Mobile workforce shift will cause security headache for many companies

Infosecurity Europe says mobile workforce shift will cause security headache for many companies

London, UK – A report just recently published that highlights the rising numbers of workers are moving to a truly mobile working environment confirms what many in the IT security industry have suspected for some time, says Claire Sellick, Event Director for Infosecurity Europe.

The iPass report, which took in responses from 1,000 enterprises, found that large swathes of enterprise staffers are using their smartphones to access their email - and a whole lot more.

"What is particularly concerning is the fact that 54 per cent of Blackberry users said they would move to an Apple iPhone if they were offered one, and 63% of employees prefer their smartphone over a laptop," she said.

"The problem here is that, whilst it's relatively easy to defend a laptop against the vagaries of a mobile Internet connection, securing a smartphone is a whole new ballgame for many IT managers," she added.

And, Sellick went on to say, as iPass said in its report, there are clear resultant risks in terms of compliance and security that arise from the migration to smartphones.

Many of the exhibitors at the upcoming Infosecurity Europe event, which takes place at London's Earl's Court exhibition centre on 27th - 29th April, are showing security solutions to what many people are calling the shift to agile working.

In addition, she explained, the show's education programme - which sees a raft of industry professionals giving their advice to visitors free of charge - will help IT managers make the transition to agile working in a safe and secure manner.

What is clear from anecdotal evidence - as well as studies of the enterprise workforce such as this latest one - is that the shift to mobile working is becoming something of a revolution, rather than the progressive evolution that many have previously observed.

"It's clear that enterprises now face the issue of workers using their smartphones, as well as their laptops, whilst on the move. One of our exhibitors has report on the subject (http://www.infosec.co.uk/ExhibitorLibrary/662/Mobile_security_26.pdf) and theme will be explored in several of our keynotes and seminars at the show," she said.

"In many ways, it is security issues such as this that makes the education programme at the show so attractive to attendees, who would normally have to pay for the free advice from a variety of industry professionals if they were at a conference," she added.

For more on the mobile workforce report: http://bit.ly/9hEHvw

To register to attend or for more information please visit www.infosec.co.uk

About Infosecurity Europe

Infosecurity Europe, celebrating 15 years at the heart of the industry in 2010, is Europe’s number one Information Security event. Featuring over 300 exhibitors, the most diverse range of new products and services, an unrivalled education programme and visitors from every segment of the industry, it is the most important date in the calendar for Information Security professionals across Europe. Organised by Reed Exhibitions, the world’s largest tradeshow organiser, Infosecurity Europe is one of five Infosecurity events around the world with events also running in Belgium, Netherlands and Russia. Infosecurity Europe runs from the 27th – 29th April 2010, in Earls Court, London. For further information please visit www.infosec.co.uk

Source: Eskenzi PR

Dell put Credant's Encryption on all Commercial client systems

Credant Announces Encryption Security Solutions Now Available Factory Installed On Dell Commercial Client Systems

Provides Customers with Compliance-Ready, Non-Disruptive, Centrally Controlled Endpoint Data Protection

Credant Technologies, the market leader in endpoint data protection solutions, will provide Dell with encryption and data protection for its commercial client systems. Beginning today, Dell customers may select the Credant Mobile Guardian Dell Edition security encryption solution factory installed on Dell Precision™ workstations, Latitude™ laptops and OptiPlex™ desktops, along with other Credant solutions through Dell’s Software and Peripheral (S&P) store with commercial laptop and desktop computer purchases.

Bob Heard, CEO of Credant Technologies, said “We are delighted that Dell, one of the leading computer companies in the world, has selected Credant as a data protection and compliance supplier. It is inspiring that Dell recognizes the importance of data security and therefore empowers its business customers with intelligent encryption technology that will help protect their data from loss or breaches, and meet their compliance obligations, from the day they purchase a new PC.”

Credant also announced the launch of Credant FDE DriveManager, which allows customers to manage self-encrypting hard drives shipped by Dell on Latitude PCs. These solutions offer customers complete flexibility in deciding which hardware and software solutions best meet their needs, safe in the knowledge that all of their data can be protected.

Credant has been providing encryption and data protection through Dell’s S&P organization since 2009. Dell customers can purchase additional Credant data encryption software and solutions to protect the data at rest on legacy PC’s, helping them meet their data compliance needs.

“Data protection is a concern that is top-of-mind for the customers we talk to on a daily basis,” said Steve Lalla, VP and GM, Commercial Client Product Group, Dell. “The Credant Mobile Guardian Dell Edition solution meets that critical need and provides compliance-ready data encryption with minimal impact on operational processes and the user experience. This allows customers to focus on their core business and end users to get more done.”

