Data breach notification legislation before Australia's parliament, if enacted, would add new dimensions to its privacy laws, perhaps influencing lawmakers elsewhere, privacy lawyer Françoise Gilbert says.
The information security industry needs to hit rock bottom, says Akamai's Joshua Corman. And then - to truly improve information risk management - it needs to develop a new, adversarial view of the world.
In the face of advanced threats, organizations need to shift their security posture from breach prevention to incident response, says Tom Cross of Lancope, who discusses new strategies.
Having the right log and access management tools in place - and not all tools are used by all agencies at all times - doesn't mean that the proper authorities are alerted in a timely manner to activities that could jeopardize the nation's security.
What is one of the most common mistakes organizations make when they uncover a data breach? Brian Laing of AhnLab tells how a seemingly innocent response often leads to costly consequences.
Regulations initially cause organizations to spend more funds on data breaches, but eventually those rules could save enterprises money, the Ponemon Institute's Larry Ponemon says in analyzing his latest study on breach costs.
On average, 86 percent of web applications have at least one serious vulnerability, and each app is attacked about 4,000 times per year, says Imperva's Terry Ray. So, how must security be improved?
Operating in a cloud environment opens up organizations to a new dimension of insider threat problems, says Alex Nicoll of Carnegie Mellon University's CERT Insider Threat Center.
Defacement and downtime are two consequences for organizations struck by distributed-denial-of-service attacks. But what's the brand impact? Akamai's Fran Trentley discusses risks and mitigation.
Collecting massive amounts of data on individuals, whether in the government or private sector, has become the norm in our society. It's not quite Orwellian, but it's a situation we might have to learn to live with.
As they develop mitigation strategies, organizations must keep in mind that all cyber-attacks, ranging from DDoS to phishing, ultimately aim to compromise data - and they virtually all are advanced and persistent.
Collaboration among public and private entities is a tough sell in any marketplace. But in Asia, the challenges are unique. Here are examples of how Asian entities are fostering information sharing.
Only a cockeyed optimist would expect the outcome of this weekend's summit between President Obama and Chinese President Xi Jinping to be a halt to Chinese cyber-attacks on U.S. computers.
What can be done to mitigate the new spear-phishing campaigns that are localized, direct and capable of slipping past most spam filters? Two security experts offer timely insights.
Since 2010, hackers from abroad have repeatedly breached Department of Veterans Affairs computers containing unencrypted data on some 20 million veterans, according to U.S. Rep. Michael Coffman.
Our website uses cookies. Cookies enable us to provide the best experience possible and help us understand how visitors use our website. By browsing inforisktoday.asia, you agree to our use of cookies.