Don’t forget, Brent will be presenting on the SANS webinar today to discuss ICS/SCADA honeypots. Check it out and register here.
See you online and we hope you enjoy the event!
			
			
						Don’t forget, Brent will be presenting on the SANS webinar today to discuss ICS/SCADA honeypots. Check it out and register here.
See you online and we hope you enjoy the event!
We have begun working on another project around helping organizations better protect their information assets and the reputations of both their employees and their firms at large. As part of that project, we would like to solicit some feedback from the readership of the blog.
Does your organization have a code of conduct for employees? Does is have a written code of conduct for management, board members and/or public relations campaigns?
Is it a living code of conduct or is it a stagnant piece of policy? How often is it updated? Does it cover social media presence, community engagement and/or public perception of the firm or individual?
Who audits the code of conduct and how is it monitored for violations?
Please feel free to give us your thoughts on the code of conduct and which industry you are in. We are taking responses via email (info <at> microsolved <dot> com) or via Twitter (@lbhuston).
Thanks for responding. Responses will be entered into a random drawing for a Starbucks gift card, so respond for a chance to win some java goodness. 🙂
Our Founder and CEO, Brent Huston (@lbhuston) will be leading a SANS webinar on ICS/SCADA honeypots. The webinar is scheduled for November, 25th, 2013 and you can find more information and register by visiting this page.
The webinar will cover when honeypots are and are not useful, basic deployment strategies and insights into using them for detection in field deployments and control environments.
Check it out, tune in and give Brent a shout out on Twitter. Thanks for reading and we hope you enjoy the webinar.
Thanks to the attendees and speakers who participated yesterday in the 3rd Annual ICS/SCADA Security Symposium. It was another great event and once again, the center of the value was in the interactions of the audience with the speakers and each other. It’s great to hear asset owners discuss what is working, what is challenging and what is critical in their minds.
Thanks again to those who attended and contributed to making this event such a wonderful thing again this year. We appreciate it and we can’t wait until next year to do it all again.
Thank YOU!
Over the years, I have watched several infosec teams grow from inception to maturity. I have worked with managers, board members and the front line first responders to help them succeed. During that time I have keyed in on three key items that really mean the difference between success and failure when it comes to growing a teams’ capability, maturity and effectiveness. Those three items are:
Where does your team fit into the picture? Are you working hard on the three key items or have they ever been addressed? How might you bring these three key items into play in your security team? Give us a shout on Twitter (@microsolved or @lbhuston) and let us know about your successes or failures.
Thanks for reading, and until next time, stay safe out there!
SANS Asia Pacific ICS Summit and Training 2013 – Singapore
If you have any responsibility for security of control systems – policy, engineering, governance or operations you won’t want to miss the Asia Pacific ICS Security Summit taking place 2-8 December 2013 where you will:
Learn all about the new Global ICS Professional Security Certification
Gain the most current information regarding Industrial Control System threats and learn how to best prepare to defend against them
Hear what works and what does not from peer organizations.
Network with top individuals in the field of Industrial Control Systems security and return from the Summit with solutions you can immediately put to use in your organization.
Listen to 15+ speakers from a variety of companies who will cover exceptional content throughout the two-day Summit.
Earn CPE credits for the summit and course you attend
ICS410: ICS Cyber Security Essentials, (Brand New course) – 4-8 December taught by SANS Faculty Fellow Dr. Eric Cole will provide a standardized foundational set of skills, knowledge and abilities for Industrial Cyber Security professionals. This course is designed to ensure that the workforce involved in supporting and defending Industrial Control Systems is trained to perform work in a manner that will keep the operational environment safe, secure and resilient against current and emerging cyber threats.
Agenda highlights for the summit include:
A Community Approach to Securing the Cyberspace to Enhance National Resilience
The Good, Bad and the Ugly: Certification of People, Processes and Devices
SCADA Security Assessment Methodology: The Malaysia Experience
The State of Critical Control System Security in Japan
Smart Security : Strengthening Information Protection in Your ICS
To learn more about the Summit and Training, or register now and save 5% on your registration with code SANSICS_MSI5, please visit: http://www.sans.org/info/142537
Mark your calendars now!!!!
The next CMHSecLunch is Monday, November 11th at the Tuttle Mall food court! Starts at 11:30 and runs to about 1 PM.
Come out and see your old friends, make some new ones and generally have a little InfoSec FUN!!!!!!
This is even a great food court, with COFFEE and ICE CREAM!!!! Fun and dessert!!!! mmmmmmmmmm 🙂
Sign up here, or just drop by and surprise us all! 🙂
See ya then!
Happy Halloween!
This time around, we thought we’d offer up a couple of infosec tricks and treats for your browsing pleasure. Around MSI, we LOVE Halloween! We dress up like hackers, bees and hippies. Of course, we do that most other days too… 🙂
Here are a couple of tricks for you for this Halloween:
Columbia University gives you some good tricks on how to do common security tasks here.
University of Colorado gives you some password tricks here.
and The Moneypit even provides some tricks on cheap home security here.
And now for the TREATS!!!!!
Here are some of our favorite free tools from around the web:
Wireshark – the best network sniffer around
Find your web application vulnerabilities with the FREE OWASP ZED Attack Proxy
Crack some Windows passwords to make sure people aren’t being silly on Halloween with Ophcrack
Actually fix some web issues for free with mod_security
Grab our DREAD calculator and figure out how bad it really is.. 🙂
Put those tricks and treats in your bag and smile. They won’t cause cavities and they aren’t even heavy enough to keep you from running from the neighborhood bully looking to steal your goodies!
Thanks for reading and have a fun, safe and happy Halloween!
This month’s Touchdown Task is to take an hour and give your phone system security a quick review. PBX hacking, toll fraud and VoIP attacks remain fairly common and many organizations don’t often visit the security of their phone systems. Thus, a quick review might find some really interesting things and go a long way to avoiding waste, fraud and abuse.
If you have a traditional PBX/analog phone system, here are some ideas for you to check out.
If you have a VoIP-based system, here are some checks to consider. (Note that this is a STIG in a zip file).
Generally speaking, you want to check passwords on voice mail boxes, give a look over to make sure that the phone system has some general logging/alerting capability and that it is turned on. Pay attention to out going dialing rules and test a few to make sure arbitrary calls can’t be made remotely. On the personnel side, make sure someone is actively monitoring the phone system, auditing the bill against “normal” and adding/deleting entries in the system properly.
Give the phone system a bit of your time. You never know what you might learn, and you might avoid tens to hundreds of thousands of dollars in fraud and abuse.
Thanks for reading and I hope you are enjoying the season!
Brent will be speaking at the NEO Security Summit again this year. He will be concluding his set of presentations on the History of Cybercrime and Toffler’s Cell Theory as its basis. TheSummit is October 24-25, 2103 in Westlake, Ohio.
Brent speaks on Thursday at 1:15 PM in “The Champagne Room A”. (Get the thought out of your mind.. You know what Chris Rock says… NSFW…)
This is the 11th annual Summit for NEO and it has history of being a fabulous, affordable event. Come out and learn some stuff, get a ton of CPEs and re-connect with old friends. You can find out more about the event and register here.
As always, thanks for reading and we hope to see you at the event!
UPDATE: Looks like I’ll be doing back to back sessions on Thursday at NEO Summit: 1:15 Crime History in Champagne A, 2:30 Defensive Tampering in Bordeax A. Come out and see me. That’s 2 chances in one day to get your heckle on!!!!