CREDANT Mobile Guardian is the only centrally managed endpoint data protection solution available providing strong authentication, intelligent encryption, usage controls, and key management for data recovery. By aligning security to the type of user, device, and location, CREDANT permits the audit and enforcement of security policies across all computing endpoints.

Heard concluded, “We are committed to delivering endpoint data protection that enables business processes to continue unhindered. By working with Dell we are delighted that its customers can utilize our technology to ensure the data on their endpoint devices is adequately protected.”

About CREDANT Technologies

CREDANT Technologies is the market leader in endpoint data protection solutions. CREDANT’s data security solutions mitigate risk, preserve customer brand, and reduce the cost of compliance, enabling business to “protect what matters.” CREDANT Mobile Guardian is the only centrally managed endpoint data protection solution providing strong authentication, intelligent encryption, usage controls, and key management for data recovery. By aligning security to the type of user, device, and location, CREDANT permits the audit and enforcement of security policies across all computing endpoints. Strategic partners and customers include leaders in finance, government, healthcare, manufacturing, retail, technology, and services. CREDANT has been recognized by Inc. magazine as the #1 fastest growing security software company in 2008 and 2007; was selected by Red Herring as one of the top 100 privately held companies and top 100 Innovators; and was named Ernst & Young Entrepreneur of the Year 2005. Austin Ventures, Menlo Ventures, Crescendo Ventures, Intel Capital (NASDAQ:INTC), and Cisco Systems (NASDAQ:CSCO) are investors in CREDANT Technologies. For more information, visit www.CREDANT.com.

Source: Eskenzi PR

ISACA Leader Says 2010 Will be Year of the Cloud

Rolling Meadows, IL, USA: Research released by Resource on Demand, an IT recruitment firm, claims to show the company has been receiving a record number of enquiries for salesforce and software-as-a-service (SaaS) specialists during the first month of the year (http://bit.ly/cZ108a).

According to Rolf von Roessing, international vice president of ISACA, the not-for-profit global association of IT security, audit and governance professionals, the 233 per cent surge in recruitment requests seen by the firm during January signals that, after brief gestation, cloud computing is firmly set to take off into the mainstream in 2010.

“The financial and organisational benefits of switching to cloud-based storage and systems are clearly driving this surge in demand, as witnessed by Gartner’s recent prediction that, within the next four years, 20 per cent of firms will have no appreciable local resources as a result from switching (http://bit.ly/7dvygF),” he said.

“It's important, however, that in the rush to embrace the obvious benefits of the cloud, businesses do not overlook the security implications of extending their IT resource into what is, to all intents and purposes, a virtual environment," he added.

Business and IT managers should take the time to review their security systems and resources, and ask themselves whether their information security management can effectively defend their data and other assets in the cloud, the ISACA leader went on to say.

And, even if an initial budget to extend and enhance a firm’s IT security resources to fully support the cloud is not apparently available, IT managers should not lose sight of the possibility that some of the direct cost savings that arise from cloud migration can be invested in security facilities, he explained.

Von Roessing, who has extensive experience in the financial services security industry, said that, in May of last year, ISACA joined the Cloud Security Alliance to promote good practices on the cloud security front (www.cloudsecurityalliance.org).

ISACA, a global association of 86,000 IT governance, security and audit professionals, also published a cloud computing white paper, titled Cloud Computing: Business Benefits With Security, Governance and Assurance Perspectives. which provides a road map for developing positive and secure relationships with cloud providers.

"The ISACA white paper is available as a free download at www.isaca.org/cloud and, along with a number of other association initiatives, ISACA remains committed to working with IT professionals to ensure the highest levels of security in the cloud," he said.

"As new computing functions and services appear in what will undoubtedly be the year of the cloud, it is important that IT professionals remain vigilant about the security implications of what is set to become a rapidly-changing IT landscape," he added. For more on ISACA: www.isaca.org

About ISACA

With more than 86,000 constituents in more than 160 countries, ISACA® (www.isaca.org) is a leading global provider of knowledge, certifications, community, advocacy and education on information systems (IS) assurance and security, enterprise governance of IT, and IT-related risk and compliance. Founded in 1969, ISACA sponsors international conferences, publishes the ISACA® Journal, and develops international IS auditing and control standards. It also administers the globally respected Certified Information Systems Auditor™ (CISA®), Certified Information Security Manager® (CISM®), Certified in the Governance of Enterprise IT® (CGEIT®) and Certified in Risk and Information Systems Control™ (CRISC™) designations.

