Welcome!


Latest Blogs from Web Security Journal
It certainly has been a wild ride thus far for 2013 as we head into the second half. Breaches, hacks, exposures, leaks, along with things like BYOD and SDN should make the next 6 months interesting. From the many headlines in 2012, you’d think organizations would be locked down tight...
The Government Accountability Office announced that federal agencies are not setting a good precedent in estimating their IT projects. Unfortunately, the data used by these agencies to measure their costs is often incomplete or gathered through word of mouth. Federal organizations woul...
If you think that small businesses are not an enticing enough target to breach, think again. While the media has certainly upped it’s coverage over the last couple years pertaining to data loss, many of the headlines involved global brands and tens of thousands records…not the corner ...
Unisys Corp. has released the findings of a survey showing most Americans worry about cyber attacks but are divided on whether the government should require private organizations to share information about cyber threats. The Unisys Security Index surveyed 1,006 Americans through phone...
Two weeks ago, Twitter announced that it was offering two-factor authentication to its customers. Experts agree it was a step in the right direction, but it’s clearly more of a cover-our-ass move than a solution. First, let me say that we here at StrikeForce Technologies are a huge pr...
Over 81 percent of organizations have suffered at least one IT data breach over the past two years, whilst the Federation of Small Business (FSB) estimate that online criminal activity is currently costing SMEs a combined £785m every year. The revolutionary concept of cloud hosting, b...
Ex·ten·si·ble (in programming): Said of a system (e.g., program, file format, programming language, protocol, etc.) designed to easily allow the addition of new features at a later date. (from Dictionary.com) Whenever I attend a F5 customer or partner gathering, I always ask of thos...
During the past month or so, Rich Mogull, analyst and CEO of securosis has published multiple blogs on cloud encryption best practices, specifically in infrastructure clouds. The final blog IaaS Encryption: How to Choose, provides a good opportunity for us to touch and expand on some o...
While movement to the cloud keeps accelerating, fears about security hang on. Let’s take a look at the most common myths about cloud security that might be holding businesses back from taking advantage of the flexibility and scalability of the cloud model. This is the piece of “common...
We had a few miscues along the way, far fewer than other shows, but none-the-less, here they are for your viewing pleasure.
Don and I have four children, all of whom have had the fortune to take piano lessons (I'm not sure if the youngest would agree he's fortunate at this point in his life but at five, he's not really able to answer the question with any degree of wisdom, anyway. Come to think of it, not s...
According to a ComputerWorld article citing a recent Gartner survey, about half the world’s companies will stop providing computing devices to employees and embrace some form of BYOD by 2017. They also noted that about 40% will offer a choice between employee owned or company issued w...
You may have heard that cloud computing and Software-as-a-Service (SaaS) models can turn software technology into a pay-as-you-go utility that businesses can “plug in to” and use like electricity? Perhaps — however, software technology is far more varied, nuanced and diverse than el...
Without an enterprise-level automated solution for ensuring the integrity of APIs and API-driven composite applications, organizations risk: Brand erosion as faulty software drives away customers Time-to-market delays that diminish market share Exposure to legal liability associated...
When you’re dealing with something as critical as your business infrastructure, you want to be sure that you’ll get what you signed up for. If a company promises something, and you promise your colleagues something based on it, you want it to happen. That’s where the service level agre...
The age of data center automation is upon us. Whether it's cloud or SDN or devops in general, automation as a means to achieve efficiency and, one hopes, free up resources that can be then redirected to focus on innovation. As is always the case when we begin to move further upwards...
The President's State of the Union address made it clear that data security is a top priority to keep personal, business-related and national security information protected. During the last State of the Union address, President Barack Obama included improving data security on his list...
As the infrastructure cloud market (IaaS and PaaS) continues to grow rapidly, we are seeing quite a few customers who are delivering an application – whether it is a mission-critical or SaaS application – and basing their solution on VMware. VMware Security Cloud Encryption cloud keyb...
My fellow Technical Evangelists and I have authored a content series that steps through building your very own Private Cloud by leveraging Windows Server 2012, our FREE Hyper-V Server 2012, Windows Azure Infrastructure Services ( IaaS ) and System Center 2012 Service Pack 1. Week-by-...
When Lori and I were writing import/export routines for a large software vendor, we had a phrase to remind ourselves that what we loved was not necessarily the all-important part of what we were doing. We used to say “It’s all about the data”, almost as a mantra, to keep our team (I wa...
