Categories: Newsletter

Networking Monitoring News – Mar 2016

Encryption

We have seen an interesting turn of events in the Government’s stance on encryption. Lawmakers are stating that security is only possible if they have access to encryption keys and have backdoor access to operating systems. Edward Snowden’s revelations led us to make sure systems are encrypted and locked down, now we are being told the Government must have access to our systems. Unfortunately, there is no right answer to this problem.

Strictly from a security perspective, if there is a backdoor in our cellphones and computer systems someone will find and exploit it. What the Government is asking us to do is allow a security hole to remain open on all devices.

Amazon announced March 3, 2016 that it has removed device encryption on its tablets as of Fire OS version 5. Many of us conduct business on our devices, without encryption, what happens if we lose a device?

Those evaluating security for their enterprise should be mindful of lawmakers efforts to add backdoors and remove encryption.

Patching Software

Patching software is still a big problem. It appears on a whole, we have not learned how to safe guard our systems. The most exploited bug in 2014 was also the most exploited bug in 2015. Sadly, this bug is over 5 years old now. We all know that applying patches is not trivial in an enterprise environment. It can be a costly process especially if patching results in a broken system. Breaking things! This was the main excuse given when asked why systems are left vulnerable. A good patch testing process will help find any issues before it is rolled into production.

Keeping software up to date on all machines will make it a lot harder for the bad guys to gain access. A well patched environment with good Network Security Monitoring will take you very far down the road to security.

Ron Samson

Share
Published by
Ron Samson

Recent Posts

SIEM Management Services: When Log Collection Becomes Too Expensive to Operate Internally

Turn SIEM logs into faster response with managed SOC services—optimize telemetry, tune detections and gain…

2 weeks ago

Cloud Security Monitoring for AWS and Azure: What Your MSSP Should Actually Watch

Detect AWS and Azure identity abuse before it becomes a breach. Learn the signals, log…

57 years ago

Security Operations Metrics That Matter: KPIs for Risk Reduction, Response Speed, and Executive Reporting

Prove security risk reduction with KPIs for exposure aging, critical asset coverage, detection quality, and…

57 years ago

Microsoft 365 Security Monitoring: What SMBs Miss After Basic Configuration

Catch MFA and OAuth abuse in Microsoft 365 before attackers create forwarding rules or steal…

57 years ago

Managed Vulnerability Management: How to Turn Scanner Findings Into Remediation That Reduces Risk

Reduce measurable exposure with managed vulnerability management: validate findings, prioritize exploitable risk, verify fixes, and…

3 weeks ago

Co-Managed Security Operations: How Internal IT Teams Can Keep Control While Gaining 24/7 Coverage

Gain 24/7 security coverage without losing control. Learn how co-managed operations cut alert fatigue, share…

57 years ago