<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/risk-management" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Risk-management ]]></title>
                <link>https://www.itpro.com/tag/risk-management</link>
        <description><![CDATA[ All the latest risk-management content from the ITPro team ]]></description>
                                    <lastBuildDate>Fri, 04 Aug 2023 09:37:25 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Rushing digital transformation will create cyber security ‘bear traps’ – here’s how to avoid them ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/digital-transformation/rushing-digital-transformation-will-create-cyber-security-bear-traps</link>
                                                                            <description>
                            <![CDATA[ Although digital transformation brings many benefits, rushing projects may result in unforeseen cyber security risks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2c2TdY4yyB6QKSLbCTCH9U</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ev4zyd4xb3H2rgpuP6qthZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Aug 2023 09:37:25 +0000</pubDate>                                                                                                                                <updated>Fri, 04 Aug 2023 14:40:40 +0000</updated>
                                                                                                                                            <category><![CDATA[Digital Transformation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sandra Vogel ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Ev4zyd4xb3H2rgpuP6qthZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A bear trap on a circuit board]]></media:description>                                                            <media:text><![CDATA[A bear trap on a circuit board]]></media:text>
                                <media:title type="plain"><![CDATA[A bear trap on a circuit board]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ev4zyd4xb3H2rgpuP6qthZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Organizations undergo <a href="https://www.itpro.com/strategy/28047/what-is-digital-transformation"><u>digital transformation</u></a> for a variety of reasons, including maximizing insights derived from data, streamlining operations, and adjusting workflows for <a href="https://www.itpro.com/business-strategy/flexible-working/369741/pushing-hybrid-work-to-new-extremes"><u>hybrid work</u></a>.</p><div  class="fancy-box"><div class="fancy_box-title">READ MORE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="V2kbhwWzFo6UsAm7M94hJB" name="V2kbhwWzFo6UsAm7M94hJB.jpg" caption="" alt="Python source code" src="https://cdn.mos.cms.futurecdn.net/V2kbhwWzFo6UsAm7M94hJB.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: n/a)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/29899/three-reasons-why-digital-transformation-is-essential-for-business-growth">Why is digital transformation important for business growth?</a></p></div></div><p>There’s no doubting the benefits. But there are potential traps along the road that businesses must also avoid, not least in the form of <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security risks</u></a>. </p><p>Typical risks may arise from failing to provide adequate resources to match a project’s ambition, lacking proficiency to handle a <a href="https://www.itpro.com/cloud/34476/what-is-multi-cloud"><u>multi-cloud</u></a> setup, and failing to align with security frameworks. These ‘bear traps’ can be more prevalent if digital transformation is rushed, and organizations speeding up their efforts must be double vigilant because, with haste, comes a lack of focus. </p><h2 id="prioritizing-security-not-project-outcomes">Prioritizing security, not project outcomes</h2><p>Security must be the primary concern for any organization undergoing digital transformation, says Rick Hemsley, UK&I government and public sector cyber security lead at EY. That’s the bottom line. Organizations need to “integrate security considerations into every aspect of the development of new systems, processes, and products,” and those that fail to do so “will only be able to take a reactive, whack-a-mole approach to cyber security, instead of adopting a proactive mindset”.</p><p>There’s more to avoiding traps than putting security at the heart of digital transformation, though. Organizations need to learn to think differently about security too, says Frank Kim, SANS Institute fellow, cloud curriculum lead, and CISO-in-residence at YL Ventures. “A key metric in the past would have been the mean time to failure, or for something bad to happen. </p><p>“But in the modern world, we look at the mean time to recover,” he tells ITPro. “We don’t think about the mean time to failure because we are expected to fail on a regular basis, so recovery is more important.” </p><p>This approach resonates with a new attitude towards risk, where risk can’t be eliminated entirely, but <a href="https://www.itpro.com/security/do-risk-awareness-and-risk-management-strategies-actually-make-a-difference">needs to be understood and managed effectively</a>. </p><h2 id="speeding-up-processes-heightens-risk-level">Speeding up processes heightens risk level</h2><p>Organizations that decide to speed up digital transformation efforts put themselves at greater risk of leaving cyber security gaps waiting to be exploited, says David Sarginson, head of software development at digital transformation consultancy Opencast. “More change means more risk,” Sarginson explains. “The more change you introduce at any time increases complexity, and therefore the chances of unanticipated consequences.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Nsdypv2KttheZCbq8CgvXM" name="Achieving transformative business results with machine learning_listing.jpg" caption="" alt="Whitepaper image with title on blue background and bottom right images of the sky and skyscrapers looking from the ground up" src="https://cdn.mos.cms.futurecdn.net/Nsdypv2KttheZCbq8CgvXM.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: AWS)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Achieving transformative business results with machine learning</strong></p><p class="fancy-box__body-text"><em>Discover why hundreds of thousands of organisations use AWS ML to resolve challenges and create new opportunities within their organisations.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/machine-learning/369914/achieving-transformative-business-results-with-machine-learning">DOWNLOAD FOR FREE</a></p></div></div><p>Further complications arise from organizations having a multi-cloud setup, Kim adds, and staff needs to be familiar with the nuances of different cloud setups, he says. “Your security team must be knowledgeable in a multi-cloud environment in each of these areas including the pitfalls, the configurations, and the mistakes that could be made. Ideally, architect from the start what those best practices are into your infrastructure.” </p><p>When process speeds are accelerated, there’s less time to get to grips with the nuances, and more opportunity for gaps in security to manifest because security likely won’t be baked in at the outset. “[By] designing best practices directly into the infrastructure code and set-up, you’re providing a paved road for internal stakeholders that need to move to the cloud and adopt these processes,” Kim continues. “When you go off the paved road you know when to pay attention a little more.”</p><h2 id="instigating-the-right-culture">Instigating the right culture</h2><p>Effectively dealing with cyber security risks associated with digital transformation, whether it’s been sped up or it’s happening at a slower pace, requires a risk-based approach from the outset, says Hemsley. The <a href="https://www.itpro.com/business/careers-and-training/the-changing-role-of-the-cio"><u>CIO</u></a> and security teams should have the right level of knowledge and resources to “create a security framework which is defined by proactivity”, he says.</p><div  class="fancy-box"><div class="fancy_box-title">READ MORE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="NpTomCFE9jkNaLFGDcybYX" name="NpTomCFE9jkNaLFGDcybYX.jpg" caption="" alt="Laptop and a typewriter sitting on a blue table" src="https://cdn.mos.cms.futurecdn.net/NpTomCFE9jkNaLFGDcybYX.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: n/a)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/digital-transformation/369535/how-to-manage-a-blend-of-legacy-and-modern-it">Managing a blend of legacy and modern IT during digital transformation</a></p></div></div><p>Achieving this might need an element of cultural change, and Kim confirms this isn’t always easy. “An organization can’t change culture overnight,” he says. “Depending on the size and the nature of the organization it takes anywhere from three to ten years to change.” </p><p>Once organizations then undergo a process of risk awareness, sufficient resources must be allocated, and all employees should be trained on cyber security best practice, adds Sarginson. In addition, his advice includes using frameworks, where possible, like the NIST Cybersecurity Framework or <a href="https://www.itpro.com/it-governance/31712/what-is-iso-27001"><u>ISO 27001</u></a>. This may help to make implementing protections more efficient by removing the need to work out a security posture from first principles.</p><p>Ultimately, avoiding cyber security bear traps involves taking the proper technical steps and the right cultural ones – or as Kim puts it: “It’s not just about implementing new technology, like lift and shift. It’s about building out your people and building out your processes.” </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Do risk awareness and risk management strategies actually make a difference? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/do-risk-awareness-and-risk-management-strategies-actually-make-a-difference</link>
                                                                            <description>
                            <![CDATA[ If cyber attacks are a matter of when, not if, it's tempting to ask whether risk awareness and risk management are effective ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HUHw8f89tHe7WPYLLjT26W</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/whPJc65oQLRkoJomfojyEd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 24 May 2023 09:31:49 +0000</pubDate>                                                                                                                                <updated>Wed, 24 May 2023 16:51:02 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sandra Vogel ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/whPJc65oQLRkoJomfojyEd-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Several green locked padlocks surrounding one orange unlocked padlock]]></media:description>                                                            <media:text><![CDATA[Several green locked padlocks surrounding one orange unlocked padlock]]></media:text>
                                <media:title type="plain"><![CDATA[Several green locked padlocks surrounding one orange unlocked padlock]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/whPJc65oQLRkoJomfojyEd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Risk awareness and risk management are crucial to safeguarding an organization’s assets from cyber attack, according to conventional wisdom. But how effective are these strategies if businesses are now told it’s not a matter of if, but when, <a href="https://www.itpro.com/security/28810/how-to-react-to-a-data-breach"><u>disaster strikes</u></a>? </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/33974/our-5-minute-guide-to-security-awareness-training">Our 5-minute guide to security awareness training</a></p></div></div><p>This “when, not if” theme arises again and again in modern <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security</u></a> discourse – suggesting falling victim to cyber crime is an inevitability. Being targeted, and cyber criminals successfully pulling an attack off, are two different things, though. Risk management and <a href="https://www.itpro.com/security/33974/our-5-minute-guide-to-security-awareness-training"><u>risk awareness</u></a> are both concepts designed to make life as difficult as possible for an attacker. </p><p>By an entire business engaging in the process of identifying and evaluating potential threats, they can offer organizations a certain base level of protection. While many might question whether these efforts – from not just the security teams – are worth the bother if an attack is ‘inevitable, they might keep organizations just on the right side of a serious incident.</p><h2 class="article-body__section" id="section-building-risk-appetite"><span>Building risk appetite</span></h2><p>Risk awareness and risk management are different things, explains EY’s UK&I government and public sector cyber security lead, Rick Hemsley.</p><p>“Whereas risk awareness refers to the proactive measures taken by organizations to educate their employees and stakeholders about potential <a href="https://www.itpro.com/security/cyber-security/360456/how-the-cyber-security-threat-landscape-is-changing"><u>cyber security risks</u></a>,” he says, “[risk] management centers around the identification, assessment, and mitigation of potential risks to a company.”</p><p>Within these two definitions lie many distinct actions and activities: some technical and some cultural. Among the most important is defining the organization’s risk appetite, ensuring this is understood across the organization, and making sure mitigations are in place that respond to risk appetite. </p><p>Risk appetite is a fundamental element of risk awareness and risk management. You can’t protect against everything. A person leaving their home in the morning might get their pocketbook stolen or there might be a water leak while they’re away. They can insure against loss of credit cards and water damage. But only if they’ve assessed the possibility, and put in place a mitigating strategy. They’ll do neither if they don’t think the risks are worth addressing – which is where risk appetite factors in.</p><h2 class="article-body__section" id="section-risk-awareness-is-essential"><span>Risk awareness is essential</span></h2><p>Risk awareness is arguably the most crucial aspect, says David Adams, Grc security consultant at Prism Infosec. “Risk management won’t be effective if risk awareness is not included as a strategy.” </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360456/how-the-cyber-security-threat-landscape-is-changing">How the cyber security threat landscape is changing</a></p></div></div><p>Staff entrusted with implementing controls will only live up to expectations if they understand why it’s important to the organization and aware of the risks of not acting. But risk awareness isn’t just something for the tech team to consider. It must be embedded in the thought patterns and working practices across the organization. </p><p>“The risk management strategy may well advise that personnel only work on encrypted personal applications, and in the risk awareness strategy this would be regularly communicated to staff but made relevant to them, perhaps in the form of awareness training,” explains Adams.</p><h2 class="article-body__section" id="section-can-we-measure-how-effective-risk-management-is"><span>Can we measure how effective risk management is?</span></h2><p>One of the issues around promoting risk awareness through an organization is it’s not always easy to measure. A risk management strategy of, say, using <a href="https://www.itpro.com/security/cyber-security/368481/what-is-threat-hunting"><u>threat analysis to identify attempted cyber attacks</u></a>, and showing which attacks are thwarted, can generate data used to demonstrate how effective these systems are and justify spending on them. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="p7aA9ci4nXKjR9pXsMHoAN" name="Mapping the digital attack surface_thumb.png" caption="" alt="Red whitepaper cover with title and logo" src="https://cdn.mos.cms.futurecdn.net/p7aA9ci4nXKjR9pXsMHoAN.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Mapping the digital attack surface</strong></p><p class="fancy-box__body-text"><em>Why global organisations are struggling to manage cyber risk</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/370166/mapping-the-digital-attack-surface"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>It’s more difficult to measure the effectiveness of risk awareness in this way. An organization can, howeer, test how well its people understand the various risks it’s identified, and measure how they implement approved behaviors. It can ealso nsure that strong systems are in place, for example by implementing a <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">zero trust framework</a> for technology. </p><p>Frequent and overt testing, as well as measuring people’s attitudes towards risk, can itself alienate staff, as can putting in place technology requirements that feel intrusive to actually getting work done. </p><p>The goal should be to guard the organization, not to corral its people. And, in any case, we can’t compare two real-world scenarios – with and without a strong risk awareness strategy in place – to quantify the effect of the strategy.</p><h2 class="article-body__section" id="section-does-risk-management-make-a-difference"><span>Does risk management make a difference?</span></h2><p>What organizations can do is be aware of the risks humans bring. Last year, the <a href="https://www3.weforum.org/docs/WEF_The_Global_Risks_Report_2022.pdf"><u>World Economic Forum (WEF)</u></a> said 95% of cyber security  issues could be traced to <a href="https://www.itpro.com/data-breaches/34355/an-inside-job-the-human-factor-of-cybersecurity"><u>human error</u></a>. </p><p>Normalising appropriate behaviours can help an organization diminish the risk of human error by increasing awareness of the consequences of certain actions – or absence of certain actions. </p><p>The key is for the organization to ensure people feel part of the strategy, not that the strategy is foisted upon them. “A good risk awareness strategy helps create a security-conscious culture across the company, making it more resilient against attacks,” Hemsley tells <em>ITPro</em>. </p><p>Adams puts it another way: “Security is the responsibility of us all and people are now much more conscious of this fact. But when it comes to the individual, relevance is key. It’s vital to make the strategy meaningful to staff.”</p><iframe width="100%" frameborder="0" allow="encrypted-media" data-lazy-priority="high" data-lazy-src="https://open.spotify.com/embed-podcast/episode/2znUT5UIPFAM1pGya83iwT"></iframe><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/five-zero-trust-pitfalls-to-avoid">Why zero trust strategies fail</a></p></div></div><p>In the end risk awareness is a key component of how an organization handles the risks its exposed to. When the organization’s people are aware of these risks, and understand how their individual actions can help – or hinder – the organization in facing up to the very real prospect of attacks, they can play a part in mitigation. </p><p>When cyber attacks are a matter of when, not if, every possible strategy and mitigation that helps an organization deal with its appetite for risk is a strategy worth having, regardless of how much effort it might take to implement.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Take control of diverse and rapidly evolving enterprise risks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/risk-management/370021/take-control-of-diverse-and-rapidly-evolving-enterprise</link>
                                                                            <description>
                            <![CDATA[ Effectively manage and report on risk and compliance ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aTakDHJQzGRoHoYQnEXejJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/XomCxZpLC3msctidSinGWD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Apr 2023 15:56:36 +0000</pubDate>                                                                                                                                <updated>Wed, 03 May 2023 13:06:41 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XomCxZpLC3msctidSinGWD-1280-80.jpg">
                                                            <media:credit><![CDATA[ServiceNow]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with image of female working at a computer with blurred image of tables and chairs in background]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with image of female working at a computer with blurred image of tables and chairs in background]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with image of female working at a computer with blurred image of tables and chairs in background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XomCxZpLC3msctidSinGWD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The disruptions of recent years have opened our eyes to entire new categories of risks, both seriously affecting business operations and negatively impacting customer experiences. A failure to respond to these threats can have a significant effect on the future of the organisation.</p><p>This paper highlights the need to transform legacy risk management approaches, and shares three key pillars that can enable businesses to proactively respond to, and overcome, the risks they face.</p><p>Download now to learn how to get ahead of the curve with real-time risk visibility, how to ensure risk management is a company-wide responsibility, and how internal audits can improve risk posture.</p><p><em>Provided by  </em><strong>ServiceNow</strong></p><iframe width="100%" height="1000" frameborder="0" data-lazy-priority="low" data-lazy-src="https://dennistrk.cvtr.io/click?lid=101754&sid=&pid=3"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Digital transformation & risk for dummies ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/risk-management/370023/digital-transformation-risk-for-dummies</link>
                                                                            <description>
                            <![CDATA[ Understand the risks to your digital business and accelerate your digital transformation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4yJXAX47Lps8oCK4wXsJnq</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3SZqn75eoPzdFjpMdpKAT3-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Feb 2023 14:31:59 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Digital Transformation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/3SZqn75eoPzdFjpMdpKAT3-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper copy with title on black colour block below a green bank with the logo, and a cartoon man&amp;#039;s face in a yellow circle next to the content summary in a green circle]]></media:description>                                                            <media:text><![CDATA[Whitepaper copy with title on black colour block below a green bank with the logo, and a cartoon man&amp;#039;s face in a yellow circle next to the content summary in a green circle]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper copy with title on black colour block below a green bank with the logo, and a cartoon man&amp;#039;s face in a yellow circle next to the content summary in a green circle]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3SZqn75eoPzdFjpMdpKAT3-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Digital transformation creates a variety of new opportunities, but unfortunately can also result in the increase of risks, and the more an enterprise can understand the risks it faces - especially as a company-wide initiative - the more successful their digitisation will be.</p><p>This special edition guide can help your employees better understand how they can be part of a successful digital risk management strategy, with practical advice on how to apply learnings to real risk management situations.</p><p>Download now to learn:</p><ul><li>The basics of risk identification and management</li><li>How to manage digital risk</li><li>As well as five tips for successful digital transformation</li></ul><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="RSr6uS55HKeiMFTSBQUk26" name="" alt="ServiceNow Logo" src="https://cdn.mos.cms.futurecdn.net/RSr6uS55HKeiMFTSBQUk26.png" mos="https://cdn.mos.cms.futurecdn.net/RSr6uS55HKeiMFTSBQUk26.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49949/servicenow-efus018166?locale=1&p=false&wp=10769"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The Forrester Wave™: Third party risk management platforms ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/370020/the-forrester-wavetm-third-party-risk-management-platforms</link>
                                                                            <description>
                            <![CDATA[ The 12 providers that matter the most and how they stack up ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">a6UrKCHG4Dky1xA5KnSQwE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YiiQFx8GtDJXQYpMpx8hXn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Feb 2023 13:36:11 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Digital Transformation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YiiQFx8GtDJXQYpMpx8hXn-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with title, logo and contributor image on black band above the summary]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with title, logo and contributor image on black band above the summary]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with title, logo and contributor image on black band above the summary]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YiiQFx8GtDJXQYpMpx8hXn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The management of third-party risk is no longer simply a box to tick for regulatory compliance. Since the global pandemic, third-party risk management (TPRM) has become an important priority to ensure the impact of an attack, or disruptive event, on partners and suppliers is limited.</p><p>A study by Forrester showed that demand for TPRM technology is at an all time high, so this commissioned report identifies and evaluates 12 of the most significant and leading TPRM service providers to see how each one measures up.</p><p>View now to see each vendor’s current offering and market presence, as well as how they score on flexibility, reporting, and value to help you identify the right one for your business needs.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="RSr6uS55HKeiMFTSBQUk26" name="" alt="ServiceNow Logo" src="https://cdn.mos.cms.futurecdn.net/RSr6uS55HKeiMFTSBQUk26.png" mos="https://cdn.mos.cms.futurecdn.net/RSr6uS55HKeiMFTSBQUk26.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49949/servicenow-efus018166-redirect1?locale=1&p=false&wp=10780"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The big book of ZTNA security use cases ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/remote-access/369413/the-big-book-of-ztna-security-use-cases</link>
                                                                            <description>