Living Social, the popular online discount site, recently experienced a cyber-attack affecting more than 50 million of their customers. Users with a Living Social account received an email explaining the data breach, which included hackers accessing customer user names, email addresses...
HIMSS 2013 was a big moment for cloud in healthcare. As a topic of discussion, it was certainly on the lips of many at the show, but increasingly the realities of cost and functionality are pushing direct-to-patient organizations to consider the cloud not only as part of how they run I...
ViPR is not a technology creation developed in a vacuum instead includes customer feedback, wants and needs. Its core themes are extensible, open and scalable. What is ViPR addressing? IT and data infrastructure (server, storage, IO and networking hardware, software) challenges for t...
One of the major challenges facing organizations as they grapple with increasing traffic, users, devices, and applications is managing the connective tissue that enables the users, devices, and applications to communicate. This was already a growing problem when virtualization and then...
As with most new exciting (read: hyped) technology there's always some initial fragmentation that occurs in the market. Everyone wants to have their fingers in the newest pie and from that comes what musicians call "variations on a theme." The melody is the same, but the harmony and ch...
I was researching something totally unrelated today, and happened upon a couple of things that made me decide to write a quick blog about SPDY support and the tools available to you relevant to SPDY. First, I found a ton of administrators asking how they could verify that SPDY was bei...
This simple phrase encapsulates so much more than just the notion of platforms capable of supporting multiple development languages. It comprises the notion of an operationalized polyglot platform, one that brings standardization to operations while providing flexibility for developers...
We were serious about getting serious about managing hybrid cloud and federating application network services Last month I brought up the need to manage application network services - load balancing, acceleration, optimization, application security.. you know, application services tha...
In my 199th F5 video, Kevin Stewart and I share how BIG-IP APM can optimize, secure and streamline Citrix XenApp and XenDesktop deployments. Make Citrix better with F5.
In-Q-Tel just posted a press release on a recent strategic partnership and technology development agreement with a firm called Apigee. That statement alone is all the savvy technologist needs to know to start diving into Apigee. In-Q-Tel has a reputation for applying lots of focused th...
What does today's retail banking customer expect from a financial institution, and how can business technology be applied to enhance the overall experience. The latest results from the Cisco Customer Experience Report focused on the retail banking sector. The global report examined co...
Next week I will be participating in the inaugural session of What’s Next in IT Debate Series, a new program of authentic debates and conversations on key technology topics. Sponsored by IBM, The Debate Series is an ongoing series of social video debates, held on Spreecast.com (a brow...
…Is one of the findings in #Verizon’s 2013 Data Breach Investigations Report, which is chuck full of interesting data. 75% of the attack victims were selected because they had a weakness that an attacker knew how to exploit rather than being specifically chosen. The difficulty of the...
A very real legal situation is brewing in the wake of the bring your own device phenomena. eDiscovery. You might be familiar with some of the various legal or liability issues that should be addressed with a BYOD policy, like privacy, the loss of personal information, working overtime ...
A number of rural areas underserved by the telcos and cable companies are attempting to bridge the digital divide by independently bring "last-mile" fiber broadband to every business and residence. For example, the Massachusetts Broadband Institute (http://broadband.masstech.org/) is ...
You don’t have to be a pre-cog to find and deal with infrastructure and application problems; you just need good monitoring. We had quite a day Monday during the EC2 EBS availability incident. Thanks to some early alerts—which started coming in about 2.5 hours before AWS started repo...
A colleague relayed this story: At a recent toastmasters meeting, they did a survey. They were asked what does each of the following words mean, when represented as a percentage? Sometimes Frequently Rarely Often Usually For example, my friend interpreted “Frequently” to mean “...
When it comes to talking IT operations and financial considerations I tend to stay away from deep economic theories. I'm not Joe Weinman, after all. But I happened upon (no, I don't recall how so don't even ask. The Internets, you see) an 1850s essay on political economics written by ...
F5 Sr. Technical Marketing Manager Lori MacVittie received CloudNOW’s prestigious Top 10 Women in Cloud award for her exceptional contributions to the cloud community. CloudNOW, an executive consortium of the leading women in cloud computing, presented the award during UBM Tech’s Cloud...
DNS, like any public service, is vulnerable. Not in the sense that it has vulnerabilities but vulnerable in the sense that it must, by its nature and purpose, be publicly available. It can't hide behind access control lists or other traditional security mechanisms because the whole poi...