Exciting news for us and pleased to announce the acquisition of BitArmor by Trustwave! The press release is here..
Quick FYI - Trustwave is a leader in delivering compliance and security solutions for thousands of large and small customers across the globe. The have a great story about PCI as well. Great to be part of an awesome company!
We believe this is an absolute perfect fit with our vision of information-centric security, our Smart Tag technology and how Trustwave sees the world of security and compliance.
Will post more in a few days.. Lots to do so gotta run!
Tuesday, January 12, 2010
BitArmor acquired by Trustwave!
Posted by
Manu Namboodiri
at
11:54 AM
0
comments
Labels: information-centric, PCI
Wednesday, December 9, 2009
New Cisco report on state of security
Cisco has just released their annual state of security report - the Cisco Annual Security Report. It mentions the normal stuff that you hear - more malware, 40% more spam in 2010, more banking trojans etc. Scary stuff, no doubt. Read more about it here.
But the stuff that worries me is what is missing (or not highlighted) in the report - i.e. data security in the enterprise. While I, being also a consumer, appreciate the issues pointed out here, the data breached from enterprises also causes significant pain.
Trojans, malware, viruses will always be around and I think we have to expect this going forward. How do we ensure that these get relegated to just annoyances and not become a security threat? This is where an information-centric approach works best - once the data is protected, only the right user opening up the document with the right application can decrypt it. The malware thus cannot access protected data since it does not have the right permissions. This might reduce the impact of much of today's malware - at least for enterprise data.
For transactional consumer data (i.e. credit card information submitted during a web session etc), we have to think of other but similar techniques...
Posted by
Manu Namboodiri
at
12:02 PM
0
comments
Labels: information-centric, Securing data
Thursday, October 8, 2009
Hannaford case reversal
Some interesting developments for those who have been following the rulings in the Hannaford breach case - the judge had ruled that since cardholders were not affected economically because credit cards were stolen (banks will cover any losses to cardholders), they dont have a civil case against Hannaford.
However, the judge recently reversed himself and asked the Maine supreme court whether "inconvenience" that the cardholders went through should be compensated... Interesting fork and one that could have strong impact to the retailers if the Maine Supreme Court indeed thinks so..
The bottom line is whether retailers should take more care of data entrusted to them - while the judge had a very narrow view of "loss" to the consumer, the defense believes that they have a shot in making cardholder rights heard...
Should be interesting to see the developments..
Posted by
Manu Namboodiri
at
7:53 AM
0
comments
Labels: data breach law, Fines
Monday, October 5, 2009
One million dollars!
As an award that is... Express Scripts has reportedly put up $1M to anyone who can provide information leading to the arrest of those responsible. Apparently the thieves wanted to get the most from the stolen data - sell it to the highest bidder or extort Express Scripts to keep it safe!
Looks like extortion is the new black- from talk show hosts to stolen data! Be interesting to see where this takes the industry. But my question is - is this extortion because the criminals do not have a market demand for the stolen data? If it has a ready market, why bother with extortion?
Posted by
Manu Namboodiri
at
8:07 AM
0
comments
Labels: data breaches
Thursday, October 1, 2009
Josh Corman at IANS
Just attended an interesting keynote by Josh Corman at the IANS event in Boston this morning. Very though-provoking stuff - he also has an article about it in CIO magazine.
Being a good marketer, Josh trimmed down the 8 secrets to 7 (but wait!, one was free and he counted from zero, so we are back to 8 :)). I had previously discussed one of his takes in this blog.
The interesting part about listening to the discussion live, is Josh's emphasis on risk. He believes that we as security professionals have been so caught up with managing around compliance mandates, we have not stepped back to think about what risk we are mitigating.
Excellent point - especially when it relates to projects on hand. Would you do disk encryption based on the knowledge that 31% of all breach incidents are the result of lost and stolen laptops? Of course you would. However, would you rethink your decision if you also know that these lost laptops account for only 9% of all data lost? Hmmm does FDE only reduce risk by 9%?
That begs the question, what else reduces risk by a larger percentage? Interesting topic and subject for another post....
Posted by
Manu Namboodiri
at
10:16 AM
0
comments
Labels: data breaches, FDE
Tuesday, September 29, 2009
Virtualization and PCI standard - can we do better?
The wheels are turning for another version of the PCI standard. And this time virtualization security is a big focus in the development of the standard. Commendable, I say. Virtualization will become a bigger deal (more than it is today) and almost all organizations will have some form of virtual environments setup.
However, are we prone to repeat the same mistakes? We still seem to be stuck in the legacy world of protecting infrastructure - security professionals have no time to look beyond the normal, staple, security diet of anti-malware, IDS/IPS, firewalls etc, to where the more active threats are.
