<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/security-information-and-event-management" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Security-information-and-event-management ]]></title>
                <link>https://www.itpro.com/tag/security-information-and-event-management</link>
        <description><![CDATA[ All the latest security-information-and-event-management content from the ITPro team ]]></description>
                                    <lastBuildDate>Fri, 20 Feb 2026 14:00:26 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Sumo Logic expands European footprint with AWS Sovereign Cloud deal ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-computing/sumo-logic-expands-european-footprint-with-aws-sovereign-cloud-deal</link>
                                                                            <description>
                            <![CDATA[ The vendor is extending its AI-powered security platform to the AWS European Sovereign Cloud and Swiss Data Center ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">25RLZZTx9rBreFguu6KuSQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/c2ioK8BSh37gJhJw7diMgP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 Feb 2026 14:00:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Computing]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/c2ioK8BSh37gJhJw7diMgP-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Sumo Logic logo pictured on the side of the company&#039;s headquarters in Redwood City, California, U.S, with grey skies in background.]]></media:description>                                                            <media:text><![CDATA[Sumo Logic logo pictured on the side of the company&#039;s headquarters in Redwood City, California, U.S, with grey skies in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Sumo Logic logo pictured on the side of the company&#039;s headquarters in Redwood City, California, U.S, with grey skies in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/c2ioK8BSh37gJhJw7diMgP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Sumo Logic is expanding its EMEA footprint with planned availability of its AI-powered security solutions on the <a href="https://www.itpro.com/cloud/cloud-computing/aws-european-sovereign-cloud-explained">AWS European Sovereign Cloud</a> and Swiss Data Center region.</p><p>The move aims to bolster support for European organizations' data privacy, sovereignty, resiliency, and security needs as they push ahead with digital and <a href="https://www.itpro.com/business/leadership/ai-employees-overload">AI strategies</a>.</p><p>Sumo Logic said the expansion will enable businesses to deploy its security analytics and SIEM capabilities while keeping data in-country or within designated time zones as demand for sovereign cloud services grows.</p><p>According to <a href="https://www.idc.com/resource-center/blog/the-high-cost-of-sovereignty-in-the-age-of-ai/" target="_blank">research from <em>IDC</em></a>, 63% of organizations are now more likely to adopt <a href="https://www.itpro.com/cloud/cloud-computing/what-is-a-sovereign-cloud">sovereign cloud</a> services due to recent geopolitical events, with spending tipped to reach more than $400 million by 2029.</p><p>Despite the growing market, Eric Avery, global head of infrastructure and data at Sumo Logic, said strict data sovereignty regulations are creating barriers for many organizations – particularly across regulated sectors such as healthcare, finance, and the public sector.</p><p>“Previously, enterprises in highly regulated industries have been limited in their choice of cloud security solutions while meeting compliance requirements like Switzerland’s FADP,” he explained. </p><p>“Sumo Logic's innovations around SIEM and agentic AI, combined with <a href="https://www.itpro.com/cloud/cloud-computing/aws-says-only-europeans-will-run-its-european-sovereign-cloud-service">AWS' European Sovereign Cloud </a>infrastructure, provides the ideal response.”</p><h2 id="aws-sovereign-cloud-and-swiss-expansion">AWS sovereign cloud and Swiss expansion</h2><p>Under the expansion, Sumo Logic’s Intelligent Security Operations platform will be made available for deployments on the AWS European Sovereign Cloud to help customers operate cloud workloads in an independently governed environment while using Sumo Logic to log, track, and secure deployments.</p><p>The security vendor also confirmed plans to roll out its platform in Switzerland in an effort to better support customers that require faster in-country data processing in line with the Swiss Federal Act on Data Protection (FADP), as well as GDPR obligations.</p><p>By expanding its footprint to the AWS Swiss Data Center, Sumo Logic said organizations operating within Swiss borders will be able to leverage its agentic AI-driven log analytics and advanced SIEM capabilities to boost compliance, while benefitting from a faster, low-latency environment.</p><p>“We deliver reliable security operations that help organizations stay secure and compliant while running services locally with the performance and scale they need,” Avery added.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Four measures SMBs can take to avoid common security pitfalls ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/four-measures-smbs-can-take-to-avoid-common-security-pitfalls</link>
                                                                            <description>
                            <![CDATA[ Security can be challenging for SMBs, but it’s possible to make yourself more resilient to reduce the impact of cyber attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UkUxqg653UoDNWLUS6ndFF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QX2iVwGXSoqdgmhNkLEveC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 31 Jul 2023 08:55:53 +0000</pubDate>                                                                                                                                <updated>Tue, 01 Aug 2023 14:47:10 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QX2iVwGXSoqdgmhNkLEveC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital render of a red, microchip-like pattern with semi-transparent white representations of an open padlock and skull and crossbones overlaid on top, alongside the text DATA LEAK, SECURITY, and EXPLOIT FOUND to represent data theft.]]></media:description>                                                            <media:text><![CDATA[A digital render of a red, microchip-like pattern with semi-transparent white representations of an open padlock and skull and crossbones overlaid on top, alongside the text DATA LEAK, SECURITY, and EXPLOIT FOUND to represent data theft.]]></media:text>
                                <media:title type="plain"><![CDATA[A digital render of a red, microchip-like pattern with semi-transparent white representations of an open padlock and skull and crossbones overlaid on top, alongside the text DATA LEAK, SECURITY, and EXPLOIT FOUND to represent data theft.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QX2iVwGXSoqdgmhNkLEveC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Many routinely assert that small and medium-sized businesses (SMBs) are less likely to be targeted than their larger counterparts, but this is far from the case. <a href="https://www.itpro.com/business-strategy/smb/360589/how-to-fix-the-weak-link-in-cyber-security"><u>SMBs have limited resources</u></a> versus their larger counterparts, which can make <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security</u></a> a challenge.</p><p>But robust security is possible if these companies take a handful of simple steps to avoid the common cyber security pitfalls and ensure they’re resilient if a cyber attack does land. </p><h2 class="article-body__section" id="section-1-plan-for-the-worst-case-scenario"><span>1. Plan for the worst-case scenario</span></h2><p>It’s true to say cyber attacks are a matter of when rather than if – regardless of the size of your business. One of the biggest traps for SMBs is fixating solely on preventing cyber attacks, says Haris Pylarinos, founder and <a href="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do"><u>CEO</u></a> of security skills company Hack The Box. This can leave firms reeling when a cyber assault does eventually get past your defenses. </p><p>He advises ensuring your business doesn’t have any weak spots through methods such as <a href="https://csrc.nist.gov/glossary/term/vulnerability_assessment"><u>vulnerability assessments</u></a> and <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing"><u>penetration testing</u></a>, as well as making sure you have an incident response plan in place.</p><p>When a cyber attack happens, one of the biggest pitfalls SMBs face is a lack of preparation, says Jack Peters, customer solutions architect at M247. He cites data from <a href="https://aag-it.com/the-latest-cyber-crime-statistics/" target="_blank"><u>AAG</u></a> showing that less than a fifth of UK businesses have a formal incident response plan in place. “It’s essential that businesses create, implement and maintain a strategy for how they will handle a cyber attack, as this will allow everyone to correctly identify any weaknesses and vulnerabilities within the IT framework,” he advises.</p><div  class="fancy-box"><div class="fancy_box-title">READ MORE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ADRYhzimysEUKbLKWUXS9V" name="ADRYhzimysEUKbLKWUXS9V.jpg" caption="" alt="An abstract image of a chain breaking in half to represent a weak link" src="https://cdn.mos.cms.futurecdn.net/ADRYhzimysEUKbLKWUXS9V.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: n/a)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/smb/360589/how-to-fix-the-weak-link-in-cyber-security"><strong>Small businesses: How to fix the weakest link in cyber security</strong></a></p></div></div><p>The plan needs to be implemented before an incident occurs, he says, highlighting that a pre-emptive approach “will be beneficial in the long-term”. </p><p>According to Pylarinos, SMBs should focus on key areas: preparation, detection and analysis, as well as containment, recovery, and post-incident analysis. </p><p>It’s also important the incident response plan is easy to understand. Although the specifics may vary depending on the size of the organization and industry, Peters advises using the <a href="https://www.nist.gov/cyberframework/online-learning/five-functions">five-step cyber security framework</a> developed by the National Institute of Standards and Technology (NIST). “This is a great model to follow.”