SDIM Project Update

Just a quick update on the Stolen Data Impact Model (SDIM) Project for today.

We are prepping to do the first beta unveiling of the project at the local ISSA chapter. It looks like that might be the June meeting, but we are still finalizing dates. Stay tuned for more on this one so you can get your first glimpse of the work as it is unveiled. We also submitted a talk at the ISSA International meeting for the year, later in the summer on the SDIM. We’ll let you know if we get accepted for presenting the project in Nashville.

The work is progressing. We have created several of the curve models now and are beginning to put them out to the beta group for review. This step continues for the next couple of weeks and we will be incorporating the feedback into the models and then releasing them publicly.

Work on phase 2 – that is the framework of questions designed to aid in the scoring of the impacts to generate the curve models has begun. This week, the proof of concept framework is being developed and then that will flow to the alpha group to build upon. Later, the same beta group will get to review and add commentary to the framework prior to its initial release to the public.

Generally speaking, the work on the project is going along as expected. We will have something to show you and a presentation to discuss the outcomes of the project shortly. Thanks to those who volunteered to work on the project and to review the framework. We appreciate your help, and thanks to those who have been asking about the project – your interest is what has kept us going and working on this problem.

As always, thanks for reading, and until next time – stay safe out there! 

MicroSolved Announces International CyberThreat Intel Briefing

MicroSolved, Inc. is proud to announce a unique event for those interested in information security.

The 2013 International Cyber Threat Intelligence Briefing, featuring internationally recognized author William Hagestad, is an executive level briefing on the latest cyber threat intelligence from around the world. This briefing will provide a unique opportunity for C-Level decision makers to understand the cyber threat to their organizations through the loss of intellectual property via the determined use of cyber espionage. Attendees will be presented with two commercial case studies focusing on Global 50 companies. Recommendations, Short & Long Term Moves will accompany this interactive cyber threat intelligence briefing.

This is an opportunity for your management team to participate in a frank, focused discussion about the international cyber threats organizations face today in the global marketplace.

To learn more or sign up to participate, please register by clicking here.

MicroSolved, Inc. Adds Threat Expert Bill Hagestad to Team

Columbus, Ohio; April 10, 2013 –MicroSolved, Inc. is proud to announce the addition of Bill Hagestad to the team. Bill is one of the most internationally recognized subject matter experts regarding the People’s Republic of China and her use of the computer as a weapon system.

 
Prior to joining MSI, Bill created the Red Dragon Rising website which is dedicated to the identification and analysis of foreign language cyber threats. He has authored numerous papers related to the People’s Republic of China and the cyber demagoguery that revolves around the Middle Kingdom. Bill literally wrote the book on Chinese cyber warfare ~ “21st Century Chinese Cyberwarfare”, which is available on Amazon.com. The international intelligence, law enforcement and military experience from the cyber realm that Bill brings to MicroSolved is a very welcome addition to MSI’s industry leading
capabilities offered to clients for more than twenty years.

 

“We are very excited about Bill joining the team and about his emerging role in developing new relationships and offerings for our clients.”, said Brent Huston, CEO of MicroSolved. “With our growth in the critical infrastructure markets in the last several years and our continued focus on bringing rational information security products and services to ICS asset owners, utilities, government agencies and banks/credit unions, Bill brings us significant additional threat intelligence and educational capabilities. After turning 20 years old last November, we wanted to position MicroSolved to bring new, even more valuable insights to our customers and the community – and that begins with deep knowledge about the global threat landscape.”, he added.

About MicroSolved, Inc.

MicroSolved, Inc. was founded in 1992, making it one of the most experienced information security services companies in the world. Providing risk assessment, ethical hacking, penetration testing and security intelligence to organizations of all sizes has been their passion for more than two decades. MSI are the inventors of HoneyPoint Security Server, a patented honeypot intrusion detection platform designed for nuance and anomaly detection. Today, they secure businesses on a global scale and still provide expertise close to home. From governments to the Fortune 500 and from small business to YOUR business, they are the security experts you can trust.  

Press Contacts

Brent Huston

CEO & Security Evangelist

(614) 351-1237 x201

Info@microsolved.com


Bill Hagestad

Senior Cyber Security Strategist

(614) 351-1237 x 250

Info@microsolved.com

Save the Date: Next CHMSecLunch is April 8th

Just a quick reminder that the next #CMHSecLunch is April 8th, 11:30 – 1 pm Eastern at North Market. (Second Monday of each month with a rotating location..)

Join us for what seems to resemble a “hallway con”, except with better food! Friends, good chats, lots of conversation and camaraderie, all can be found here. Open to all interested folks, admission is FREE – but you buy your own vittles. 😉

See you there! 

Pssst: For those interested, May will be at Easton and June will be at Polaris mall food courts.

We also now have a new Eventbrite page for the event, with a schedule through the end of 2013 – sign up or find out more by clicking here!

New Project: Stolen Data Impact Model (SDIM)

This is just a quick announcement about a new project we are starting at MSI. The name of the project is the Stolen Data Impact Model (SDIM).

The goal of the project is to identify a methodology for scoring the impact of data stolen in a breach. We believe the scoring mechanism will be some kind of curve, based on the impact of the loss over time. Currently, we are spreading that loss over four time frames: immediate, short term, intermediate term and long term.

We also believe that there are more than one facet of impact that could be in play and we are currently discussing how to handle the multiple facets.

