10 Data Security Tips: Keep Your Sensitive Information Where it Belongs
Posted: Monday, June 17, 2013 9:30 AM by Tom Clare
Last week’s headlines revealed that the NSA PRISM program details were exfiltrated using a USB thumb drive. The news is filled with cautionary tales of data theft and cyber espionage. With advanced cyberattacks, data theft by employees through portable...   Read more >
Attending the 2013 Gartner Security & Risk Management Summit?
Posted: Thursday, June 06, 2013 12:05 AM by Tom Clare
Once again, Websense has prepared a very comprehensive agenda for the Gartner Security & Risk Management Summit in Washington D.C. next week at the Gaylord Hotel. We look forward to you joining the sessions we've created especially for the event...   Read more >
ATM Cyber Heist Underscores Need for DLP Technology
Posted: Friday, May 10, 2013 6:55 AM by Joerg Sieber
A fascinating cybercrime story about an "unlimited operation" in New York involving the theft of debit card information from payment processors, and the resulting theft of $45 Million from thousands of ATMs by an international gang of hackers...   Read more >
Six Steps for Deploying Data Security Controls (Part II)
Posted: Friday, April 05, 2013 3:34 PM by Neil Thacker
Earlier this week I made my case on why it’s time to move from infrastructure-only security to infrastructure AND data security control. Below are six steps for a successful data security control implementation. Step one: Calculate the value of...   Read more >
Turning the Lights On… Infrastructure Security vs. Data Security (Part I)
Posted: Wednesday, April 03, 2013 4:06 PM by Neil Thacker
The only thing more challenging than seeing something in the dark is explaining what you can see to others. That’s how I characterize the often-difficult process of explaining the importance of data security to your executives and employees. Clearly...   Read more >
Five Ways the Gartner DLP MQ Report Can Help You Define Your DLP Strategy
Posted: Wednesday, March 06, 2013 11:05 AM by Rose Ryan
Today's business environment is exposed to advanced threats and data theft, plus evolving regulatory compliance controls. The question is whether you can contain such threats, protect sensitive data from leaving your organization and meet compliance...   Read more >
Websense Takes Home Best Web Content Management and Best Regulatory Compliance at the 2013 SC Magazine Awards US
Posted: Wednesday, February 27, 2013 8:05 AM by April Tellez
The wins continue to pile up for Websense at the SC Magazine Awards US. This year, we took home two awards: - Best Web Content Management Product for Websense Web Security Gateway Anywhere (WSGA) - Best Regulatory Compliance Solution for Websense Data...   Read more >
2013 Threat Report: Web Got “Dramatically Darker” – Pre-Order Now
Posted: Thursday, February 07, 2013 1:00 PM by Bob Hansmann
The 2013 Threat Report from Websense Security Labs is now available for pre-order. In it, you'll learn about alarming increases in threats, and how it's creating a real crisis of trust among security professionals and the users they support. Websense's...   Read more >
Practical IT: Key Takeaways from the New York Times Breach
Posted: Wednesday, February 06, 2013 1:00 PM by Lamont Orange
Last week, we all woke to the New York Times announcing they were victims of an ongoing attack by Chinese hackers, resulting in the accounts of several reporters being compromised. The article went on to describe details of the breach including four months...   Read more >
Best Practice Tips for CIOs: How to Prevent Information Leaks
Posted: Thursday, January 31, 2013 11:43 PM by Rose Ryan
The U.S. government established Data Privacy Day four years ago. Unfortunately, a lot of the primary concerns that led them to recognize the challenge of data privacy are either still here or are even stronger. Businesses are encountering a barrage of...   Read more >
TechTarget: Deploying DLP technology requires hands-on approach, experts say
Posted: Wednesday, December 12, 2012 3:26 PM by April Tellez
About a year and a half ago, Mark Jackson, the information security officer at San Rafael, Calif.-based Westamerica Bank, began researching data loss prevention products for the regional community bank. His search began after a Department of Financial...   Read more >
Avoiding Android's Malware Influx
Posted: Wednesday, November 07, 2012 8:30 AM by Stacey Garcia
Attackers setting their sights on Android users seem to have upped their game over the last few weeks. Reports have shown a flurry of new attacks and vulnerabilities that have turned that cute little green robot into a proverbial punching bag. Here's...   Read more >
EMEA Webcast: Seven Stages of Advanced Threats & Data Theft
Posted: Monday, September 10, 2012 7:59 AM by Spencer Parker
The seven stages hackers follow to steal data have been exposed! Traditional URL and AV defences are no longer effective in blocking targeted attacks. Cloud apps, mobility and remote users have all contributed to a growth in SSL traffic, which is a major...   Read more >
10 New Defenses That Help Prevent Data Loss and Theft
Posted: Thursday, August 09, 2012 12:11 AM by Tom Clare

 

Last week we announced several new, important core security technologies that we added to our TRITON architecture. Websense ACE now includes 10 new defense innovations; seven are focused on outbound traffic to keep data theft and call-home communications contained, preventing theft or loss. Because so many of them are industry firsts, I wanted to take a moment to explain what many of these do and why we created them.

Truth is, the bad guys are stealing corporate data and avoiding detection using advanced techniques. In just the last year, we've seen key intellectual property and user identities stolen from corporations and government agencies, including some you would least expect-including entertainment (gaming) and security companies!

Below are a few examples of how cyber criminals are going undetected, stealing your IP, and how we can stop it from happening.

More

...   Read more >
Webinar Wednesday: 7 Stages of Advanced Threats & Data Theft
Posted: Monday, August 06, 2012 10:18 PM by Tom Clare

Every day, organizations worldwide are targeted by data-stealing attacks. While these attacks have evolved in frequency and sophistication, many security defenses have failed to adapt. Old techniques don’t address containment against data theft and cybercrime call-home communications. The growing prevalence of cloud apps, along with increases in SSL traffic, mobility and remote users are also adding more blind spots to traditional defenses.