ISACA offers the Business Model for Information Security (BMIS) and the IT Assurance Framework (ITAF). It also developed and maintains the COBIT®, Val IT™ and Risk IT frameworks, which help IT professionals and enterprise leaders fulfill their IT governance responsibilities and deliver value to the business.

Source: Eskenzi PR

Web 2.0 services are the next security hurdle says 360°IT – The IT Infrastructure Event

Planning is are now well under way for the first 360°IT – The IT Infrastructure Event, due to take place at London's Earls Court this coming September.

And, says, Natalie Booth, the Event Director, even at this early stage, it is clear that Web 2.0 services – and in particular social networking sites such as Facebook and Twitter – are becoming a new battleground between criminal hackers and Internet using businesses.

"If you look at all the research into workplace use of the Internet, and the threats it poses, the topic of social networking comes up time and time again, mainly because of the volume of malware infections and data leakages that accrue from staff using these services," she said.

"But the real battle has yet to come, as there are signs that conventional IT security may not be enough to defend against the diverse vagaries of social networking sites," she added.

Earlier this week, Ray Stanton, BT's global head of security, gave a security show keynote at which he said that many companies have been struggling with social networking sites, but that the problem had spilled beyond the IT department and over into human resources.

The problem identified by Stanton, says Booth, is that staff productivity is now under threat as a result of employees spending too much time interacting on the Internet, and not enough time doing their daytime jobs.

According to Booth, the scale of the problem has yet to break into the mainstream, as few employees are yet aware that their staff productivity is being eroded by staff – quite literally – whiling away the hours in the office on Facebook, Myspace and Twitter.

Ray Stanton correctly identified that, although the task of securing staff access to social networking sites and services isn't an easy one, but it can be achieved, she explained.

But the real problem, Booth went on to say, is that there is a danger of the productivity issue jurisdiction falling between the IT and human resources departments, when, in fact, it should be a boardroom and senior management issue.

"Just as staff need to be disciplined if they are found to be wasting company time with inappropriate behaviour, so inappropriate or excessive social network site usage needs to be added to the list of possible disciplinary offences," she added.

"It's against this backdrop that we expect social networking site usage to become a major talking point as the months count down to 360°IT – The IT Infrastructure Event in September. Web 2.0 services bring a lot to the better business table, but they also pose a potential serious company risk, and not just on the security level," she added.

For more on Ray Stanton's social networking keynote: http://bit.ly/96u0le

For more on the 360°IT – The IT Infrastructure Event: www.360itevent.com

About 360°IT – The IT Infrastructure Event

360°IT is the event dedicated to the IT community addressing the needs of IT professionals responsible for the management and development of a flexible, secure and dynamic IT infrastructure.

With high level strategic content, product demonstrations and technical workshops, 360°IT will provide an essential road map of current and emerging technologies to deliver end to end solutions.

360°IT will facilitate vendor and end user collaboration to create the IT infrastructure necessary to achieve key business objectives – improving service, reducing cost and managing risk whilst gaining competitive advantage and growth.

Eskenzi PR

MiFi and MC998D launch on Virgin Mobile Canada

Virgin Mobile Canada Launches Novatel Wireless MiFi Intelligent Mobile Hotspot 2372 and MC998D USB Modem

Connectivity Solutions Offer Convenience, Flexibility and Increased Productivity for Canadian Customers

SAN DIEGO AND TORONTO – February, 2010 – Novatel Wireless, Inc. (Nasdaq: NVTL), a provider of wireless broadband access solutions, and Virgin Mobile Canada, announced the launch of the Novatel Wireless MiFi Intelligent
Mobile Hotspot 2372 and Ovation MC998D Wireless Broadband USB modem on
Virgin Mobile Canada¹s HSPA network.

The Novatel Wireless MiFi 2372 represents the industry¹s first Intelligent Mobile Hotspot, a new category of mobile broadband that lets users put their world of content, services and connectivity in their pocket. The MiFi platform includes a microSD slot for expandable memory of up to 16 gigabytes and supports up to five simultaneous users or mobile Internet devices, located within 30 feet of the unit.

The Ovation MC998D Wireless Broadband USB modem is an HSPA+ device that
works on 850, 1900 and 2100MHz HSPA+/UMTS bands and Quad Band GPRS/EDGE providing download speeds of up to 28.8 Mbps. Featuring multiple input multiple output (MIMO) and diversity antenna technologies, autoinstalling
software for Windows and Mac, and integrated microSD storage, the MC998D
provides flexibility and ultra fast connectivity virtually anywhere in the world.

