Multi Factor Authentication Considerations

It still is somewhat shocking to me that most businesses still aren't taking Multi Factor Authentication seriously, and don't mandate it for the employees and like I mentioned the other day for executives. Yet, I see articles like this one from Yubico that shows that people are making the effort in increasing spending by 75%. This is great, and [...]

Q&A Monday: Is IT Security nothing but paperwork?

Oh boy, I'm excited, I haven't done one of these in a while! Question: In my current company, I just switched over from the server operations side to the security side of the business. While I have only been in this position for about two weeks so far, I've been doing more meetings and paperwork than I have other work. Is security nothing [...]

Q&A Monday: Starting a Cyber Security Program

Question:I work for a small company and my boss recently tasked me to start to strengthen our defenses against a cyber attack, but I'm not a security expert, whats the best way to plan this out before I get started.Oda CoxNorway Answer: Thanks for the question, I'm glad you kept it at planning level because it's not something that you can do [...]

Information Security Core Knowledge

Every so often, I get asked by someone who want to get into the InfoSec field, what is at the core of knowledge that is needed. Now I know a lot of people have a lot of different answers to this question, but I think there are some things that are important, that are easier to attain. These aren't particular things to memorize, there are more [...]

How to rethink your backup strategy

One of the things that was drilled into my head when I was starting out in my IT career was the backup philosophy of 3-2-1. This stood for you should have 3 copies of your data (the production data and two backups), on 2 different media types and 1 of them being offsite. This is still the recommended method of CERT (see here). Yet I found it [...]

Q&A Monday: Defense Against Ransomware

Question:There has been a lot in the news about ransomware, what can I do to protect myself? Melody CarrollDayton, MN Answer: There isn't a day that goes by that you don't hear about ransomware hitting a company or targeting another industry and that can make people like yourself want to guard themselves against this particular type of [...]