</p><h2 class="article-body__section" id="section-2-get-the-basics-right"><span>2. Get the basics right</span></h2><p>As a foundation for all things security, SMBs should ensure they are getting the basics right. As part of this, it’s key to update your devices regularly. Many smaller businesses suffer irreparable damage after falling victim to a cyber attack that could have been prevented if they’d taken the time to update systems. </p><p>One way to ensure you are protected is to update your devices automatically, advises Elliott Wilkes, <a href="https://www.itpro.com/strategy/28237/cto-job-description-what-does-a-cto-do"><u>CTO</u></a> at consultancy and managed service provider Advanced Cyber Defence Systems. This should include all devices that access company data such as computers, smartphones, servers, <a href="https://www.itpro.com/cloud/virtual-machines/355269/getting-started-with-virtual-machines"><u>virtual machines (VMs)</u></a>, and <a href="https://www.itpro.com/cloud-computing/28037/what-is-iot"><u>Internet of Things (IoT)</u></a> devices, he says. “It sounds simple, but you’d be surprised at how many ransomware events have taken place over the past few years using well-known vulnerabilities that have been fixed, but the organization didn’t deploy the patch.” </p><p>While it might seem obvious, ensuring all devices <a href="https://www.itpro.com/security/antivirus/367785/best-business-antivirus"><u>have an antivirus system</u></a> and that team members use <a href="https://www.itpro.com/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password"><u>strong passwords</u></a> including random words, numbers, and symbols can “provide a first line of defense”, says David Clarke, head of security at IT consultancy Quostar. </p><p>Craig Jones, VP of security operations at security firm Ontinue advises creating and implementing policies around secure internet use and handling sensitive data. “This includes avoiding suspicious emails or links, not sharing passwords, and not using unsecured <a href="https://www.itpro.com/networking/27835/best-wi-fi-routers"><u>Wi-Fi networks</u></a> for work-related tasks. Don’t assume everyone knows the basics – even simple mistakes can lead to significant breaches.” </p><h2 class="article-body__section" id="section-3-use-technology-like-mfa-wisely"><span>3. Use technology like MFA wisely </span></h2><p>Technology isn’t everything, but it can help boost security when resources are limited. Cheap and easy to use, one of the best additions to your security strategy is <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication"><u>multi-factor authentication (MFA)</u></a>. Adding this extra layer of defense will help avoid your business being caught out by <a href="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022"><u>weak passwords</u></a> and it also reduces the margin for human error.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="rSLpVvmLYDC6iry7xEeD93" name="GettyImages-1252213663.jpg" caption="" alt="A close up photo of the side of a dark blue conference booth with a glowing neon IBM sign on the side" src="https://cdn.mos.cms.futurecdn.net/rSLpVvmLYDC6iry7xEeD93.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The Total Economic Impact™ Of Turbonomic Application Resource Management</strong></p><p class="fancy-box__body-text"><em>See how customers are using IBM&apos;s Turbonomic Application Resource Management to optimize key application resourcing levels and scale.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/business-apps/368465/the-total-economic-impacttm-of-turbonomic-application-resource"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Wilkes advises enabling MFA on all accounts where possible, using an app such as Google or Microsoft Authenticator. “If you only have the option to use SMS, that’s ok too – but try to use an app if you can. These store temporary codes that you enter along with your password to login to a website or application.”</p><p>For super-robust defenses, especially if your business operates in a high-risk industry vertical, you could consider a physical token to secure your accounts, such as a Yubico YubiKey. “These provide authentication that is much more resistant to phishing emails, which is an increasingly common way criminals gain access to an organization’s systems and data,” says Wilkes.</p><p>Additionally, if it’s feasible within your budget, SMBs should consider security information and event management platforms (SIEMs) which feature vulnerability assessments and cyber threat intelligence technology, says Clarke. “Regular cyber security assessments can be critical to protecting firms by helping them identify weaknesses and potential entry points into their networks.”</p><h3 class="article-body__section" id="section-4-invest-time-and-effort-into-cyber-security-training"><span>4. Invest time and effort into cyber security training</span></h3><p>It’s often said that employees are a firm’s weakest link, and many cyber attacks are successful due to a simple mistake made by a member of staff. A costly blind spot for any business, particularly SMBs, is failing to invest in <a href="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training"><u>cyber security training</u></a>, says Pylarinos. “With cyber threats on the rise and growing in sophistication, training your staff to combat the latest risks is crucial.”</p><iframe width="100%" frameborder="0" allow="encrypted-media" data-lazy-priority="high" data-lazy-src="https://open.spotify.com/embed-podcast/episode/2znUT5UIPFAM1pGya83iwT"></iframe><div  class="fancy-box"><div class="fancy_box-title">READ MORE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="87dZRKooaAKTpD9dtiBV3d" name="87dZRKooaAKTpD9dtiBV3d.jpg" caption="" alt="Network and security" src="https://cdn.mos.cms.futurecdn.net/87dZRKooaAKTpD9dtiBV3d.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training"><strong>A guide to cyber security certification and training</strong></a></p></div></div><p>As part of this, SMBs should ensure they are encouraging <a href="https://www.itpro.com/security/33974/our-5-minute-guide-to-security-awareness-training"><u>cyber awareness</u></a> among all employees, says Pylarinos. This is often overlooked: In 2022, the <a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2022/cyber-security-breaches-survey-2022" target="_blank"><u>UK Government</u></a> found only one in five businesses (17%) provided awareness sessions for those not directly involved in cyber security. </p><p>This is despite the fact that the majority of breaches <a href="https://aag-it.com/the-latest-phishing-statistics/#:~:text=Phishing%20is%20the%20most%20common%20form%20of%20cyber%20crime.,were%20the%20victim%20of%20phishing." target="_blank"><u>(83%)</u></a> were a result of <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> – seeing employees mistakenly clicking on malicious links or downloading malware-ridden documents. “By consistently training employees of all levels on the basics of cyber awareness, SMBs can spot phishing or <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one"><u>social engineering</u></a> lures and thwart cyber threats across their organization,” says Pylarinos.</p><p>Employee training can be performed in a number of ways, using educational platforms and exercises. Experts also agree it should be done regularly to ensure you are up to date with the latest threats.</p><p>Lewis West, head of cyber security at recruitment firm Hamilton Barnes, advises SMBs to be focused on building a “strong security culture” and increasing awareness across the entire team. “Training employees to become more aware of security and adversaries’ methods is an effective way to reduce the number of successful cyber attacks.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Automate security intelligence with IBM Security QRadar SIEM ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369799/automate-security-intelligence-with-ibm-security-qradar-siem</link>
                                                                            <description>
                            <![CDATA[ Simplify and improve threat detection, investigation and response with reducing overheads ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">it22DtURa1QUHyVvirJcp5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LTMrgEvSNMdUH7gB9RYH7b-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 05 Jan 2023 11:01:38 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Big Data]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/LTMrgEvSNMdUH7gB9RYH7b-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with title, logo on black header banner, and bar graphs]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with title, logo on black header banner, and bar graphs]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with title, logo on black header banner, and bar graphs]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LTMrgEvSNMdUH7gB9RYH7b-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Research from the Enterprise Strategy Group (ESG) reveals that IT professionals struggle to identify the most valuable data available to them, so priority investments include the centralisation of data with increased security controls, as well as comprehensive analytics to identify complex attacks. As a solution, organisations are investing in SIEM infrastructure but admit they find it difficult to manage it effectively.</p><p>In this technical product review of IBM Security QRadar SIEM, ESG makes several observations, including QRadar's ability to prioritise events, lower costs, integrate with both IBM and 3rd party solutions, and more.</p><p>Download the full report for more details and how to overcome the most challenging attributes of SIEM for your business.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="rQy9MUeL7vDLefQJcJuEZZ" name="" alt="IBM logo" src="https://cdn.mos.cms.futurecdn.net/rQy9MUeL7vDLefQJcJuEZZ.png" mos="https://cdn.mos.cms.futurecdn.net/rQy9MUeL7vDLefQJcJuEZZ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49900/ibm-q1-2023-en?locale=1&p=false&wp=10659"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How governments can build resilience in a new normal ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/367526/how-governments-can-build-resilience-in-a-new-normal</link>
                                                                            <description>
                            <![CDATA[ The cloud enables the flexibility public organisations need to overcome disruption ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6B9tZWfHpciowU1EVsbeLy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VQbwzBT8BwD5RLgcGWWdkj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 28 Apr 2022 12:16:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VQbwzBT8BwD5RLgcGWWdkj-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Black whitepaper cover with title]]></media:description>                                                            <media:text><![CDATA[Black whitepaper cover with title]]></media:text>