“Virgin Mobile¹s customers are constantly on the move and want to be able to connect online wherever they are. These new additions to our line-up make it easy for them to stay connected to all of their social networks – with photos, messaging, music and more – while on the go,” said Robert Blumenthal, President, Virgin Mobile Canada. “We are excited to partner with Novatel Wireless to provide our customers a simple, fast and convenient way to hook up online using either one of these mobile broadband products on Canada¹s largest high-speed network.”

"Demand for cutting edge mobile connectivity for both business and casual use continues to grow on a global scale," said Rob Hadley, CMO, Novatel Wireless. “Partnering with Virgin Mobile Canada will enable us to provide streamlined, ultra high-speed wireless Internet solutions for our combined customers across Canada.”
Compatible with Windows, Mac and Linux operating systems, the MiFi 2372 delivers download speeds up to 7.2 megabits per second with enhanced performance for simultaneous uploads/downloads and large file transfers. The MiFi 2372 also offers optimized functionality for video streaming and online gaming.

For more info, visit www.virginmobile.ca.

About Virgin Mobile Canada

The Virgin Mobile group of companies has attracted more than 13.8 million customers worldwide. As the No.1 mobile youth network, Virgin Mobile Canada's mission is to be Canada¹s most loved mobile company with the hottest phones and plans on the hottest network. Its plans with extra for no extra make it easy for members to find the perfect plan for them to connect to e-mail, social networks, texting and GPS navigation with the smartest phones and mobile Internet products. Virgin Mobile members also get access to the hottest events, global roaming and the best customer service. J.D. Power and Associates 2009 Canadian Wireless Customer Satisfaction Study has awarded Virgin Mobile “Highest in Customer Satisfaction With Prepaid Wireless Service, Five Years in a Row” and it has ranked Virgin Mobile "Highest in Customer Satisfaction With Postpaid Wireless Service". 91% of
customers would also recommend Virgin Mobile to a friend.

Virgin Mobile phones are available at more than 4,000 locations nationally
including The Source, Virgin Mobile retail locations and additional retails
partners. Virgin Mobile products can also be purchased at The Source
locations, online at www.virginmobile.ca or by calling 1-888-999-2321. Get
personal with Virgin Mobile Canada on Facebook at
facebook.com/virginmobilecan and Twitter at twitter.com/virginmobilecan.

ABOUT NOVATEL WIRELESS

Novatel Wireless, Inc. is a leader in the design and development of innovative wireless broadband access solutions based on 3G and 4G wireless technologies. Novatel Wireless' Intelligent Mobile Hotspot products, software, USB modems and embedded modules enable high-speed wireless Internet access on leading wireless data networks. The Company delivers specialized wireless solutions to carriers, distributors, OEMs and vertical markets worldwide. Headquartered in San Diego, California, Novatel Wireless is listed on NASDAQ: NVTL. For more information please visit www.novatelwireless.com. (NVTLG)

<>

It’s Better to Prevent than to Cure

Alexandra Tsybulskaya, Corporate Sales, Elcomsoft

Last week a company that rents an office floor next to ours fell prey to a malicious attack. The employees of the company use instant messengers to communicate with their existing and potential customers. Although it is a common knowledge that the improper use of instant messengers can pose a great risk to an enterprise, people still click on the links they receive. The addresser of such messages and links is often an attacker. In the case with our neighboring company there was no happy ending: each employee who clicked on the link leading to a scammer’s website lost her ICQ ID. As the sales department relied greatly on this type of communication with customers, the loss of the company is to be estimated.

In the age of information technologies, each employee – not only IT department staff – should be familiar with how to keep their valuable data safe and secure. To fulfill this task in a proper way one should try to halt hidden security threats, with those lying on the surface, in order to avoid grave consequences and damage for the whole company. Employees’ information security literacy is a job of both IT guys and HR professionals. That is the reason we listed the most wide-spread hidden security threats for you to be aware of.

Lost Laptops, Exposed Data

The mobility of employees is constantly increasing in the modern world, and the rapid growth of the supply of mobile gadgets is rooted in the huge demand for such devices not only for personal use, but for working purposes. However, if your laptop or smartphone, you are accessing your work e-mail inbox or office PC from, falls into the wrong hands, unauthorized users may easily obtain the sensitive data that you've stored there.

One of the ways out is encrypting your data. You can use an encryption program, such as TrueCrypt <http://www.truecrypt.org/>(available for free under open-source licensing), to protect your data from unauthorized access.

