Showing posts with label devices. Show all posts
Showing posts with label devices. Show all posts

Tuesday, November 10, 2015

Hospital Held Hostage

  A number of people alerted me that a recent episode of CSI:Cyber, which aired on 11/1/15, had as its theme a cyber attack on a hospital.  The episode was entitled "hack E.R." (see what they did there??? :-) )

   The episode begins with an ominous image showing up on computer screens and all systems in a fictional hospital being under the control of an online attacker.  They threaten to kill a victim every four hours if not paid a ransom.  They then kill a victim by causing an infusion pump to deliver a fatal dose of morphine while preventing the patient's heart monitor from alarming.

   We then follow the CSI:Cyber team and the hospital staff as they try to solve the mystery and track down and stop the attacker.  I won't give a full synopsis nor a review.  You can find some of that here and here (spoiler alert - these linked articles do give away the ending).

   Let's review what was potentially real and some of the deficiencies of the episode.  First the realistic.

Tuesday, July 22, 2014

Beach to Breach - It's not just for work data!

   I heard a great term recently... Beach to Breach.  SC Magazine did an article about a Sourcfire study on employees bringing their portable devices on vacation.  They found that 77% of employees bring their devices with them on vacation to keep in touch with work and that 97% of the use is email.

   Hopefully you can see some of the security problems right away... the devices have a good chance of getting lost or stolen when one is out of their "element"; plenty of opportunities to connect to unknown networks; potential to use hotel printers; possible "incentive" to bypass controls to see that one "important" message, and of course; sand in our devices!

   Organizations certainly should be concerned about the potential for breach of data or loss of equipment.  But what about the rest of us?  Should we take extra precautions with our personal devices and information when out of town?... Definitely!

Tuesday, May 21, 2013

The Business (not Blind) Side

   A Doctor, Lawyer, Salesperson and Systems Adminstrator walk into a bar...

   As I mentioned last week, the Secure360 conference was in town.  And as always, it was a great show.  I was pretty busy and had 3 different talks.  The first was a 4 hour pre-conference session on BYOD. (slides here)

   After talking about the history of portable devices and framing the issues with which organizations struggle, we did something a bit different.

Tuesday, December 25, 2012

A Few of My Favorite Things - Apps

   I recently (finally) got modern smartphone.  My previous phone was the "free" phone from over 2 years ago.  Even when I had a basic smartphone I very quickly found useful apps that used everyday.

   Someone was recently asking me what apps I use on my phone.  I thought it would be useful to make a list of some of my favorites here and focus on those that I use most.

Tuesday, December 4, 2012

Keeping Up and Podcasts

   Recently I was talking with a colleague about keeping up with information. We actually were comparing smartphones. During the conversation we talked about podcasts and podcatching software. I'll talk about what I use below.
   We are talking about what podcasts we listen to.  One thing that was surprised me was that he mentioned that many technical people he interacts with don't listen to podcasts! I found that surprising. I figured most technical and security people know all about podcasts. Podcasts are hardly new.
   There are podcasts for all kinds of subjects. I listen to podcasts about security, technology, sports, news, science, leadership, getting things done/productivity and other subjects.
   I think that listening to podcasts is one of the best ways to both learn and keep up.

Tuesday, September 11, 2012

Mobility not just Mobile

   Yesterday I gave a talk at CSO Magazine's The Security Standard conference in NY.  There was a great group of attendees and the conference has been excellent.  My talk was on the Embracing the IT Consumerization Imperative.  You can view the slides on the conference site or my slideshare site.

   One of the important points I made, and a frequent theme for me, is the need for alignment between business and security and IT.  It's too easy for those of us in the technology space to get caught up with the devices, toys and tech solutions.  We too often get disconnected from the business need.  Security and IT groups exist to service the business.  Business drives security; business drives IT... not the other way around.