                                <media:title type="plain"><![CDATA[Black whitepaper cover with title]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VQbwzBT8BwD5RLgcGWWdkj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The cloud was instrumental in allowing the public sector to keep the wheels on in the face of several years of huge disruption, with those organisations that embraced the scalable services on offer being much better equipped to confront these seismic changes. </p><p>This whitepaper dives into how governments’ resilience is critical to managing disruption across different areas of the public sector, and the ways in which the cloud is enabling adaptability and responsiveness that is needed.</p><p>Download now to discover the emerging practices that will build public sector resilience in the face of current and future uncertainty.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TTFdqMZ2i4cHSjQkyxGMJ" name="" alt="AWS logo" src="https://cdn.mos.cms.futurecdn.net/TTFdqMZ2i4cHSjQkyxGMJ.jpg" mos="https://cdn.mos.cms.futurecdn.net/TTFdqMZ2i4cHSjQkyxGMJ.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49633/aws-standard-form-en?locale=1&p=false&wp=9007"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The event mesh: A primer ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-insights/analytics/361161/the-event-mesh-a-primer</link>
                                                                            <description>
                            <![CDATA[ Benefits of an event-driven architecture ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jQ4DXfVBDeg8NU7EHwG4XC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UnTqQYfRzRDR3eYkGTi46Y-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 07 Oct 2021 16:19:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Machine learning]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/UnTqQYfRzRDR3eYkGTi46Y-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mesh/netting floating against a blue background ]]></media:description>                                                            <media:text><![CDATA[Mesh/netting floating against a blue background ]]></media:text>
                                <media:title type="plain"><![CDATA[Mesh/netting floating against a blue background ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UnTqQYfRzRDR3eYkGTi46Y-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>Provided by </em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="WmNGsv6UaiPmvR4AYnmFuP" name="" alt="Red Hat logo" src="https://cdn.mos.cms.futurecdn.net/WmNGsv6UaiPmvR4AYnmFuP.png" mos="https://cdn.mos.cms.futurecdn.net/WmNGsv6UaiPmvR4AYnmFuP.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>A change in a system, like a customer updating their information or placing an order, produces a notification called an event. </p><p>To best manage the increasing volume of event producers and consumers in your TT ecosystem and make use of the information in event streams, your organisation needs an event-driven architecture (EDA). </p><p>Download this whitepaper to learn about the key capabilities of an EDA, like: </p><ul><li>Pub-sub and message-oriented middleware to reliably move event messages</li><li>Streaming analytics, which applies machine learning to make decisions</li><li>Event mesh, a dynamic infrastructure that allows message to be delivered across a distributed enterprise</li></ul><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/redhat-redhat-cloud-native-integrated-abm-non-abm-q321?locale=1&p=false&wp=7252"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Customer identity and access management for dummies ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/identity-and-access-management-iam/360520/customer-identity-and-access-management-for</link>
                                                                            <description>
                            <![CDATA[ Why CIAM matters now (more than ever) and what to look for in a CIAM solution ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">r559iHGgEmTGyAd2KpjNnW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eUKgj9ZRPzQdGDXgMPUybY-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 09 Aug 2021 13:53:20 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/eUKgj9ZRPzQdGDXgMPUybY-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper front cover]]></media:description>                                                            <media:text><![CDATA[Whitepaper front cover]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper front cover]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eUKgj9ZRPzQdGDXgMPUybY-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aVingsbZaxsFEzjgWucZgF" name="" alt="Okta logo" src="https://cdn.mos.cms.futurecdn.net/aVingsbZaxsFEzjgWucZgF.png" mos="https://cdn.mos.cms.futurecdn.net/aVingsbZaxsFEzjgWucZgF.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Most often than not, as a consumer, you will have been used to experiencing customer identity and access management with your own favourite apps and websites, whether that’s online banking on your smartphone, or online shopping through your social media. CIAM provides the digital identity layer for businesses to identify who you are, across multiple touchpoints, as well as the registration and sign-up process in order to keep your information secure.</p><p>In this dummies guide brought to you by OKTA, you’ll realise how CIAM can support your business to deliver secure, seamless digital experiences for your customers and what the key CIAM capabilities are.</p><p>Download to learn:</p><ul><li>What the future looks like for CIAM</li><li>What to look for in a modern CIAM solution</li><li>Ten important things to consider in CIAM</li></ul><p><em>Fill out the form below to access this resource</em></p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/okta-interim-form-1?locale=1&p=false&wp=7078"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ From zero to hero: The path to CIAM maturity ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/identity-and-access-management-iam/360519/the-path-to-ciam-maturity</link>
                                                                            <description>
                            <![CDATA[ Your guide to the CIAM journey ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">98Xr1cCNBaLLDY962em8Bc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/46MS25Ne58gQYeTNcHoXhW-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 09 Aug 2021 13:38:39 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/46MS25Ne58gQYeTNcHoXhW-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper front cover]]></media:description>                                                            <media:text><![CDATA[Whitepaper front cover]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper front cover]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/46MS25Ne58gQYeTNcHoXhW-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aVingsbZaxsFEzjgWucZgF" name="" alt="Okta logo" src="https://cdn.mos.cms.futurecdn.net/aVingsbZaxsFEzjgWucZgF.png" mos="https://cdn.mos.cms.futurecdn.net/aVingsbZaxsFEzjgWucZgF.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Customer identity and access management (CIAM) allows customers to have the constant, immediate access to digital services they expect, while also keeping them secure. Organisations moving towards identity and access management can often struggle with security vulnerabilities, however far along the process they are, which in turn affects their customers’ confidence in them.</p><p>To eliminate this, businesses need to put their customers first, with an effective CIAM solution that covers authentication, authorisation and user management. By implementing this robust infrastructure, you can protect your customers’ data and re-inspire their trust.</p><p>Download this guide from OKTA to understand the four key phases on the path to CIAM, as well as the pain points your business may come up against, and the solutions to them.</p><p><em>Fill in the form below to access this resource</em></p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/okta-interim-form-1?locale=1&p=false&wp=7077"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Five questions to ask before you upgrade to a modern SIEM ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/security-information-and-event-management-siem/360173/five-questions-to-ask-before-you</link>
                                                                            <description>
                            <![CDATA[ Do you need a better defense strategy? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5kCUnhvP2QQhhQPNDDumqs</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yi42ZzWeFY9Fmacd8eDdk3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 09 Jul 2021 10:40:56 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yi42ZzWeFY9Fmacd8eDdk3-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[White title against a dark blue background - whitepaper from IBM]]></media:description>                                                            <media:text><![CDATA[White title against a dark blue background - whitepaper from IBM]]></media:text>
                                <media:title type="plain"><![CDATA[White title against a dark blue background - whitepaper from IBM]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yi42ZzWeFY9Fmacd8eDdk3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>Provided by </em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TDE4LyFCjKBJzACUQeK6rZ" name="" alt="IBM logo" src="https://cdn.mos.cms.futurecdn.net/TDE4LyFCjKBJzACUQeK6rZ.png" mos="https://cdn.mos.cms.futurecdn.net/TDE4LyFCjKBJzACUQeK6rZ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Did you know that the average enterprise security team sees 200,000 security events per day? </p><p>As attackers become more dangerous and the regulatory environment continuously evolves, basic tools just can’t keep up. This is why upgrading to a Modern Security Information and Event Management (SIEM) solution is crucial.</p><p>SIEM solutions go beyond the automatic collection, parsing and normalising of logs. They apply advanced correlation and analytics to automatically detect threats, assess their severity and filter through the noise to alert you to critical events. They leverage built-in automation and intelligence to keep you protected — while simultaneously freeing up time to focus on remediation and recovery. </p><p>However, before you upgrade to a modern SIEM solution you need to be able to determine the best solution for your organisation. This report explores the five key questions to help you make this decision.</p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/li-285388-ibm-security-geo-qradar-q3-21-uk?locale=1&p=false&wp=6725"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Aberdeen Report: How a platform approach to security monitoring initiatives adds value ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/360172/aberdeen-report-how-a-platform-approach-to-security-monitoring-initiatives-adds</link>
                                                                            <description>
                            <![CDATA[ Integration, orchestration, analytics, automation, and the need for speed ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gcVHRREfGrnNWtcM5PwZVG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MhoDQHbDgtzbg6RyMTEvAn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 09 Jul 2021 10:20:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MhoDQHbDgtzbg6RyMTEvAn-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[White text against a pink-red background - whitepaper from IBM]]></media:description>                                                            <media:text><![CDATA[White text against a pink-red background - whitepaper from IBM]]></media:text>
