a comfortable rubber-overmold grip, a 24-position real-time adjustment dial and full-size accelerator and brake pedals. SRP for this is 99.99 GBP incl. VAT.

Source: VisionRacer & Logitech
<>

‘Classified Information’ … Can companies learn from Government?

Dr. Bernard Parsons, CEO, BeCrypt.

Historically, Governments has well understood the need for data classification as a tool for protecting information. The UK Government has a well established scheme of protective marking that applies from state secrets, to information that would cause only embarrassment if lost. However, systems and processes that have worked well for decades, have failed to meet today’s demands. In the UK Ministry of Defence report commissioned following last year’s data losses, Sir Edmund Burton describes how the well developed processes ingrained during the Cold War have not translated in to the Information Age.

The mind set of today’s “Face book Generation” is as applicable to the Public Sector as it is elsewhere, and they expect easy access to and sharing of data. However, even for those familiar with technology, security risks are non-intuitive: a single CD struggles to command the same respect as a box of paper personnel records.

The UK Government data security policies have historically prioritised confidentiality at the expense of availability and data integrity, with this in-balance frequently detracting from system usability. At the same time, there has been a growing need to store personally identifiable information. Much of this data has not fitted within existing data classification regimes, and significantly, there has been little inclination to consider the impact of the accumulation of large quantities of such data. As a consequence, many systems at the lower end of data sensitivity have not had adequate safeguards (both system and procedural) in place, creating a new and arguably more significant Information Assurance challenge to Government. Gartner highlight the relevance of this to the private sector by stating ‘Organizations that do not have an effective data classification program usually fail at their data encryption projects’.

A “critical mass” of public sector data breaches occurred in the UK around the beginning of ’08, typically relating to personal data, after which, events that would previously have gone un-noticed, caused public dismay. This provided a catalyst for change that has been seized upon by the Information Assurance community to drive home widespread improvements. Recognition that the solution was cultural and not prescriptive has lead to the establishment of a risk management culture aimed at rebuilding the citizens’ confidence in the storage and management of their data.

The risk management culture has involved a shift in focus from protective marking, to the consideration of business impact levels. This encourages consideration of the value of data; risks associated with loss of confidentiality, integrity or availability; and the corresponding impact to the business. With an inclusion of data accumulation and aggregation elements, personal data can now be required to receive the same treatment previously reserved for higher levels of classification.

A set of new minimum mandatory measures including reporting and compliance mechanisms is described within the recently published Government Security Policy Framework. As a public domain document, this replaces the protectively marked Manual of Protective Security. This underlines a new level of openness, as well as illustrating the increasing similarity in data and risks to data across the public and private sectors. A public domain Information Assurance Maturity Model has been published by Government, providing a practical framework for IA compliance. This is consistent with and builds upon existing standards and regulation relevant to the private sector, such as ISO 27001 and the UK Data Protection Act.

There is increasing commonality between assurance schemes for technological solutions between public and private sectors, allowing products to be developed and deployed for common goals. This factor assists in keeping solution costs low for Government. This is key, as the requirement for departments to comply has not been accompanied by additional budget.

An example of a common goal addressed at low-cost relates to the mandatory requirement to provide “Urgent consideration ….of simple, affordable solution to enable the safe, authorised, use of privately owned computers for limited Government tasks..”.

Through an agile public-private consultation process, technology has been developed and certified to allow the secure use of un-managed machines for remote working. CSC is an example of an organisation using this and Virtualisation technology to allow dynamic secure remote access to corporate resources.

Irrespective of the need to protect national secrets, intellectual property or personal information, today’s technology has placed similar demands on all sectors, and each sector has provided examples of best and worst practice. The UK Government reacted with a framework to encourage a culture change. This contains effective guidelines that are open to review by all, the lessons for Corporations are there to be learnt and adopted.

BeCrypt is exhibiting at Infosecurity Europe 2009, the No. 1 industry event in Europe held on 28th – 30th April in its new venue Earl’s Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk

Source: InfosecurityPR
<>