“Doing Time Before Being Convicted?” – Analyist Accuses Merchant of PCI Non-Compliance May 11, 2012
Posted by Chris Mark in cybersecurity, Data Breach, Industry News, InfoSec & Privacy.Tags: bankinfosecurity, Chris Mark, cybersecurity, data breach, Gartner, opening ceremony, PCI DSS, security
add a comment
I wrote this in May 2012. Given the current position in the industry if proclaiming victims of cybercrime to be wholly responsible, I thought it appropriate to publish again.
I was reading a an article on BankInfoSecurity.com titled: “Online Retailer Breached”. I am taken aback at the attitude of the quoted analyst. A Gartner analyst took a very bold step of accusing the merchant of “non compliance” then seemingly qualifying his statement by adding: “The attacker was probably able to attack unencrypted card numbers,” he says. “But given the lack of details, it’s hard to say for certain.” (more…)
“US Snipers Changing Warfare” – USAToday May 9, 2012
Posted by Chris Mark in Industry News, terrorism, weapons and tactics.Tags: Chris Mark, iraq, Quanitco, Scout Sniper, sniper school, usatoday, USMC
add a comment
UPDATE: I forgot to hyperlink to the story 😉 There goes my Pulitzer. You can find the story here.
USAToday published a very interesting and enlightening piece on how US Snipers are being used with great effect in Iraq and Afghanistan. While I think their assertion that snipers are “changing warfare” is a bit of a stretch, I do agree that the use of snipers is, and always has been, very effective. I am somewhat disappointed that they didn’t talk about how smart, handsome, dashing, incredibly brave, selfless, and (did I say handsome already?) Marine Scout/Snipers are. (yes…I was a USMC SS but I am NOT biased ;). The story does give some insight into the training and how snipers are used in warfare. Overall, a very good read on the subject.
“CyberSecurity Cold War” – Spending ourselves into Oblivion May 8, 2012
Posted by Chris Mark in competitive intelligence, cybersecurity, Industry News.Tags: bloomberg, Chris Mark, cold war, cybersecurity, mark consulting group, reagan, risk management, security, soviet union, victory school
1 comment so far
A recent report published by Bloomberg outlines the challenges of securing critical infrastructure against cyber attacks in the 21st century. According to a survey of 172 companies in six industries, current security measures are only stopping 69% of cyber attacks against banks, utility companies and other ‘critical assets’. To stop 95% of attacks, companies would need to spend 7 times more than they are today. This would increase spending from $5.3 billion$30.8 million average) to $46.6 ($270.9 million average). This, it is estimated, would still only prevent 95% of attacks. While not a consistent increase, it could be calculated that for every 1% increase in protection, another $1.588 billion would need to be spent by the group. This amounts to roughly $9.23 million per company…for each 1% increase in protection. If this is indeed accurate, it is clear that the current perspectives and strategy of cybersecurity is fatally flawed.
During the 1980’s the US and Soviet Union were fully engaged in a Cold War. With the election of President Ronald Reagan, the US’s strategy changed. A major component of Reagan’s strategy was to exploit the inherent inefficiencies in the Soviet Union’s command economy. By increasing spending, and forcing the Soviets to match spending on an arms race, the theory held that the SU could be bankrupted. This has become known as the “Reagan Victory School” and while not completely responsible for the collapse of the Soviet Union, can be credited as hastening their demise. As outlined in a Stanford piece: “A central instrument for putting pressure on the Soviet Union was Reagan’s massive defense build-up, which raised defense spending from $134 billion in 1980 to $253 billion in 1989. This raised American defense spending to 7 percent of GDP, dramatically increasing the federal deficit. Yet in its efforts to keep up with the American defense build-up, the Soviet Union was compelled in the first half of the 1980s to raise the share of its defense spending from 22 percent to 27 percent of GDP, while it froze the production of civilian goods at 1980 levels.” (more…)
“Poisoned Apple?” – OSX Lion Encryption Passwords Insecure May 7, 2012
Posted by Chris Mark in cybersecurity, Industry News, InfoSec & Privacy, PCI DSS.Tags: Apple, Chris Mark, cybercrime, cybersecurity, encryption, FileVault, InfoSec & Privacy, mark consulting group, password, security
add a comment
For years many Apple purists (I used to be one) have been touting the inherent security of the Apple operating system. According to Techcrunch in February, 2012 it was discovered that OSX Lion (the newest OS from Apple) had a major security weakness and released widely within the last few days. It was disclosed that the FileVault encryption passwords are now visible in plain text outside of a computer’s encrypted area. This effectively renders the encryption useless as the keys (the passwords) are not secure. While it was originally believed that the vulnerability as specific to the encrypted File Vault solution, it appears now that the vulnerability is larger…potentially much larger. Sophos Naked Security blog states: “Anyone with access to the disk can read the file containing the password and use it to log into the encrypted area of the disk, rendering the encryption pointless and permitting access to potentially sensitive documents. This could occur through theft, physical access, or a piece of malware that knows where to look.” Key management and password security continue to be the weakest link in most encryption implementations.
Airstrike Kills Al Qaeda Leader wanted in USS Cole Bombing May 6, 2012
Posted by Chris Mark in Industry News, Risk & Risk Management, terrorism.Tags: al qaeda, Al-Quso, Chris Mark, mark consulting group, terrorism, USS cole, yemen
add a comment
Foxnews reported that an airstrike on Sunday killed an Al Qaeda leader on the FBI’s most wanted list for the 2000 bombing of the USS Cole. According to Foxnews: ” Fahd al-Quso was hit by a missile as he stepped out of his vehicle, along with another Al Qaeda operative in the southern Shabwa province, Yemeni military officials said. They were speaking on condition of anonymity in accordance with military regulations.”
“Al-Quso, 37, was on the FBI’s most wanted list, with a $5 million reward for information leading to his capture. He was indicted in the U.S. for his role in the 2000 bombing in the USS Cole in Aden, Yemen, in which 17 American sailors were killed and 39 injured. (more…)