                                <media:title type="plain"><![CDATA[White text against a pink-red background - whitepaper from IBM]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MhoDQHbDgtzbg6RyMTEvAn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>Provided by </em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TDE4LyFCjKBJzACUQeK6rZ" name="" alt="IBM logo" src="https://cdn.mos.cms.futurecdn.net/TDE4LyFCjKBJzACUQeK6rZ.png" mos="https://cdn.mos.cms.futurecdn.net/TDE4LyFCjKBJzACUQeK6rZ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>The most productive security teams are going beyond the use of tactical tools for investigation and reporting of security incidents.</p><p>Instead, they are taking a more strategic, proactive, platform-oriented approach to identifying and assessing security-related risks, proving compliance, and maturing the flexibility and resilience of ongoing operations.</p><p>Download this resource now to see how security strategies have been evolving in recent years and how a platform-oriented approach improves visibility, analytics, automation, and more. </p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/li-285388-ibm-security-geo-qradar-q3-21-uk?locale=1&p=false&wp=6728"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ManageEngine Log360 review: SIEM for all seasons ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/security-information-and-event-management-siem/356712/manageengine-log360-review-siem-for</link>
                                                                            <description>
                            <![CDATA[ ManageEngine shows log management needn’t cost a king’s ransom ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ibYDjth7RHKsthR2tMdwkh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QSZy4fda3NRDRZBthFXsoc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2020 08:26:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QSZy4fda3NRDRZBthFXsoc-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QSZy4fda3NRDRZBthFXsoc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Part of ManageEngine’s burgeoning product portfolio, Log360 delivers a complete SIEM (security information and event management) solution that’s priced right for SMBs and mid-sized organizations. It teams up a choice selection of ManageEngine’s IT security management products, amalgamates them into a single web console for easy access and offers optional add-on products to further enhance its efficacy.</p><p>The Log360 web site is a tad vague about what is actually included in the suite so we asked ManageEngine support to clarify. It advised us that the base Log360 suite includes ADAudit Plus, EventLog Analyzer, O365 (Office 365) Manager Plus and Log360 UEBA (user and entity behavior analytics).</p><p>Add-ons include Exchange Reporter Plus for on-premises mail server auditing and ADManager Plus, which adds a heap of Active Directory reporting tools. DataSecurity Plus also provides file server auditing and DLP (data leak prevention) while Cloud Security Plus collects and analyzes log data from <a href="https://www.itpro.com/amazon-web-services-aws/34126/amazon-web-services-review-aws-packs-in-more-features-than-any-other" data-original-url="https://www.itpro.com/amazon-web-services-aws/34126/amazon-web-services-review-aws-packs-in-more-features-than-any-other">AWS</a>, <a href="https://www.itpro.com/microsoft-azure/34048/microsoft-azure-review-competitive-cloud-pricing-takes-a-bite-out-of-aws" data-original-url="https://www.itpro.com/microsoft-azure/34048/microsoft-azure-review-competitive-cloud-pricing-takes-a-bite-out-of-aws">Azure</a>, Google Cloud and <a href="https://www.itpro.com/software-as-a-service-saas/33817/salesforce-essentials-review-stripped-back-crm-wins-on" data-original-url="https://www.itpro.com/software-as-a-service-saas/33817/salesforce-essentials-review-stripped-back-crm-wins-on">SalesForce</a>.</p><h2 id="manageengine-log360-review-pricing-and-getting-started">ManageEngine Log360 review: Pricing and getting started</h2><p>Prices for Log360 start at around £452 but costs will depend entirely on what you want to monitor. We requested a quote from ManageEngine for 1 domain controller, 5 Windows servers, 5 syslog sources, 100 workstations, 5 Windows file servers, 5 application auditing licenses, AD reporting, an Exchange server, UEBA and a single Office 365 tenant and it came back the next day with annual subscription cost of only £4,078.</p><p>Initial installation of the base Log360 suite is simple, as it’s handled by a single routine. We loaded in on a Windows Server 2019 Hyper-V VM logged in as a domain member, and the suite was ready to go in 20 minutes.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FKEsfMZEUaV48UHbgURtdX" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/FKEsfMZEUaV48UHbgURtdX.jpg" mos="https://cdn.mos.cms.futurecdn.net/FKEsfMZEUaV48UHbgURtdX.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Each individual component has its own web console with a dedicated port number and Log360 provides a single pane of glass for accessing them all. If you install more components later on, you can add them to the main Log360 console by entering their host name and service port number.</p><p>We suggest adhering to the recommended host hardware specification as the minimum requirement is nowhere near enough - our VM initially had 2 CPU cores plus 8GB of memory and Log360 ate the lot. In fact, we weren’t happy with performance until we had assigned 8 virtual Xeon Scalable Gold cores and 32GB of memory to the Log360 VM.</p><h2 id="manageengine-log360-review-adaudit-plus-and-eventlog-analyzer">ManageEngine Log360 review: ADAudit Plus and EventLog Analyzer</h2><p>The Log360 console opens with dashboard status overviews of all components, and each one can be quickly accessed from the side bar. ADAudit Plus presents graphs for at-a-glance views of user logon failures, account deletion, modification and creation activities, logon failure error reasons, logon activity, account lockouts and password changes.</p><p>It offers access to hundreds of exportable reports on all manner of AD activity (and Azure AD if configured), while the Compliance tab provides reports on regulatory standards including SOX, PCI-DSS, <a href="https://www.itpro.com/marketing-comms/communications/355204/how-technology-is-changing-healthcare" data-original-url="https://www.itpro.com/marketing-comms/communications/355204/how-technology-is-changing-healthcare">HIPAA</a> and, <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/30107/get-gdpr-ready" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/30107/get-gdpr-ready">of course, GDPR</a>. You can peruse activity on Windows, NetApp, Dell EMC and Synology file servers, use analytics to spot anomalous activity and choose when to archive logs for 24 different AD categories</p><p>EventLog Analyzer supports over 750 log sources so you can integrate data from your core servers, firewalls, routers, switches, databases, VMware and Hyper-V hypervisors, web servers, vulnerability scanners and endpoint security products. Logs are easily managed as it provides full archiving facilities, where you specify intervals and retention periods and elect to have the files securely encrypted and time-stamped.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="vpPBacBkX4ajrS5FBqYP59" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/vpPBacBkX4ajrS5FBqYP59.jpg" mos="https://cdn.mos.cms.futurecdn.net/vpPBacBkX4ajrS5FBqYP59.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Log interrogation features are outstanding; you can use the console’s top search bar for fast results or create more complex queries using wild-cards, phrases, Boolean operators, groups and ranges. Log data can be correlated from multiple sources and reporting tools include a range of canned reports plus a full set for GDPR compliance.</p><h2 id="manageengine-log360-review-o365-manager-plus-and-log360-ueba">ManageEngine Log360 review: O365 Manager Plus and Log360 UEBA</h2><p>O365 Manager Plus just required us to enter our tenant details and we could then use its customisable dashboard to view mail traffic, malware and spam activity, top senders or receivers, mobile users, mailbox quotas and much more. The usage view required ManageEngine’s RESTful API access to be enabled and then we could view our user’s <a href="https://www.itpro.com/desktop-software/19337/office-365-review" data-original-url="https://www.itpro.com/desktop-software/19337/office-365-review">OneDrive</a>, <a href="https://www.itpro.com/software/355452/skype-review-retrofitted-for-the-modern-age" data-original-url="https://www.itpro.com/software/355452/skype-review-retrofitted-for-the-modern-age">Skype</a> and <a href="https://www.itpro.com/software/33703/microsoft-teams-review-a-no-brainer-for-microsoft-shops" data-original-url="https://www.itpro.com/software/33703/microsoft-teams-review-a-no-brainer-for-microsoft-shops">Teams</a> activities.</p><p>Reports are available for all Office 365 functions and range from mailboxes and mail traffic to all things related to users, groups, contacts, account security and registered Azure AD devices. Extensive auditing for both Exchange Online and <a href="https://www.itpro.com/cloud/microsoft-azure/355686/hackers-spoof-new-azure-ad-and-microsoft-365-sign-in-pages" data-original-url="https://www.itpro.com/cloud/microsoft-azure/355686/hackers-spoof-new-azure-ad-and-microsoft-365-sign-in-pages">Azure AD</a> is only a few clicks away and logs older than a set number of days can be archived and password protected.</p><p>Log360 UEBA opens with an informative dashboard showing how many events have been ingested, anomalies detected, trends over time plus users and devices being tracked. Each user and entity is assigned a risk score based on their activities, which you can view from the relevant dashboard to see why they have been marked up for attention and generate detailed anomaly reports on areas such as failed logins, registry activities, firewall changes and even USB device usage.</p><h2 id="manageengine-log360-review-optional-add-ons">ManageEngine Log360 review: Optional add-ons</h2><p>If you have an on-prem Exchange server then Exchange Reporter Plus is well worth considering. Its main dashboard shows all inbound and outbound mail activity along with a traffic summary and a sidebar which highlights alerts you need to investigate. Extensive predefined reports tell you everything you need to know about your organisation’s email while the auditing section keeps you informed of any changes to your Exchange databases along with mailbox permissions and properties.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="pyX9bYEXzQSwB5CUyVsira" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/pyX9bYEXzQSwB5CUyVsira.jpg" mos="https://cdn.mos.cms.futurecdn.net/pyX9bYEXzQSwB5CUyVsira.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Another add-on that’s worth a look is ADManager Plus, as this takes AD reporting to a higher level. However, note that this is a cut down version for Log360 that doesn’t include the AD object management tools provided by the full standalone version.</p><h2 id="manageengine-log360-review-verdict">ManageEngine Log360 review: Verdict</h2><p>Businesses <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/31065/gdpr-compliance-checklist-is-your-organisation-gdpr" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/31065/gdpr-compliance-checklist-is-your-organisation-gdpr">worried about GDPR compliance</a> can rest easy with Log360 at their side as it delivers an excellent range of event log and security management tools. Best installed on a dedicated host, it neatly integrates everything into one central console, more components can be added as required and it’s all offered at a competition-thrashing price.</p><h2 id="manageengine-log360-system-requirements-recommended">ManageEngine Log360 system requirements (recommended)</h2><div ><table><tbody><tr><td  ><strong>CPU</strong></td><td  >3GHz, 8 cores</td></tr><tr><td  ><strong>Memory</strong></td><td  >16GB</td></tr><tr><td  ><strong>Disk space</strong></td><td  >150GB</td></tr><tr><td  ><strong>OS</strong></td><td  >Windows 7, Server 2012 R2 upwards</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The tech industry must embrace automation if it wants better security analysts ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/34719/the-tech-industry-must-embrace-automation-if-it-wants-better-security-analysts</link>