It’s imperative that we continue to stay up-to-date on the latest tactics and tricks. Join me this Wednesday, August 8, 2012 from 10 a.m. - 11 a.m. PT for a webinar on the seven stages of data theft. We’ll be covering each of these steps:

Reconnaissance - Targeted attackers access credentials and research online profiles, email IDs, org. chart information, hobbies and interests from social profiles to gain insight on their victims.

Lures - Designed to prey on human curiosity, web lures often link to videos or breaking news, while email lures are more business-focused on transaction and fake delivery notices.


Redirects - Users are usually directed to a survey, rogue anti virus offer or a fake web page where an exploit kit is waiting. Traditional redirects are injection attacks, while newer ones focus on social networking wall postings, fake plug-ins, fake certificates and heavily obfuscated java script.


Exploit Kits - The exploit kit objective is like that of a sniper: take the shot with a malware dropper file only when an open door for tested vulnerabilities is found.


Dropper Files - This stage is what most people consider the focus of their forward-facing defenses: analyze every file that comes into the network for malware. The problem is dropper files use dynamic packers, so known signatures and patterns are not available.


Call-Home - This stage involves calling home for malware downloads and tools, and for sending back information, standard procedure for any successful online attack. The problem is that most defenses are only forward-facing and do not analyze the outbound traffic from infected systems.


Data Theft - This is what they are after. The ability to contain an attack and stop data theft raises many questions that we will address. Can your defenses detect password files leaving your network or the use of custom encryption on outbound files?

In addition, we’ll be covering: why current defenses are failing; today’s new security requirements; and the newest, bleeding edge advanced threat and data theft defenses to emerge thus far.

We look forward to having you join the webinar. Bring your questions and be ready to talk threats!

 

...   Read more >
Black Hat Briefings & Exhibits: Day One...
Posted: Thursday, July 26, 2012 7:46 PM by Bob Hansmann

Time for Black Hat again! Day one is almost complete and I’ve seen some big themes.

There’s some of the usual. Vulnerability scanning and pen testing are definitely present and the topics of identifying and learning from data breaches are still big—especially around the area of SIEM. There are also some new developments. For example, more exhibitors are simply about education, including your typical certification schools, but general higher learning institutions, like the University of Maryland, are also here.

As usual, Black Hat USA is full of security vendors and their products, but there seem to be more ‘service’ offerings showcased this year. This may not be surprising to those who have heard analysts increasingly discuss the weaknesses assumed by an organization that is overly dependent on purely in-house resources.

Education, services and research tools are obviously taking center stage in the battleagainst cybercrime. All this focus on education is precisely why we’ve developed a few new tools and resources to help resource-strapped customers tap into the expertise of the Websense® Security Labs™ researchers.

Sometimes you need more than what you have on-hand—especially when you are dealing with highly advanced malware and complex data stealing attacks. That’s when you need an expert security researcher to help. Our Websense Security Labs have morethan one hundred team members worldwide, hip–deep in the latest threats. The new Websense CyberSecurity Intelligence™ (CSI) servicesannounced today, help extend their expertise and educational benefits right into your organization.

Websense CSI services offer both online and 1:1 time with our researchers, through tools, training, in-person guidance and malware forensics.

All Websense CSI customers will have access to ThreatScope™, an online sandbox environment, to safely test potential malware. It uses our Websense Advanced Classification Engine (ACE) analytics to compile an extensive report of observed behavior on an uploaded file. Insights include the infection process; post-infection activities (such as calling home); system-level events and processes; registry changes and filemodifications.

Think about it, Black Hat USA only comes around once a year, but every day needs to be about education in the security field. Websense CSI services can be an extension of your learning process— giving you access to our researchers and the necessary tools to help you become more educated on the threats of today.

If you could study one aspect of today’s threats, what would you dive into?

...   Read more >
Computer Weekly: Websense launches cyber security intelligence services
Posted: Wednesday, July 11, 2012 10:41 PM by Patricia Hogan
Security firm Websense is to launch cyber security intelligence services to enable businesses to tap into the resources of its research teams. “In the event of a security incident, researchers will help CSI Live customers with the investigation...   Read more >
Computer Weekly: Websense takes aim at modern hacker attack methods
Posted: Wednesday, July 11, 2012 10:39 PM by Patricia Hogan
“This approach", said Tom Clare, senior director, product marketing at Websense , "enabled a US healthcare organisation to reduce outages of mission critical systems due to malware by 50% and a US federal agency to reduce the need to re...   Read more >
Securebuzz.ca: Threat trends lead to 10 new defenses
Posted: Tuesday, July 10, 2012 10:30 PM by Patricia Hogan
Websense has released 10 new defenses, focused on stopping advanced malware and data theft. “Over the past 18-24 months advanced malware incidents are heating up… it’s probably the worst I’ve seen in frequency and severity of...   Read more >
Going to TechEd? Come see our Microsoft Windows 2012 DAC integration
Posted: Sunday, June 10, 2012 5:02 PM by Farley Stewart

This week at the annual TechEd conference Websense will be showcasing how our Websense DLP technology integrates with the new Dynamic Access Control (DAC) capabilities of Microsoft Windows® 2012.

Built on the foundation of Websense data classification expertise, this collaboration allows organizations to accurately monitor, identify, categorize, and ensure protection and proper use of sensitive information—as it is being authored. This is true, dynamic categorization in action. Here is a video that shows how it works...

...   Read more >
More Posts Next page »