How do we bring the security world (as well as the business world) forward to rethink how to enable secure business? I have strong opinions on this - I believe an information-centric security approach is vital and imperative in virtualized environments. In fact, I can go so far as to say that this is the only logical and enforceable method, that enables virtualization to be all-it-can-be - so that business can be all it can be!
Let not PCI be a reflection of the past threats - let it become what we need now and prepare us for the future. This is the only way it can stay relevant and useful.
Posted by
Manu Namboodiri
at
11:12 AM
0
comments
Labels: PCI, virtualization security
Friday, September 18, 2009
Gartner - Pay now or pay (a lot) later!
Read a few weeks ago a very interesting (and perhaps one of the few) analyst reports that analyze the costs of a fixing a breach as compared to prevention. Check it out here..
The basic premise of Gartner analyst, John Girard, is that the costs of prevention are insignificant compared to the costs of cleanup - less than 2%! How can management of any organization look at this and say that "let's cross our collective fingers" and hope for the best?
Data protection if done correctly, does not have to be expensive. I just read this article based on a survey that said most organizations in MA feel that the costs of data security are hurting firms. While I agree there is an investment to be made. the costs of cleanup are far higher. In fact a recent Ponemon report showed that over 60% of organizations have had breaches in the last 12 months - what this means is any organization has a 60+% chance of a breach!
Any organization should at least start protecting its most vulnerable assets - data in vulnerable locations. Be it on mobile devices such as laptops, USB devices or on file shares.
These costs are minimal compared to the costs of payment later...
Posted by
Manu Namboodiri
at
10:15 AM
0
comments
Labels: data breaches, Fines, surveys
Tuesday, September 15, 2009
SB-20: A California refresh!
The updated California breach law, SB-20, is finally on the Governator's table. It has been a while coming and is most interesting since it finesses the grand-daddy of all breach laws, SB-1386. For more information, check out Ariel Silverstone's blog. There is a very good analysis of the new law.
I like the use of the work "unencrypted" in the new law - implies that even if data was encrypted but the keys were lying around, you cant claim immunity :) Contrast this language with something like "plain" or "open"...
I think this is a good step forward, especially around the notification, use of plain language etc. I would have liked it to be more focused on remedies and "get-out-of-jail" by using encryption (the MA law is one such).
Posted by
Manu Namboodiri
at
11:15 AM
0
comments
Labels: data breach law
Friday, September 11, 2009
My black-market value? 32 bucks
Interesting tool that Symantec has unveiled - an online risk calculator that figures out how much your identity could be auctioned off for! Apparently I am cheap and can be had for $32.29 - no idea how they got the accuracy down to 29 cents!
Without going into the merits of the calculator (and the random number generator behind it :)), I think it is an interesting thought. While a criminal might not be targeting you specifically, breaching and then auctioning off thousands of such records can make someone some pretty good coin.
It is also likely that the guys who breach have their specialty - getting the records. It is upto the buyer now to steal the actual cash from the accounts or credit cards that have been turned over! Specialization and job segmentation at its best!!
Posted by
Manu Namboodiri
at
12:56 PM
1 comments
Labels: data breaches
Saturday, September 5, 2009
Virtualization security compliance guidelines - quite off base!
I don't know if it is a challenge with today's compliance rules or how folks perceive virtualization security, but the recent guidelines published by VMware and RSA seemed to have missed the mark. I don't want to add the word "completely", but I do think they are quite off base.
Not to say they dont have some good things in there, like platform hardening, network segmentation, change management, admin access control etc.. But this is something one would be doing for non-virtual environments as well - not much different here, just common sense.
A reason for missing the mark is the non-focus on virtualizaiton itself. Virtual environments are different. I think they need some fundamental rethinking of security, including focus on statelessness, shorter session-lifetimes and a true focus on data.
What fills me with a sense of incompleteness from these guidelines is the total non-focus on data! C'mon what are we trying to protect here? It's the data!! And nary a single mention?
Posted by
Manu Namboodiri
at
8:02 AM
0
comments
Thursday, September 3, 2009
WhoHooo! BitArmor recognized in the latest Magic Quadrant!
Apologize for getting a bit excited - BitArmor is named in the 2009 Gartner Magic Quadrant for Mobile Data Protection! The full report can be read from the Gartner website. Our release about this recognition can be read from our website.
In this blog, I usually talk about my thoughts on the industry, evolution of security etc and I don't blog much about our product and the company. However, this I do think is a good excuse to do so :) It is good to be recognized by leading security analysts as John Girard and Eric Ouellet!
