It's Patch Tuesday and Microsoft has just released a record 15 security bulletins, nine of which are critical. The bulletins contain fixes for 35 newly-discovered security holes in Windows, Office and Internet Explorer.
"These vulnerabilities could be exploited to booby trap Web sites, Office and media files to gain control over vulnerable computers simply by tricking victims into opening a malicious file or clicking a malicious link," says Dave Marcus, director of security research and communications at McAfee Labs.
Home PC users should make sure Windows Auto Update service is enabled and configured to automatically download and install these latest patches. You will be required to reboot your PC to complete the process.
Business users ought to accelerate testing and get all Windows PCs patched as have quickly as possible. "This will be a disruptive Patch Tuesday given the broad range of products impacted and the required restarts," says Paul Henry analyst for network seucurity firm Lumension.
Read full story.
Enforced encryption, reporting and biometric technology are among the tools required for the modern IT manager’s arsenal
Businesses are seeing an increase in malicious insider activity, according to the 2010 Data Breach Report from Verizon Business released last week.
But it is not just insider threats that are a concern to businesses. External threats targeting cloud services are also increasing. For example, last month US-based telco AT&T’s servers were breached. This resulted in the leakage of 114,000 email addresses of government and military officials.
So how can CIOs mitigate such attacks?
Insider risk
First, it is important to understand why they are increasing. Paul Henry, forensic and security analyst at Lumension, a global IT security provider, said: “It is partly driven by the economy. In a good economy you only need to worry about bad people doing bad things. In a bad economy, some of the good people are driven the same way.”
Increased regulation
Last week information security professionals body the Information Systems Audit and Control Association said reporting data security breaches should be mandatory in quarterly and annual company reports. Many firms only become aware of data breaches when notified by a third party – regulation will help them prioritise maintenance of their security infrastructure.
Cloud computing
If a company uses cloud computing, much of the network infrastructure moves outside of its direct control. This brings its own risks, as Henry explained.
Lumension’s Endpoint Protection Solution Lauded in Technical Review for its Return-on-Investment, Seamless Integration and Ease-of-Use
Lumension today announced that its solution for medium and large-sized enterprises, Lumension® Endpoint Protection, which is comprised of Lumension® Device Control, Lumension® Application Control and Lumension® AntiVirus, has been recognized with 5-star product ratings by SC Magazine.
In its technical review, SC Magazine lauded Lumension Endpoint Protection for its excellent integration with existing environments and wealth of features and benefits available across application control, device control and threat management capabilities. With Lumension’s Endpoint Protection suite, organizations can prevent known and unknown malware as well as centrally manage, monitor and control applications. By employing an application whitelisting approach, users can ensure that only authorized applications are allowed to run on laptops, PCs, mission-critical servers and POS terminals, preventing the execution of unknown or malicious code.
With Lumension Endpoint Protection, operational desktop management is improved by eliminating unnecessary support calls and performance issues that come with managing unauthorized and illegal software. And, you can easily demonstrate compliance by enforcing software license policies and by providing a detailed audit trail of all application execution attempts. In addition, with Lumension Device Control capabilities, also available as part of the Lumension® Endpoint Protection suite, users can easily enforce organization-wide usage policies for removable devices, removable media, and data. Using a “default deny” approach, administrators can centrally manage devices and data, allowing organizations to embrace productivity-enhancing tools while limiting the potential for data leakage and its impact.
SC Magazine also recognized Lumension’s product for its simple installation process, superior protection features and product documentation, saying the product is “a great value for the money and customer can also purchase any of the three components separately depending on their needs, which provides flexibility.”
“We are thrilled to be recognized by SC Magazine for our superior endpoint security offerings, it further validates what we are hearing from customers, that organizations are looking for a seamless view of everyone accessing or attempting to access the network through corporate endpoints from a device and application perspective,” said chairman and CEO of Lumension, Pat Clawson. “Our continued philosophy is that security efforts should proactively stay one step ahead of emerging threats, not simply react to them and Lumension’s Endpoint Security solutions have been integral components to this approach, keeping customer’s sensitive information safe from both external and internal threats.”
The recent 5-star ratings follow a string of recent positive reviews of Lumension corporate products. This includes a 4-star rating by SC Magazine of Lumension® Scan, a component of the larger Lumension® Vulnerability Management suite that is a complete standalone, network-based scanner that performs a comprehensive scan of all devices connected to the network.
Supporting Resources:
* About Lumension Endpoint Protection
* To view full SC Magazine Product Review
About Lumension Security, Inc.
