Articles
Featured
Retailers everywhere are developing mobile applications to interact socially, send coupons, disburse advertisements and increase sales. As mobile access and applications grow, however, so do the security challenges. So, how do you keep the bad guys out while still being innovative and keeping up with the latest technologies? This white paper outlines the top 10 must-know tips for deploying secure mobile applications.
Advanced Persistent Threats (APT) are a serious concern in the today’s threat landscape. They represent a threat to an organization’s intellectual property, financial assets and reputation. The defensive tools, procedures and other controls commonly put in place to handle commodity security threats are often ineffective against targeted APT-style attacks.
Managing information security is one of the most challenging and important issues facing hospitals and other healthcare organizations today. But in the barrage of priorities, it often takes second place to other issues such as budget concerns and patient care initiatives.
Forrester has released its March 2012 Wave report on managed security service providers, reporting on nine companies that are rated as Leaders or Strong Performers. Forrester researched, analyzed and scored the providers on 60 criteria, with a goal of helping security, risk and IT professionals select the right partner for their managed security services.
Across the US and the UK, adoption of the Payment Card Industry or PCI compliance requirements is slowly gaining momentum. However, many organizations are finding that they are not prepared for their next round of assessments, despite having successfully met PCI requirements previously, as demonstrated by a Report on Compliance (ROC) or Self-Assessment Questionnaire (SAQ). This paper outlines the challenges of maintaining compliance, and three important steps merchants can take to successfully address them.
Are you waving the white flag? Has your SIEM failed to meet expectations despite your significant investment? If you are questioning whether your existing SIEM can get the job done, you are not alone. Given the rapid evolution of SIEM/Log Management offerings – and the evolution of requirements with new application models and cloud – you should be wondering whether a better, easier, less expensive solution can meet your needs. This white paper from security analyst firm Securosis takes a candid look at the reasons to consider a new security management platform and best practices for doing so.
The retail landscape is changing faster and more dramatically than ever before. At the same time, retailers face an ever-growing threat of losses through attacks against point-of-sale systems, mobile devices and computers by criminals trying to steal payment card data and customer information. This paper outlines the problems retailers face and why it is a target, and provides practical recommendations on what they can do to address these challenges.
Maintaining adequate data security is challenging for investment firms and banks, which must grapple with a widening array of security and regulatory issues. With attacks leading to losses in the hundreds of millions of dollars, many financial firms are seeking — and finding — help in the battle against online crime. This paper outlines the threats facing banks, credit unions, and other financial institutions, and what they can do to address them.
Dell SecureWorks has been positioned in the Leaders quadrant of Gartner's newly released Magic Quadrant for MSSPs, North America, 2011. The Gartner Magic Quadrant is a graphical portrayal of vendor performance in a market segment, including categories for leaders, challengers, visionaries and niche players. Criteria by which the vendors are measured include a company’s completeness of vision and ability to execute.
If you are evaluating how to meet an information security or compliance need, and want to be sure the investment will pay off for your organization, having credible information from a trusted authority is invaluable. This case study will help you. Read a commissioned study conducted by Forrester Consulting, “The Total Economic Impact of Dell SecureWorks Managed Security Services.” (Study published Nov. 2011)
As mobile device usage in healthcare organizations and clinical settings has proliferated, risks and breaches have followed. This paper outlines how mobile devices are used today in healthcare and where the investments in this technology are heading. The paper also outlines what the common specific risks and breach repercussions are in using mobile devices, and how to mitigate these risks using four key tactics.
This paper outlines the federal Meaningful Use data security requirement, the penalties and incentives associated with Meaningful Use, and elements to create a successful strategy for developing a strong security posture. Also detailed is the importance of fitting a security risk analysis into the larger picture of maintaining HIPAA compliance.
Security concerns in healthcare have compounded as more providers move online due to increasing incentives and penalties in a complex regulatory environment where enforcement is encroaching. Concurrent with this trend, though, major breaches continue to occur, and are likely accelerating. Healthcare companies need to have a sound strategy in place for addressing these concerns, and a well-rounded understanding of the risk they are individually tasked with managing. This article explains some of these trends, outlines the risks involved, and offers potential solutions to reduce risk in an increasingly complex healthcare data environment.
