Disclaimer: The opinions of the columnists are their own and not necessarily those of their employer.

The New Identity Theft Red Flags Rule: Does it Raise “Red Flags” for Information Security?

– On May 10, 2006, President Bush signed an Executive Order creating the nation’s “first ever” Identity Theft Task Force.  The purpose of this ad hoc committee, chaired jointly by the Attorney General and by the Chair of the Federal Trade Commission (FTC), was “to help law…

Forget The IT Security Strategy, Just Get R Done!

– In recessionary times, how many organizations say, “We need to send more people to training, increase our travel budgets, and hire some strategy people? ” These activities just don’t happen. Why is that? Let’s say that you are nearing retirement and have put in place a 10…

How Deep in DLP Are You?

– While every security tool a vendor advertises to or demonstrates for you is purportedly the silver bullet that saves your organization from drowning in a virtual sea of hackers, rogues and spies, data-leakage protection – or prevention (DLP) is one for which many electrons have been slain to…

Security in Times of Crisis

– Who would have thought, when I wrote my three-part column on “Security and Change” (here, here and here) that all three aspects would hit us at the same time. There was Hurricane Ike, the disappearance and takeovers of major financial institutions, and the massive credit freeze…

The Status of Recent Research Concerning Data Breaches and Reputational Risk

– Nearly three years ago, Ken Belva wrote a paper intended to be a “starting point for further, positive discussion” regarding the topic of data breaches and reputational risk.  The title of the paper also presented Ken’s major theme:  “How It’s Difficult to Ruin a…