                                                                            <description>
                            <![CDATA[ There’s no reason why we shouldn’t be automating menial security processes in 2019, according to McAfee ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kUXNhBNRrEyyHVRtSSmeUk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SH5RnQGPYn8N4DQPzkkFS4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 31 Oct 2019 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Careers and Training]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SH5RnQGPYn8N4DQPzkkFS4-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber security automation mockup]]></media:description>                                                            <media:text><![CDATA[Cyber security automation mockup]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber security automation mockup]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SH5RnQGPYn8N4DQPzkkFS4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Automating necessary, but menial and time-consuming functions in a business could be the key to unlocking the next wave of advanced analysts and threat hunters.</p><p>'There really isn't any reason to avoid automation,' according to Michael Leland, chief technology strategist at McAfee, adding that only through embracing the automation of tasks, specifically in a company's security operations centre (SOC), can they hope to free up valuable human brainpower for other things.</p><p>Speaking at (ISC)2 Security Congress, Leland said every tier 1 analyst wants to move up to tier 2, but are stymied by the relentless and menial work they have to do.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/automation/33000/how-automation-can-help-digital-transformation" data-original-url="/automation/33000/how-automation-can-help-digital-transformation">How automation can help digital transformation</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/29594/what-is-workload-automation" data-original-url="/strategy/29594/what-is-workload-automation">What is workload automation?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/33565/amazons-human-workers-are-safe-for-now-but-the-tide-of-automation-is-rising" data-original-url="/business-strategy/33565/amazons-human-workers-are-safe-for-now-but-the-tide-of-automation-is-rising">Amazon's human workers are safe for now, but the tide of automation is rising</a></p></div></div><p>"A tier one analyst whose job is to pick through the events at a very low level I hate to call them it trained monkey work but at the end of the day, a lot of the work they're doing is mindless." he said.</p><p>"But I can tell them that I'm reducing the workload by 80% by allowing a bunch of <a href="https://www.itpro.com/strategy/29594/what-is-workload-automation" target="_blank" data-original-url="https://www.itpro.com/strategy/29594/what-is-workload-automation">the automation</a> to do his job. That time restriction now is removed and he can start performing more advanced techniques that you might want to learn."</p><p>These monotonous duties preventing tier 1 analysts progressing to tier 2 and beyond include triaging all the events that pop up in the SOC and evaluating whether they need remediation.</p><p>The time it takes a human to triage an event and perform remediation takes around 75 minutes, what's known as dwell time. An automated process could do it in just two, according to Leland and the efficacy of a SOC is measured, in part, on the dwell time it takes to remediate issues.</p><p>"The only way to achieve this kind of efficiency is to automate as many of these tasks as possible, whether that's an AI engine, whether it's machine learning or simply mining data," he said.</p><p>The value of a unified and automated architecture is huge. Automating processes in a SOC can lead to a 1,000% or more increase in event handling capacity, a 65% quicker triage rate and this is all done with a much greater degree of accuracy compared to what a human can produce.</p><p>This is due to a few things, the first being a human's inability to multi-task. Leland referenced an experiment McAfee did with people who were originally told to enter a room, scan it and then recall all the items they saw in that room after.</p><p>People were able to score a 98% recall rate in the first test condition, but when the researchers made them unlock a door before entering the room an added task the recall rate tumbled to 67%.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="p9JgJVaV6Vg5VYzrXiWn3c" name="p9JgJVaV6Vg5VYzrXiWn3c.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/p9JgJVaV6Vg5VYzrXiWn3c.png" mos="https://cdn.mos.cms.futurecdn.net/p9JgJVaV6Vg5VYzrXiWn3c.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>How AI and automation are changing the way work gets done</strong></p><p class="fancy-box__body-text">Intelligent automation will be a defining factor for the future workforce</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/automation/354065/how-ai-and-automation-are-changing-the-way-work-gets-done" data-original-url="/business-strategy/automation/354065/how-ai-and-automation-are-changing-the-way-work-gets-done">FREE DOWNLOAD</a></p></div></div><p>"We think that the combination of humans and machines, the concept of human-machine teaming is probably the only way that we are going to achieve better accuracies, reduced timeframes for meantime detection, reduced meantime for remediation and reducing alert fatigue," said Leland.</p><p>Another factor affecting the effectiveness of a SOC program is the constraints on resources that businesses face. By freeing up tier 1 analysts, organisations can use their analyst's free time to explore opportunities to improve what those analysts are already doing, or do new things to benefit the business while the automated SOC works in the background.</p><p>The need for automation has never been greater for businesses and that's evidenced by the sheer number of events that trigger alerts in a SOC environment.</p><p>Leland said, on average, an enterprise of a significant size will be alerted to 3.2 billion events a month. 3,000 of these will require investigation and only 13 will be critically dangerous.</p><p>"How else would you find those 13 in 3.2 billion if you have a human bottleneck? Automation is the only way to achieve that."</p><p>Automation may be one of the industry's most feared buzzwords it <a href="https://www.itpro.com/business-strategy/33565/amazons-human-workers-are-safe-for-now-but-the-tide-of-automation-is-rising" target="_blank" data-original-url="https://www.itpro.com/business-strategy/33565/amazons-human-workers-are-safe-for-now-but-the-tide-of-automation-is-rising">threatens the jobs</a> of many real people working in the industry but a rise in automation should instil fear in no-one, Leland claims.</p><p>"The idea behind robots replacing humans is probably something that we're not going to see in our lifetime," he said. "But what is more realistic is that we're going to build environments where humans and AI or computers work better together to create greater value."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Privacy International claims most Android apps share data with Facebook without user consent ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/privacy/32634/android-apps-share-data-facebook-without-user</link>
                                                                            <description>
                            <![CDATA[ The social media giant’s third-party tracking via the Facebook SDK may constitute a GDPR breach ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">as5Ub2yQvHJNfY4PaqLT3y</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aSkeUjffMXVdTtw3gigp7T-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Jan 2019 10:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aSkeUjffMXVdTtw3gigp7T-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Graphic of individuals being glared at by cameras and having their privacy invaded]]></media:description>                                                            <media:text><![CDATA[Graphic of individuals being glared at by cameras and having their privacy invaded]]></media:text>