                            <![CDATA[ Know your ZTNA protection index ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9rc1xiqx9NyaTCdoFPwf3R</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iZbRits5t8eoFtzAsZbNoV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 27 Oct 2022 15:03:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Digital Transformation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iZbRits5t8eoFtzAsZbNoV-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with bold blue header banner with title and image of man at a workstation with multiple screens]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with bold blue header banner with title and image of man at a workstation with multiple screens]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with bold blue header banner with title and image of man at a workstation with multiple screens]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iZbRits5t8eoFtzAsZbNoV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In a new hybrid world of work, distributed workforces and remote access points to business networks are prime targets for cybercriminals, looking to exploit the weakened security measures of multiple unmanaged devices.</p><p>This guide shares relatable cyber security breach examples, highlighting key areas at risk, and how Zero Trust security measures could reduce risk exposure and support your current cyber security measures.</p><p>Download this white paper now to fully understand your own risk exposure, and learn why additional protection measures—including zero-trust architectures—are critical to stop data breaches.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="vt9Hn8kHfKUiKra3x8KVNE" name="" alt="Citrix logo" src="https://cdn.mos.cms.futurecdn.net/vt9Hn8kHfKUiKra3x8KVNE.png" mos="https://cdn.mos.cms.futurecdn.net/vt9Hn8kHfKUiKra3x8KVNE.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49860/citrix-sia?locale=1&p=false&wp=10460"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cloud and cyber security certifications remain highest paying for IT professionals ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/careers-training/369201/cloud-and-cyber-security-certifications-remain-highest</link>
                                                                            <description>
                            <![CDATA[ Digital learning firm Skillsoft has analysed the data of thousands of IT professionals from around the world ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gGoaznh9dAZs1NBqTWdst7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MKSXwG97gK5Ce6UgJjKus7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 29 Sep 2022 13:00:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Careers and Training]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MKSXwG97gK5Ce6UgJjKus7-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A female IT worker in front of multiple monitors displaying code]]></media:description>                                                            <media:text><![CDATA[A female IT worker in front of multiple monitors displaying code]]></media:text>
                                <media:title type="plain"><![CDATA[A female IT worker in front of multiple monitors displaying code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MKSXwG97gK5Ce6UgJjKus7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cloud and cyber security orientated certifications continue to be the highest paying for IT professionals, the latest research from Skillsoft has revealed.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="pFJcpVRGtzBivW3SJxEQa6" name="pFJcpVRGtzBivW3SJxEQa6.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/pFJcpVRGtzBivW3SJxEQa6.png" mos="https://cdn.mos.cms.futurecdn.net/pFJcpVRGtzBivW3SJxEQa6.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Cyber security in manufacturing</strong></p><p class="fancy-box__body-text">The increasing cost of cyber crime means manufacturers need to adapt</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/369195/cyber-security-in-manufacturing" data-original-url="/security/cyber-security/369195/cyber-security-in-manufacturing">FREE DOWNLOAD</a></p></div></div><p>The digital learning firm analysed data from thousands of IT professionals around the world as part of its annual IT Skills and Salary survey, resulting in a list of the <a href="https://www.itpro.com/business-strategy/careers-training/359789/best-paying-tech-jobs" data-original-url="https://www.itpro.com/business-strategy/careers-training/359789/best-paying-tech-jobs">top paying certifications</a> in the industry today.</p><p>However, while the report reveals that the top jobs to have higher salaries associated with them, those figures are the culmination of several factors, Skillsoft said – including the ability to apply certified skills at work, job role, continuous professional development, tenure, and hard work.</p><p>With this in mind, the three highest paying credentials were found to be:</p><h3 class="article-body__section" id="section-1-cissp-certified-information-systems-professional"><span>1. CISSP – Certified Information Systems Professional </span></h3><h3 class="article-body__section" id="section-salary-104-862-96"><span>Salary: $104,862.96</span></h3><h3 class="article-body__section" id="section-price-749"><span>Price: $749</span></h3><p>Top of the pile, the CISSP certification has been compared to earning a <a href="https://www.itpro.com/business-strategy/careers-training/354847/is-a-degree-still-necessary-to-get-ahead-in-it" data-original-url="https://www.itpro.com/business-strategy/careers-training/354847/is-a-degree-still-necessary-to-get-ahead-in-it">master’s degree in IT security</a> as it equips professionals to effectively design, implement, and manage a cyber security programme. </p><p>The exam itself focuses on eight key areas within information security, including security and risk management, asset security, security architecture, <a href="https://www.itpro.com/business-strategy/careers-training/356509/how-to-become-a-software-developer" data-original-url="https://www.itpro.com/business-strategy/careers-training/356509/how-to-become-a-software-developer">software development</a> security, and more.</p><p>Candidates require a minimum of five years of paid, relevant work experience in two or more CISSP domains. Those that lack the experience can still take the exam, and become an Associate of (ISC)2 if they pass.</p><h2 id="2-aws-certified-solutions-architect-professional">2. AWS Certified Solutions Architect – Professional</h2><h3 class="article-body__section" id="section-salary-100-718-97"><span>Salary: $100,718.97</span></h3><h3 class="article-body__section" id="section-cost-300"><span>Cost: $300</span></h3><p>Solutions architects are currently among the <a href="https://www.itpro.com/business-strategy/careers-training/354917/the-most-in-demand-tech-jobs" data-original-url="https://www.itpro.com/business-strategy/careers-training/354917/the-most-in-demand-tech-jobs">most in-demand tech roles</a>, with organisations requiring professionals to design, deploy, and support complex cloud infrastructure. This certification from AWS validates a professional’s ability in this area.</p><p>The cloud giant recommends two or more years of hands-on experience and familiarity with a scripting language, Windows, Linux, and many AWS services.</p><h2 id="3-cism-certified-information-security-manager">3. CISM – Certified Information Security Manager</h2><h3 class="article-body__section" id="section-salary-97-303-57"><span>Salary: $97,303.57</span></h3><h3 class="article-body__section" id="section-cost-575-for-isaca-members-760-for-non-members"><span>Cost: $575 for ISACA members, $760 for non-members</span></h3><p>As cyber security continues to be a top priority for organisations, the ISACA’s Certified Information Security Manager (CISM) certification highlights an individual’s ability to lead security teams and efforts effectively.</p><p>It validates a professional’s ability to manage, design, and assess an enterprise’s information security and proves expertise across information security governance, information security risk management, information security programme, as well as incident management.</p><p>IT professionals must have five years of relevant professional work experience before they can sit the exam.</p><h2 id="tech-salaries-continue-to-rise">Tech salaries continue to rise</h2><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/359789/best-paying-tech-jobs" data-original-url="/business-strategy/careers-training/359789/best-paying-tech-jobs">Highest paying tech jobs of 2022</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/360701/it-pro-panel-do-we-still-need-certifications" data-original-url="/business-strategy/careers-training/360701/it-pro-panel-do-we-still-need-certifications">IT Pro Panel: Do we still need certifications?</a></p></div></div><p>The findings align with recent research from <a href="https://hired.com/state-of-tech-salaries/2022">Hired</a>, which found that tech salaries have continued to rise despite the pandemic and recent economic struggles around the world.</p><p>In the US, the <a href="https://www.itpro.com/business-strategy/careers-training/359789/best-paying-tech-jobs" data-original-url="https://www.itpro.com/business-strategy/careers-training/359789/best-paying-tech-jobs">highest paying tech roles</a> were found to be Engineering Management ($196,193), <a href="https://www.itpro.com/business-strategy/careers-training/356692/the-ultimate-guide-to-becoming-a-software-engineer" data-original-url="https://www.itpro.com/business-strategy/careers-training/356692/the-ultimate-guide-to-becoming-a-software-engineer">Software engineering</a> ($160, 469), Product Management ($157, 602), Developer Operations ($156, 321), and Design ($153, 005).</p><p>In the UK, the average UK tech salary has increased year-over-year from £76,000 in 2021 to £83,000 in 2022, with half of employees expecting a salary increase by next year.</p><p>The aim is to keep salaries high to win over top talent, meet candidate expectations, as well as prevent future job-hopping, the firm said.</p><p>“Employers continue to explore new markets and time zones for the best talent while valuing the efficiency of responsive, engaged candidates,” Hired explained. “Jobseekers still maintain a lot of power in the market.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Economic downturn now perceived a bigger threat to business than ransomware ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/business-strategy/368618/economic-downturn-perceived-bigger-threat-than-ransomware</link>
                                                                            <description>
                            <![CDATA[ Businesses are advised to conduct regular risk assessments and embrace the economic threat as an opportunity for growth ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ft8Q7e7zMMaTqqgxnNM35K</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/L738DRCeuCNYpwkWs9PZth-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 21 Jul 2022 11:30:52 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Leadership]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/L738DRCeuCNYpwkWs9PZth-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A close up shot of a street window display showing a series of falling stock prices]]></media:description>                                                            <media:text><![CDATA[A close up shot of a street window display showing a series of falling stock prices]]></media:text>
                                <media:title type="plain"><![CDATA[A close up shot of a street window display showing a series of falling stock prices]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/L738DRCeuCNYpwkWs9PZth-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Leading business executives have grown more fearful of a looming macroeconomic downturn in 2022, more so than ransomware attacks or the effects of the Russian invasion of Ukraine.</p><p>Data released by Gartner this week for Q2 2022 showed that ransomware has slipped to the third-most feared emerging risk to businesses, overtaken by economic uncertainty after it took the top spot in Q1.</p><p>The potential <a href="https://www.itpro.com/business/business-strategy/368496/why-businesses-should-invest-their-way-out-of-a-downturn" data-original-url="https://www.itpro.com/business/business-strategy/368496/why-businesses-should-invest-their-way-out-of-a-downturn">economic downturn</a> jumped from fifth to first between Q1 and Q2 of 2022, Gartner’s Emerging Risk Reports showed.</p><p>The top five emerging risks to business - Q2 2022:</p><ol><li>Macroeconomic downturn</li><li>Escalation of conflict in Europe</li><li>State-sponsored cyber attacks</li><li>Energy price inflation</li><li>Key material shortages</li></ol><p>“The top five risks reported by respondents were notable both for their interconnectedness and origination outside of the organisation,” <a href="https://www.gartner.com/en/newsroom/press-releases/2022-07-20-gartner-survey-shows-economic-downturn-now-top-emerging-risk-worrying-executives">said</a> Chris Matlock, vice president at the Gartner legal, risk and compliance practice.</p><p>“While interconnected, many of the top risks send conflicting signals on the state of the economy, which makes the role of emerging risk management (ERM) leaders especially crucial in filtering the most relevant, organisation-specific information up to the c-suite and board.”</p><p>Gartner said it was ‘notable’ that all of the top five risks were external factors – outside the direct control of a business – and the impact of each would be felt differently depending on the industry and location of the business.</p><p>The leading risk, macroeconomic downturn, was described by Gartner as a high-impact factor on businesses, the full effects of which are expected to be felt over the next two years.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/368496/why-businesses-should-invest-their-way-out-of-a-downturn" data-original-url="/business/business-strategy/368496/why-businesses-should-invest-their-way-out-of-a-downturn">Why businesses should invest their way out of a downturn</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/components/367758/short-circuit-will-the-chip-shortage-end-this-year" data-original-url="/hardware/components/367758/short-circuit-will-the-chip-shortage-end-this-year">Short circuit: Will the chip shortage end this year?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/finance/368343/swift-exit-how-the-world-cut-off-russian-banks" data-original-url="/business-operations/finance/368343/swift-exit-how-the-world-cut-off-russian-banks">Swift exit: How the world cut off Russian banks</a></p></div></div><p>A shortage in key materials will also be a high-impact factor that affects businesses within a year, it said. Many technology companies are already reeling from <a href="https://www.itpro.com/strategy/28710/what-is-the-supply-chain-1" data-original-url="https://www.itpro.com/strategy/28710/what-is-the-supply-chain-1">supply chain</a> issues, chiefly from the <a href="https://www.itpro.com/hardware/components/367758/short-circuit-will-the-chip-shortage-end-this-year" data-original-url="https://www.itpro.com/hardware/components/367758/short-circuit-will-the-chip-shortage-end-this-year">semiconductor shortage</a>.</p><p><a href="https://www.itpro.com/security/cyber-security/367420/nation-state-hacking-tools-target-ot-businesses" data-original-url="https://www.itpro.com/security/cyber-security/367420/nation-state-hacking-tools-target-ot-businesses">State-sponsored cyber attacks</a> are considered high-impact for businesses, too, with Gartner predicting the fullest effects of the threat to be felt between one and two years in the future.</p><p>The most-feared risks are likely to be long-term influencers on business decisions, the analysts said. There is no apparent date by which the conflict in Ukraine will end, nor is there one for the associated <a href="https://www.itpro.com/business-operations/finance/368343/swift-exit-how-the-world-cut-off-russian-banks" data-original-url="https://www.itpro.com/business-operations/finance/368343/swift-exit-how-the-world-cut-off-russian-banks">sanctions placed on Russia</a> by global nations.</p><p>Businesses are advised to continually reassess their macroeconomic outlook and regularly conduct both top-down and bottom-down risk assessments, balancing the findings from each.</p><p>They are also advised to embrace the risks presented to their industry and use them as an opportunity for understanding that could eventually propel a company ahead of competitors.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Death of the tick mark ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-governance/368135/death-of-the-tick-mark</link>
                                                                            <description>
                            <![CDATA[ How to prevent internal audit becoming obsolete ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5LVvReSf1pRMbdZoBLLddV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9N4bQ9sjXRDaa3JaZz7rdc-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Jun 2022 13:12:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Big Data]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/9N4bQ9sjXRDaa3JaZz7rdc-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with image of a hand holding a pen over a tick list]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with image of a hand holding a pen over a tick list]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with image of a hand holding a pen over a tick list]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9N4bQ9sjXRDaa3JaZz7rdc-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Auditing is an independent consulting activity, intended to help organisations improve their operations, as it evaluates ways to improve risk management. However within the technology industry, auditors are being replaced by automation, and with CFOs looking to reduce spending, the function of audit and compliance could become obsolete.</p><p>The audit process needs to change for the better, and with emerging technology, there’s great potential for auditing to adapt and drive real value in relation to data analytics and risk management monitoring.</p><p>Download this whitepaper to learn where audit technology is headed, and what it means for your organisation.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="UtvAeeAcF8dVU7LoiMht4J" name="" alt="Diligent logo" src="https://cdn.mos.cms.futurecdn.net/UtvAeeAcF8dVU7LoiMht4J.png" mos="https://cdn.mos.cms.futurecdn.net/UtvAeeAcF8dVU7LoiMht4J.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49676/diligent-fy22-risk-and-compliance?locale=1&p=false&wp=9650"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Nine steps to IT audit readiness ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/risk-management/368132/nine-steps-to-it-audit-readiness</link>
                                                                            <description>
                            <![CDATA[ How technology can help win back your time and reduce IT risk ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o7HnY8K9jA4yme5KvGmpLz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zoqTYfttWyamiHY8XhBKKN-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Jun 2022 13:05:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/zoqTYfttWyamiHY8XhBKKN-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with image of female employee wearing glasses reflected in a screen of data graphs]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with image of female employee wearing glasses reflected in a screen of data graphs]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with image of female employee wearing glasses reflected in a screen of data graphs]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zoqTYfttWyamiHY8XhBKKN-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In today’s hybrid working world, with the increased number of devices, data and systems, the risk to global IT is significant, making the regulatory environment more complex.</p><p>With IT leaders facing more challenges than ever before, the differing regulations and compliance frameworks means a vast amount of work for an often resource-limited team. But being able to get to a stage of IT compliance, ready for audit, is achievable with the right technology.</p><p>Download this whitepaper to understand the key components when it comes to being IT audit-ready - including process, technology, and people - with clear steps to follow, ensuring your business gets there.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="UtvAeeAcF8dVU7LoiMht4J" name="" alt="Diligent logo" src="https://cdn.mos.cms.futurecdn.net/UtvAeeAcF8dVU7LoiMht4J.png" mos="https://cdn.mos.cms.futurecdn.net/UtvAeeAcF8dVU7LoiMht4J.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49676/diligent-fy22-risk-and-compliance?locale=1&p=false&wp=9647"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ KRI basics for IT governance ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/risk-management/368130/kri-basics-for-it-governance</link>
                                                                            <description>
                            <![CDATA[ How information technology & information security can implement this crucial part of risk management ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dyR9hTBF75c6rKs1YphLew</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/artk5m3dxh2auzw8iwrhAe-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Jun 2022 12:44:30 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/artk5m3dxh2auzw8iwrhAe-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with worker holding a tablet and looking at a server]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with worker holding a tablet and looking at a server]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with worker holding a tablet and looking at a server]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/artk5m3dxh2auzw8iwrhAe-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Key risk indicators (KRIs) can help predict adverse events that may impact your organisation and are widely considered an essential part of good governance. These indicators link to a range of operational risk-management activities and processes, making them especially beneficial as metrics of changes in a company’s risk profile.</p><p>Here, you’ll learn how to implement, manage and maintain KRIs within your IT department:</p><ul><li>Choosing appropriate KRIs can benefit your organisation</li><li>Examples of effective KRIs</li><li>KRIs/KRI selection worksheet</li><li>Implementing automated reporting</li></ul><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="UtvAeeAcF8dVU7LoiMht4J" name="" alt="Diligent logo" src="https://cdn.mos.cms.futurecdn.net/UtvAeeAcF8dVU7LoiMht4J.png" mos="https://cdn.mos.cms.futurecdn.net/UtvAeeAcF8dVU7LoiMht4J.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49676/diligent-fy22-risk-and-compliance?locale=1&p=false&wp=9407"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Third party risk management essentials ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/risk-management/368125/third-party-risk-management-essentials</link>
                                                                            <description>
                            <![CDATA[ How to manage third party risk within your organisation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">v5C2or9yTj76omJJab9DN9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2ZectTY68dYi6NTUYFCcWo-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Jun 2022 12:26:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/2ZectTY68dYi6NTUYFCcWo-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with shaded image of data graph in the background]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with shaded image of data graph in the background]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with shaded image of data graph in the background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2ZectTY68dYi6NTUYFCcWo-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>While it’s easy to see the benefits of bringing third parties on board – higher revenues and lower costs - outsourcing can introduce a significant threat of risk that can bring long-term reputational and financial damage to your organisation.</p><p>In this e-book, you’ll learn about the challenges of third-party risk management, the differences between vendor risk management (VRM) and third-party risk management (TPRM) and discover a framework to help mitigate this risk:</p><ul><li>Essentials of third-party risk management</li><li>Ways third parties can introduce risk</li><li>Real-life third-party failures</li><li>Robust TRPM framework to ensure good governance</li></ul><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="UtvAeeAcF8dVU7LoiMht4J" name="" alt="Diligent logo" src="https://cdn.mos.cms.futurecdn.net/UtvAeeAcF8dVU7LoiMht4J.png" mos="https://cdn.mos.cms.futurecdn.net/UtvAeeAcF8dVU7LoiMht4J.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49676/diligent-fy22-risk-and-compliance?locale=1&p=false&wp=9405"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Recommendations for managing AI risks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence-ai/367499/recommendations-for-managing-ai-risks</link>
                                                                            <description>
                            <![CDATA[ Integrate your external AI tool findings into your broader security programs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ikJ9LY1RmCnWRkFzqH4PhL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NJSDBJZzAjpg5aq4yVq3A8-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 26 Apr 2022 11:40:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/NJSDBJZzAjpg5aq4yVq3A8-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Yellow whitepaper cover with two flying robots, with desktop computers inside their heads]]></media:description>                                                            <media:text><![CDATA[Yellow whitepaper cover with two flying robots, with desktop computers inside their heads]]></media:text>
                                <media:title type="plain"><![CDATA[Yellow whitepaper cover with two flying robots, with desktop computers inside their heads]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NJSDBJZzAjpg5aq4yVq3A8-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Cyber Resilience Think Tank is an independent group of industry influencers dedicated to understanding the cyber resilience challenges facing organisations and providing possible solutions, with this paper in particular focussing on AI.</p><p>For CISOs using vendors that employ AI, it’s less about what intelligence their tools provide, and more about how the organisation’s internal security team can integrate external AI tool findings into their broader security programs.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="PsftVtHsoiGYz7AFifMahD" name="" alt="Mimecast logo" src="https://cdn.mos.cms.futurecdn.net/PsftVtHsoiGYz7AFifMahD.png" mos="https://cdn.mos.cms.futurecdn.net/PsftVtHsoiGYz7AFifMahD.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49638/form-9771?locale=1&p=false&wp=9053"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How a platform approach to security monitoring initiatives adds value ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/367042/how-a-platform-approach-to-security-monitoring-initiatives-adds-value</link>
                                                                            <description>
                            <![CDATA[ Integration, orchestration, analytics, automation, and the need for speed ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dnP93SwkUbq8cZ4NS2v1Bc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mG92862tEkcmYjwLpumZzk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Mar 2022 13:57:25 +0000</pubDate>                                                                                                                                <updated>Fri, 01 Apr 2022 13:57:25 +0000</updated>