We are just starting the project, and plan to work through it with the input f the community. We searched for models to address this, but were unable to identify any. If your organization has a model, methodology or process for this and you are open to sharing, please get in touch. You can always contact us in the comments or via Twitter (@lbhuston) or (@microsolved).

Thanks and we hope to present more on this topic shortly.

CMHSecLunch for February

J0289893

This month’s CMHSecLunch is February 11th, at the Polaris Mall food court. It starts at 11:30 am Eastern and goes to 1pm Eastern. The Twitter chat runs at the same time if you can’t join in person – use the hashtag #CMHSecLunch to get in on the virtual event.

This is a great opportunity to meet with friends, peers and folks you may not have gotten to hang out with in a while. It is open to the public, there is no cost or registration hassles. You just go to the mall food court for lunch and sit down with friends to talk or maybe even make some new friends.

Turn outs have been great and the group of folks participating is growing. Each month, on the second Monday, we rotate between mall food courts around town so everyone gets a chance to be “close to home”. Seriously, it’s worth coming out. Think of this as the best part of security conferences (the chance to hang out and chat in the hallways), without the con flu or need to travel on an airplane.

Hopefully, the Twitter hashtag will grow as well and we can use it for folks that are/were in our community, but can’t get to the physical event for whatever reason. 

As always, thanks for reading StateOfSecurity and engaging with MicroSolved. We love the CMH infosec community and organizing this event is just another way we hope to give back for all you have done for us over the last two decades! Thanks!!! 

Kicking Off an Interview Series: Three Tough Questions

Beginning in the next few weeks, we will be kicking off a new series of blog posts called 3 Tough Questions. The format will be either text or audio interviews with infosec, ICS/SCADA, government and other experts. We will be asking strong questions about where we are today in infosec, how we got here and we are going tomorrow. 

Who would you like to see us interview? Drop me a line on Twitter (@lbhuston) or via email/comments and let me know. If you have a burning question or two as well, send them over! 

Thanks for reading and we hope you enjoy the new series! 

Event Announcement: ICS/SCADA Security Briefing

MSI, along with the teams at NexDefense and Critical Intelligence, will be participating in an online webinar about ICS/SCADA Security. The date of the event is February, 6th and you can learn more about it here

The event is free to attend, though registration is required. You can earn a CPE for participating! 

We hope you will tune in and check us out!

Overview of the event: 

Learning Objectives

  • Significant trends in the threat and vulnerability environment
  • Relevant trends in ICS technology
  • What proactive steps you can take
  • How to leverage security intelligence

Agenda

  • Introductions
  • ICS Cyber Security Intelligence Briefing, Michael Assante
  • ICS Threat Update, Brent Huston
  • How to Leverage Security Intelligence, Bob Huber
  • Live Q&A

Who Should View?

  • Senior Information Security Leaders, CISOs and CTOs
  • Security and Risk Analysts
  • Control system security engineers
  • Security operation leads for ICS reliant organizations

Come Grow with MicroSolved

MSI is currently seeking two full time team members to help grow our information security offerings to our clients. 

We are seeking a sales person to assist current customers with their needs, conduct campaigns to identify new prospects, work directly with the security engineers to scope engagements and complete the process by closing engagements and working with the project managers to complete the work plan. The successful sales person will be detail oriented, friendly, self motivated and willing to engage with customers with a high level of passion and energy. Our sales process is mature, transparent and client focused and that has helped us become one of the oldest information security firms in the country. The sales position can be filled by someone located anywhere in the mid-west, as long as they are open to some travel to visit clients and occasional travel back to Columbus as needed. 

The other position is a security team member. This is a technical position, with the primary duties being penetration testing of networks, applications and electronic devices. Security team members also back up the risk assessment team, perform consulting duties and help with development of products and services across the MSI offerings. Some security experience is required, along with expected proficiency with operating systems, networking and some basics of coding/scripting. The security team member position should live in Central OH. We need physical presence for much of the work in our lab, so this person has to be close to HQ. 

To apply for either of these positions, please drop us an email with a resume, a short bio and few paragraphs that explain exactly what you bring to the table and why we should add you to our team. Email us at INFO(at sign)microsolved.com. Thanks for reading and we look forward to hearing from you! 

Help Us Help the World with Information Security

We are seeking a motivated, IT knowledgeable sales person to help our information security firm reach new clients and new markets. 
 
We have a strong history of excellent work, terrific products that stand out in the crowd, and an amazingly skilled and friendly team. We are a results oriented work environment with a laser focus on serving our customers well.
 
The position is full time, with benefits, and enjoys a salary plus commission and bonuses pay structure. The duties include maintaining current client relationships, conducting targeted marketing campaigns to connect with prospects, working with security engineers to help scope solutions to customer problems and closing sales for products and services. We have an open, well defined, mature sales process that includes ongoing feedback, real world metrics and shared goal setting. 
 
The successful candidate can be in Columbus, located somewhere else in Ohio or throughout the mid-west. To succeed in the position, you should be detail oriented, self motivated and be ready to engage with some of the most amazing clients in the world. 
 
Please provide a high level bio, a resume and a quick couple of paragraphs that explain the value you can bring to our team. We look forward to hearing from you! 
 
You can reach us via email at INFO(at sign)microsolved.com or via Twitter (@lbhuston).