                                <media:title type="plain"><![CDATA[Graphic of individuals being glared at by cameras and having their privacy invaded]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aSkeUjffMXVdTtw3gigp7T-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Privacy International has found that more than half of Android apps, including big names like Skyscanner and Tripadvisor, automatically transfer data to Facebook when opened without user consent.</p><p>In a 51-page report titled <a href="https://privacyinternational.org/report/2647/how-apps-android-share-data-facebook-report" target="_blank"><em>'How Apps on Android Share Data with Facebook'</em></a>, Privacy International revealed 61% of the 34 apps tested transfer data such as "app installed" or "SDK initialised" when the app is opened. The app also sends data about the nature of the device the user owns, and the user's location based on language and time zone settings.</p><p>According to researchers, this data is gathered by Facebook regardless of consent, or whether users even have a Facebook account.</p><p>The data reveals how often people use these apps, according to Privacy International's analysis, and is often sent with a unique identifier such as Google Advertising ID (AAID), or Apple's IDFA. Together, the data could be used by advertisers to link data about user behaviour and paint a comprehensive profile.</p><p>"If combined, data from different apps can paint a fine-grained and intimate picture of people's activities, interests, behaviours and routines, some of which can reveal special category data, including information about people's health or religion," the report warned.</p><p>"For example, an individual who has installed the following apps that we have tested, "Qibla Connect" (a Muslim prayer app), "Period Tracker Clue" (a period tracker), "Indeed" (a job search app), "My Talking Tom" (a children's' app), could be potentially profiled as likely female, likely Muslim, likely job seeker, likely parent."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/32395/whats-been-going-on-with-facebook" data-original-url="/business-operations/32395/whats-been-going-on-with-facebook">What's been going on with Facebook?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/social-media/31055/why-facebook-could-become-the-next-myspace" data-original-url="/social-media/31055/why-facebook-could-become-the-next-myspace">Why Facebook could become the next Myspace</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/32211/facebook-fined-500000-for-cambridge-analytica-data-scandal" data-original-url="/policy-legislation/32211/facebook-fined-500000-for-cambridge-analytica-data-scandal">Facebook fined £500,000 for Cambridge Analytica data scandal</a></p></div></div><p>The report also found that some apps routinely send Facebook data that is highly detailed and occasionally sensitive, including data on users who do not have Facebook accounts.</p><p>Privacy International highlighted how travel app KAYAK, for example, would send information about flight searches including departure dates, departure city, destination, number of tickets, number of children and class of ticket.</p><p>"Facebook places the sole responsibility on app developers to ensure that they have the lawful right to collect, use and share people's data before providing Facebook with any data," the report continued.</p><p>"However, the default implementation of the Facebook SDK is designed to automatically transmit event data to Facebook."</p><p>The digital rights group suggested this constitutes a breach of the EU's General Data Protection Regulation (GDPR) given the Facebook SDK automatically shares data before apps are able to ask users to agree or consent.</p><p>In light of developers filing 'bug reports' last year, Facebook released a voluntary feature that should allow developers to delay collecting automatically logged events, such as "SDK initialised", until after they acquire user consent. This feature was only launched 35 days after GDPR took effect on 25 May, however, and only works with SDK version 4.34 and later.</p><p>"Prior to our introduction of the "delay" option, developers had the ability to disable transmission of automatic event logging data, except for a signal that the SDK had been initialised," Facebook said in response to the report.</p><p>"Following the June change to our SDK, we also removed the signal that the SDK was initialised for developers that disabled automatic event logging.</p><p>"In June we also introduced another option for businesses that want to use our auto-event logging feature in compliance with our Business Tools Terms.</p><p>"Today, an app developer can either choose to use a pre-installed mechanism for obtaining an end user's prior informed consent (as they could in the past), or use the SDK delay feature."</p><p>Privacy International's report insisted that despite these options for developers, automatic data transmission was still detected for the majority of apps tested.</p><p>A number of possible factors could explain this, including the fact that data sharing is the default option, and that many apps run older versions of the Facebook SDK. Skyscanner, for instance, was running version 4.33.0 of the SDK when tested in early December, while Spotify was running version 4.310.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kali Linux installation on Windows 10 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/linux/31023/kali-linux-installation-on-windows-10</link>
                                                                            <description>
                            <![CDATA[ Follow these simple steps to install the security-focused Linux distro from the Microsoft Store ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fx9hv5FpjVpiWMoepKPng2</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dF5KwnXo7RGbYHjT7MtqHQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 30 Apr 2018 14:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Linux]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dF5KwnXo7RGbYHjT7MtqHQ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dF5KwnXo7RGbYHjT7MtqHQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Ethical hackers got a real treat last month, when Kali Linux officially became available on the Microsoft Store, running on Windows Subsystem for Linux (WSL).</p><p>Kali Linux is a security-focused Linux distro based on Debian and is designed primarily for 'offensive security', which is a branch of cyber security that involves ethical hackers attacking businesses in order to expose flaws in their networks that can then be fixed, a process known as penetration testing.</p><p>The software comes pre-packaged with a variety of different command line hacking tools, including password crackers, packet sniffers and exploit tools. But you need to install it before you can make use of these pen-test treasures. Luckily, it's fairly simply to do that. Following the steps <a href="https://www.kali.org/news/kali-linux-in-the-windows-app-store" target="_blank">laid out on Kali Linux's open source project page</a>, maintained and funded by Offensive Security, you can set up your machine with all the tools you need to perform a comprehensive pen test.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/penetration-testing/30697/kali-linux-comes-to-windows-10-handing-hacking-tools-to-pen-testers" data-original-url="/penetration-testing/30697/kali-linux-comes-to-windows-10-handing-hacking-tools-to-pen-testers">Kali Linux comes to Windows 10, handing hacking tools to pen testers</a></p></div></div><h3 class="article-body__section" id="section-update-windows-10"><span>Update Windows 10</span></h3><p>Firstly, if this is your first time using WSL, you'll need to update your Windows 10 machine to install it. You can do this by navigating to the Control Panel and go to 'Apps and Features', select 'Programs and Features' from the right panel and click 'Turn Windows features on or off' from the left menu. Select WSL and save it. </p><p>Alternatively you can open an administrative PowerShell window and install WSL by running the following command: Enable-WindowsOptionalFeature -Online -FeatureName Microsoft-Windows-Subsystem-Linux.</p><p>Whichever method you choose, Windows 10 will then reboot and you'll be able to then find, download and install the Kali Linux app in the Microsoft Store.</p><h3 class="article-body__section" id="section-install-kali-linux"><span>Install Kali Linux</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7cFxSgDtkAgrWtMGrmg534" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/7cFxSgDtkAgrWtMGrmg534.png" mos="https://cdn.mos.cms.futurecdn.net/7cFxSgDtkAgrWtMGrmg534.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>One you have launched the application, you'll need to create a default UNIX account as part of the installation process, and add a password. Once you do so, WSL will automatically complete the installation and open a new console window.</p><p>Kali Linux's open source creators advise users to run an upgrade to keep up with the latest packages, and to clean up the apt-cache to save space on your drive.</p><p>The official page also points out that due to the tools' pen-test nature, some antivirus software will identify them as malware. To whitelist Kali tools, Offensive Security recommends allowing antivirus exceptions on the directory Kali sits in.</p><p>Offensive Security's explainer <a href="https://www.kali.org/news/kali-linux-in-the-windows-app-store" target="_blank">has plenty more troubleshooting advice</a> for running Kali Linux on Windows 10 if you experience any issues once you have it installed and running.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security giants go cloud crazy with RSA launches ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/639178/security-giants-go-cloud-crazy-with-rsa-launches</link>
                                                                            <description>
                            <![CDATA[ HP and RSA are two of the biggest firms launching cloudy products on the first day of the major security conference. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hrEuBKrEst5eco9Fyf5c5a</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9v9yMqD6aCgKvxzkpYZpba-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Feb 2012 20:58:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9v9yMqD6aCgKvxzkpYZpba-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud security]]></media:description>                                                            <media:text><![CDATA[Cloud security]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9v9yMqD6aCgKvxzkpYZpba-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A load of vendors have chosen to hone in on the cloud craze on the first day of RSA 2012, including HP and the host itself.</p><p>HP announced an expansion of its Security Intelligence and Risk Management (SIRM) offerings, which together are similar to other security information and event management (SIEM) products, such as <a href="https://www.itpro.com/639061/ibm-builds-on-q1-labs-acquisition-with-qradar-boost" target="_blank" data-original-url="https://www.itpro.com/639061/ibm-builds-on-q1-labs-acquisition-with-qradar-boost">IBM's recently-updated QRadar platform</a>.</p><p>The SIRM offering builds on HP's major acquisitions in the security sector over the past two years, including Arcsight, which was seen as the leader in the SIEM space.</p><p>RSA NetWitness Live has been instrumental to our customers in detecting and defeating advanced threats.</p><p>It also ties in Fortify and TippingPoint technology, packing in various pieces to help companies get a good view over " traditional, mobile and cloud environments."</p><p>The HP EnterpriseView feature, which starts at $250,000, gives an overall view of security, including a dashboard and heat map designed to let users know where the greatest risk lies.</p><p>The HP Application Security Monitor (AppSM), which starts at $5,000 per application server, brings centralised searching, reporting and analysis covering Java/.Net applications, including mobile ones.</p><p>Those two features are expected to arrive "soon," whilst others, including HP Mobile Application Security, the HP Compliance Stack and the HP TippingPoint Next-Generation Intrusion Prevention System are already available.</p><p>The host with the most?</p><p>Not to be outdone by partners on the first day of its flagship conference, RSA introduced an update of its NetWitness technology, acquired last year by EMC.