                                                                                                                                            <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mG92862tEkcmYjwLpumZzk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with title on burgundy square graphic]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with title on burgundy square graphic]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with title on burgundy square graphic]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mG92862tEkcmYjwLpumZzk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The most productive security teams are going beyond the use of tactical tools for investigation and reporting of security incidents. Instead, they are taking a more strategic, proactive, platform-oriented approach to identifying and assessing security-related risks, proving compliance, and maturing the flexibility and resilience of ongoing operations.</p><p>Read this report to learn about the evolution of security monitoring capabilities and discover what comprehensive security technologies companies are investing in to support their work from anywhere (WFA) / hybrid work model.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="rQy9MUeL7vDLefQJcJuEZZ" name="" alt="IBM logo" src="https://cdn.mos.cms.futurecdn.net/rQy9MUeL7vDLefQJcJuEZZ.png" mos="https://cdn.mos.cms.futurecdn.net/rQy9MUeL7vDLefQJcJuEZZ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49614/ibm-q2-2022?locale=1&p=false&wp=8951"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Improve security and compliance ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/365337/improve-security-and-compliance</link>
                                                                            <description>
                            <![CDATA[ Adopting an effective security and compliance risk management approach ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">i5Xd1mCKpiWygADAHtfanW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yPTxiHXTa3TryGiia9DSw4-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Mar 2022 09:46:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/yPTxiHXTa3TryGiia9DSw4-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with image of a shield with red outline, red numbers 1s &amp;amp; 0s, red cubes and white cloud outlines]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with image of a shield with red outline, red numbers 1s &amp;amp; 0s, red cubes and white cloud outlines]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with image of a shield with red outline, red numbers 1s &amp;amp; 0s, red cubes and white cloud outlines]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yPTxiHXTa3TryGiia9DSw4-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IT security and compliance are key concerns for all organisations. Not only are threat landscapes increasing, poor oversight of their IT and a lack of headcount means compliance tasks have to be done manually.</p><p>Having an effective security and risk management approach, which assesses the security of infrastructure & workload environments - and prioritises remediation quickly - is essential.</p><p>Download this whitepaper for key considerations around security and compliance in Linux environments, with recommended tools and actionable insight.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zBPPYq2D9HQEFvE6RuUKxd" name="" alt="Red Hat & Intel logo" src="https://cdn.mos.cms.futurecdn.net/zBPPYq2D9HQEFvE6RuUKxd.png" mos="https://cdn.mos.cms.futurecdn.net/zBPPYq2D9HQEFvE6RuUKxd.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49534/redhat-q1-eng?locale=1&p=false&wp=8425"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Modern governance: The how-to guide ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/it-governance/361792/modern-governance-the-how-to-guide</link>
                                                                            <description>
                            <![CDATA[ Equipping organisations with the right tools for business resilience ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cjz4fexkozCZv4jy6L4nN3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/twFQWGnpSuXfswsCrh4NE4-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Dec 2021 14:32:02 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Digital Transformation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/twFQWGnpSuXfswsCrh4NE4-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with solid red vertical line, and the title and Diligent logo]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with solid red vertical line, and the title and Diligent logo]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with solid red vertical line, and the title and Diligent logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/twFQWGnpSuXfswsCrh4NE4-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Modern technology is evolving just as fast as the business landscape and to stay ahead, organisations need to remain informed, protected, collaborative and goal-focussed in real time and in all situations. </p><p>Having modern governance can enable your business to remain productive while progressing with your digital transformation, so that you can emerge stronger than the competition.</p><p>Download this whitepaper to learn best practices and insights in:</p><ul><li>Strategy & governance</li><li>Security & collaboration</li><li>Risk & accountability</li></ul><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="UtvAeeAcF8dVU7LoiMht4J" name="" alt="Diligent logo" src="https://cdn.mos.cms.futurecdn.net/UtvAeeAcF8dVU7LoiMht4J.png" mos="https://cdn.mos.cms.futurecdn.net/UtvAeeAcF8dVU7LoiMht4J.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49474/diligent-corporation-form?locale=1&p=false&wp=8107"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Marsh McLennan reveals its cyber risk analytics center ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/risk-management/361269/marsh-mclennan-reveals-its-cyber-risk-analytics-center</link>
                                                                            <description>
                            <![CDATA[ The center combines the expertise of Marsh, Guy Carpenter, Mercer, and Oliver Wyman ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cCGgmFJ2jRztBG52h1ANwr</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Xtx8rK72HcYorinhyiM3Ma-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 15 Oct 2021 18:04:20 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Xtx8rK72HcYorinhyiM3Ma-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hand hovering over laptop with padlock graphic superimposed]]></media:description>                                                            <media:text><![CDATA[Hand hovering over laptop with padlock graphic superimposed]]></media:text>
                                <media:title type="plain"><![CDATA[Hand hovering over laptop with padlock graphic superimposed]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Xtx8rK72HcYorinhyiM3Ma-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Marsh McLennan has announced the launch of its cyber risk analytics center to help clients better understand the risks they face.</p><p>In addition to providing a holistic view of cyber threats, the platform helps businesses evaluate the effectiveness of existing and prospective control mechanisms, economic impacts of risks, and more.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/359520/cyber-risk-planning-for-directors-six-principles-to-follow" data-original-url="/security/cyber-security/359520/cyber-risk-planning-for-directors-six-principles-to-follow">Cyber risk planning for directors – six principles to follow</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-crime/30911/scale-of-cyber-risk-to-uk-businesses-is-bigger-than-ever" data-original-url="/cyber-crime/30911/scale-of-cyber-risk-to-uk-businesses-is-bigger-than-ever">Scale of cyber risk to UK businesses is "bigger than ever"</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/361093/how-to-manage-ai-risk" data-original-url="/technology/artificial-intelligence-ai/361093/how-to-manage-ai-risk">How to manage AI risk</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/361182/singapore-launches-new-cyber-security-framework" data-original-url="/business-strategy/careers-training/361182/singapore-launches-new-cyber-security-framework">Singapore launches new cyber security framework</a></p></div></div><p>The center integrates the <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> capabilities of Marsh McLennan’s Marsh, Guy Carpenter, Mercer, and Oliver Wyman businesses.</p><p>Commenting on available features, Marsh McLennan said its <a href="https://www.itpro.com/tag/analytics" data-original-url="https://www.itpro.com/analytics">analytics</a> center delivers a comprehensive suite of tools and critical risk insights, ranging from malicious code to complex webs of digital connections.</p><p>Per reports, the center will be led by the firm's managing director Scott Stransky. </p><p>Marsh McLennan's global network of commercial, government, and academic partners will also assist with research and development through the center. </p><p>“Cyberattacks routinely cause millions of dollars in loss to our clients and billions of dollars in loss to the global economy every year. It is no surprise that business, government, and other leaders continue to rank cyber risk as one of the most pervasive and urgent risks for society,” said John Doyle, president and <a href="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do" data-original-url="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do">CEO</a> of Marsh and vice chairman at Marsh McLennan. </p><p>Doyle added, “For many leaders, however, their concern exceeds their ability to measure and manage cyber risk alone. Our investment in the Marsh McLennan Cyber Risk Analytics Center will help clients confront this risk by connecting them with experts and capabilities from across our businesses, data-driven insights, and a global ecosystem of risk and cybersecurity experts.”</p><p>Lastly, the firm aims to enhance the cyber modeling and analytics ecosystem, so clients can make informed decisions about how they identify, prepare for, and recover from cyber risk.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to increase cyber resilience within your organisation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/359468/how-to-increase-cyber-resilience-within-your-organisation</link>
                                                                            <description>
                            <![CDATA[ Cyber resilience for dummies ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">g2z3vdssfjFYRsD9Wp5GdB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gGRwbS6T2JYCbdQmJ8xJri-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 May 2021 10:40:33 +0000</pubDate>                                                                                                                                <updated>Thu, 15 Jul 2021 10:40:33 +0000</updated>
                                                                                                                                            <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/gGRwbS6T2JYCbdQmJ8xJri-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber resilience for dummies - How to improve cyber resilience within your organisation - whitepaper from Mimecast]]></media:description>                                                            <media:text><![CDATA[Cyber resilience for dummies - How to improve cyber resilience within your organisation - whitepaper from Mimecast]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber resilience for dummies - How to improve cyber resilience within your organisation - whitepaper from Mimecast]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gGRwbS6T2JYCbdQmJ8xJri-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="PsftVtHsoiGYz7AFifMahD" name="" alt="Mimecast logo" src="https://cdn.mos.cms.futurecdn.net/PsftVtHsoiGYz7AFifMahD.png" mos="https://cdn.mos.cms.futurecdn.net/PsftVtHsoiGYz7AFifMahD.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Ensuring your business continuity and compliance in the age of disruption is becoming a top priority, with more and more organisations investing in cyber risk management and awareness.</p><p>The ANZ Mimecast Special Edition of <em>Cyber Resilience For Dummies</em> explores how to:</p><ul><li>Be both cyber secure and cyber resilient</li><li>Defend your organisation from phishing scams and ransomware</li><li>Reduce the impact of cyber disruptions</li><li>Train your team to stay cyber aware</li></ul><p><em>Fill out the form below to access the free resource. </em></p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/li-284842-mimecast-q2-fy22?locale=1&p=false&wp=6713"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Observability in 2020: A manifesto ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/risk-management/357885/observability-in-2020-a-manifesto</link>
                                                                            <description>
                            <![CDATA[ Ten principles for observability success ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">254RSHjvrLHtiAZmUihjsS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WvDuZSTBErMNqyavrdrNC5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 24 Nov 2020 16:24:44 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WvDuZSTBErMNqyavrdrNC5-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WvDuZSTBErMNqyavrdrNC5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="M5pyVT8pK3RafTsomCjwFo" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/M5pyVT8pK3RafTsomCjwFo.png" mos="https://cdn.mos.cms.futurecdn.net/M5pyVT8pK3RafTsomCjwFo.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Businesses that only monitor passively, fixing problems once they’ve already happened, will always be one step behind, and this will eventually show in dropped revenue after many bad customer experiences. Observability, however, can prevent you from falling into this trap. </p><p>Observability is an active approach that helps you understand why things are going wrong, that gives you metrics and actionable insights so that you can do better next time. This whitepaper distils the topic of observability down to ten key principles, as defined by developers and engineers.</p><p>Download it now to start applying these principles to your observability practice today. </p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/new-relic-france-uae?locale=1&p=false&wp=5508"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Leadership compass: Privileged Access Management ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/risk-management/357883/leadership-compass-privileged-access-management</link>
                                                                            <description>
                            <![CDATA[ Securing privileged accounts in a high-risk environment ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7EWokahqPhhmiBtU7N4gvn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fS4WdFBWG8az3bibxVZVdG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 24 Nov 2020 15:42:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fS4WdFBWG8az3bibxVZVdG-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Priviledged Access Managenment whitepaper]]></media:description>                                                            <media:text><![CDATA[Priviledged Access Managenment whitepaper]]></media:text>
                                <media:title type="plain"><![CDATA[Priviledged Access Managenment whitepaper]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fS4WdFBWG8az3bibxVZVdG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="PnasmgPNPsmptxecQQ2rRf" name="" alt="Bytes" src="https://cdn.mos.cms.futurecdn.net/PnasmgPNPsmptxecQQ2rRf.png" mos="https://cdn.mos.cms.futurecdn.net/PnasmgPNPsmptxecQQ2rRf.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Privileged Access Management (PAM) is a vital aspect of risk management and security. It has become one of the fastest growing areas of cyber security in recent years as cyber crime and compliance regulations grow. </p><p>Hijackers are drawn to the increase in privileged accounts and the valuable information held there, and so a strong PAM solution is now essential for upholding regulatory compliance and keeping accounts secure. This whitepaper provides an overview of PAM and the catalysts for its growth. </p><p>Download it now for a clear outline of the requirements of a strong PAM solution and advice for selecting the right vendor for your business needs.</p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/one-identity?locale=1&p=false&wp=5284"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Bigleaf Networks’ AI-powered feature translates network events into actionable risks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/risk/357387/bigleaf-networks-ai-powered-feature-translates-network-events-into</link>
                                                                            <description>
                            <![CDATA[ AI-widget identifies risks triggered by a site and highlights only the top three with actionable solutions ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mz2kikUo1AxZEj7jBAiGj4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Yvm4ZK7TEB5q57eZPXVuPL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 09 Oct 2020 19:04:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Yvm4ZK7TEB5q57eZPXVuPL-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Bigleaf risk monitoring dashboard]]></media:description>                                                            <media:text><![CDATA[Bigleaf risk monitoring dashboard]]></media:text>
                                <media:title type="plain"><![CDATA[Bigleaf risk monitoring dashboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Yvm4ZK7TEB5q57eZPXVuPL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Bigleaf Networks has announced a new <a href="https://www.itpro.com/strategy/28181/what-is-ai" data-original-url="https://www.itpro.com/strategy/28181/what-is-ai">AI</a>-based feature called Risk Monitoring within its <a href="https://www.bigleaf.net/overview">Cloud-first SD-WAN platform</a>. The feature addresses the most pressing problem IT companies face today: high risk-alert noise.</p><p>"The complexity of networks in today's IT-lean enterprises where they have tens or hundreds of cloud applications running across hundreds or thousands of branch and home internet connections has reached a point where all sense of control and excellence has been lost," said Joel Mulkey, co-founder and <a href="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do" data-original-url="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do">CEO</a>, Bigleaf.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/612901/is-apples-corporate-culture-a-security-risk" data-original-url="/612901/is-apples-corporate-culture-a-security-risk">Is Apple's corporate culture a security risk?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/95080/mobile-users-underestimate-virus-risks" data-original-url="/95080/mobile-users-underestimate-virus-risks">Mobile users underestimate virus risks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/103007/world-economic-forum-internet-increases-global-risk" data-original-url="/103007/world-economic-forum-internet-increases-global-risk">World Economic Forum: Internet increases global risk</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/99305/it-departments-cant-quantify-security-risks" data-original-url="/99305/it-departments-cant-quantify-security-risks">IT departments can't quantify security risks</a></p></div></div><p>"People can't process and troubleshoot the volume of alerts and events on networks anymore. It's not a matter of not wanting to. It's that there's simply too much information, most of which is noise. You've got to have intelligent software to solve this problem. By building a platform that takes control of processing and interpreting those events, we've now established true network control for our customers."</p><p>Through contextual alerting, Bigleaf’s Risk Monitoring feature allows companies to reduce the unabating noise. The widget translates high-volume network events into prioritised, actionable risks, slashing the risk-alert noise levels by almost 50%. </p><p>Proving its point further, Bigleaf exposed as many as 12 risks in the initial launch of its new feature. The risks include, among others, extended periods of elevated health alarm levels, critical traffic volume exceeding the capacity of backup circuits and site outage.</p><p>The feature can also highlight the top three risks out of all risks triggered by a site. Each risk alert presents an easy-to-understand explanation of a threat and how to solve it to allow quick decision-making. Any scenario that poses a risk to a customer's business or its site's continuity will trigger an alert.</p><p>"This new feature brings incredible relief to daily pain our customers and others in the industry feel. It also brings significant value to our <a href="https://www.itpro.com/security/33890/hackers-target-msps-to-launch-supply-chain-ransomware-attacks" data-original-url="https://www.itpro.com/security/33890/hackers-target-msps-to-launch-supply-chain-ransomware-attacks?amp">MSP</a> partners who now have a tool that lets them see risks across all of the companies they manage and helps them better determine where they should spend their limited time and resources to keep their customers happy," continued Mulkey.</p><p>Existing Bigleaf customers can access the feature by logging into their Bigleaf web dashboard.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Digital transformation? Don’t bother unless you plan to address risk ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/risk-management/354865/digital-transformation-risk-profiles</link>
                                                                            <description>
                            <![CDATA[ How has your organisation’s risk profile changed in recent years due to its digital transformation? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">u8DvegRwg19rstHyCPiCiM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iiB6QBechRHdboBBzRbb3d-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 27 Feb 2020 10:08:49 +0000</pubDate>                                                                                                                                <updated>Wed, 24 Mar 2021 11:03:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Digital Transformation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Cooper ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iiB6QBechRHdboBBzRbb3d-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[security in either data protection or cyber security ]]></media:description>                                                            <media:text><![CDATA[security in either data protection or cyber security ]]></media:text>
                                <media:title type="plain"><![CDATA[security in either data protection or cyber security ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iiB6QBechRHdboBBzRbb3d-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/strategy/28047/what-is-digital-transformation" data-original-url="https://www.itpro.com/strategy/28047/what-is-digital-transformation">Digital transformation</a> is a concept that has dominated the business world for some time now. Everybody’s planning it, doing it or wondering why they haven’t taken the leap yet.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7X65CAHDzSqvQhaB7Dc4xg" name="7X65CAHDzSqvQhaB7Dc4xg.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/7X65CAHDzSqvQhaB7Dc4xg.png" mos="https://cdn.mos.cms.futurecdn.net/7X65CAHDzSqvQhaB7Dc4xg.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The people factor: A critical ingredient for intelligent communications</strong></p><p class="fancy-box__body-text">How to engage employees in digital transformation</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/business-communications/358721/the-people-factor-a-critical-ingredient-for" data-original-url="/marketing-comms/business-communications/358721/the-people-factor-a-critical-ingredient-for">FREE DOWNLOAD</a></p></div></div><p>The <a href="https://www.itpro.com/strategy/29899/three-reasons-why-digital-transformation-is-essential-for-business-growth" data-original-url="https://www.itpro.com/strategy/29899/three-reasons-why-digital-transformation-is-essential-for-business-growth">benefits</a> to your company can be endless, from streamlining processes to making your next big innovation. Of course, the value of digital transformation has been particularly prominent in the last year, where COVID-19 and its associated lockdowns completely upended the way many businesses operate at a fundamental level. Digital transformation went rapidly from a ‘nice to have’ to an essential for allowing employees to work remotely and continuing to serve your company’s customers. Organisations of all kinds adopted cloud services and productivity and collaboration apps to keep their staff working even though they were stuck at home.</p><p>In a recent McKinsey Global Survey of executives, respondents estimated that the digitisation of their customer and supply-chain interactions and of their internal operations had been accelerated by three to four years. As for the share of digital or digitally enabled products in their portfolios, those had been moved ahead by as much as seven years.</p><p>Respondents also said that they are anticipating the majority of these changes to be long lasting. Many have already made significant investments in time, money and resources to ensure that these are changes that will endure.</p><p>Outside of the pandemic, another specific motivator of digital transformation is the opportunity to eliminate risks that stem from legacy processes. However, at least in the short term, this will bring forth new pressures which will alter an organisation’s risk profile.</p><p>That’s because digital transformation is a catalyst for change. As workflows migrate to the digital realm, organisations are met with a host of new threats which affect their risk profile. This is demonstrated in <a href="https://www.itpro.com/business-strategy/risk-management/354778/digital-risk-report-2020" data-original-url="https://www.itpro.com/business-strategy/risk-management/354778/digital-risk-report-2020">RSA’s 2020 Digital Risk Report</a>, which includes findings from a study conducted across the globe which asked the question: ‘How has your organisation’s risk profile changed over the past two years, due to its digital transformation?’ Respondents also reported how they expect their risk profile to change over the following two years.</p><p>The results are in. In Western Europe, 87% stated that digital transformation is expanding their risk profiles due to new or increasing risk. The principle is a simple one: as an organisation’s digital surface area expands, more things come into contact with it. </p><p>Over the following two years, this statistic is expected to drop by a fraction, yet the unpredictability and ubiquitous nature of cyber risk could mean a greater period of time must elapse before risk profiles truly settle in the wake of digital transformation. What’s more, these patterns are similar globally, with North America and the APJ region yielding equally startling results. </p><p>There exists an ongoing tug-of-war. On the one side are the digital transformation initiatives essential to modern-day business survival, pulling enterprises towards success; on the other are the risks such initiatives simultaneously cause.</p><p>Digital transformation must dig in its heels to win the match, something that can only be achieved if management teams keep a close eye on both ends of the rope. </p><h2 id="build-your-risk-profile">Build your risk profile</h2><p>While risk profiles may more traditionally refer to health and safety, taking the time to identify what risks your digital transformation will unearth will allow your organisation to avoid them. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/29899/three-reasons-why-digital-transformation-is-essential-for-business-growth" data-original-url="/strategy/29899/three-reasons-why-digital-transformation-is-essential-for-business-growth">Five reasons why digital transformation is essential for business growth</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/28550/why-ceos-are-in-sourcing-digital-transformation" data-original-url="/strategy/28550/why-ceos-are-in-sourcing-digital-transformation">Why CEOs are in-sourcing digital transformation</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/digital-transformation/31524/how-to-spot-a-failing-digital-transformation-project" data-original-url="/digital-transformation/31524/how-to-spot-a-failing-digital-transformation-project">How to spot a failing digital transformation project</a></p></div></div><p>An organisation’s risk profile is comprised by evaluating the variety of threats faced. Numerical values are assigned to variables, quantifying the threat level each poses. The risk profile is closely associated with the risk appetite; that is to say, the amount of risk an organisation is willing to take on. Balancing the two is the key to ensuring digital transformation initiatives prove to be a success.</p><p>Here, organisations must ask themselves what threats a digital transformation initiative will come into contact with, and whether they are manageable or too hefty a meal for their appetite.</p><p>For instance, will transitioning from <a href="https://www.itpro.com/hybrid-cloud/29599/five-obstacles-holding-your-hybrid-cloud-strategy-back" data-original-url="https://www.itpro.com/hybrid-cloud/29599/five-obstacles-holding-your-hybrid-cloud-strategy-back">physical data centres to a cloud provider</a> be too great a shift in controls? If you cannot afford the protocols that ensure cloud security, your appetite is too small and the initiative should, for now, be put on hold.</p><h2 id="how-to-manage-risk">How to manage risk</h2><p>Building a risk profile allows the organisation to identify where their security and risk management is lacking, and subsequently expand their capabilities in these areas. RSA’s 2020 report found that respondents indicated a desire to invest in risk management solutions proportional to the extent of digital transformation. With your risk profile in front of you, management can ensure that they spend the right amount on the right things to elevate initiatives.</p><p>This proportionality is indicative of the desire to keep pace with the rapid change that comes part and parcel with digital transformation. Effective digital risk management can keep digital initiatives on schedule, and ensure their effectiveness; conversely, retrofitting controls after implementation is generally much more costly and less effective. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7X65CAHDzSqvQhaB7Dc4xg" name="7X65CAHDzSqvQhaB7Dc4xg.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/7X65CAHDzSqvQhaB7Dc4xg.png" mos="https://cdn.mos.cms.futurecdn.net/7X65CAHDzSqvQhaB7Dc4xg.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The people factor: A critical ingredient for intelligent communications</strong></p><p class="fancy-box__body-text">How to engage employees in digital transformation</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/business-communications/358721/the-people-factor-a-critical-ingredient-for" data-original-url="/marketing-comms/business-communications/358721/the-people-factor-a-critical-ingredient-for">FREE DOWNLOAD</a></p></div></div><p>There is no avoiding that a crucial element in managing risk is an <a href="https://www.itpro.com/business/business-strategy" data-original-url="https://www.itpro.com/business-strategy/34495/it-budgets-set-to-grow-next-year">expansion of resources</a>. A flexible budget is necessary to handle the risk landscape’s rate of change. Expertise must be invested in to oversee security measures including threat detection and response, network security, and vulnerability management. </p><p>Managing risk isn’t solely about tackling the negative symptoms caused by digital transformation; instead, organisations must focus on the cause, namely, the initiative itself. Balancing the costs and benefits of initiatives, both in isolation and as part of wider movements, is the most effective method of addressing risk profiles that are threatening to spiral out of control. </p><p>While digital transformation is essential in the modern-day, too much of a good thing threatens to <a href="https://www.itpro.com/digital-transformation/31524/how-to-spot-a-failing-digital-transformation-project" data-original-url="https://www.itpro.com/digital-transformation/31524/how-to-spot-a-failing-digital-transformation-project">negate its benefits</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Digital Risk Report 2020 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/risk-management/354778/digital-risk-report-2020</link>
                                                                            <description>
                            <![CDATA[ A global view into the impact of digital transformation on risk and security management ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bM1S7ZdagGGpUtoLpzMehB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Cyy66TCaGMjzkuoVqXsYDg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Feb 2020 12:27:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Cyy66TCaGMjzkuoVqXsYDg-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Cyy66TCaGMjzkuoVqXsYDg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="yxj6oo35x3Fb9fFF2ZPoPF" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/yxj6oo35x3Fb9fFF2ZPoPF.png" mos="https://cdn.mos.cms.futurecdn.net/yxj6oo35x3Fb9fFF2ZPoPF.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Organisations depend more than ever on digital business operations and digital products and services to compete. While digital transformation abounds with new business opportunity, it also introduces new and unknown risks.</p><p>The RSA Digital Risk Report 2020 offers important global perspectives from 1,050 organisations on the state of digital risk including top risk management priorities, the changes being implemented to manage risk today and drivers for future investment.</p><p>Download it now to explore the opportunities and risks involved in digital transformation.</p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/rsa-form?locale=1&p=false&wp=4135"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Your guide to managing cloud transformation risk ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/354743/your-guide-to-managing-cloud-transformation-risk</link>
                                                                            <description>
                            <![CDATA[ Realise the benefits. Mitigate the risks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vyiRLmsrdCc5T3wageo67p</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9e4dKMckRoBvuMKeQESHeM-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Feb 2020 09:55:34 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/9e4dKMckRoBvuMKeQESHeM-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9e4dKMckRoBvuMKeQESHeM-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="RdwBA28Z8caxMvMMFLsj2e" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/RdwBA28Z8caxMvMMFLsj2e.png" mos="https://cdn.mos.cms.futurecdn.net/RdwBA28Z8caxMvMMFLsj2e.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>With cloud computing promising to increase flexibility, scope for scalability, automatic updates and simplified collaboration, it’s no wonder that cloud-adoption is at the heart of most organisations’ digital transformation strategies. </p><p>Yet on the way to achieving these benefits, organisations face an array of new security challenges, including obscured visibility into users, data and applications, an endless stream of tech changes security teams must stay on top of, and an increasingly diverse ecosystem of employees and third parties using these services.</p><p>This whitepaper snapshots the changing security landscape, identifying the key challenges digital transformation projects face, and the myriad of tools available to resolve them. </p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/bluefort-form?locale=1&p=false&wp=4163"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Micro Focus suffers shares slump amid revenue fears ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/acquisition/30791/micro-focus-suffers-shares-slump-amid-revenue-fears</link>
                                                                            <description>
                            <![CDATA[ CEO Chris Hsu leaves as analyst points finger at HPE merger difficulties ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mZK4wctzxShBsSHcWXKM3s</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HkqEUG87Jb2V9KjpyEMBnK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 19 Mar 2018 11:22:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Acquisition]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HkqEUG87Jb2V9KjpyEMBnK-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Growing graph]]></media:description>                                                            <media:text><![CDATA[Growing graph]]></media:text>
                                <media:title type="plain"><![CDATA[Growing graph]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HkqEUG87Jb2V9KjpyEMBnK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Micro Focus has seen its shares collapse and CEO depart after it issued a sales warning to investors this morning.</p><p>The British company, <a href="https://www.itpro.com/strategy/29368/hpe-completes-88bn-software-spin-off-to-micro-focus" target="_blank" data-original-url="https://www.itpro.com/strategy/29368/hpe-completes-88bn-software-spin-off-to-micro-focus">which completed an $8.8 billion "spin-merge" with the software division of Hewlett Packard Enterprise (HPE) in September 2017</a>, warned year-on-year revenue is likely to fall by between 6% and 9%.</p><p>Previously it had predicted a slowdown of just 2% to 4% for the 12 months ending 31 October 2018, but worse than expected results in January have caused it to downgrade its forecast.</p><p>The company's shares fell 41% to their lowest value since 2006 as markets opened in London, hitting 11.16. The price has continued to fall throughout the day.</p><p>CEO Chris Hsu, who joined Micro Focus from HPE following the spin-merge last year, departed the company with immediate effect on Sunday. Stephen Murdoch, until now the organisation's COO, has taken Hsu's place.</p><p>In <a href="http://www.techmarketview.com/ukhotviews/archive/2018/03/19/micro-focus-shares-in-freewill-following-revenue-warning" target="_blank">a blog post</a>, TechMarketView analyst Angela Eager pointed squarely at the HPE deal as the cause of the problem.</p><p>"It was always going to be a big meal but Micro Focus is finding it harder to digest HPE Software than expected," Eager said.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/27212/hpe-sells-non-core-software-assets-to-uks-micro-focus" data-original-url="/strategy/27212/hpe-sells-non-core-software-assets-to-uks-micro-focus">HPE sells "non-core" software assets to UK's Micro Focus</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/29368/hpe-completes-88bn-software-spin-off-to-micro-focus" data-original-url="/strategy/29368/hpe-completes-88bn-software-spin-off-to-micro-focus">HPE completes $8.8bn software spin off to Micro Focus</a></p></div></div><p>"There will be a knock-on effect on adjusted EBITDA (earnings before interest, taxes, depreciation and amortisation) margin percentage (which is the KPI Micro Focus rates above revenue), although the company says it will be mitigated by the cost reduction programme which is ahead of schedule. Micro Focus now expects an Adjusted EBITDA margin percentage of approximately 37%, which is way down on the 46.2% of the year ending April 2017 (prior to the HPE Software merger)."</p><p>Other areas blamed by Micro Focus for its troubles include implementation issues with a new IT system that has cause problems with sales efficiency, the ability to transact with partners and cash collection; sales staff attrition due to integration and the IT-related issues: disruption of ex-HPE global customer accounts as a result of the spin-merger; and continued sales fulfilment issues, particularly in North America.</p><p>In an interview with <a href="https://www.bloomberg.com/news/articles/2018-03-19/micro-focus-issues-sales-warning-alongside-ceo-resignation" target="_blank"><em>Bloomberg</em></a>, Kevin Loosemore, chairman of Micro Focus, said: "Clearly we have let people down with this execution and we have to rebuild that trust."</p><p>He remained positive about the HPE deal, however, adding: "The strategy remains the same. We believe this deal will turn out to be a good deal. We think the market in infrastructure software will continue to consolidate and we hope to participate in this consolidation."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple and Cisco tempt businesses with cybersecurity discount ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/risk-management/30469/apple-and-cisco-tempt-businesses-with-cybersecurity-discount</link>
                                                                            <description>
                            <![CDATA[ Kaspersky claims it sets a "worrying precedent" of insurance companies claiming to be better informed on security ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uDsSwxAtCbpvf8Zf1cdduP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/B8FsAoansEa8UzQKwSWe9J-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 06 Feb 2018 11:02:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/B8FsAoansEa8UzQKwSWe9J-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/B8FsAoansEa8UzQKwSWe9J-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Businesses using Apple and Cisco products will now qualify for better cybersecurity insurance terms as part of a deal with European insurer Allianz, the companies announced on Monday.</p><p>Companies could also qualify for reduced, or even no, deductibles as part of the deal with Allianz, which said the service is designed to help a wider range of organisations protect themselves against ransomware and malware threats.</p><p>Those companies using Cisco's Ransomware Defense suite, which is offered as part of Cisco's security portfolio, as well as those that have rolled out iPhones, iPads and Macs to their employees, will qualify for the favourable terms.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/26179/how-apple-built-a-25-billion-enterprise-business-in-three-years" data-original-url="/strategy/26179/how-apple-built-a-25-billion-enterprise-business-in-three-years">How Apple built a $25 billion enterprise business in three years</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-breaches/30238/2018-the-year-of-data-insurance" data-original-url="/data-breaches/30238/2018-the-year-of-data-insurance">2018: The year of data insurance</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-security/30122/cyber-security-spending-will-hit-96bn-in-2018" data-original-url="/cyber-security/30122/cyber-security-spending-will-hit-96bn-in-2018">Cyber security spending will hit $96bn in 2018</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/leadership/22726/apple-and-ibm-a-new-alliance" data-original-url="/strategy/leadership/22726/apple-and-ibm-a-new-alliance">Apple and IBM: a new alliance</a></p></div></div><p>The contract will also offer a "Cyber Resilience Evaluation" provided by services firm Aon, which will assess a company's security posture and recommend ways to improve its defences. Organisations will also have access to Cisco and Aon's incident response teams in the event of a malware attack.</p><p>Allianz has said the move is an attempt to address the trend of companies failing to take our cyber security insurance at a time when malware attacks have become a daily occurrence.</p><p>US cyber security premiums amounted to $1.35 billion in 2016, according to data gathered by <a href="https://www.reuters.com/article/us-cyber-insurance-apple-cisco-systems/apple-cisco-team-up-with-insurance-companies-to-offer-cyber-policy-discounts-idUSKBN1FP1NM" target="_blank"><em>Reuters</em></a> from the National Association of Insurance Commissioners, and Monday's deal may go some way to entice businesses looking to protect their systems.</p><p>The move is also the latest in a string of deals Apple has struck with B2B companies, including a <a href="https://www.itpro.com/strategy/leadership/22726/apple-and-ibm-a-new-alliance" target="_blank" data-original-url="https://www.itpro.com/strategy/leadership/22726/apple-and-ibm-a-new-alliance">long-running partnership</a> with IBM to enhance enterprise mobility through a range of applications and services and <a href="http://www.cloudpro.co.uk/marketing/5998/apple-signals-b2b-push-letting-developers-build-sap-powered-iphone-and-ipad-apps" target="_blank">a business app development deal with SAP</a>.</p><p>A <a href="https://www.itpro.com/mobile/29340/apple-partnering-with-accenture-for-business-apps-on-ios" target="_blank" data-original-url="https://www.itpro.com/mobile/29340/apple-partnering-with-accenture-for-business-apps-on-ios">deal with Accenture</a> last year also saw the creation of a suite of tools to help businesses better engage their users through iPhones and iPads.</p><p>Apple has confirmed to <em>IT Pro</em> that there are no specific requirements for how Apple products are purchased, and that businesses would qualify regardless of whether devices are procured or used through BYOD schemes.</p><p>"The choice of technology providers plays a critical role in any company's defense against cyber attacks," said Apple CEO Tim Cook. "That's why, from the beginning, Apple has built products from the ground up with security in mind, and one of the many reasons why businesses around the world are choosing our products to power their enterprise."</p><p>An Allianz spokesperson told <em>IT Pro</em> this offering "will be available initially in the US market, with the intention of expanding globally in time".</p><p>However, what's still uncertain is the exact terms of the contracts, and although Allianz has said deductibles will be non-existent in some cases, it isn't clear to which cases that would apply.</p><p>The news that an insurer will now dictate which security products qualify for the best deals has drawn concern from the security industry.</p><p>"It's reasonable for home contents insurers to give residents discounts if they have dead-bolts, window-locks and an alarm - but it would be outrageous if insurers instructed that these had to be for specifically branded locks or alarms," said David Emm, principal security researcher at Kaspersky.</p><p>"What makes theirs a better-informed decision than the customers, or an independent reviewer? This move in the cyber-insurance industry sets a worrying precedent. By being guided towards certain providers, customers won't have full freedom to choose the best product."</p><p><em>Picture: Shutterstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Judge says LinkedIn cannot block third-parties from accessing profile data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-intelligence/29223/judge-says-linkedin-cannot-block-third-parties-from-accessing-profile</link>
                                                                            <description>
                            <![CDATA[ The ruling may have implications for social media users wishing to control how their data is collected ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mfC4kJgbphnAWC58SS9RWY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vJHo9MSnBth7LM45jUWzk5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 15 Aug 2017 10:28:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vJHo9MSnBth7LM45jUWzk5-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[LinkedIn]]></media:description>                                                            <media:text><![CDATA[LinkedIn]]></media:text>
                                <media:title type="plain"><![CDATA[LinkedIn]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vJHo9MSnBth7LM45jUWzk5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A US federal judge has ruled that Microsoft cannot block a startup from accessing data held on its LinkedIn platform, a decision that is likely to have further implications for social media companies wishing to control data that is considered publicly available.</p><p>San Francisco judge Edward Chen sided with tech firm hiQ Labs, granting a preliminary injunction that ordered LinkedIn to remove any blocks preventing the startup from accessing profile data, according to <em><a href="https://uk.reuters.com/article/us-microsoft-linkedin-ruling-idUKKCN1AU2BV">Reuters</a></em>.</p><p>"To the extent LinkedIn has already put in place technology to prevent hiQ from accessing these public profiles, it is ordered to remove any such barriers," read the court order.</p><p>HiQ Labs required access to the data, which is considered publicly available, to build algorithms designed to predict employee behaviour through their social media activities. The service provides "a crystal ball that helps you determine skills gaps or turnover risks months ahead of time", according to its website, essentially alerting bosses to employees thinking of leaving a firm.</p><p>The company has hailed the ruling as a major victory for those relying on public data to deliver services.</p><p>"HiQ believes that public data must remain public, and innovation on the internet should not be stifled by legal bullying or the anti-competitive hoarding of public data by a small group of powerful companies," the company said in a statement to Reuters.</p><p>LinkedIn has been battling with the startup since May, when it sent a cease and desist order to hiQ Labs in an effort to stop the company lifting profile data from its site. It argued that the use of its data in this way was a breach of its terms of service, and potentially went against the Computer Fraud and Abuse Act (CFAA).</p><p>LinkedIn said it planned to challenge the decision, according to a statement to Reuters.</p><p>"We're disappointed in the court's ruling," said LinkedIn spokeswoman Nicole Leverich, to <em>IT Pro</em>. "This case is not over. We will continue to fight to protect our members' ability to control the information they make available on LinkedIn."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/26714/microsoft-buys-linkedin" data-original-url="/strategy/26714/microsoft-buys-linkedin">Microsoft buys LinkedIn</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/161343/where-next-for-linkedin" data-original-url="/161343/where-next-for-linkedin">Where next for LinkedIn?</a></p></div></div><p>The decision leaves social media companies in a tricky spot. Users signing up to the service, particularly job hunting sites like LinkedIn, rely on the ability to have their profile publicly accessible to others, yet they do not necessarily want their data being used by third-party platforms. Currently, the only way to prevent data from being scalped from social media sites is to make your account private.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Six ways boards can step up support for cyber security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/strategy/29101/six-ways-boards-can-step-up-support-for-cyber-security</link>
                                                                            <description>
                            <![CDATA[ Security is an enterprise-wide risk management concern, not merely an IT issue ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kkxbQJgyPHRHA9fXZJ8vG4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9mhDVbhaNN3QbuzGhTRRE7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Jul 2017 15:37:00 +0000</pubDate>                                                                                                                                <updated>Thu, 22 Jul 2021 17:00:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Careers and Training]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Esther Kezia Thorpe ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPPgWan5PqHyFNtSS9gnbR.png ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9mhDVbhaNN3QbuzGhTRRE7-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A corporate boardroom filled with empty chairs against a long table]]></media:description>                                                            <media:text><![CDATA[A corporate boardroom filled with empty chairs against a long table]]></media:text>
