Author Archives: Steve Addison

URL Shortening as a Security Threat?

http

Most of us are familiar with URL shortening websites such as bit.ly, tinyurl.com, and is.gd. It’s one of the technologies that’s fuelling the explosive growth of social networks such as Twitter – after all, 140 characters isn’t a lot of … Continue reading

Posted in Information Security | Leave a comment

Shopping Tips from the FBI

holiday2009

Following my post about McAfee’s 12 Scams of Christmas, here’s some safe shopping advice from the FBI. Good source material for a seasonal security awareness message to your staff.

Posted in Information Security | Leave a comment

Scanners and Shared Drives

scanner2

Along the same lines as my recent post on photocopiers and information security, a friend of mine tells me that, in his organization: … we have a major issue with people leaving scanned expenses on a shared drive. It’s great … Continue reading

Posted in Information Security | Leave a comment

Sometimes the Medium Can Be the Message

bw

An article in a recent issue of Business Week highlighted security issues with software produced by Adobe – especially Adobe Reader which is widely used in small and large organizations. The article quotes Kapersky researcher Roel Schouwenberg saying “Adobe at … Continue reading

Posted in Information Security | 1 Comment

FBI Warning – Hackers Targeting Law Firms and PR Companies

email2

The Washington Post talks about a recent FBI warning that hackers are increasingly attacking law firms and PR companies using spear-phishing emails. These emails – previously used against military and defense targets – contain hyperlinks or file attachments which launch … Continue reading

Posted in Information Security | Leave a comment

The 12 Scams of Christmas

holiday2009

Plenty of people are blogging, tweeting and quoting this article from McAfee posted on CNET, and justifiably so – it’s well-timed and contains pertinent information. If you’re involved in an ongoing process of security awareness training, consider including these topics … Continue reading

Posted in Information Security | Leave a comment

Photocopiers and Information Security

copier

Are you covering the security risks of photocopiers (and multi-function machines) in your security awareness training? A recent news report from WINK-TV in Fort Myers, FL, has reminded us that the humble photocopier can be a security threat. Or perhaps … Continue reading

Posted in Information Security | Leave a comment

Cost of a Careless Mouse Click – $195,000

money

The Washington Post is reporting that the American Realty company lost $195,000 when an employee clicked on a link in an email that purported to be from the IRS. The link then installed a Trojan Horse which stole passwords that … Continue reading

Posted in Information Security | Leave a comment

Call Centers Not Erasing Credit Card Data from Audio Recordings

creditcards2

Call centers routinely record calls for quality control and training purposes. In a recent survey by Veritape reported in The Register, 95% of the call centers surveyed were found to be storing credit card data such as the three-digit verification … Continue reading

Posted in Information Security | Leave a comment

A Reminder About Availability

sidekicks

When we talk to end users about security, we usually focus on the confidentiality part of the CIA triad – probably because it’s the most visible part of information security. But, every now and then, there’s a news item that … Continue reading

Posted in Information Security | Leave a comment