Lumension Security, Inc., a global leader in endpoint management and security, develops, integrates and markets security software solutions that help businesses protect their vital information and manage critical risk across network and endpoint assets. Lumension enables more than 5,100 customers worldwide to achieve optimal security and IT success by delivering a proven and award-winning solution portfolio that includes Vulnerability Management, Endpoint Protection, Data Protection, Antivirus and Reporting and Compliance offerings. Lumension is known for providing world-class customer support and services 24x7, 365 days a year. Headquartered in Scottsdale, Arizona, Lumension has operations worldwide, including Virginia, Texas, Utah, Florida, Ireland, Luxembourg, the United Kingdom, Australia, and Singapore. Lumension: IT Secured. Success Optimized.™ More information can be found at www.lumension.com.
Leading Security-Solutions Provider Selects Xceedium GateKeeper to Meet Their Clients Increasing Access Control & Audit Needs
Xceedium Inc., the leader in Zero Trust Access Control, and FishNet Security, the nation's leading provider of information security solutions, today announced a strategic partnership agreement that will allow FishNet to offer their clients the Xceedium GateKeeper. The Xceedium GateKeeper is a Zero Trust Access Control system that integrates easily into existing network and security infrastructure and allows organizations to meet security and compliance needs by controlling and auditing privileged access to critical IT infrastructure and regulated data.Kansas City, Missouri-based FishNet Security specializes in providing corporations and government agencies with enterprise-class security solutions tailored to meet their unique security needs. Under the terms of the agreement between the companies, FishNet Security will resell the Xceedium GateKeeper across North America and provide turnkey installation, deployment, and integration services. The two companies have already partnered to implement the Xceedium GateKeeper solution within several major corporations to date. This initial set of customers is using the product to control and audit privileged access to IT infrastructure and regulated data by vendors, contractors and administrators. The solution has allowed them to address the business imperative of providing broad access to employees and partners while also meeting compliance and security risk management requirements for audit-quality logging and proof of controls.
“Our agreement with Xceedium lets us provide our customers with a unique all-in-one solution for access control and audit, which allows us to address the increasing security and compliance demands we are seeing in the marketplace,” said Gordon Shevlin, FishNet Security Executive Vice President of Vendor Relations. “We have already partnered on several enterprise projects and deployments, including installations at a number of Fortune 500 companies. We are pleased to formalize what we know will continue to be a very strategic and mutually rewarding partnership.”
“FishNet Security is one of the most respected reseller brands in the security market and our partnership with them has had an immediate impact on new business,” said Jay A. Zimmet, Executive Vice President, Global Sales of Xceedium, Inc. “FishNet Security serves numerous customers in the regulated industries, including energy, financial services, healthcare, and retail where the need for a Zero Trust Access Control solution is critical to meeting their regulatory compliance mandates. FishNet Security’s expertise and emphasis on providing total security solutions ensures that our mutual customers will experience the maximum value from this compelling new security offering.”
About FishNet Security
FishNet Security is the number 1 provider of information security solutions that combine technology, services, support and training. Organizations are opening their computing environments to accelerate business initiatives and are concerned about the increase in risk. FishNet Security provides the most comprehensive security offering which enables clients to effectively manage risk, meet compliance requirements, and reduce costs while maximizing security effectiveness and operational efficiency. Unlike Systems Integrators, Technology Resellers, and VARS who have limited offerings, security knowledge, and experience, FishNet Security is committed to information security excellence, has the most comprehensive offering and a track record of delivering quality solutions to over 4,500 clients nationwide. For more information visit www.fishnetsecurity.com.
About Xceedium
Xceedium Inc., is the leading provider of Zero Trust Access Control solutions for managing access to critical infrastructure and sensitive data by privileged users, 3rd-party vendors, and contractors.
Employing unique and patent-pending technologies, the Xceedium GateKeeper hardened appliance enables organizations to extend and manage access while safeguarding business critical assets, demonstrating compliance and decreasing business risk. Its key differentiators lie in its ability to enforce policy by identity, contain users based on the user’s explicit privileges, and record users for audit and compliance. Deployed in the largest enterprise, and federal government environments, Xceedium’s ever-expanding client base includes household names in financial services, healthcare, pharmaceutical, retail, MSP and other key verticals.
Headquartered in New Jersey with offices in Virginia, Xceedium has been honored with a number of prestigious industry awards, including recognition by Forrester Research as a “Hot Company to Watch,” by Gartner, Inc. as a “Cool Vendor in Infrastructure Protection 2009,” and by Red Herring as a “Top 100 Global Company.” For more information, visit www.xceedium.com.
Page 1 of 29