                                <media:title type="plain"><![CDATA[A corporate boardroom filled with empty chairs against a long table]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9mhDVbhaNN3QbuzGhTRRE7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For organisations both large and small, cyber attacks are a constant concern, with a recent <a href="https://www.accenture.com/_acnmedia/PDF-96/Accenture-2019-Cost-of-Cybercrime-Study-Final.pdf#zoom=50" target="_blank">study</a> revealing that 68% of business leaders feeling like their risks are increasing. Accountability for breaches and incidents now extends far beyond IT, and organisations are beginning to push <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> responsibility into the hands of the executive team and board.</p><p>Business leaders don't want to be making headlines for being the latest victim of a data breach, and as a result, are actively trying to manage risk. Cyber threats represent the lion's share of potential harm, and strategies to deal with security need to be aligned with wider business priorities. A <a href="https://www.csoonline.com/article/3338562/cyber-risk-management-theres-a-disconnect-between-business-and-security-teams.html" target="_blank">survey</a> by the Enterprise Strategy Group showed that four in 10 executives and directors now want security status reports for cyber risk associated with end-to-end business processes.</p><p>So how can boards step up to the cyber security challenge and work effectively with CISOs?</p><h3 class="article-body__section" id="section-expand-board-expertise"><span>Expand board expertise</span></h3><p>Business leaders are beginning to understand that cyber security is an enterprise-wide risk management concern, not merely an IT issue. While the <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do" target="_blank" data-original-url="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO role</a> is evolving, the makeup of the board is evolving too.</p><p>Corporate boards are looking for increased technical literacy and are actively pursuing digital directors and advisors that can deliver high levels of both technical and business acumen.</p><p>All board members need to fully understand the role they play in overseeing cybersecurity and push for board-specific reporting and cyber security transparency. This combination increases the board's availability to ask the right questions and provide the right communication opportunities for the CISO.</p><h3 class="article-body__section" id="section-build-collaborative-relationships-with-the-ciso"><span>Build collaborative relationships with the CISO</span></h3><p>Collaboration is the essence of good cyber security practices, and that's why all parties need to work together to ensure clear lines of communication and incident preparation. One way to strengthen collaboration is for executive leaders and board members to be proactive about working hand-in-hand with CISOs. This will allow everyone to position themselves within the company and withstand the incessant onslaught of attacks.</p><p>Nearly one-third of board members are dissatisfied with the quality of information they get regarding cyber security risk, so CISOs and board members must work together to have meaningful conversations with all parties involved by telling them what information they want and how often they need it. An open dialogue about current threats, emerging attack patterns and incident response protocol leads to smarter decisions and better business outcomes.</p><p>However, the boards should also remember that cyber security doesn’t end with the CISO, but also the team of cyber security experts managed by them. Like many parts of the tech industry, cyber security is rife with difficult working conditions and stressful conditions, which enable a culture of toxicity and bullying. A <a href="https://www.itpro.com/business-strategy/careers-training/360316/one-third-cyber-sec-pros-experienced-harassment" data-original-url="https://www.itpro.com/business-strategy/careers-training/360316/one-third-cyber-sec-pros-experienced-harassment">recent survey</a> found that 47% of cyber security professionals have experienced some degree of bullying behaviour in the office, something that Respect in Security co-founder Nikki Webb claims has been further magnified by the <a href="https://www.itpro.com/business-strategy/flexible-working/356902/continued-remote-working-could-lead-to-ghost-towns" data-original-url="https://www.itpro.com/business-strategy/flexible-working/356902/continued-remote-working-could-lead-to-ghost-towns">shift to remote working.</a></p><p>Moreover, reporting workplace harassment is often looked down upon due to the misconception that doing so means that the victim is disloyal to the company or the community. Respect in Security found that, of 302 professionals surveyed, 16% said they wouldn’t report an instant of harassment, either by choosing not to (9%) or because of fear (7%), and the lack of discussion surrounding harassment in the cyber security sector means that the issue is likely just the tip of the iceberg.</p><p><a href="https://www.itpro.com/business-strategy/careers-training/356647/how-do-we-undo-securitys-toxic-culture" data-original-url="https://www.itpro.com/business-strategy/careers-training/356647/how-do-we-undo-securitys-toxic-culture">Last year</a>, Jinan Budge, principal analyst for security and risk at Forrester Asia Pacific told <em>IT Pro</em> that a toxic work environment leads to lower productivity, making the organisation more vulnerable to cyber threats:</p><p>“The ultimate problem with a toxic culture is that it means you’re not looking after the organisation’s cybersecurity, which is effectively the team’s sole reason for being. I’ve seen this happen – teams are so busy dealing with in-fighting that they’re unproductive. Sometimes the biggest enemy is not actually the adversary, but the team itself,” he said.</p><h3 class="article-body__section" id="section-understand-the-impact-of-cyber-threats"><span>Understand the impact of cyber threats</span></h3><p>While many businesses have developed cyber security strategies and <a href="https://www.itpro.com/strategy/29648/how-to-create-a-business-continuity-plan" target="_blank" data-original-url="https://www.itpro.com/strategy/29648/how-to-create-a-business-continuity-plan">business continuity</a> plans, the government's <a href="https://www.gov.uk/government/news/uk-boards-of-biggest-firms-must-do-more-to-be-cyber-aware" target="_blank">Cyber Governance Health Check</a> showed that less than a fifth (16%) of the board had a comprehensive understanding of the impact of loss or disruption associated with cyber threats. That's despite 96% of them having a cyber security strategy in place.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/enterprise-security/34017/who-should-take-ownership-of-your-cyber-security-strategy" data-original-url="/enterprise-security/34017/who-should-take-ownership-of-your-cyber-security-strategy">Who should take ownership of your cyber security strategy?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29068/is-your-company-taking-enough-accountability-on-cybersecurity" data-original-url="/security/29068/is-your-company-taking-enough-accountability-on-cybersecurity">Is your company taking enough accountability on cyber security?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="/security/28133/what-is-cyber-security">What is cyber security?</a></p></div></div><p>In addition to showing support for a company's cyber security strategy and initiatives, boards should actively engage the CISO to work with them on other organisational approaches, such as incident response programmes, which need to be continuously reevaluated and updated to address increasing activity in cyber attacks.</p><h3 class="article-body__section" id="section-expect-security-reporting-discipline"><span>Expect security reporting discipline</span></h3><p>Security is now a key business function and should be treated that way. It is vital to ensure CISOs know what reporting metrics and benchmarks are valuable to the board by applying a reporting discipline with consistent benchmarks and actionable information.</p><p>Although approaches and formats may vary, board members look for regularity in reporting from CISOs. Some look for programme-level updates for defined benchmark presentations where any important changes are highlighted. Boards and CISOs, then, should work together to develop a functional reporting system which can be delivered regularly.</p><h3 class="article-body__section" id="section-be-clear-about-your-innovation-needs"><span>Be clear about your innovation needs</span></h3><p>In an industry where every operational change is technology-driven, continual investment in new functions and capabilities to spark innovation is essential. At the same time, there is a balance to be struck between innovation and introducing technology that risks your business effectiveness, and this can create a state of constant security and compliance catch-up.</p><p>Business growth may be at the heart of most organisations, but the board is charged with helping to determine the trade-offs between risk and returns. Clearly communicated financial and operational risk tolerance prioritisation from the board and executive team will allow the CISO to effectively manage expectations.</p><h3 class="article-body__section" id="section-request-regular-attendance-at-meetings"><span>Request regular attendance at meetings</span></h3><p>Where CISOs were once asked to appear at meetings on specific occasions, CISO attendance at regular board meetings is now much more common. Boards should proactively allocate time at board meetings to hear from the CISO and examine future trends and risks as well as more immediate priorities.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="yi42ZzWeFY9Fmacd8eDdk3" name="yi42ZzWeFY9Fmacd8eDdk3.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/yi42ZzWeFY9Fmacd8eDdk3.jpg" mos="https://cdn.mos.cms.futurecdn.net/yi42ZzWeFY9Fmacd8eDdk3.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Five questions to ask before you upgrade to a modern SIEM</strong></p><p class="fancy-box__body-text">Do you need a better defense strategy?</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/security-information-and-event-management-siem/360173/five-questions-to-ask-before-you" data-original-url="/security/security-information-and-event-management-siem/360173/five-questions-to-ask-before-you">FREE DOWNLOAD</a></p></div></div><p>"Cyber security is a mainstream business risk, and board members need to understand it in the same way they understand financial or health and safety risks," <a href="https://www.gov.uk/government/news/uk-boards-of-biggest-firms-must-do-more-to-be-cyber-aware" target="_blank">said</a> Ciaran Martin, CEO of the NCSC.</p><p>As cyber threats continue to evolve, it may not be possible to completely eliminate the possibility of falling victim to an attack. But with a proactive cybersecurity strategy in place that is supported by the board, <a href="https://www.grantthornton.co.uk/insights/why-boards-need-to-pay-attention-to-cyber-security" target="_blank">research</a> has shown that financial losses in the event of a successful attack are lower.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Read Google's five rules for human-friendly AI ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/public-sector/26766/read-googles-five-rules-for-human-friendly-ai</link>
                                                                            <description>
                            <![CDATA[ Google updates Asimov's Three Laws of Robotics for AI developers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">n2NtByyhw9arEkPjEiP5nE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zDhxLYt7ztgZdgbntwEoDS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jun 2016 11:04:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Machine learning]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Aaron Lee ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zDhxLYt7ztgZdgbntwEoDS-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zDhxLYt7ztgZdgbntwEoDS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has come up with five rules to create human-friendly AI - superseding Isaac Asimov's <a href="https://en.wikipedia.org/wiki/Three_Laws_of_Robotics" target="_blank">Three Laws of Robotics</a>.</p><p>The tech giant, whose DeepMind division recently devised <a href="https://www.itpro.com/strategy/26189/alphago-emerges-victorious-in-human-vs-ai-go-battle" target="_blank" data-original-url="https://www.itpro.com/strategy/26189/alphago-emerges-victorious-in-human-vs-ai-go-battle">an AI capable of beating the world's best Go player</a> - believes AI creators should ask themselves these <a href="https://research.googleblog.com/2016/06/bringing-precision-to-ai-safety.html" target="_blank">five fundamental questions</a> to avoid the risk of a singularity in which robots rule over humankind.</p><p>Google Research's Chris Olah outlined the questions in a research paper titled <em><a href="https://arxiv.org/abs/1606.06565" target="_blank">Concrete Problems in AI Safety</a></em>, saying: "While possible AI safety risks have received a lot of public attention, most previous discussion has been very hypothetical and speculative.</p><p>"We believe it's essential to ground concerns in real machine learning research, and to start developing practical approaches for engineering AI systems that operate safely and reliably."</p><p>Published in collaboration with OpenAI, Stanford and Berkley, the paper takes a cleaning robot as an example to outline the following five rules.</p><p><strong>Avoiding negative side effects:</strong> Ensuring that an AI system will not disturb its environment in negative ways while completing its tasks.</p><p><strong>Avoiding reward hacking:</strong> An effective AI needs to complete its task properly without cutting corners.</p><p><strong>Scalable oversight:</strong> AI needs to learn from feedback, and should not need continuous feedback from a human programmer.</p><p><strong>Safe exploration:</strong> AI needs to avoid damaging objects in its environment as it performs its task.</p><p><strong>Robustness to distributional shift:</strong> AI should be able to adapt to an environment that it has not initially been conditioned for, and still perform.</p><p>Google has thrown much of its resources at developing deep learning and AI, amid a backdrop of fear of robots, voiced by luminaries including SpaceX founder Elon Musk and <a href="https://www.itpro.com/it-legislation/23829/stephen-hawking-signs-open-letter-against-ai-pitfalls" target="_blank" data-original-url="https://www.itpro.com/it-legislation/23829/stephen-hawking-signs-open-letter-against-ai-pitfalls">scientist Stephen Hawking</a>.</p><p><a href="https://www.itpro.com/strategy/26677/googles-big-red-button-should-stop-ai-becoming-too-powerful" target="_blank" data-original-url="https://www.itpro.com/strategy/26677/googles-big-red-button-should-stop-ai-becoming-too-powerful">DeepMind is working on a failsafe</a> that would effectively shut off AI in the event it attempted to disobey its users.</p><p>Other firms including Microsoft are exploring AI, getting <a href="https://www.itpro.com/desktop-software/26681/microsoft-s-new-ai-tells-stories-based-on-your-photos" target="_blank" data-original-url="https://www.itpro.com/desktop-software/26681/microsoft-s-new-ai-tells-stories-based-on-your-photos">AI to tell stories about holiday photos</a>, and debuting its <a href="http://www.cloudpro.co.uk/marketing/5889/microsoft-follows-tay-chatbot-with-fresh-bot-projects-for-cortana-and-skype" target="_blank">tween chatbot, Tay, which spouted rude replies on Twitter</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft targets .NET Core with new bug bounty rewards ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/26694/microsoft-targets-net-core-with-new-bug-bounty-rewards</link>
                                                                            <description>
                            <![CDATA[ Redmond offers more cash prizes for sourcing errors in its upcoming web frameworks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hQsr7aFMmbiQAVpacQq5hw</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iBN5XN9Pa9q83iPiUcp8ni-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Jun 2016 10:33:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Microsoft]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Aaron Lee ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iBN5XN9Pa9q83iPiUcp8ni-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft Sign]]></media:description>                                                            <media:text><![CDATA[Microsoft Sign]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft Sign]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iBN5XN9Pa9q83iPiUcp8ni-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has expanded its bug bounty programme to include new web and application technologies that are due for release in the coming months.</p><p>The company's latest programme will focus on the web application frameworks .NET Core and ASP.NET Core RC2 beta builds, which were revealed <a href="https://blogs.msdn.microsoft.com/webdev/2016/05/16/announcing-asp-net-core-rc2" target="_blank">last month</a>.</p><p>Jason Shirk, senior director of Microsoft's Security Response Center, said the latest programme will run until 7 September this year.</p><p>The platforms for testing will be Windows, OS X and Linux.</p><p>Rewards for qualifying bug discoveries will range from a minimum of $500 up to $15,000, depending on the severity of the security flaw.</p><p>In order to qualify for a reward, researchers must submit an eligible and previously unreported bug. Accepted submissions include remote code execution (RCE) faults, security design flaws, remote denial-of-service (DoS) holes, spoofing weaknesses, information leaks and XSS vulnerabilities.</p><p>"Bounties will be worked alongside the Security Development Lifecycle (SDL), Operational Security Assurance (OSA) framework, regular penetration testing of our products and services, and Security and Compliance Accreditations by third party audits," said Shirk.</p><p>This new programme has succeeded Microsoft's previous CoreCLR and ASP.NET 5 beta bounty hunts.</p><p>Other Microsoft bounty programmes include the ongoing Nano Server beta, Online Services, and Mitigation bypass and Bounty for Defense programme.</p><p>More information about the .NET Core and ASP.NET Core RC2 programme can be found on the <a href="https://blogs.technet.microsoft.com/msrc/2016/06/07/microsoft-bounty-program-expansion-net-core-and-asp-net-rc2-beta-bounty" target="_blank">Microsoft blog</a> and <a href="https://technet.microsoft.com/en-us/security/mt574248" target="_blank">technet programme page</a>.</p><p>The RC2 application can be <a href="https://www.microsoft.com/net/download#core" target="_blank">downloaded here</a>.</p><p>Microsoft frequently runs bug bounty programmes on its services. In 2014 it ran a <a href="https://www.itpro.com/desktop-software/23180/microsoft-opens-up-bug-bounty-programme-for-online-services" target="_blank" data-original-url="https://www.itpro.com/desktop-software/23180/microsoft-opens-up-bug-bounty-programme-for-online-services">programme for Office 365</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Man who 'deleted company with one line of code' admits it was all a hoax ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/networking/26363/man-who-deleted-company-with-one-line-of-code-admits-it-was-all-a-hoax</link>
                                                                            <description>
                            <![CDATA[ Marco Masala admits the story was a viral marketing ploy ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kMGYkBPVb3VxpEQkBMkyjw</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hgcRdTjdVBZQ4iUBSY8GAa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 18 Apr 2016 10:04:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Backup]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Aaron Lee ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hgcRdTjdVBZQ4iUBSY8GAa-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hgcRdTjdVBZQ4iUBSY8GAa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A man who supposedly erased his entire company with a single line of faulty code has admitted to crying wolf.</p><p>Marco Marsala invented the whole story as a guerrilla marketing ploy in order to promote his start-up, which provides outsourced server management, according to an interview with Italian publication <a href="http://www.repubblica.it/tecnologia/2016/04/15/news/cancella_l_azienda_per_sbaglio_la_disavventura_tecnologica_di_marco_marsala-137693154/?ref=twhr&timestamp=1460722285000&utm_source=dlvr.it&utm_medium=twitter&refresh_ce" target="_blank"><em>Repubblica</em></a>,.</p><p>Marsala gained internet notoriety last week, after news broke that he had apparently torpedoed his entire web hosting company by accidentally wiping the servers with the command 'rm - rf'.</p><p>In a now-deleted post on the support website Server Fault, he asked if there was anything he could do. General consensus was that the error was irreversible. In the words of one commenter: "you're going out of business. You don't need technical advice, you need to call your lawyer".</p><p>It turns out, however, that the open-source Ansible platform actually prevents catastrophic errors such as this - at least, according to Marsala.</p><p>"The command that I mentioned in the article is harmless but it seems that almost no one has noticed", he said. "Almost every serious administrator uses it but among those who answered no one seems to know."</p><p>The story of nuking an entire company with one command is not completely fabricated, though - Marsala claimed that it really happened to an acquaintance. "There was an article in the newspaper", he added.</p><p>Marsala also told the publication he invented the story as "an experiment", in order to test how knowledgeable developers are about this type of thing. "With the inaccuracies that are there in the online comments I could write a book", he said.</p><p><strong>15/04/2016: Hosting provider accidently obliterates his company with one line of bad code</strong></p><p>A web host appears to have accidently wiped the entire computer network for his company and its clients, obliterating his business in the process.</p><p>Hosting provider Marco Marsala accidently instructed his computer to delete everything stored on his servers, removing all of his own company data and that of his 1,535 customers.</p><p>After running the destructive code on his own network, Marsala turned to <a href="http://serverfault.com/questions/769357/recovering-from-a-rm-rf">Server Fault</a>, a forum for server experts, to seek assistance for how he might recover his lost data.</p><p>Unfortunately, instead of a workable solution, one after another, the experts told him, "your company is now essentially dead".</p><p>The problem command was rm -rf', a piece of code that will delete everything it is instructed to. The rm' portion tells the computer to remove; the r deletes everything within a select directory; and the f stands for force', instructing the computer to ignore the standard warning notifications that come when deleting critical files.</p><p>Usually, this piece of code would be used only to wipe specific directories that it was directed it. But because Marsala made an error in his selection, he managed to accidently instruct the computer to wipe everything.</p><p>"I run a small hosting provider with more or less 1,535 customers and I use Ansible to automate some operations to be run on all servers," wrote Marsala on the forum.</p><p>"Last night I accidentally ran, on all servers, a Bash script with a rm -rf {foo}/{bar} with those variables undefined due to a bug in the code above this line."</p><p>In a situation such as this, the natural expectation would be for a hosting provider to reach for its system-wide backup. But it seemed that Marsala had managed to lose that, too.</p><p>"All servers got deleted and the offsite backups too because the remote storage was mounted just before by the same script (that is a backup maintenance script)."</p><p>One respondent felt Marsala's should have kept his backups separate from all of his other server data.</p><p>"Backups need to be offsite, offline, and incremental. That you could delete them from your main server means they weren't what I would call backups," wrote Tim.</p><p>Others were more blunt in their appraisal of the situation, such as Andr Borie, who wrote: "If you really don't have any backups I am sorry to say but you just nuked your entire company".</p><p>Michael Hampton wrote: "You're going out of business. You don't need technical advice, you need to call your lawyer".</p><p>IT Pro contributor Stephen Pritchard wrote last year that <a href="https://www.itpro.com/data-loss-prevention/24086/fail-to-plan-plan-to-fail-firms-neglect-recovery-plans-at-their-peril" target="_blank" data-original-url="https://www.itpro.com/data-loss-prevention/24086/fail-to-plan-plan-to-fail-firms-neglect-recovery-plans-at-their-peril">firms neglect disaster recovery plans at their peril</a>. In this particular case, perhaps a watertight insurance policy may also be necessary.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Uber launches bug bounty programme with $10k prize ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/26256/uber-launches-bug-bounty-programme-with-10k-prize</link>
                                                                            <description>
                            <![CDATA[ Keen bug tracers will need to find five genuine bugs to receive their first payout ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2EBfmAvQuL4yPWZ94hCYFt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EoN4fAypkarxjMpe2xbbuN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Mar 2016 11:29:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Aaron Lee ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EoN4fAypkarxjMpe2xbbuN-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A red padlock with a binary code label surrounded by circuits.]]></media:description>                                                            <media:text><![CDATA[A red padlock with a binary code label surrounded by circuits.]]></media:text>
                                <media:title type="plain"><![CDATA[A red padlock with a binary code label surrounded by circuits.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EoN4fAypkarxjMpe2xbbuN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Uber has launched an official bug bounty programme, and is offering cash rewards of up to $10,000 (7,049) for the discovery of errors in its systems.</p><p>The transport company ran a trial programme with 200 security researchers last year who found almost 100 bugs, which Uber said it has already fixed.</p><p>The success of that trial is why it has chosen to launch a public bug bounty programme now.</p><p>In addition to up to the monetary reward for the discovery of "critical issues", Uber said it is creating a "first-of-its-kind loyalty reward programme" to incentivise the security community to help quash bugs in its systems.</p><p>"Even with a team of highly-qualified and well trained security experts, you need to be constantly on the look out for ways to improve," said Joe Sullivan, chief security officer at Uber.</p><p>"This bug bounty program will help ensure that our code is as secure as possible. And our unique loyalty scheme will encourage the security community to become experts when it comes to Uber."</p><p>Uber's first reward programme season will commence on 1 May and will last 90 days.</p><p>Bug tracers will be eligible for the reward programme once they have found four issues that have been accepted by Uber as genuine bugs.</p><p>If they then find a fifth issue within the 90-day session, they will get a bonus payout equivalent to 10 per cent of the average payouts for all the other issues found in that session.</p><p>Uber has put together a <a href="https://eng.uber.com/bug-bounty" target="_blank">rolling guide</a> to show researchers how to find different classes of bug across its codebase.</p><p>More information about the programme can be <a href="https://hackerone.com/uber" target="_blank">found here</a>.</p><p>Bug bounty programmes are a fairly common part of the ecosystem for large tech businesses today, with Microsoft recently adding <a href="http://www.cloudpro.co.uk/collaboration/5882/microsoft-adds-onedrive-to-bug-bounty-programme" target="_blank">OneDrive to its bug bounty programme</a>.</p><p>Although Uber's technical presence has set an example for others, the company has been fighting court battles over its car sharing networks. Most recently two Uber executives in French <a href="https://www.itpro.com/public-sector/26042/trial-of-two-french-uber-executives-begins" target="_blank" data-original-url="https://www.itpro.com/public-sector/26042/trial-of-two-french-uber-executives-begins">denied their involvement in what has been deemed an "illegal" taxi service</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Worst passwords’ list 2015 topped by 123456 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/25894/worst-passwords-list-2015-topped-by-123456</link>
                                                                            <description>
                            <![CDATA[ Annual list of most commonly used passwords included Star Wars-related terms ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xzHhfHcaePk2kmgZnxUXqy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eJcZhZKtCnpLaUjBtujfFL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 20 Jan 2016 12:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Aaron Lee ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eJcZhZKtCnpLaUjBtujfFL-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Password label]]></media:description>                                                            <media:text><![CDATA[Password label]]></media:text>