The report highlights our unique information-centric security approach to protecting data. It also talks about our No-Breach Guarantee. And one phrase I like is "far advanced" - as a way to describe our technology. Nice!
Being information-centric in our approach to data protection makes us a bit different from the other vendors in the document - most of them protect mobile devices. Because of our Smart Tag technology, BitArmor is able to protect the data itself at all times - thus the protected data can move to a laptop, USB device, via email as attachments or via FTP. It can also move from a file share to a data center server to a backup tape and still remain protected. From this perspective, we are truly fulfilling the real "Mobile Data Protection". I think the naming of this Magic Quadrant report is a bit ahead of its times!
However, as it stands now, most people associate data protection with "mobile devices" - i.e. protecting the devices that the data rests on (laptops, USBs, phones etc). And possibly for good reason - there were no good enough or usable enough technologies that could truly protect the data itself and that too persistently. Until now, of course!
I do think the Mobile Data Protection Magic quadrant will evolve more towards a data or information-centric approach in the coming years. Looking forward to our footprint trending, nay jumping, up and to the right!
Posted by
Manu Namboodiri
at
8:20 AM
0
comments
Labels: encryption, FDE, information-centric
Wednesday, September 2, 2009
Another case for information-centric security
The more I read about how criminals are breaching the perimeter and getting access to sensitive data in an organization, the more I am convinced an information-centirc approach is the only way to go.
Case in point is the recent article from Information Week - 5 Security Lessons from Real World Breaches. Fun stuff!! Here is a short excerpt from one attack the article describes - the conclusion..
"...The attackers used the compromised server as their home base. They deployed tools and scanners and spent several months meticulously mapping the network without being detected. Once they found the systems that contained the data that they were looking for, they simply copied the information, put it into a Zip file, and moved it out."
Emphasis above is mine - basically compromised a server and then copied data out. This data-at-rest protection being perceived as the end-all, is making me frustrated. If this data were protected using an information-centric approach - i.e. protect the data and keep it protected at all times (at rest and in motion), this would have been much harder. All the criminals would have gotten is encrypted data.
I am also looking at the 5 guidelines/conclusions from the report and besides a short mention of layered security and isolation, there is not much emphasis on data protection. I think the authors are missing the point. You can never have enough perimeter security - IDF/IPF, anti-malware works only to a certain extent.
You need to recognize that data is the critical asset,not the network or the server. Protect the data, damn it!!
Posted by
Manu Namboodiri
at
12:29 PM
0
comments
Labels: information-centric
New HIPAA breach laws taking effect
More rules and more rules... The HHS has issued final guidelines on breach notification requirements for organizations under the HIPAA law. They take effect Sept 23rd... Just in time for the G20 summit?
Maybe not. However, the reality is that organizations are having to now deal with a bevy of such requirements and the bigger problem is not in complying with basic standards, but ensuring the lowest common denominator (or in this case the strictest rules) are being met...
Posted by
Manu Namboodiri
at
11:53 AM
0
comments
Labels: data breach law, patient records
Saturday, August 29, 2009
Encrypted is not a boolean variable
Posted by
Tim Hollebeek
at
9:19 PM
1 comments
Friday, August 28, 2009
Bernanke hit by ID breach
Did the thief think he could cash into the billions that the Fed chief oversees :) Or maybe he was looking for a bailout himself!
Will this put some fire under the administration to think seriously about national laws for breach? Always seems to happen when something hits close to home and personally...
Interesting news, nontheless...
Posted by
Manu Namboodiri
at
11:06 AM
0
comments
Labels: data breaches, Data Privacy
Monday, August 24, 2009
Dirty secrets and the non-existent perimeter
The perimeter is dead - long live the perimeter (the new perimeter, that is). Which obviously is the data.
I am also intrigued by an article by Joshua Corman from IBM, in CIO magazine, that discusses this. Check out Dirty Secret #3. "There is no perimeter". I love it. Mostly because it is true. And for some small selfish reasons as well... :)
Here is what he says - very eloquently, I might add..
"We need to define what the perimeter is," he said. "The endpoint is the perimeter, the user is the perimeter. It's more likely that the business process is the perimeter, or the information itself is the perimeter, too. If you design your security controls with no base assumption of a perimeter, when you have one you are more secure. The mistake we tend to make is, if we put the controls at the perimeter, then we will be fine. For many threats, we couldn't be more wrong."
The bold emphasis above in mine - and not from Joshua. But I do it to illustrate my point (which I put forth in a recent blog on the benefits of an information-centric security approach as well). Security professionals need to move beyond the perimeter and thinking that has dominated for the past 30-40 years and recognize the world is different now.
