Incident Response

Forget AI: Millions of Humans Needed To Close Cybersecurity Gap

Despite advances in automation, millions of additional people are still needed… An article review. If you follow cybersecurity news you’d be forgiven if you thought that humans were rapidly becoming obsolete: everywhere you turn there are articles extolling the virt...

A Seven Step Process to Combat Insider Threats

Incident response testing is the stone that kills many birds… Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . Good morning.  It’s 5:00am on a weekend, and I’m preparing my talk for the Cybersecurity Conference t...

NSA to Establish Cybersecurity Directorate

In a change for the Agency, the new directorate will have a defensive focus… An article review. Over the last few years, we’ve seen a cat and mouse game between hackers and the good guys: from potential foreign influence in elections to the establishment of the US “...

Coders’ Rights: Protecting Security Researchers

We rely on them to keep our systems safe, but who is protecting the security researchers? An article review. Over the past few decades there have been a number of laws and regulations enacted with the goal of improving computer security, but due to the way many of them ha...

Incident Response Boilerplate Update

We have recently made a significant change to our Incident Response Policy regarding Disclosure Incidents. At infotex we are always revising and updating our boilerplates. We have recently made a significant change to our Incident Response Policy regarding Disclosure Incid...

Cyber Challenge: A Community Bank Cyber Exercise

The FDIC has released new training material to help small banks start a discussion on risk… An article review. Sometimes it can be difficult to find a starting point when getting your employees discussing risk and technology, and while we do provide our own resource...

The Cost of Being Unprepared

A new study has identified the most profitable malware, showing just how much unprepared businesses have paid. An article review. Despite pleas from various experts and authorities, it looks like a significant number of organizations ultimately decide to pay the criminal ...

Firewall Log Retention: Beyond The Guidance

In the absence of specific guidance, organizations are left to use their judgement in retaining logs… Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . Not long ago a Client asked for my input on their firewall lo...

Object Access Limitations

Object Access Limitations. . . While offering some visibility, there are limitations to object access monitoring. If your organization has to comply with industry regulations such as GLBA, HIPAA, or Sarbanes Oxley, you know that maintaining data security and privacy are im...

The Top 3 Articles of 2018

The Top 3 Articles of 2018 2018 has now come to an end, but what a year it was for articles on the infotex blog! Not only did the “infotex writing team” published twenty-two article reviews, (thanks in large part to our Clients for sending them to us), but we a...