                                <media:title type="plain"><![CDATA[Password label]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eJcZhZKtCnpLaUjBtujfFL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The most commonly used password of 2015 was '123456', according to an annual list from security firm SplashData.</p><p>The company has been compiling a list of the world's most common passwords, and by extension the "worst passwords", for five years, reminding people that a poor password leaves them more exposed hacking or having their personal details accessed.</p><p>SplashData's report was compiled from more than two million leaked passwords during 2015. '123456' and 'password' have held onto the top two positions since the first list in 2011.</p><p>Other passwords in the top 10 include 'qwerty', 'football' and 'baseball'.</p><p>Last year, however, the top 25 most common passwords also included 'starwars', as well as terms that could well be related to the popular sci-fi series, which was a talking point throughout 2015.</p><p>New terms in the 2015 list that bear relation to Star Wars included: 'princess' (as in Princess Leia) and 'solo' (as in Han Solo). Not to mention the returning term 'master' (as in Jedi master).</p><p>Other passwords on the 2015 list that did not appear on the 2014 list included 'welcome', 'login' and 'passw0rd'. The Force was not strong with these passwords, SplashData quipped.</p><p>Having a strong password is not a guarantee of security. 2015 witnessed major hacks against <a href="https://www.itpro.com/security/24136/talktalk-hack-two-men-plead-guilty-to-talktalk-hack" data-original-url="https://www.itpro.com/security/24136/talktalk-hack-two-men-plead-guilty-to-talktalk-hack">TalkTalk</a>, and previously unknown sites like <a href="https://www.itpro.com/security/25171/ashley-madison-data-breach-leads-to-112m-settlement" data-original-url="https://www.itpro.com/security/25171/ashley-madison-data-breach-leads-to-112m-settlement">Ashley Madison</a>. But it's not just online account information at risk. A poor password on a Wi-Fi router or your tablet computer could expose you to data theft locally.</p><p>In the five years that SplashData has been compiling its list, many of the passwords in the top 25 -- often basic numerical strings '1234567890' -- have remained that same.</p><p>In order to better protect themselves, the company recommends that people use passwords or passphrases of 12 characters or more with mixed types of characters; avoid using the same password over and over again on different websites; and use a password manager to organise, protect and generate random passwords.</p><p>Reflecting on this year's list, SplashData CEO, Morgan Slain, said: "We have seen an effort by many people to be more secure by adding characters to passwords, but if these longer passwords are based on simple patterns they will put you in just as much risk of having your identity stolen by hackers."</p><p>The full list of 2015's 25 most commonly used passwords is below:</p><ul><li>password</li><li>12345678</li><li>qwerty</li><li>12345</li><li>123456789</li><li>football</li><li>1234</li><li>1234567</li><li>baseball</li><li>welcome</li><li>1234567890</li><li>abc123</li><li>111111</li><li>1qaz2wsx</li><li>dragon</li><li>master</li><li>monkey</li><li>letmein</li><li>login</li><li>princess</li><li>qwertyuiop</li><li>solo</li><li>passw0rd</li><li>starwars</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Lumension takes wraps off new enterprise security product ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/19703/lumension-takes-wraps-new-enterprise-security-product</link>
                                                                            <description>
                            <![CDATA[ LEMSS 7.3 promises to protect against more pernicious attacks, such as RMI, says vendor. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">i65AwxaSyAwQxBBQoRiemH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6xBrYBEAS4v6TtLinhArye-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 25 Apr 2013 13:09:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6xBrYBEAS4v6TtLinhArye-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6xBrYBEAS4v6TtLinhArye-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Endpoint security company Lumension has unveiled the latest version of its Lumension Endpoint Management and Security Suite (LEMSS), which offer enterprises enhanced protection against advanced persistent threats (APTs).</p><p>The company is particularly keen to emphasise LEMSS 7.3's ability to protect against reflective memory injections (RMIs) that it claims can be virtually impossible to detect or remove.</p><div><blockquote><p>MDM is moving very quickly with BYOD initiatives and what people require seems to be changing almost weekly.</p></blockquote></div><p>Alan Bentley, SVP worldwide at Lumension, told <em>IT Pro</em>: "These types of attack compromise legitimate applications through their memory.</p><p>"The difficulty with memory-based threats is, if it is not doing anything through the OS, is not using OS functions or is not writing anything to disk, it will go undetected by traditional antivirus."</p><p>Bentley explained that anything sat in the memory, such as an RMI, can be got rid of by rebooting the affected machine, it is often too late by then, as the code from the RMI has been used to compromise the target application with malicious code.</p><p>While this is not a method of malware infection that is seen very often, Bentley believes it is something that is going to increase in popularity among the cyber criminal community.</p><p>The organisation also intends to introduce new mobile device management (MDM) functionality to LEMSS, although that is not included in the current 7.3 release.</p><p>"This whole MDM space is moving very quickly with the bring your own device (BYOD) initiatives and what people require seems to be changing almost weekly. So we decided to start where we knew our customers wanted to go," said Bentley.</p><p>"We talked to a number of our customers and asked if we were to bring in on platform MDM, what that would need to look like and have decided to build it up ourselves. Just like the rest of LEMSS, it is about giving visibility to administrators and assigning different policies and protections according to device type, ownership and so on," he concluded.</p><p>LEMSS with MDM capability is expected to be available in the latter half of the year.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cryptzone CEO gives his account of the events that led to NETconsent MBO ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/644575/cryptzone-ceo-gives-his-account-of-the-events-that-led-to-netconsent-mbo</link>
                                                                            <description>
                            <![CDATA[ Security vendor's CEO denies challenges around acquisitions were factor in NETconsent's retreat. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">epgs871fj8WCg4y6DQZZfb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mnKDhhJkBWcbJGXMPuMwj9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Dec 2012 15:46:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mnKDhhJkBWcbJGXMPuMwj9-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Deal torn up]]></media:description>                                                            <media:text><![CDATA[Deal torn up]]></media:text>
                                <media:title type="plain"><![CDATA[Deal torn up]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mnKDhhJkBWcbJGXMPuMwj9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security vendor Cryptzone has spoken out about NETconsent's management buyout, denying an inability to integrate its acquisitions was the cause of the breakup.</p><p>Cryptzone chief Einar Lindquist spoke to <em>IT Pro</em> after NETconsent's CEO Dominic Saunders claimed his firm had struggled to give NETconsent the attention it needed after acquiring the firm in 2010.</p><p>Saunders also claimed Cryptzone had found it difficult to integrate its other acquisitions and manage UK-based NETconsent from its base in Sweden.</p><p>Lindquist said acquiring a company is "always a challenge", let alone one that is based overseas.</p><p>"You have to keep in mind when you acquire a business you don't acquire the product, you acquire people. It sounds very brutal, but that is the way it is, and we acquired the full team of NETconsent," he said.</p><p>"So they didn't need us to manage the business, they needed us to integrate the business and that is not easy when you are in two different countries," he added.</p><p>However, these difficulties were not a factor in the decision to part ways, Lindquist said.</p><p>Instead, a decision to retrench in the company's core business of security was the deciding factor, he claimed.</p><p>Lindquist told <em>IT Pro</em> he had spoken with Saunders when he took over as Cryptzone's CEO in June 2012, telling him he would not have "the muscle or economy" to support NETconsent given the direction the company had decided to take over the next few years.</p><p>"We decided then that it was a good chance for him to take care of NETconsent, which has been a good acquisition for us and is a good buyback for him. It is a win-win," Lindquist added.</p><p>The company is in the process of doing a management buyout with another of its 2010 acquisitions, Swedish firm SE46, Lindquist revealed.</p><p>"[Secure access product AppGate and security for SharePoint] will be our main offerings in the future, which means that is where we are going to invest our money," he said.</p><p>"NETconsent and SE46 have been good acquisitions, but are not where we are going in the future, so it is a very conscious decision [to divest]."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cambridge University boffins to combat rise of the machines ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/644335/cambridge-university-boffins-to-combat-rise-of-the-machines</link>
                                                                            <description>
                            <![CDATA[ Scientists to look at ways to see off Terminator-style threat ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6Y3ns7GF5EubPgbJjVMdNq</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Wga7jERrmoszMTBMfMWLyc-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 26 Nov 2012 10:46:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/Wga7jERrmoszMTBMfMWLyc-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Brain]]></media:description>                                                            <media:text><![CDATA[Brain]]></media:text>
                                <media:title type="plain"><![CDATA[Brain]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Wga7jERrmoszMTBMfMWLyc-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cambridge University is set to open a centre to study the possible dangers of advanced artificial intelligence.</p><p>The proposed Centre for the Study of Existential Risk (CSER) will open on campus next year by philosophy professor Huw Price, cosmology professor Martin Rees, and Skype co-founder Jann Tallinn.</p><p>The centre will look into the possible ways artificial intelligence could "threaten our own existence".</p><p>We shouldn't take artificial general intelligence (AGI) for granted.</p><p>"At some point, this century or next, we may well be facing one of the major shifts in human history perhaps even cosmic history when intelligence escapes the constraints of biology," said Price.</p><p>"We need to take seriously the possibility that there might be a Pandora's box' moment with AGI that, if missed, could be disastrous. I don't mean that we can predict this with certainty, no one is presently in a position to do that, but that's the point! With so much at stake, we need to do a better job of understanding the risks of potentially catastrophic technologies."</p><p>Price, alongside his colleagues questioned whether the increasing amount of technological progress will increase humanity's chance of survival.</p><p>"Think how it might be to compete for resources with the dominant species," said Price. "Take gorillas for example the reason they are going extinct is not because humans are actively hostile towards them, but because we control the environments in ways that suit us, but are detrimental to their survival."</p><p>People from the fields of science, policy, law, risk and computing from across the university and outside are set to become advisors to the new centre.</p><p>"The basic philosophy is that we should be taking seriously the fact that we are getting to the point where our technologies have the potential to threaten our own existence in a way that they simply haven't up to now, in human history," said Price.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Data security: is breach mitigation all that's left? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/641989/data-security-is-breach-mitigation-all-thats-left</link>
                                                                            <description>
                            <![CDATA[ If you accept the premise that it's inevitable your enterprise network will be attacked, and most likely breached, then is mitigation really where the IT security focus should be? Davey Winder investigates... ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uSdEFeZWAVjc33mG4C8Ro4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DWknACHYxTv4TgBoUVKPuU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 30 Jul 2012 08:34:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DWknACHYxTv4TgBoUVKPuU-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[security on computer]]></media:description>                                                            <media:text><![CDATA[security on computer]]></media:text>
                                <media:title type="plain"><![CDATA[security on computer]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DWknACHYxTv4TgBoUVKPuU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>COMMENT: I was recently talking to someone who brute forced a BT Business Hub, the sort used by hundreds of thousands of businesses across the UK, using hardware costing less than 35 and it supposedly took him less than 48 hours to crack the 10 character default WPA key.</p><p>Invest just a little more money and that timescale starts to look like an absolute age. The truth is that it's a lot easier than you may imagine to breach the network perimeter these days, and if an attacker is determined enough then the chances are they will succeed.</p><p>Iit's better to assume your organisation has already been compromised and develop defences based around that assumption.</p><p>Even large corporates can fall foul of the weakest link scenario, with the hacker following a likely looking 'suit' home and cracking the most likely default Wi-Fi router encryption. From here it's a relatively simple journey to the machine they have attached to the corporate VPN.</p><p>"All organisations are susceptible to being breached and anything contrary to that fact is false," claims Marcus Carey, a security researcher at Rapid7. "It is impossible to eliminate all risk when it comes to network security." IT security is all about minimising the risk level through the use of defence in-depth strategies and incident response plans: detect and destroy is the motto of the day.</p><p>So is it right to suggest, as I have done in the introduction to this piece, that a network breach is all but inevitable? Perhaps unsurprisingly opinion is divided on this one. Wade Baker, director of risk intelligence at Verizon, reckons that taking such a view is "unhelpful at best" and points out that "97 per cent of the attacks analysed in the 2012 Verizon Data Breach Investigation Report were avoidable, without the need for organisations to resort to difficult or expensive countermeasures."</p><p>He does, however, admit that the security industry has long been guilty of placing the emphasis on prevention and not enough into detection and response. "Risk mitigation implies companies assume an almost passive role, checking no alarms have been tripped and watching who is trying to climb over the walls," Baker insists, concluding "I would suggest that we need agile security teams that can take a proactive role and not only monitor external attacks, but also gain visibility of what is going on inside the network to check no one has sneaked past defences."</p><p>Darien Kindlund, senior staff scientist at security specialist FireEye, is succinct in his disagreement. "In fact, it's better to assume your organisation has already been compromised and develop defences based around that assumption," he told <em>IT Pro</em>. "You will be less surprised and better prepared, accordingly".</p><p>Or, as Arun Sood from SCIT Labs puts it: "The current cyber security approaches rely on prior knowledge of the vulnerabilities and the threats. However, the current approaches are in-adequate. Ensuring reliable and accurate knowledge of the vulnerabilities and the attacker, is impossible - there are far too many threads to track at any one time. Attempts at increasing probability of detection leads to rapid increase in false positives and thus security operations costs. Thus we believe that intrusions are inevitable. Mitigation strategies are required for limiting the losses".</p><p>Dead duck security?</p><p>But if the mitigation argument holds up, where does that leave attack prevention? Is it really pointless to try and prevent a breach, and should resources therefore be focused on containment instead? Filippo Cassini, vice president of International Systems Engineering at Fortinet, certainly doesn't hold with the 'pointless' argument, suggesting that leaving prevention out of the equation "would be like taking away seat belts from a car because we have airbags." Or as</p><p>Kevin Dowd, CEO at CNS says "surviving an advanced and sustained attack would be difficult for many businesses, but that doesn't mean they should give up." Indeed, he believes they should have counter measures in place that make an attack too challenging in terms of the resources needed. "This is where most businesses could do better," Dowd insists. "Often, SMEs think that they are too small or not visible enough to be a target."</p><p>Consequently, detective capabilities are often weak, the Verizon 2012 Data Breach Investigations Report found that 92 per cent of incidents were discovered by a third party, and businesses end up developing their security strategy under duress.</p><p>Mitigating post-hack is more difficult and expensive. "We estimate that every pound spent up front on security measures is worth ten pounds after a breach, when businesses can be faced with high emergency response rates and consultants on site for longer than would have previously have been necessary," Dowd adds.</p><p>Much of this can be mitigated into oblivion by getting rid of the sensitive data in the first place - by out sourcing payments so as to avoid holding card data, for example - and improving the governance structure.</p><p>In conclusion</p><p>It's all very well talking about mitigation in terms of containment and analysis, but this whole argument surely stands or falls on whether the breach itself is detected in a timely fashion. I would argue that, in far too many instances, detection doesn't happen until weeks after the breach event itself and sometimes those weeks can run into months.</p><p>Verizon's Baker told me that amongst the more advanced attacks he has investigated, such as those which target intellectual property, which are difficult to spot "many take a year or more to pinpoint, and we suspect that many more are simply never discovered by the victim."</p><p>I'm not suggesting that breach mitigation is a red herring, and it's certainly no dead duck either, but for mitigation strategy to work successfully it has to be coupled with effective real-time breach detection technology to prevent data loss.</p><p>"To be successful in attack mitigation you need to firstly, understand what's happening and then target your resources appropriately to contain and eradicate the threat," says Don Smith, director of technology at Dell SecureWorks, who warns that learning from your mistakes is a vital link in the chain and one that reactive mitigation alone is unlikely to forge.</p><p>"If your focus is always on reacting to successful breaches you are going to be the easiest target and will be breached a lot," Smith says. "You need to focus on prevention, monitoring and how you successfully respond to a breach, not spend all your time looking at the past."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ RSA's Art Coviello: Security industry going through hell ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/639205/rsas-art-coviello-security-industry-going-through-hell</link>
                                                                            <description>
                            <![CDATA[ A year after the hack on RSA, Art Coviello says the entire security industry has been going through 'hell.' ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cDQa6uiWqqETkENtKpsBww</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tTfu6kD4Kj7thByEM7JSyY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 28 Feb 2012 16:51:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tTfu6kD4Kj7thByEM7JSyY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security hell]]></media:description>                                                            <media:text><![CDATA[Security hell]]></media:text>
                                <media:title type="plain"><![CDATA[Security hell]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tTfu6kD4Kj7thByEM7JSyY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>RSA chairman Art Coviello opened his company's premier conference today by saying security providers have been "going through hell in the last 12 months."</p><p>Coviello was in boisterous mood during the <a href="https://www.itpro.com/639178/security-giants-go-cloud-crazy-with-rsa-launches" target="_blank" data-original-url="https://www.itpro.com/639178/security-giants-go-cloud-crazy-with-rsa-launches">RSA 2012</a> keynote as he took to the stage a year after the <a href="https://www.itpro.com/632023/rsa-servers-hacked-as-securid-data-stolen" target="_blank" data-original-url="https://www.itpro.com/632023/rsa-servers-hacked-as-securid-data-stolen">successful hack</a> of his own business, saying the industry was facing some "harsh realities."</p><p>"Never have so many security firms been attacked directly," Coviello said.</p><p>"An attack on one of us is an attack on all of us, but together we can all learn from these experiences and emerge from this hell, smarter and stronger than we were before.</p><p>An attack on one of us is an attack on all of us.</p><p>"As Winston Churchill once said, if you're going through hell keep going... We must fight back the only way we know how, through creativity and innovation."</p><p>Coviello issued a rallying call for the industry to produce different kinds of technologies, insisting vendors needed to move away from the old, perimeter-focused mentality.</p><p>The industry should focus on creating technologies that leverage big data to gather information on threats to then counter them, he said.</p><p>The end point protections of old are not good enough, nor are they flexible enough, the RSA chairman added.</p><p>"Today's systems are a patchwork of controls... serving up far too much data and not enough intelligence," he said.</p><p>Earlier today, RSA moved to align itself with a security start up that is pushing such innovation and moving away from the classic signature-based models.</p><p>The <a href="https://www.itpro.com/639202/rsa-and-zscaler-concocting-cloud-authentication-cure" target="_blank" data-original-url="https://www.itpro.com/639202/rsa-and-zscaler-concocting-cloud-authentication-cure">deal with Zscaler</a> will see the two selling a product that combines the agent-less, cloud-based model of the start up with RSA's well-known authentication services.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security giants go cloud crazy with RSA launches ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/639178/security-giants-go-cloud-crazy-with-rsa-launches</link>
                                                                            <description>
                            <![CDATA[ HP and RSA are two of the biggest firms launching cloudy products on the first day of the major security conference. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hrEuBKrEst5eco9Fyf5c5a</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9v9yMqD6aCgKvxzkpYZpba-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Feb 2012 20:58:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9v9yMqD6aCgKvxzkpYZpba-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud security]]></media:description>                                                            <media:text><![CDATA[Cloud security]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9v9yMqD6aCgKvxzkpYZpba-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A load of vendors have chosen to hone in on the cloud craze on the first day of RSA 2012, including HP and the host itself.</p><p>HP announced an expansion of its Security Intelligence and Risk Management (SIRM) offerings, which together are similar to other security information and event management (SIEM) products, such as <a href="https://www.itpro.com/639061/ibm-builds-on-q1-labs-acquisition-with-qradar-boost" target="_blank" data-original-url="https://www.itpro.com/639061/ibm-builds-on-q1-labs-acquisition-with-qradar-boost">IBM's recently-updated QRadar platform</a>.</p><p>The SIRM offering builds on HP's major acquisitions in the security sector over the past two years, including Arcsight, which was seen as the leader in the SIEM space.</p><p>RSA NetWitness Live has been instrumental to our customers in detecting and defeating advanced threats.</p><p>It also ties in Fortify and TippingPoint technology, packing in various pieces to help companies get a good view over " traditional, mobile and cloud environments."</p><p>The HP EnterpriseView feature, which starts at $250,000, gives an overall view of security, including a dashboard and heat map designed to let users know where the greatest risk lies.</p><p>The HP Application Security Monitor (AppSM), which starts at $5,000 per application server, brings centralised searching, reporting and analysis covering Java/.Net applications, including mobile ones.</p><p>Those two features are expected to arrive "soon," whilst others, including HP Mobile Application Security, the HP Compliance Stack and the HP TippingPoint Next-Generation Intrusion Prevention System are already available.</p><p>The host with the most?</p><p>Not to be outdone by partners on the first day of its flagship conference, RSA introduced an update of its NetWitness technology, acquired last year by EMC.</p><p>NetWitness Live has been given something of a turbo boost with 30 per cent more threat content and integration with RSA's analytics platforms to give companies a greater knowledge about dangers facing their networks.</p><p>"RSA NetWitness Live has been instrumental to our customers in detecting and defeating advanced threats," said Amit Yoran, senior vice president and general manager of RSA's security management and compliance division.</p><p>"By tapping into the collective intelligence and analytical skills of the global security community, the RSA NetWitness Live service helps organisations significantly enhance their situational awareness and shorten their time to respond to potential threats."</p><p>The cloud-based technology brings together information from the global intelligence community, amounting to around 100 different sources - 300 less than IBM's aforementioned QRadar service.</p><p>As for the analytics integration, customers will now be able to share relevant threat data across the RSA NetWitness for Logs platform and the RSA NetWitness Spectrum malware detection product.</p><p>The event has also seen Qualys, one of the original proponents of cloud-based security, <a href="https://www.itpro.com/639175/qualys-brings-ironbee-waf-to-life" target="_blank" data-original-url="https://www.itpro.com/639175/qualys-brings-ironbee-waf-to-life">launch its open source web application firewall</a>.</p><p>More cloudy announcements are expected over the next couple of days, so check back at <em>IT Pro</em> for all the latest from RSA 2012.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Are you ready to launch IPv6 securely? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/639139/are-you-ready-to-launch-ipv6-securely</link>
                                                                            <description>
                            <![CDATA[ Davey Winder says that despite the unnecessary scare stories, businesses need to think about migrating to IPv6 securely now. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">i4RiLVmcdVj1JSKPxdGDv1</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pcZNYg2praktFiaTK3eBFD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Feb 2012 15:18:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pcZNYg2praktFiaTK3eBFD-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IPv6]]></media:description>                                                            <media:text><![CDATA[IPv6]]></media:text>