</p><p>NetWitness Live has been given something of a turbo boost with 30 per cent more threat content and integration with RSA's analytics platforms to give companies a greater knowledge about dangers facing their networks.</p><p>"RSA NetWitness Live has been instrumental to our customers in detecting and defeating advanced threats," said Amit Yoran, senior vice president and general manager of RSA's security management and compliance division.</p><p>"By tapping into the collective intelligence and analytical skills of the global security community, the RSA NetWitness Live service helps organisations significantly enhance their situational awareness and shorten their time to respond to potential threats."</p><p>The cloud-based technology brings together information from the global intelligence community, amounting to around 100 different sources - 300 less than IBM's aforementioned QRadar service.</p><p>As for the analytics integration, customers will now be able to share relevant threat data across the RSA NetWitness for Logs platform and the RSA NetWitness Spectrum malware detection product.</p><p>The event has also seen Qualys, one of the original proponents of cloud-based security, <a href="https://www.itpro.com/639175/qualys-brings-ironbee-waf-to-life" target="_blank" data-original-url="https://www.itpro.com/639175/qualys-brings-ironbee-waf-to-life">launch its open source web application firewall</a>.</p><p>More cloudy announcements are expected over the next couple of days, so check back at <em>IT Pro</em> for all the latest from RSA 2012.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IBM builds on Q1 Labs acquisition with QRadar boost ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/639061/ibm-builds-on-q1-labs-acquisition-with-qradar-boost</link>
                                                                            <description>
                            <![CDATA[ Big Blue launches an updated version of the QRadar SIEM software it acquired after buying Q1 Labs last year. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m4g1dJEWimoJfG9ReaQsPT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8vkXMYdayhYKW4WTxywuL6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Feb 2012 12:01:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8vkXMYdayhYKW4WTxywuL6-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security]]></media:description>                                                            <media:text><![CDATA[Security]]></media:text>
                                <media:title type="plain"><![CDATA[Security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8vkXMYdayhYKW4WTxywuL6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IBM has issued the first major update of the security information and event management (SIEM) software it bought in its <a href="https://www.itpro.com/636514/ibm-agrees-to-acquire-q1-labs" target="_blank" data-original-url="https://www.itpro.com/636514/ibm-agrees-to-acquire-q1-labs">Q1 Labs acquisition</a>, claiming it is blowing the competition out of the water with the amount of data feeds it has collated.</p><p>Big Blue said the QRadar Security Intelligence Platform, built mainly of Q1 Labs sauce rather than IBM's own code, draws together 400 sources on threats giving IT pros a wider knowledge of dangers facing their networks.</p><p>IBM has hooked up its own X-Force threat feed to the <a href="https://www.itpro.com/636556/what-siems-to-be-the-problem" target="_blank" data-original-url="https://www.itpro.com/636556/what-siems-to-be-the-problem">SIEM</a> offering, which monitors 13 billion security events per day.</p><p>A host of other Big Blue offerings have been integrated into QRadar, including IBM Security Identity Manager and IBM Security Access Manager to mitigate the insider threat.</p><p>There are no vendors that can cover that breadth and that's really the value we bring.</p><p>Future integration modules are also being released for non-IBM products, including Symantec DLP, Websense Triton, Stonesoft, Stonegate and others.</p><p>"Essentially we support Symantec and McAfee and can extend to others. We don't support HP Arcsight," IBM told <em>IT Pro</em>.</p><p>Martin Borrett, director of the Institute of Advanced Security at IBM, said there had been a "wealth of excitement" around what Big Blue could do with Q1 Labs technology.</p><p>"We've been trying to figure out how IBM can take it to the next level, integrating our research and existing product line," Borrett told <em>IT Pro</em>.</p><p>"At this stage, apart from driving more scalability into the platform itself with new appliances, it's really about those flows in and out. We had all the insight from the X-Force but it just wasn't plugged into the platform in the way that it will be now. It's really about that crucial integration."</p><p>The release also marks another major moment for IBM in establishing itself as a major security services player.</p><p>However, it faces strong competition in the SIEM space, with Symantec already offering a well-respected product, HP running its Arcsight-based offerings and McAfee set to boost its presence in the market after <a href="https://www.itpro.com/636520/mcafee-to-buy-siem-provider-nitrosecurity" target="_blank" data-original-url="https://www.itpro.com/636520/mcafee-to-buy-siem-provider-nitrosecurity">acquiring Nitro Security</a>.</p><p>Borrett said IBM had "significant differentiation" in the market, thanks to the large number of sources QRadar can access and the insight it can get from the data.</p><p>"There are no vendors that can cover that breadth and that's really the value we bring," he claimed.</p><p>"The depth of the analytics we can get out of the Q1 platform I think is significantly stronger and better than our competition. Because of the context we can do it in... and the real-time capability [QRadar] is significantly better than the competition."</p><p>As for the SIEM market in general, with major players coming in and swamping the market, Borrett claimed there was still room for smaller players to partner with bigger vendors to supply more insight for bigger offerings.</p><p>"The important thing is that those capabilities integrate into these other platforms and into our platforms in particular," he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What SIEMs to be the problem? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/636556/what-siems-to-be-the-problem</link>
                                                                            <description>
                            <![CDATA[ Thanks to some big acquisitions in the SIEM space, the industry is going to change dramatically in appearance. Tom Brewster explores why... ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6oFgoiK6GiAAqTcLAk8W6K</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Nnrkory7o28qb3Au6nEaLa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Oct 2011 13:29:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Nnrkory7o28qb3Au6nEaLa-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security]]></media:description>                                                            <media:text><![CDATA[Security]]></media:text>
                                <media:title type="plain"><![CDATA[Security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Nnrkory7o28qb3Au6nEaLa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>COMMENT In the space of a few hours, two big announcements from the security information and event management (SIEM) industry hit yesterday.</p><p>Intel-owned McAfee decided it wanted a piece of the pie so it <a href="https://www.itpro.com/636520/mcafee-to-buy-siem-provider-nitrosecurity" target="_blank" data-original-url="https://www.itpro.com/636520/mcafee-to-buy-siem-provider-nitrosecurity">snapped up Nitro Security</a>.</p><p>Meanwhile, IBM joined the party by <a href="https://www.itpro.com/636514/ibm-agrees-to-acquire-q1-labs" target="_blank" data-original-url="https://www.itpro.com/636514/ibm-agrees-to-acquire-q1-labs">agreeing to acquire Q1 Labs</a> a company which was adamant it was not for sale just 12 months ago.</p><p>Last year, HP spent an absolute fortune on getting its mitts on ArcSight - a company then (and still) ranked as the market leader.</p><p>This would all indicate the SIEM industry is rather big one. The irony is, these three major acquisitions may actually herald the end of the SIEM market as we know it.</p><p>It's not an industry, it's a feature</p><p>In all three acquisitions noted above, the acquired party has or will see its technology rolled into a bigger package. In the case of Q1 Labs, it will form part of an entirely new division within IBM. Recently-appointed CEO of Q1 Labs, Brendan Hannigan, will even head that division once the deal goes through.</p><p>Everyone knows that SIEM is just one layer of what companies would need for effective protection, but these recent acquisitions have indicated SIEM is not an industry on its own. With these big deals came an acceptance that SIEM is really just a feature.</p><p>During a press conference yesterday, Hannigan even admitted that SIEM was just a part of what he called "security intelligence."</p><p>"The end point is security intelligence which is broader than SIEM," Hannigan told <em>IT Pro</em>.</p><p>"Firms that focus just on log management and event correlation will be limited. Security intelligence is the key."</p><p>Hannigan said the best way for Q1 Labs to provide its services to end customers was to through a larger vendor in this case IBM. "We will be able to offer significantly better solutions than we could have done before," he added.</p><p>Put simply, expect the rest of the SIEM industry to be gobbled up by tech giants in the coming months. Their products will also be rolled into existing, wider ranging security offerings, leaving the sector looking rather thin.</p><p>Just like deduplication in storage, SIEM is just a piece of a larger pie that vendors won't be able to rely on as a sole selling point in the future.</p><p>What will Symantec do?</p><p>So HP, IBM and McAfee have all joined the party. That leaves one notable absentee: Symantec.</p><p>Earlier this week, Symantec CEO Enrique Salem said his company was considering spending another $1 billion on acquisitions. However, Salem did not mention the SIEM, or security intelligence, segment. Instead he focused on mobile, virtual spaces and the cloud.</p><p>Nevertheless, with chief rival McAfee making a splash yesterday, Symantec will be keen to show it isn't off the pace.</p><p>Of course, Symantec already has a product in the area the unimaginatively titled Security Information Manager.</p><p>But to consolidate its dominance of the security landscape, it will want to have the best of breed in the intelligence space. With others acquiring some impressive companies, Symantec would do well to show it wants to be a serious player in this space.</p><p>So who could it be looking at? Rapid7 is one growing company in this area. Just today it announced it was expanding into Europe with a new base on the continent.</p><p>However, it didn't appear on Gartner's SIEM Magic Quadrant from earlier this year. Now that Q1 Labs and NitroSecurity have been snapped up, the best option from Gartner's rankings appears to be LogLogic.</p><p>It is still a relatively small comoany, with just 150 employees, but that might make it even more attractive for a prospective buyer, given how highly rated the company is.</p><p>Symantec has had its options cut thanks to IBM and McAfee, but there's still plenty of choice.</p><p>We'll just have to wait and see if Salem will want to splash some of the companies millions (possibly billions) on an intelligence firm. It would be a smart move doing so sooner rather than later.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ McAfee to buy SIEM provider NitroSecurity ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/636520/mcafee-to-buy-siem-provider-nitrosecurity</link>
