Boards Had Better Start Paying Attention to Cybersecurity

Yesterday Forbes featured an excellent article that explained why it is important for companies to create Board-level committees to focus exclusively on the issue of cybersecurity. Here is just a teaser but I encourage you to read the entire article. Step one for every board is to understand that it is supposed to be offering oversight on …

#SonyHack: Will Executives’ Embarrassing Emails Better Motivate Cybersecurity Change?

Sitting in the Miami airport at 5:00 am I am reading news updates on the #SonyHack and a thought just occurred to me: Previously, many of us preaching the “you better take your company’s security seriously” message to the C-Suites have been wondering if it would take a court decision finding C-Levels or Board members …

#SonyHack shows there are no “safe secrets” in the corporate world – what do you do?

The #sonyhack will change the way the corporate world operates in many ways that we cannot even yet imagine. Yes, there are obvious data security implications that I usually drone on about, but there is another change that we may see come about. The now outdated idea that internal corporate secrets will remain corporate secrets. You know, …

The Best Evidence Why Your Company Needs a CISO Before a Data Breach

“The proof is in the pudding,” goes the old saying. When it comes to organizational changes companies make following a data breach, If the proof is in the pudding, then the verdict is clear: companies should hire a Chief Information Security Officer (CISO) before they have a data breach. Why? According to this article in …

Check out my first post on Norse’s DarkMatters > Sony Hack: Where Do We Die First?

Hey everybody, go check out my first post on Norse’s DarkMatters blog — yeah, you know, Norse with the awesome Live Cyber Attack Map! Now that you’re mesmerized by the map, here’s the post and please share it! Sony Hack: Where Do We Die First?

Platform Magazine Quotes Tuma Discussing CyberGard: The Public Relations Side of a Data Breach

Thank you to Platform Magazine for quoting me discussing the PR component of my CyberGard – Business Cyber Risk Protection Program in this forward thinking article about the value of getting public relations on board before your company has a data breach. In a recent post I explained why a data breach response must focus on the …

The Art of Cybersecurity: How Sun Tzu Masterminded the Home Depot Data Breach

Sun Tzu taught that, when it comes to the art of cybersecurity, you must be wary of your business associates and other third parties. Why? Have you heard that Home Depot had a data breach? That hackers were able to exfiltrate 56 million payment cards and 53 million customer email addresses from its systems? Did …

Podcast: #DtR Episode on Lines in the Sand on “Security Research”

You really need to hear this podcast where we draw lines in the sand staking out what is — and what is not — security research.  The #DtR Gang [Rafal Los (@Wh1t3Rabbit), James Jardine (@JardineSoftware), and Michael Santarcangelo (@Catalyst)] invited me to tag along for another episode of the Down the Security Rabbit Hole podcast. Also joining us for this episode were …

Stop lying to yourself — your business is not prepared for data breach risk

Ponemon studies from September 2014 tell us that 43% of US companies had a data breach last year, even if they are not aware of it, and 78% either do not have a data breach response plan in place or have not updated it in a timely manner. This means that your business must be ready …

Yes, I will mention this post in tomorrow’s seminar on data breach! “Who’s Gonna Get It?”

This is one of my favorite and my most popular posts ever — and you better believe I will find a way to mention it to this group of CEOs to help them understand why it is important to take seriously the data security threat! Data Breach – Who’s Gonna Get It? | business cyber …