Security is the major concern for companies that are considering moving their data and business processes to the cloud. To have sound security in the cloud, companies need to enforce precise access management controls and practice very disciplined, rigorous cloud vendor management. This paper offers 10 tips that businesses should implement in order to reduce the security risks in the cloud.
According to Dell SecureWorks' data, hacker attacks targeting its retail customers increased 43 percent between the last nine months of 2010 and the first nine months of 2011. From January through September 2011, SecureWorks blocked an average of 91,500 attacks per retail customer, as compared to 63,581 attacks per retail customer April through December 2010.
Small and mid-sized businesses are losing as much as $1 billion per year to cybercrime by some estimates, and SMBs are finding it more and more challenging to protect themselves. SMBs need to have comprehensive endpoint security in place as well as sound network security. This paper lists 8 simple steps that your organization can take to help protect financial data and minimize the risk.
This Tech Republic guide to SMB security is designed for small and mid-sized business owners and managers. It explains how you can defend your business against attack and theft across the digital domain, how you can set up layers of protection and how to protect your bottom line from both external and internal threats.
Today’s smartphones and tablets represent the easiest means for a hacker to gain access to your corporate network. Protecting these devices is much more difficult since they have fewer API’s and lack an operating system as robust as Windows or Linux. Organized crime is focusing on smartphones because it’s much easier to get the data they want. This paper describes the 10 most common smartphone threats and offers high level best practice suggestions for mitigating the risk.
We have recently released a white paper on firewall management which defines five focus areas that are keys to an effective firewall defense. The five areas were defined by our security operations team, based on real-life experience and cases. Each is illustrated with a specific, real-life example. Following the five recommendations in this report can save you time, money and administrative headaches. Download the report today.
Cyber attacks on law firms are growing and 46 states have enacted or are considering data breach notification legislation that can have costly consequences for law firms. Those are just two reasons why it is critical for law firms to stay current on info security threats and potential solutions.
More than 40 million U.S. consumers will be using mobile banking by 2012, The Tower Group research firm predicts. Protecting confidential data on mobile devices presents a number of special challenges. For example, most mobile devices do not delete data in the same way that laptop computers do, increasing the risk that someone could access confidential data if it is not properly encrypted. This brief white paper provides six key guidelines for developing and maintaining secure mobile banking apps.
In the confidentiality, integrity, and availability metrics of information security, also known as the CIA Triad, denial-of-service (DoS) attacks impact availability. In a broad context, the term 'denial-of-service' has a general definition covering many types of attacks.
Security Information Management(SIM) can be a very valuable tool for any organization. There is work to be put in with this solution though, and there are some pitfalls as well.
If you are a manager responsible for information security, it is likely that you constantly look for the most cost-effective ways to secure your organization. In most cases, that includes periodically evaluating “doing security in-house” vs. working with a managed security provider.
This new white paper --- based on a survey of 150 info security and IT professionals --- may help you if you are thinking about that question.
Dell SecureWorks has been positioned in the Leaders quadrant of Gartner's newly released Magic Quadrant for MSSPs, North America, 2010. Dell SecureWorks is a leading provider of world-class information security services with more than 2,900 clients worldwide. Organizations of all sizes, including more than fifteen percent of the Fortune 500, rely on Dell SecureWorks to protect their assets, support compliance and reduce costs.
This white paper from SANS, written by analyst David Hoelzer, reviews the new PCI DSS 2.0 requirements published in October 2010. It discusses what's new and what still needs more attention in the PCI DSS, including gaps in storage encryption, wireless networking and other issues.
What questions should you ask when choosing a QSA for a PCI compliance assessment? For many organizations, keeping costs low is their top priority--but that can be a risky strategy. This white paper written by SANS analyst Dave Shackleford reviews the five critical questions you should ask when choosing a QSA. Making the right choice can have a long lasting
This paper provides an executive-level primer on cybercrime by covering key profiles of cyber criminals, their methods and their motivations. After reading this Executive Brief, you will have a better understanding of the cybercrime threat.
Additional Articles, White Papers and Podcast