                                                                            <description>
                            <![CDATA[ McAfee wants a bigger slice of the SIEM market so looks to NitroSecurity. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">DqzeU4DXEnqbaiUWr7k1F</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Q9rDaWLKYeHygw99B3b2N6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Oct 2011 15:47:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Acquisition]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Q9rDaWLKYeHygw99B3b2N6-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[McAfee]]></media:description>                                                            <media:text><![CDATA[McAfee]]></media:text>
                                <media:title type="plain"><![CDATA[McAfee]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Q9rDaWLKYeHygw99B3b2N6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Intel-owned <a href="https://www.itpro.com/636379/mcafee-beats-symantec-and-kaspersky-to-all-in-one-security" target="_blank" data-original-url="https://www.itpro.com/636379/mcafee-beats-symantec-and-kaspersky-to-all-in-one-security">McAfee</a> has made a splash in the security information and event management (SIEM) market by announcing it is to acquire NitroSecurity.</p><p>The announcement came on the same day <a href="https://www.itpro.com/636514/ibm-agrees-to-acquire-q1-labs" target="_blank" data-original-url="https://www.itpro.com/636514/ibm-agrees-to-acquire-q1-labs">IBM made its own SIEM purchase in agreeing to acquire Q1 Labs</a>.</p><p>McAfee now wants a piece of the SIEM pie and offer its customers greater security intelligence so they can learn about security issues affecting their organisation.</p><p>With NitroSecurity's technology and talent, McAfee can expand its reach into the fast growing SIEM market.</p><p>NitroSecurity offerings will be rolled into current McAfee offerings, including the security giant's SIEM product known as the ePolicy Orchestrator.</p><p>NitroSecurity's SIEM offering has already passed integration testing with ePolicy Orchestrator, so the wheels are already in motion.</p><p>"NitroSecurity's technology supports a broad range of information sources including network security devices, firewalls, operating system and application logs, vulnerability assessment scans, identity and access management systems and privacy systems," said Ken Levine, chairman and chief executive officer at NitroSecurity.</p><p>"It will complement the extensive McAfee security portfolio and help to meet the demanding compliance and protection needs of our joint customers."</p><p>McAfee expects the deal to be sewn up by the close of 2011's fourth quarter.</p><p>"With NitroSecurity's technology and talent, McAfee can expand its reach into the fast growing SIEM market," said Stuart McClure, general manager and senior vice president for the risk and compliance business unit at McAfee, in a <a href="http://blogs.mcafee.com/enterprise/management/mcafee-to-acquire-nitrosecurity?utm_source=twitterfeed&utm_medium=twitter" target="_blank">blog post</a>.</p><p>"NitroSecurity is quite simply the most advanced SIEM on the market This capability provides the most visibility and the most advanced correlation capabilities giving McAfee true situational awareness.'"</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IBM agrees to acquire Q1 Labs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/636514/ibm-agrees-to-acquire-q1-labs</link>
                                                                            <description>
                            <![CDATA[ Q1 Labs is to be folded into the new IBM Security Systems division. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gfFXfnHhq1b6W6psh7tfGz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EorR7Spd3wCPcfEYXAxH56-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Oct 2011 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EorR7Spd3wCPcfEYXAxH56-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Deal]]></media:description>                                                            <media:text><![CDATA[Deal]]></media:text>
                                <media:title type="plain"><![CDATA[Deal]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EorR7Spd3wCPcfEYXAxH56-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Q1 Labs will no longer be able to claim it is the number one independent security information and event management (SIEM) company after agreeing to be acquired by IBM.</p><p>The <a href="https://www.itpro.com/627226/q1-labs-launches-real-time-social-network-tracking" target="_blank" data-original-url="https://www.itpro.com/627226/q1-labs-launches-real-time-social-network-tracking">SIEM vendor was adamant it was not for sale</a> when <em>IT Pro</em> caught up with the company last September, saying it was delighted <a href="https://www.itpro.com/626893/hp-arcsight-buy-the-industry-impact" target="_blank" data-original-url="https://www.itpro.com/626893/hp-arcsight-buy-the-industry-impact">HP had bought chief rival ArcSight</a>.</p><p>Q1 Labs then claimed it was in a better position in the SIEM market as a result of HP's purchase. It said it wanted to become the "Oracle of security intelligence."</p><p>Realigning IBM's security expertise in a new division with a greater focus on analytics is a bold step.</p><p>That will no longer be the case, as Q1 Labs is set to be rolled into the new IBM Security Systems division as part of the proposed acquisition. Q1 Labs CEO Brendan Hannigan will lead the division once the deal is closed.</p><p>Hannigan was only promoted to the CEO role in May, amidst questions of when the company was planning to go public. The Q1 Labs board described him as "the perfect candidate to lead Q1 Labs as we anticipate our Initial Public Offering."</p><p>"Since perimeter defense alone is no longer capable of thwarting all threats, IBM is in a unique position to shift security thinking to an integrated, predictive approach," Hannigan said of the IBM deal.</p><p>"Q1 Labs' security analytics will add greater intelligence to IBM's security portfolio and continue to distinguish IBM from competitors."</p><p>Even though the deal has not yet closed, IBM Managed Security Services has made a cloud-based service of Q1 Labs' SIEM offering available to customers.</p><p>Meanwhile, Q1 Labs will be working on creating "a common security platform for IBM's software, hardware, services and research offerings."</p><p>"Realigning IBM's security expertise in a new division with a greater focus on analytics is a bold step IBM is taking to help clients stay ahead of growing security threats," said Robert LeBlanc, senior vice president for IBM Middleware Software.</p><p>Financial terms of the deal were not disclosed.</p><p>The move means IBM will be going into more direct competition with HP in the security space.</p><p>Intel will be looking on with interest too after its subsidiary McAfee bought SIEM vendor NitroSecurity today.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Q1 Labs launches real-time social network tracking ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/627226/q1-labs-launches-real-time-social-network-tracking</link>
                                                                            <description>
                            <![CDATA[ Q1 Labs' new SIEM system brings real-time social network and application monitoring to the market. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iv78CxeXYn3qsqrHt2FnVD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SuP2ofembYDV4nByuA5k4X-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Sep 2010 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SuP2ofembYDV4nByuA5k4X-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Social Networking]]></media:description>                                                            <media:text><![CDATA[Social Networking]]></media:text>
                                <media:title type="plain"><![CDATA[Social Networking]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SuP2ofembYDV4nByuA5k4X-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Q1 Labs has launched a new security information and event management (SIEM) system, giving companies the ability to track employees' social network and multimedia use.</p><p>QRadar 7.0 is able to check anomalies in workers' use of applications to help detect any threats, as well as pick up on the kinds of information employees are making public in real-time.</p><p>Social network use can also be correlated with other access information. This allows administrators to check what sensitive databases have been accessed before the user has visited a social network, in case of any foul play or unwanted transmission of information onto the likes of Facebook or Twitter.</p><p>Another major feature of <a href="http://q1labs.com" target="_blank">Q1 Labs'</a> newest product is client-side vulnerability profiling, which identifies any potential threats on a network and then alerts when these are exposed.</p><p>Firms using QRadar 7.0 can also prioritise remediation steps based on the risk profile of each application.</p><p>On showing <em>IT PRO</em> the product in action, John Burnham, vice president of marketing for Q1 Labs, explained how the firm was delighted to have achieved an industry first in its social media and application monitoring, stressing the impact social networks have had on business.</p><p>"Social media is what the web was to enterprises in the mid-1990s," Burnham said.</p><p>The recent <a href="https://www.itpro.com/626893/hp-arcsight-buy-the-industry-impact" target="_blank" data-original-url="https://www.itpro.com/626893/hp-arcsight-buy-the-industry-impact">HP acquisition of ArcSight</a>, along with the addition of this new product, will place Q1 Labs in a better position in the SIEM space, Burnham suggested.</p><p>"We were really pleased ArcSight was bought," he explained, adding that Q1 Labs is now the biggest independent firm in security intelligence.</p><p>As for whether Q1 Labs would ever be sold, Burnham stressed the company is "not for sale," although he expected to see other acquisitions in the space.</p><p>"Our goal is to become the Oracle of security intelligence," he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>