Cyber Kill Chain and The Four Pillars of Endpoint Security

One of the bigger network security defense methodology trends over the past couple of years, Lockheed Martin’s Cyber Kill Chain model is useful for analyzing and mitigating Advanced Persistent Threat (APT) attacks in the enterprise. The sequential nature of the chain model expresses how the attack itself is vulnerable to disruption, and hence provides avenues…

Mitigating the Pass the Hash Exploit on Windows

Pass the Hash (PTH) is one of the most potent exploits in the hacker arsenal for gaining system administrator privilege and compromising an entire enterprise network. Why? Because PTH can be successful simply by compromising a single machine. PTH works by extracting credential information from the computer’s memory. Any credential present on the computer is…

Data protection requires layers; create a Stronghold

Due to the BYOD and cloud computing trends, as well as to the presence of insider threats and sophisticated overseas adversaries, the enterprise network perimeter is a myth. That is, you can’t depend on an internet firewall to protect the critical data that defines a business. What can you do? Effective data protection requires layers…

From CARTES America 2014: Using NSA Tradecraft to Protect Data on Mobile Devices

Big thank you to CARTES America 2014 for hosting my presentation, Using NSA Tradecraft to Protect Data on Mobile Devices. And who doesn’t love visiting Las Vegas before it gets really hot? All of the slide decks from CARTES America 2014 are available here.

Endpoint security: the challenge is part of the reward

Network security requires both top-down and bottom-up thinking. Read more about securing network endpoints in the 25th edition of the JW Secure Informer.

RSA expo session this morning on security automation

Reminder to those attending RSA in San Francisco this week: the below session is this morning and is free to Expo pass holders. In addition to the 10am panel, we’ll also be demonstrating the JW Secure StrongNet solution interoperating with a Continuous Monitoring agent from Microsoft Trustworthy Computing. Consistent with the theme of the TCG…

Get Proactive with Security: Using Trusted Computing to Free Security Resources for the Day-to-Day Fires

Coming to RSA in San Francisco this year? The conference organizers would like to remind you that there is compelling content on the first day of conference, Monday, February 24, 2014. And an expo pass is enough to get you into these… any you get a free lunch! I’ll be participating in the following moderated…

How do you protect big data?

The secret to protecting big data isn’t to put it under a big tarp. Or to guard it with a big dog. No! The secret to protecting big data is encryption. And you don’t even need big encryption. Just regular encryption will do it. Information security is all about the basics: access control, authorization, confidentiality….

I’m Enterprise Security MVP for 2014

My Microsoft MVP-ness got renewed for the sixth consecutive year! I’ve been keeping busy. Check out my public MVP profile; it lists the technical community-oriented activities that have made me worthy.

Please welcome Jeff Sigman to JW Secure!

Our rock star technical team has just grown to include fellow ex-MSFT colleague Jeff Sigman! Jeff started at Microsoft in 1997 and spent most of his 16 year career in the Windows division focused on networking and security. His work can be seen in every major Windows release since Windows 2000 and included software development…