For heaven's sake, the internet that allows for rapid dissemination of data and collaboration is already a teenager! Why do we still protect this environment with stuff built for the 70's?
Posted by
Manu Namboodiri
at
11:27 AM
0
comments
Labels: information-centric
Sunday, August 23, 2009
Benefits of information-centric security
For a while I have been meaning to write a short article on what I think information-centric security is - so here goes.
Organizations have focused on securing sensitive data by protecting the infrastructure that hosts the data. This could be implemented by hosting the servers inside a data center, using firewalls and similar perimeter protection techniques to prevent external attackers, encrypting whole drives or encrypting networks. I think of these as protecting data by proxy - i.e. protect the network to protect the data, protect the perimeter to protect the data, protect the device to protect the data.
Information-centric security is the concept of focusing the protection on the data itself as opposed to the device – protection that stays with the data while at rest and while in motion. Access controls and other policies are embedded in data and follow it wherever it goes - thus enforcing these policies at the data level, regardless of where the data is.
This approach has several advantages:
- Continuous protection: Data always remains protected since it does not get decrypted as it moves - this has performance benefits as well as security benefits
- Device independence: Data can be protected regardless of the devices it rests on or travels between. For eg, it data moves to a USB device, to a backup tape, it still remains protected. No need to deploy a USB protection solution or a backup tape solution separately.
- Enabling secure collaboration: Since the data remains persistently protected, you can share it better - the proper access controls of who can access the data remain with the data itself! Therefore data can be self-defending. No need to provide access to networks, file shares etc to share data.
- Lower costs and complexity: all this comes down to much lower costs and complexity - no need to have multiple device or network centric products protecting data and that too by proxy..
Posted by
Manu Namboodiri
at
1:46 PM
0
comments
Labels: information-centric
Tuesday, August 18, 2009
The same TJX hacker?
How many more breaches were perpetrated by Albert Gonzalez? According to new charges, he is saddled with TJX (from before) and now with Heartland as well as Hannaford! The guy has been busy, no doubt.
What was it that made these breaches similar? And what did we not learn from the first ones that we let Albert and gang do it again and again? Obviously there are many theories - but my view is, at the end of the day, infrastructure protection can get you only so far.
We need an information-centric approach to protection where the focus is not on the pathways, perimeters and devices, but on the data itself. Imagine if this were the case in the above breaches, where data was stripped of networks, or from servers. If that data were protected at rest and in flight, it would not have mattered if the data were copied outside the company - it is protected! It remains encrypted!
Better, more logical and more effective security. But seems like folks are still in the rush of "protect the infrastructure"...
Posted by
Manu Namboodiri
at
1:19 PM
0
comments
Labels: data breaches, information-centric
Thursday, July 30, 2009
Persistent, information-centric protection, PCI and the Network Solutions breach
The more news I see regarding various breaches, the more I am convinced of the superiority of persistent and information-centric security. For example, take the latest breach at Network Solutions - a PCI compliant organization. Over half a million cards stolen.
Comments galore:
Here is what they say "The company determined that the unauthorized code may have been used by cybercriminals to capture transaction data, including customer names, addresses, and credit card numbers, and transfer it to servers outside of the company...."
Now look at the statements below from industry experts:
"...many enterprises are behind in security protection efforts such as anti-virus updates due to shrinking IT budgets, which results in unpatched vulnerabilities that are easily exploited"
Seems like anti-virus and unpatched systems are the main culprit - long live infrastructure protection!
"...the incident illustrates the risks of cloud computing."
A broad general statement - not clear what the implication is :)
The point:
My point is that the industry is so wrapped around protecting the infrastructure - i.e. protecting dat aby proxy, that they forget what it is they are really trying to protect. With an information-centric security solution, the credit card data would be protected persistently. Even if the data were to be "..transferred over to servers outside the company..", it would still remain encrypted thus making it much harder for criminal organizations to obtain any value from the data.
The last and best line of defense is the data - this is how layered security should be.
Posted by
Manu Namboodiri
at
9:39 AM
0
comments
Labels: data breaches, information-centric
Friday, July 24, 2009
Where does a £3M fine hurt?
Not sure, but we will know. Regulatory bodies are becoming increasingly tough on lax organizations for not protecting sensitive data - HSBC was recently fined £3M for not adequately protecting customer records.
The interesting part to notice is the fine was applied even though no customer had an unfortunate incident after the breach - I presume like a lost identity, stolen money from their bank etc.
And even more interesting was that HSBC got a 30% discount for cooperating :). Good boy!
Posted by
Manu Namboodiri
at
10:54 AM
0
comments
Labels: data breaches, Fines