Imran Awan case shows lax security controls for Congressional IT staff

By Kevin McDonald Investigations into the conduct of the IT staff of the House of Representatives raised alarms. Kevin McDonald explains what we can learn from the case of Imran Awan. Those who operate with high-level system access, [...]

Imran Awan case shows lax security controls for Congressional IT staff2020-05-18T15:07:45-07:00

GDPR: The Regulatory Iceberg of 2018

You're heading into dangerous waters. On May 25, 2018, the European Union (EU) General Data Protection Regulation (GDPR) goes into full effect, and it will almost certainly affect you. If you are not compliant with the GDPR by this date, you could [...]

GDPR: The Regulatory Iceberg of 20182020-05-18T15:12:15-07:00

Average Ransomware Attack Infects 16 Workstations, 5 Servers and 22 Users

Midmarket firms are getting hit hardest by ransomware. Data from 2017 shows that 29% of the companies with 1,000 to 5,000 employees are getting struck by ransomware. If companies that size—who presumably have the resources to guard against this scourge—are [...]

Average Ransomware Attack Infects 16 Workstations, 5 Servers and 22 Users2021-01-27T21:47:04-08:00

What can my cloud provider do with my data?

Take a moment from your day and pull out the last three or four cloud services agreements your company has entered into. Now, highlight the provisions in those agreements that specifically define how the vendor may use your data. You [...]

What can my cloud provider do with my data?2024-03-14T00:14:56-07:00

Meltdown and Spectre news round-up for week of February 5, 2018

A running log of Meltdown and Spectre news can be found at Meltdown & Spectre: How to avoid the biggest cyber threat in modern computing. February 5, 2018 - At this point in time, Alvaka Networks is not advising [...]

Meltdown and Spectre news round-up for week of February 5, 20182020-02-04T01:49:22-08:00

Private sector’s national cybersecurity strategy contributions lacking

By Kevin McDonald The U.S. government has been very public about its concern for national cybersecurity. There have been grandiose speeches, presidential declarations and several attempts by the legislature to pass new cybersecurity laws. Private companies should be responsible for [...]

Private sector’s national cybersecurity strategy contributions lacking2020-05-27T16:41:09-07:00

“Are the risks from Meltdown and Spectre overblown?”…asks an IT professional

I participate in IT professional industry forums, where peers ask questions of other peers. Someone in the forum made a somewhat disjointed post questioning the severity for the recent Meltdown and Spectre security vulnerabilities. I paraphrase his long question: About [...]

“Are the risks from Meltdown and Spectre overblown?”…asks an IT professional2018-03-01T10:55:39-08:00

What does a FIPS 199 impact assessment mean to you?

If you are a subcontractor to a prime defense contractor like Lockheed Martin, Northrop Grumman, Raytheon, Boeing, General Dynamics and others, you need to know about FIPS 199 and why doing a FIPS impact assessment is important to your DFARS [...]

What does a FIPS 199 impact assessment mean to you?2024-03-13T23:54:59-07:00