                                <media:title type="plain"><![CDATA[IPv6]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pcZNYg2praktFiaTK3eBFD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Did you know that 6 June 2012 is <a href="https://www.itpro.com/638371/world-ipv6-launch-scheduled-for-6-june" target="_blank" data-original-url="https://www.itpro.com/638371/world-ipv6-launch-scheduled-for-6-june">IPv6 launch day</a>?</p><p>Nope me neither, but according to the Internet Society it is and everyone, it says, should be thinking about making the permanent move from their current IPv4 network to the new whizz-bang IPv6 one.</p><p>So will you be one of them? More to the point, are there any pressing security reasons why you shouldn't?</p><p>Arbor Networks has published the results of some research into the first wave of Distributed Denial of Service (DDoS) attacks on IPv6 networks, and the good news is that the figure is pretty damn low with just four per cent of those operating such networks reporting DDoS activity.</p><p>Time and research has shown that IPv6 is not more secure than IPv4.</p><p>In fact, the chances are high that these are not actually the first DDoS attacks against IPv6 networks at all, but rather the first ones that have been detected and reported. Which is also good news. It means that, at long last, we are starting to see discussions on this kind of threat in relation to IPv6.</p><p>But in less good news, the reports of DDoS attacks targeting IPv6 networks do suggest that as adoption amongst organisations picks up pace, so does the value to the bad guys.</p><p>Indeed, the fact that these attacks are happening at all suggests that the bad guys are also adopting IPv6 as they need a platform from which to launch them, and that platform has to be an IPv6 endpoint. That they have managed to compromise enough of these to launch DDoS attacks at all is worrying, and raises questions about how well those networks are being secured against such an eventuality.</p><p>"More than six years ago, one of the frequent rallying points for IPv6 was that it was more secure than IPv4... Time and research has shown that IPv6 is not more secure than IPv4," said Arbor Networks engineer Bill Cerveny.</p><p>Many security experts with an engineering bent seem to readily agree, with the consensus of opinion being that the notion of greater security was based around the time at which IPv6 was being developed (mid-nineties) when the internet had not yet experienced the growth we have seen since. That growth had a knock-on effect of creating masses of fresh security threats.</p><p>While IPv6 may well have been 'more secure' in terms of the earliest threats, there is really no great body of evidence to suggest it has any real advantage over IPv4 when it comes to the current threatscape. The truth is that it's just as exposed, and possibly more so. We have already seen evidence of old IPv4 threats surfacing on IPv6 and there will be IPv6 specific vulnerabilities to throw into the risk assessment mix as well.</p><p>So is that reason enough to think that the Internet Society has jumped too soon with the IPv6 launch day idea? Certainly not. IPv6 has been around for what seems like forever (especially given the never-ending media obsession with reporting how many IP addresses it can support) and DNS use within IPv6 was given the go-ahead in 2008 to coincide with the Olympic Games of that year, which made good use of it. Today some three per cent of domain names and 12 per cent of internet connected networks support IPv6 according to the Global IPv6 Deployment Progress Report.</p><p>I'm not suggesting that the time is now for everyone to start their migration from IPv4, but what I am saying is that the time is certainly long overdue for everyone to be investigating how that migration can be made in a timely and secure fashion. For too long people have been happy to have their heads buried neck deep, ignoring the arrival of IPv6, courtesy of the 'lack of security' comfort zone.</p><p>Although the IP address sky has yet to fall, despite media Chicken Little claims that it has been doing just that for ten years or more, the fact is addresses are running out and at some point the move to IPv6 will be necessary.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Juniper splashes £80m on 'intrusion deception' firm ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/639091/juniper-splashes-80m-on-intrusion-deception-firm</link>
                                                                            <description>
                            <![CDATA[ The networking firm buys Mykonos, which looks to catch cyber criminals during their reconnaissance phase. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">83CF1q3BsETYkaTtSYTbAc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UE7dkrL2zaB7MsbM6Ao2mD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Feb 2012 09:59:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UE7dkrL2zaB7MsbM6Ao2mD-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security]]></media:description>                                                            <media:text><![CDATA[Security]]></media:text>
                                <media:title type="plain"><![CDATA[Security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UE7dkrL2zaB7MsbM6Ao2mD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/637216/juniper-red-faced-as-bgp-issue-causes-widespread-outages" target="_blank" data-original-url="https://www.itpro.com/637216/juniper-red-faced-as-bgp-issue-causes-widespread-outages">Juniper Networks</a> has acquired intrusion prevention firm Mykonos Software for $80 million, as it looks to up its security game against rivals like <a href="https://www.itpro.com/638839/cisco-brings-quad-to-5000-virgin-seats" target="_blank" data-original-url="https://www.itpro.com/638839/cisco-brings-quad-to-5000-virgin-seats">Cisco</a>.</p><p>According to the networking firm, Mykonos offers the only intrusion prevention system in the industry "capable of detecting an attacker before an attack is in progress."</p><p>Mykonos places what it calls "a random and variable minefield" over web applications by inserting various "detection points" in bits of the app's code, in areas like forms and server files.</p><p>The company tries to ensnare hackers during their reconnaissance phase of their attacks, meaning it holds a niche position in the security market. Mykonos also calls its product an "intrusion deception system."</p><p>Once hackers have been caught, Mykonos can then track them beyond their IP addresses by identifying the attackers' device.</p><p>"Mykonos' intrusion deception technology is an innovative defence against zero-day web attacks, automated hacker tools, malicious web content, and similar threats aimed at companies' websites and web applications," said Jeff Wilson, principal analyst atInfonetics Research.</p><p>"There are opportunities for Juniper to sell standalone and integrated versions of the Mykonos solution."</p><p>David Koretz, chairman and chief executive officer Mykonos Software, was excited by the prospect of taking the product to bigger firms.</p><p>"We believe the combination of Mykonos' ground breaking technology and Juniper's proven expertise in delivering innovative security products at the largest scale, will enable us to provide solutions to immediate and pressing security threats for the largest enterprises and public sector institutions," Koretz said.</p><p>Juniper will be hoping to bounce back in 2012 after a weak 2011. The company's fourth quarter results showed revenue declining six per cent year-over-year, marking a poor end to the year that surprised the company's owners.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IBM builds on Q1 Labs acquisition with QRadar boost ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/639061/ibm-builds-on-q1-labs-acquisition-with-qradar-boost</link>
                                                                            <description>
                            <![CDATA[ Big Blue launches an updated version of the QRadar SIEM software it acquired after buying Q1 Labs last year. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m4g1dJEWimoJfG9ReaQsPT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8vkXMYdayhYKW4WTxywuL6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Feb 2012 12:01:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8vkXMYdayhYKW4WTxywuL6-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security]]></media:description>                                                            <media:text><![CDATA[Security]]></media:text>
                                <media:title type="plain"><![CDATA[Security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8vkXMYdayhYKW4WTxywuL6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IBM has issued the first major update of the security information and event management (SIEM) software it bought in its <a href="https://www.itpro.com/636514/ibm-agrees-to-acquire-q1-labs" target="_blank" data-original-url="https://www.itpro.com/636514/ibm-agrees-to-acquire-q1-labs">Q1 Labs acquisition</a>, claiming it is blowing the competition out of the water with the amount of data feeds it has collated.</p><p>Big Blue said the QRadar Security Intelligence Platform, built mainly of Q1 Labs sauce rather than IBM's own code, draws together 400 sources on threats giving IT pros a wider knowledge of dangers facing their networks.</p><p>IBM has hooked up its own X-Force threat feed to the <a href="https://www.itpro.com/636556/what-siems-to-be-the-problem" target="_blank" data-original-url="https://www.itpro.com/636556/what-siems-to-be-the-problem">SIEM</a> offering, which monitors 13 billion security events per day.</p><p>A host of other Big Blue offerings have been integrated into QRadar, including IBM Security Identity Manager and IBM Security Access Manager to mitigate the insider threat.</p><p>There are no vendors that can cover that breadth and that's really the value we bring.</p><p>Future integration modules are also being released for non-IBM products, including Symantec DLP, Websense Triton, Stonesoft, Stonegate and others.</p><p>"Essentially we support Symantec and McAfee and can extend to others. We don't support HP Arcsight," IBM told <em>IT Pro</em>.</p><p>Martin Borrett, director of the Institute of Advanced Security at IBM, said there had been a "wealth of excitement" around what Big Blue could do with Q1 Labs technology.</p><p>"We've been trying to figure out how IBM can take it to the next level, integrating our research and existing product line," Borrett told <em>IT Pro</em>.</p><p>"At this stage, apart from driving more scalability into the platform itself with new appliances, it's really about those flows in and out. We had all the insight from the X-Force but it just wasn't plugged into the platform in the way that it will be now. It's really about that crucial integration."</p><p>The release also marks another major moment for IBM in establishing itself as a major security services player.</p><p>However, it faces strong competition in the SIEM space, with Symantec already offering a well-respected product, HP running its Arcsight-based offerings and McAfee set to boost its presence in the market after <a href="https://www.itpro.com/636520/mcafee-to-buy-siem-provider-nitrosecurity" target="_blank" data-original-url="https://www.itpro.com/636520/mcafee-to-buy-siem-provider-nitrosecurity">acquiring Nitro Security</a>.</p><p>Borrett said IBM had "significant differentiation" in the market, thanks to the large number of sources QRadar can access and the insight it can get from the data.</p><p>"There are no vendors that can cover that breadth and that's really the value we bring," he claimed.</p><p>"The depth of the analytics we can get out of the Q1 platform I think is significantly stronger and better than our competition. Because of the context we can do it in... and the real-time capability [QRadar] is significantly better than the competition."</p><p>As for the SIEM market in general, with major players coming in and swamping the market, Borrett claimed there was still room for smaller players to partner with bigger vendors to supply more insight for bigger offerings.</p><p>"The important thing is that those capabilities integrate into these other platforms and into our platforms in particular," he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Symantec: Disable your pcAnywhere software ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/638524/symantec-disable-your-pcanywhere-software</link>
                                                                            <description>
                            <![CDATA[ The security giant advises users against running pcAnywhere until it has fixed vulnerabilities highlighted by a source code leak. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jX46q6ZYcjRopGiy6hq1zu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hcyxywth5vHt4zuGYsyTrL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 26 Jan 2012 13:42:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hcyxywth5vHt4zuGYsyTrL-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacking]]></media:description>                                                            <media:text><![CDATA[Hacking]]></media:text>
                                <media:title type="plain"><![CDATA[Hacking]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hcyxywth5vHt4zuGYsyTrL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Symantec is telling IT departments to disable its remote access software solution pcAnywhere after a <a href="https://www.itpro.com/638362/symantec-2006-hack-leaked-source-code" target="_blank" data-original-url="https://www.itpro.com/638362/symantec-2006-hack-leaked-source-code">source code leak</a> meant the product faced an "increased security risk."</p><p>The security giant said it was reaching out to customers to warn them of additional dangers, after it admitted source code relating to various products was stolen.</p><p>Hacktivist group Anonymous had threatened to release Symantec source code earlier this month, leading the Norton provider to admit a breach in 2006 had compromised information.</p><p>Symantec recommends disabling the product until we release a final set of software updates.</p><p>Prior to today's revelation, Symantec had simply asked IT departments to ensure best practices with pcAnywhere use. The reviewed advice indicates the 2006 hack exposed more than initially thought.</p><p>"Symantec has taken an aggressive position to ensure pcAnywhere customers are protected. At this time, Symantec recommends disabling the product until we release a final set of software updates that resolve currently known vulnerability risks," a spokesperson said.</p><p>"For customers that require pcAnywhere for business critical purposes, it is recommended that customers understand the current risks, ensure pcAnywhere 12.5 is installed, apply all relevant patches as they are released, and follow general security best practices."</p><p>From the 2006 hack, affected products include old versions of Norton Antivirus Corporate Edition, Norton Internet Security, Norton SystemWorks (Norton Utilities and Norton GoBack), as well as pcAnywhere. Symantec Endpoint Protection (SEP) 11.0 and Symantec AntiVirus 10.2 also inherited a very small amount of exposed code.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google dumps disaster recovery product amidst clean out ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/638443/google-dumps-disaster-recovery-product-amidst-clean-out</link>
                                                                            <description>
                            <![CDATA[ The internet giant dumps the Google Message Continuity product to focus on its Apps lineup. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m41qc69Fhb34zQHTQQJbaU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Zx8WCnAmN5wFYvXeDuH9td-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Jan 2012 09:54:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Zx8WCnAmN5wFYvXeDuH9td-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Tech in bin]]></media:description>                                                            <media:text><![CDATA[Tech in bin]]></media:text>
                                <media:title type="plain"><![CDATA[Tech in bin]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Zx8WCnAmN5wFYvXeDuH9td-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has continued to realign its services, cutting away unwanted fat to ensure it isn't wasting time and money on unneeded products.</p><p>The email disaster recovery product Google Message Continuity (GMC), launched in December 2010, has been closed.</p><p>The internet giant said it wanted to focus on Google Apps, which includes an email disaster recovery capability.</p><p>All GMC customers can continue to use the service until their contract runs out.</p><p>We've been sticking to some old resolutionsthe need to focus on building amazing products.</p><p>The Needlebase data management platform, acquired from ITA Software, is also set for the scrapheap on 1 June 2012 and is being considered for integration into other Google services.</p><p>"As we head into 2012, we've been sticking to some old resolutionsthe need to focus on building amazing products that millions of people love to use every day," said Dave Girouard, vice president of product management at Google, in a <a href="http://googleblog.blogspot.com/2012/01/renewing-old-resolutions-for-new-year.html" target="_blank">blog post</a>.</p><p>"That means taking a hard look at products that replicate other features, haven't achieved the promise we had hoped for or can't be properly integrated into the overall Google experience."</p><p>Picnik, the online photo editor acquired in 2010, has been ditched and will be put to rest on 19 April. The Picnik team will continue to work at Google, however, contributing to other photo software.</p><p>Google has made the premium version of Picnik free to everyone until it is killed off. Those who have already paid for a premium suscription are to be given a full refund in the coming weeks.</p><p>The Social Graph API, which made data about public connections between users available to developers, will be retired on 20 April. It was not getting the adoption Google wanted.</p><p>Google is still placing a heavy emphasis on a more social experience for its users, recently updating search to reflect this.</p><p>However, the changes came under fire from Twitter, which <a href="https://www.itpro.com/638242/twitter-slams-google-search-changes" target="_blank" data-original-url="https://www.itpro.com/638242/twitter-slams-google-search-changes">claimed Google was warping results</a> so users would not be presented with the most valuable results.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Symantec: 2006 hack leaked source code ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/638362/symantec-2006-hack-leaked-source-code</link>
                                                                            <description>
                            <![CDATA[ The security giant publicly discloses a breach of its network - almost six years after it took place. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qU6exyWiZVLDfjQmC7DH3U</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pbWp4R9pMmFPAfL4vpZLT7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 18 Jan 2012 10:41:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pbWp4R9pMmFPAfL4vpZLT7-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Symantec]]></media:description>                                                            <media:text><![CDATA[Symantec]]></media:text>
                                <media:title type="plain"><![CDATA[Symantec]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pbWp4R9pMmFPAfL4vpZLT7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/636499/symantec-unveils-dlp-for-ipad" target="_blank" data-original-url="https://www.itpro.com/636499/symantec-unveils-dlp-for-ipad">Symantec</a> has backtracked on how source code relating to its products was leaked, revealing its own network was hacked in 2006.</p><p>The revelation came after hacktivist group Anonymous claimed it was going to release the full source code of Symantec's flagship Norton anti-virus software.</p><p>The security giant said it believed the data acquired by hackers came after a hack in 2006, although it could not confirm to <em>IT Pro</em> how the break-in took place.</p><p>Symantec customers - including those running Norton products - should not be in any increased danger of cyber attacks.</p><p>Earlier this month, Symantec confirmed <a href="https://www.itpro.com/638173/symantec-confirms-product-source-code-theft" target="_blank" data-original-url="https://www.itpro.com/638173/symantec-confirms-product-source-code-theft">some source code relating to older enterprise products had been stolen</a>. At the time, it claimed Norton products were unaffected and its own network had not been breached.</p><p>Hackers calling themselves The Lords of Dharmaraja threatened to publish the information online, saying they acquired the information from the Indian military.</p><p>From the 2006 hack, affected products include old versions of Norton Antivirus Corporate Edition, Norton Internet Security, Norton SystemWorks (Norton Utilities and Norton GoBack) and its remote access software solution pcAnywhere.</p><p>Symantec Endpoint Protection (SEP) 11.0 and Symantec AntiVirus 10.2 inherited a very small amount of exposed code, the company said. There are no indications customers data has been stolen, it added.</p><p>"Due to the age of the exposed source code, except as specifically noted below, Symantec customers - including those running Norton products - should not be in any increased danger of cyber attacks resulting from this incident," a spokesperson said.</p><p>"Customers of Symantec's pcAnywhere product may face a slightly increased security risk as a result of this exposure if they do not follow general best practices. Symantec is currently in the process of reaching out to our pcAnywhere customers to make them aware of the situation and to provide remediation steps to maintain the protection of their devices and information. Since 2006, Symantec has instituted a number of policies and procedures to prevent a similar incident from occurring."</p><p>Symantec said businesses do not need to take any additional steps to protect themselves as a result of the hack. The company recommended customers ensure their software is up to date.</p><p>For any IT departments still concerned about the source code leak, Symantec has set up an <a href="http://www.symantec.com/theme.jsp?themeid=anonymous-code-claims" target="_blank">advice page here</a>.</p><p>Symantec did not disclose the 2006 hack publicly at the time, meaning it has taken between five and six years for the breach for the security firm to reveal what happened, or that the company did not know source code had gone missing back then.</p><p>RSA was heavily criticised for not immediately publicly disclosing a breach last year, when information relating to its SecurID product was compromised.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Oracle issues 78 vulnerability patches ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/638341/oracle-issues-78-vulnerability-patches</link>
                                                                            <description>
                            <![CDATA[ Combined with Microsoft and Adobe patches, Oracle has made IT departments' lives a little harder this month. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vZY1FJyZBvZFb8UUJf68CU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nLJcAjC4FM9vMf3HdXwxwB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 17 Jan 2012 10:56:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nLJcAjC4FM9vMf3HdXwxwB-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Oracle]]></media:description>                                                            <media:text><![CDATA[Oracle]]></media:text>
                                <media:title type="plain"><![CDATA[Oracle]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nLJcAjC4FM9vMf3HdXwxwB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Oracle today released patches for 78 flaws in its software, covering the majority of its products.</p><p>A total of 16 are categorised as critical, meaning they could be exploited for remote code execution.</p><p>"Most of their products, including the acquisitioned PeopleSoft, JD Edwards, Weblogic and the recent Sun/MySQL lines, are affected by this update," advised Wolfgang Kandek, CTO of security company Qualys.</p><p>"Only PeopleSoft and the virtualisation products are not affected by this critical rating - everybody else should pay close attention to the release.</p><p>"One notable exception is the Java programming language as it is updated on a separate schedule and had its last release in December 2011."</p><p>You can find the full list of affected products <a href="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" target="_blank">here</a>.</p><p>Oracle's list of patches makes for a busy January for IT departments, following <a href="https://www.itpro.com/638197/microsoft-and-adobe-plan-busy-january-patch-days" target="_blank" data-original-url="https://www.itpro.com/638197/microsoft-and-adobe-plan-busy-january-patch-days">Adobe and Microsoft announcements</a> from earlier this month.</p><p>Microsoft, which usually keeps January quiet for patching, issued seven security bulletins covering eight vulnerabilities. One of those covered the BEAST SSL flaw highlighted by researchers last year.</p><p>Researchers found a way to exploit a long-known flaw in TLS (Transport Layer Security) that could have undermined the security credentials of the SSL cryptographic protocol and affected millions of sites. However, little emerged from the discovery and the Redmond giant now has Windows users' backs covered.</p><p>Adobe, meanwhile, addressed critical flaws in Reader and Acrobat on the same day (10 January).</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft and Adobe plan busy January patch days ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/638197/microsoft-and-adobe-plan-busy-january-patch-days</link>
                                                                            <description>
                            <![CDATA[ IT departments will have a busy month of patching to kick off 2012. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9beNmYP7ETAjXFPvY6vp8f</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GLDgJGdTbzMkJi2fhFXRf7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 09 Jan 2012 11:12:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GLDgJGdTbzMkJi2fhFXRf7-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Patch Tuesday]]></media:description>                                                            <media:text><![CDATA[Patch Tuesday]]></media:text>