Another possibility is to use a recovery service. If your equipment gets lost or stolen, and you can't get it back, you'll at least want to erase the data it holds. Some vendors, such as HP and Dell, offer services that try to do both for selected laptop models.

Weak Passwords

Use stronger passwords: Longer passwords are better; more characters take longer to crack. Keep in mind that the character diversity makes your password significantly harder to guess or crack. The situation will be definitely improved just if one sticks to a simple and widely accepted rule that a password must consist of uppercase and lowercase letters, numbers, preferably, special characters and be at least 9 characters long.

Rogue Wi-Fi Hotspots

Free Wi-Fi networks are available almost everywhere your employees go. Attackers, however, sometimes set up a malicious open Wi-Fi network to lure unsuspecting users into connecting. Once you have connected to a rogue wireless network, the attacker can capture your PC's traffic and gather any sensitive information you send. Verifying the network's name may help in this case.

Weak Wi-Fi Security

If you're cautious, you've already secured your wireless network with a password to keep outsiders from accessing it or using your Internet connection. But password protection alone may not be sufficient.

It’s highly advisable as well to use stronger encryption. Several types of Wi-Fi network encryption are available. WEP (Wired Equivalent Privacy) encryption is the most common variety employed on wireless networks, but it can be easily cracked. The newer encryption types such as WPA (Wi-Fi Protected Access) or its successor, WPA2 resolve the weaknesses of WEP and provide much stronger protection.

Web Snooping

Now that so much entertainment, shopping, and socializing have shifted online, every Internet user leaves a rich digital trail of preferences. The best way out in this case is to use private browsing, which ensures that the site history, form data, searches, passwords, and other details of the current Internet session don't remain in your browser's cache or password manager once you shut the browser down.

Unpatched Software

Microsoft's products have long been favorite targets for malware, but the company has stepped up its game, forcing attackers to seek other weak links in the security chain. One of the most trivial preventive measures in this case is to have all security updates installed, thus keeping your operating system and applications up-to-date.

Each self-respecting company or enterprise should cooperate with IT security departments, for only mutual cooperation can bring evident results.

Elcomsoft is exhibiting at Infosecurity Europe 2010, the No. 1 industry event in Europe held on 27th - 29th April in its new venue Earl's Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk

Courtesy: Eskenzi PR

SANS Institute recommends for more code development practices

Fortify gives thumbs up to SANS Institute-led request for more secure code development practices

Reports that a group of organisations, led by the SANS Institute and Mitre Group, are calling for corporate customers to request more secure code development practices from their software suppliers have been applauded by Fortify Software.

The software security specialists says that Tuesday's announcement (http://bit.ly/dwO19P) by a consortium of more than 30 enterprise customers of software vendors is good news as it give companies the draft text for use in their procurement contracts with vendors.

"Best practice in code development has been under active discussion by the software vendor community for some time, but it's good to hear that the SANS Institute has grasped the bull by the horns, and done something practical about the issue," said Richard Kirk, Fortify's European director.

"Our own observations suggest that a large number of successful hacker attacks are caused, in part, by software flaws, which give the hackers a small chink in an application's armour to prise open," he added.

According to Kirk, by encouraging companies to include suitable language in their procurement contracts, the consortium will hopefully drive the software development industry to adopt the best practices that a number of experts have been calling on for some time.

The Fortify director went on to say that, in his company's March 2009 report – 'Building in security in government software' (http://bit.ly/9f53Ge) – it recommended that the industry should adopt a best practice approach to software code development, building in security from the earliest point in an application's development and to conduct thorough security tests of software prior to acceptance.

The report, which was issued around the time of President's Obama's appointment of a federal chief technology officer, noted that the appointment - in the US at least - was an opportunity for government to adopt these best practices across the board.

It was interesting, said Kirk, to read that former White House security advisor Howard Schmidt - and president of the Information Security Forum - commenting that, despite its excellent goals, the US Federal Information Security Management Act (FISMA) has not managed to solve the software development industry's security problems (http://bit.ly/c0phgR).

"But, as Fortify's founder and chief scientist Brian Chess also said at the time, if FISMA has done nothing else, it has helped to identify the problem," he explained.

It's against this backdrop that Fortify is pleased to add its support to the SANS Institute-led call for more secure program code development, and the introduction of best practices in the application development industry.

"Changes of this type aren't going to happen overnight, as software vendors will have to engender new working practices in their code development operations," he said.

"However, if their clients start mandating the use of best practices in their commercial agreements - through the use of the correct language in procurement contracts - then that is something we can wholly support," he added.

For more on Fortify Software: http://www.fortify.com

Source: Eskenzi PR