                                <media:title type="plain"><![CDATA[Patch Tuesday]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GLDgJGdTbzMkJi2fhFXRf7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Both <a href="https://www.itpro.com/637990/microsoft-spots-malware-posing-as-police" target="_blank" data-original-url="https://www.itpro.com/637990/microsoft-spots-malware-posing-as-police">Microsoft</a> and <a href="https://www.itpro.com/637753/another-adobe-zero-day-strikes" target="_blank" data-original-url="https://www.itpro.com/637753/another-adobe-zero-day-strikes">Adobe</a> have welcomed the new year by announcing some notable patching days for IT departments to be aware of.</p><p>Microsoft usually keeps Patch Tuesdays quiet in January, but has issued <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-jan" target="_blank">seven security bulletins</a> for eight vulnerabilities.</p><p>One of those is a critical remote code execution vulnerability in Media Player, although for users of Windows 7 and Windows 2008 R2 its severity is downgraded to 'important.'</p><p>The remaining bulletins are ranked as important. One of those covers the <a href="https://www.itpro.com/636304/ssl-under-threat-as-flaw-exploited" target="_blank" data-original-url="https://www.itpro.com/636304/ssl-under-threat-as-flaw-exploited">BEAST SSL flaw</a> highlighted by researchers last year.</p><p>Next Tuesday it will be interesting to see, which exact Windows features are involved and how this vulnerability can be used by attackers.</p><p>Researchers found a way to exploit a long-known flaw in TLS (Transport Layer Security) that could have undermined the security credentials of the SSL cryptographic protocol and affected millions of sites. However, little emerged from the discovery.</p><p>"Bulletins three and five, while rated 'important' both involve Remote Code Execution, most likely through a specifically crafted input file to one of the Windows standard programs and should also be high on your list of bulletins to look at," recommended Wolfgang Kandek, CTO of Qualys.</p><p>"Bulletin two stands out as it is tagged as 'Security Feature Bypass,' which is a new category. Next Tuesday it will be interesting to see which exact Windows features are involved and how this vulnerability can be used by attackers."</p><p>Adobe will join Microsoft in issuing updates tomorrow (10 January). It will address critical flaws in Reader and Acrobat.</p><p>"These updates will include fixes for CVE-2011-2462 and CVE-2011-4369, previously addressed in Adobe Reader and Acrobat 9.x for Windows," Adobe said in its <a href="http://www.adobe.com/support/security/bulletins/apsb12-01.html" target="_blank">advisory</a>.</p><p>Oracle is also due to issue its quarterly security update on 17 January, making it a busy month of patching for IT managers.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Q&A: All about BlackBerry Mobile Fusion ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/637624/qa-all-about-blackberry-mobile-fusion</link>
                                                                            <description>
                            <![CDATA[ We spoke to Tim Hodkinson, RIM's director of enterprise marketing for Europe, the Middle East and Africa (EMEA) about the company's latest announcement and what it means for businesses. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">a3qMkzkX75yLUyZFW71Si9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mVrExS9xEtJEoCqtyucmXM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 30 Nov 2011 16:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[iOS]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Apple]]></category>
                                                                                                                    <dc:creator><![CDATA[ Maggie Holland ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mVrExS9xEtJEoCqtyucmXM-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[BlackBerry Mobile Fusion website homepage]]></media:description>                                                            <media:text><![CDATA[BlackBerry Mobile Fusion website homepage]]></media:text>
                                <media:title type="plain"><![CDATA[BlackBerry Mobile Fusion website homepage]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mVrExS9xEtJEoCqtyucmXM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For those who haven't seen the announcement, can you recap what BlackBerry Mobile Fusion is and why IT departments should be getting excited?</p><p>We're announcing BlackBerry Mobile Fusion. It's a next-generation enterprise mobility solution. It's really our entry into the multi-platform mobile device management (MDM) marketplace.</p><p>For many years we've provided MDM for BlackBerry smartphones. Over the last few years, we've seen a significant increase in customer demand to</p><p>extend the management capabilities that they've already got with their</p><p>BlackBerry platform into other areas.</p><p>With this introduction we're also providing device management for the PlayBook and enabling customers to manage iOS-based and Android-based</p><p>smartphones and tablets from a single user interface. If a business user has a mixture of devices, such as a personal BlackBerry smartphone and a corporate-issued PlayBook, with perhaps another device maybe largely corporate or personally liable, it will enable their IT department to manage those devices all from a single console.</p><p>We've seen a significant increase in customer demand to extend the management capabilities that they've already got with their BlackBerry platform into other areas.</p><p>The customer demand has been coming from the enterprise because of the rise of consumerisation and a real willingness to allow personally liable or bring your own devices and policies into the workplace.</p><p>We do have a lot of customers out there who are extremely security</p><p>conscious, particularly in the public sector and financial services, so we don't expect all customers will want to put this type of technology in, but certainly many of them have been asking for this kind of service for some time.</p><p>We acquired a company called Ubitexx at the end of May and we've been working on [making use of] its technology since then to get it to market. BlackBerry Mobile Fusion includes not only existing BlackBerry management for smartphones but also the new mobile device management for PlayBooks, Android and iOS devices.</p><p>We've had [interest] from our partners and both enterprise and SME-focused operators across, as well as systems integrators - they also want to provide MDM as a service to their clients as the number of devices increases in the workplace and as many of them will be personally liable rather than corporate issued.</p><p>When will it be available to businesses?</p><p>We've been running betas with customer across the European region, North America and Asia Pacific for some time now. Closed beta opens in January and customers can register their interest for that. We expect full availability at the end of March.</p><p>Will you be taking that time and feedback to iron out any issues and bugs?</p><p>Yes. We're getting some really strong feedback from our beta customers. They tend to be some of our really large customers with large device estates. Also, it's a really evolving marketplace. We've been in the MDM space for many years but this is really our first step into multi-platform MDM. We see that as a real growth market. There are a lot of companies entering that space. It's a really nascent market.</p><p>So it's a growth opportunity as well as a platform development opportunity more widely.</p><p>How can customers register interest in the beta programme?</p><p>They can register for news updates on the BlackBerry Mobile Fusion website, contact their BlackBerry account manager or their mobile operator...</p><p>The first step is to register interest. We've got large number of beta customers already so the closed beta will be available from January and the general availability will be March.</p><p>We've not put a cap on beta numbers at the moment but we've had a lot of interest in the first beta. We've tended to work with our largest customers for the first set of betas as we want really big device</p><p>estates but don't have a cap on it.</p><p>We have the ability to scale those betas up really fast. We're well versed in large beta programmes as it's super important for us to get that customer feedback before we fully launch.</p><p>You said this product was borne out of customer demand, was that in mind when you acquired Ubitexx?</p><p>The Ubitexx acquisition was really in response to customer demand. [It's also based on] what we've heard in last few years as our consumer retail business has grown enormously.</p><p>If you take the UK, we have more than eight million users in the UK market and many of those are consumers. Those consumer users are bringing their BlackBerry smartphones into previously quite locked-down enterprise environments and requesting that the IT department connect their mail and applications. Last year, when we launched BlackBerry Enterprise Service Express (BESX) and new capabilities like BB Balance, that was in response to personal liable bring your own BlackBerry devices coming into the workplace so this is just an [extension] og that.</p><p>It's also worth pointing out that across our whole portfolio now we have introduced quite a few MDM capabilities. Earlier in the year we launched BlackBerry Protect, which gives remote lock and wipe</p><p>and location discovery for lost or mislaid phones over the air (OTA) for an individual consumer user. That's a cloud-based service. We also introduced the BlackBerry Management Centre, which allows small and medium business, up to 100 users, to do many of the same things. Again as a cloud-based service. We've now got MDM for our own products all the way from an individual user right up to the largest enterprise. We wanted to extend that at the top end to allow larger businesses to support other platforms.</p><p>We've got a big installed base of customers who are using our MDM</p><p>capabilities already so our first initiative is to help them deal with bring your own device (BYOD) and personally liable devices. Then we'll look at how we roll out BB Mobile Fusion to others. So, initially, it's [just aimed at] large corporates and public sector organisations.</p><p>What are the headline features? As an IT manager why should I choose BlackBerry Mobile Fusion rather than A N Other MDM solution?</p><p>The reason you'd come to us first of all is you prob already have BlackBerry device management in your corporate infrastructure, so being able to upgrade that to simply add BlackBerry PlayBook device management, iOS and Android smartphone and tablet device management means not having to invest in a new device management platform. That's really what customers have been telling us. That they already manage their BlackBerry smartphones, and they'd like to be able to manage other devices, and multiple devices per user through a single user interface and single experience rather than having to have several different pieces of software or services.</p><p>Some 90 per cent of the Fortune 500 already have us in their IT infrastructures so it's a natural extension for them as they start introduce a multi-platform or BYOD policy.</p><p>Does it just slot on to what they have already then?</p><p>Absolutely. It is a new user experience... Our current user experience for device management is web-based anyway. This just adds an extra layer. It will be familiar but will allow the IT department to get asset management, configuration, security, lock and wipe, administer users at either an indiviual or group level but also deal with environments where you have multiple devices per user.</p><p>It's BlackBerry, Playbook, iPad and Android management capabilities.</p><p>What about usability? Can users expect the same experience?</p><p>Yes. We put a lot of effort into making the user experience was smooth and graphically rich. The IT department wants something quick and simple to use that is easy on the eye as well.</p><p>The real difference thing here is if you're looking at a user, you'll be able to see all of their devices in one management console. It will show you the status of all those devices even though there will be a different set of policies and management capabilities potentially for each device.</p><p>With BlackBerry devices we have security and management built in from the hardware right through the infrastructure to our device management software. We're now providing device management for third party devices, so the APIs may not be available for all of them. We have BlackBerry Balance for example and that level of functionality is not yet currently available for iOS and Android. It may well be in the future.</p><p>Our committment is that we will allow our customers to manage those third-party devices to the greatest extent that we can and secure them to the greatest extent we can.</p><p>Which is a bigger draw for businesses - security or managability?</p><p>Security and the ability to apply security polices remotely and</p><p>OTA is probably one of the most important things for many of our customers.</p><p>But [from a priority standpoint] security and management are on a par as it really differs from customer to customer. The public sector, particularly defence and local government and financial services, need to be secure and this is possibly higher up the IT director or CIO's list of concerns. In other sectors, pure manageability aspects might rank more highly. It really depends on the individual customer and</p><p>security sensitivity of that industry.</p><p>Some may think it's a bit of a risky move, supporting competing devices. Is this brave on RIM's part or something you have to do to respond to customer demand?</p><p>It's about responding to customer demand. We've benefited enormously from consumerisation as business. The large number of BlackBerry smartphones going into consumer channels are coming back into the enterprise and users with their individual handsets are asking to have corporate applications and mail on those devices.</p><p>We're fully supportive of cosumerisation and of helping our customers and making it as easy as possible for them to secure and manage devices on whatever platform. We see it as an opportunity.</p><p>The MDM market is a real growth area. Wee have this heritage in device</p><p>management of BlackBerry smartphones and a large customer base so extending that to other operating systems is really a natural step for us.</p><p>Is it the case BYOD and consumerisation is invetiable so you might as well make it safe and secure?</p><p>That's spot on.</p><p>Can we expect further moves, like the acquisition, in response to different business needs?</p><p>Yes. Certainly when it comes to device management and security. This year has been one of our biggest years for introducting device management capabilities all the way from BlackBerry protect to the BlackBerry Management Centre fo SMEs. We recently anouncned BB Cloud Services for Microsoft Office 365 and cloud-based device management for</p><p>Microsoft customers.</p><p>Whether it's the individual user all the way up to the largest corporate business or public sector organisation, we want to respond to their requirements for managing and securing, locking and wiping and scaling up those devices. The simple demand of employees and end users to have more mobility in their working lives and have more</p><p>control, is encouraging organisations across the board to open up their doors to consumerisation.</p><p>Do you have any details about pricing?</p><p>BlackBerry Mobile Fusion is going to be price competitive. We're already price competitive in pure device management terms for BlackBerrys so now we will be [here].</p><p>We're not releasing detailed pricing info yet, it will be released in the new year but, absolutely, our intention is to be as price competitive [as we can] for device management of other operating systems.</p><p>One thing we hear from customers a lot is there is a significant value associated with having a single platform for device management. It's only when you have that single platform you can compare the cost of ownership, the TCO the reliability and the impact on the business of the different smartphones and tablet platforms and operating systems you're using.</p><p>From a customer point of view, they want to be able to look across their whole estate at old versions of device X to new devices and</p><p>tablets and different form factors of the future and be able to</p><p>say this is the reliabilty of this device in this particular user environment, this is the cost, the data efficiency, the security and be able to compare those.</p><p>We see a lot of demand for that comparative cost not just in terms of the device themselves and the data they use but also the cost of managing and securing them. That's another driver behind us launching BlackBerry Mobile Fusion.</p><p>Our general message to customers is consumerisation is something we encourage them to embrace but we also recognise that they may be in a very security conscious industry or mindset so the ability to control policies is absolutely essential. We give them that ability to take a different approach.</p><p>Someone in a less security conscious role in the same organisation may want to use BESX and allow them to bring their own BlackBerry smartphone in and have a different level of access and control over apps and emails. And have a diff set of policies to someone in the same organisation who has a BlackBerry and iOS or Android-based device. It's that ability to take the policies and apply them by either user or group across multiple devices per user. Customers want flexibility.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GFI WebMonitor 2011 R3 review ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/637561/gfi-webmonitor-2011-r3-review</link>
                                                                            <description>
                            <![CDATA[ GFI's WebMonitor software focuses on providing stiff web content security and costs a lot less than an appliance. Dave Mitchell loads it up in the lab to see if it can keep your users out of trouble and your network safe. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9ekqf1xbYWSXKXFgC5v4rR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/D6kJrwg7agb8ty44T6AZhR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 25 Nov 2011 15:39:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/D6kJrwg7agb8ty44T6AZhR-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[GFI WebMonitor 2011 R3]]></media:description>                                                            <media:text><![CDATA[GFI WebMonitor 2011 R3]]></media:text>
                                <media:title type="plain"><![CDATA[GFI WebMonitor 2011 R3]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/D6kJrwg7agb8ty44T6AZhR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="GGTgtQXTWh5XnWT2mRJGDZ" name="" alt="ITPRO Value award" src="https://cdn.mos.cms.futurecdn.net/GGTgtQXTWh5XnWT2mRJGDZ.jpg" mos="https://cdn.mos.cms.futurecdn.net/GGTgtQXTWh5XnWT2mRJGDZ.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>UTM appliances are a simple one-stop security shop for many businesses but not everyone wants to cough up for the full works, especially if they don't need all those features. GFI's WebMonitor 2011 is a software-based alternative that focuses purely on web content security and is hosted on your own hardware platform.</p><p>The latest R3 version supports the ThreatTrack service which uses GFI's SandBox malware analysis tool to check web sites to see if they're harbouring malicious content. These are added to the ThreatTrack data feeds which WebMonitor uses to check sites being accessed so it can block them immediately.</p><p>Previous versions had limited IM app controls but, along with Windows Live Messenger, R3 can now block Yahoo! Messenger, Gmail chat and other IM portals including Facebook. Streaming media also comes under WebMonitor's remit and a soft blocking feature allows trusted users to override a warning page and continue browsing.</p><p>WebMonitor is available in three versions with the WebFilter Edition enforcing policies for web content filtering, browsing time and media streaming. If you just want anti-virus scanning, phishing protection, IM app controls and ThreatTrack then check out the WebSecurity Edition which uses scanning engines from Norman, BitDefender or Kaspersky.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="3H4Gaw2jhWj9ctTQQyPkP9" name="" alt="WebMonitor supports two deployments, but the gateway mode is easier as it doesn’t need any extra router configuration." src="https://cdn.mos.cms.futurecdn.net/3H4Gaw2jhWj9ctTQQyPkP9.png" mos="https://cdn.mos.cms.futurecdn.net/3H4Gaw2jhWj9ctTQQyPkP9.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>WebMonitor supports two deployments, but the gateway mode is easier as it doesn't need any extra router configuration.</p><p>On review covers the UnifiedProtection Edition which combines everything from the other two versions. The price we've shown includes dual scanning engines from Norman and BitDefender. Kaspersky is an extra 12 per seat which does increase costs significantly.</p><p>Prior to installation you must decide how you want to deploy WebMonitor. The simple proxy mode only requires one network port on the host, but your router must block all web traffic coming from the LAN. We opted to load it in gateway mode on a Windows Server 2008 R2 system with two network ports as this doesn't require any router changes. Ensure you have all required ports active before loading the software as the installation wizard only offers deployment choices based on what it can see.</p><p>The WebMonitor console is a tidy affair that provides a top level dashboard of graphs and tables showing current web activity. Options are provided for viewing general web traffic, blocked sites, the most popular categories and so on. Each panel can be moved around using drag and drop.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mpJG8MRaU8zuiVufXFrorh" name="" alt="The Dashboard provides plenty of detail on real time web activity and can be customised using drag and drop." src="https://cdn.mos.cms.futurecdn.net/mpJG8MRaU8zuiVufXFrorh.png" mos="https://cdn.mos.cms.futurecdn.net/mpJG8MRaU8zuiVufXFrorh.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>The Dashboard provides plenty of detail on real time web activity and can be customised using drag and drop.</p><p>Web access is controlled with policies applied to users, groups and IP addresses. Separate policies are used to manage web content access, browsing periods, anti-virus scanning, streaming media, file downloads and IM apps.</p><p>For web filtering you can choose from over seventy WebGrade categories. For each one you can block or allow them, or use the quarantine option which blocks access to a site and makes the user wait for administrative approval.</p><p>Selected users and groups may be permitted to browse certain categories or web sites, but time-based policies can be used to restrict how long they can access them for. These limits can be based on daily, weekly or monthly usage or you can apply download limits in KB or MB for these periods instead.</p><p>HTTPS scanning comes as standard and WebMonitor provides a wizard that runs through certificate creation. The host system can also cache downloaded files and web content to improve response times.</p><p>Virus scanning policies are accessed from the WebSecurity console section. You can choose from a list of file types, pick the engines for scanning and decide whether to delete or quarantine infected files. When downloading files, users can be redirected to a web page showing their progress and only when the file is deemed to be safe will they be allowed to save it to their system.</p><p>You could use GFI's ReportPack instead, as this free component can do this for you. WebMonitor must be configured to download its logs to a SQL database and we had no problems using the freely available SQL Express 2005. You'll need the Management Studio Express to create a new database and owner. Add these details to the WebMonitor Reporting page and it'll download all its data on first contact with the database.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="dEVqzhMoRjMBjkhhxrzg3U" name="" alt="Get the ReportPack add-on - it’s free and provides a heap of useful reporting tools for WebMonitor." src="https://cdn.mos.cms.futurecdn.net/dEVqzhMoRjMBjkhhxrzg3U.jpg" mos="https://cdn.mos.cms.futurecdn.net/dEVqzhMoRjMBjkhhxrzg3U.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>For a freebie, the ReportPack is to be recommended as it provides a complete set of default reports covering a wide range of activities and trends. These can be customised to suit, date ranges of up to a year can be applied and the results exported to formats such as PDF, Word and Excel and emailed as well.</p><p>GFI's WebMonitor is better value than many security appliances and can run on lowly specified host systems. We found it performed very well during testing and is capable of enforcing a wide range of AUPs in the workplace.</p><p><a href="https://www.itpro.com/637561/gfi-webmonitor-2011-r3-review" target="_blank" data-original-url="https://www.itpro.com/637561/gfi-webmonitor-2011-r3-review">So what's our verdict?</a></p><h2 id="verdict">Verdict</h2><p>Businesses and educational establishments that want quality web content management and monitoring, but don’t want to pay a premium for an appliance, should consider GFI’s WebMonitor. Host hardware requirements are quite reasonable, the software is easy to deploy and it has a good range of top performing security measures and reporting tools.</p><p>Memory: 4GB Hard disk: 12GB OS: Windows XP SP2, Vista, 7, Server 2003, Server 2008</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security software rebounded strongly in 2010 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/634036/security-software-rebounded-strongly-in-2010</link>
                                                                            <description>
                            <![CDATA[ Gartner finds the security software market has reasons to be cheerful following a decent 2010. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aXrar5dy3biHAP5oJASvBU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DXWD342NVEdkoYgxKgnU3C-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Jun 2011 15:31:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DXWD342NVEdkoYgxKgnU3C-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Graph rise]]></media:description>                                                            <media:text><![CDATA[Graph rise]]></media:text>
                                <media:title type="plain"><![CDATA[Graph rise]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DXWD342NVEdkoYgxKgnU3C-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/security" target="_blank" data-original-url="https://www.itpro.com/security">security</a> software market rebounded well in 2010 following a disappointing 2009, Gartner has claimed.</p><p>The market grew 12 per cent last year as total revenue hit $16.5 billion - up from 2009 revenue of $14.7 billion.</p><p>"Products within the security market are undergoing rapid evolution, in terms of both new delivery models with security as a service showing increasing popularity and new technologies being introduced, often by startup companies," said Ruggero Contu, principal research analyst at Gartner.</p><p>"Key vendors continued to expand their product portfolios, buying companies where appropriate and expanding their reach into emerging markets."</p><p><a href="https://www.itpro.com/633976/android-droiddream-nightmare-continues" target="_blank" data-original-url="https://www.itpro.com/633976/android-droiddream-nightmare-continues">Symantec</a> remained the dominant force in the industry, although experienced below average growth over the year.</p><p>It achieved 18.9 per cent market share in 2010, compared to McAfee on 10.4 per cent in second place.</p><p>Out of the top 5 players, Trend Micro in third saw the lowest growth with 5.8 per cent.</p><p>IBM was in fourth, followed by EMC, which achieved an impressive 25.6 per cent growth over 2010.</p><p>As for a breakdown of the different segments of the market, Gartner noted more mature areas like endpoint security and web access management showed single-digit growth.</p><p>In comparison, areas including security information and event management (SIEM) and secure web gateway products experienced double-digit growth.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>