Websense News & Views
all posts insights blog channel blog news releases media coverage accolades
Published Monday, June 17, 2013 9:30 AM by Tom Clare
Last week’s headlines revealed that the NSA PRISM program details were exfiltrated using a USB thumb drive. The news is filled with cautionary tales of data theft and cyber espionage. With advanced cyberattacks, data theft by employees through portable...

Published Friday, May 10, 2013 6:55 AM by Joerg Sieber
A fascinating cybercrime story about an "unlimited operation" in New York involving the theft of debit card information from payment processors, and the resulting theft of $45 Million from thousands of ATMs by an international gang of hackers...

Published Friday, April 05, 2013 3:34 PM by Neil Thacker
Earlier this week I made my case on why it’s time to move from infrastructure-only security to infrastructure AND data security control. Below are six steps for a successful data security control implementation. Step one: Calculate the value of...

Published Thursday, January 31, 2013 11:43 PM by Rose Ryan
The U.S. government established Data Privacy Day four years ago. Unfortunately, a lot of the primary concerns that led them to recognize the challenge of data privacy are either still here or are even stronger. Businesses are encountering a barrage of...

Published Tuesday, August 28, 2012 9:54 AM by Jason Woo
Leading analyst firm Gartner just released the 2012 Magic Quadrant for Secure Email Gateways (SEG) * and noted an uptick in targeted phishing attacks. The report states "Phishing attacks continue to oscillate, while more targeted phishing attacks...

Published Sunday, June 10, 2012 5:02 PM by Farley Stewart

This week at the annual TechEd conference Websense will be showcasing how our Websense DLP technology integrates with the new Dynamic Access Control (DAC) capabilities of Microsoft Windows® 2012.

Built on the foundation of Websense data classification expertise, this collaboration allows organizations to accurately monitor, identify, categorize, and ensure protection and proper use of sensitive information—as it is being authored. This is true, dynamic categorization in action. Here is a video that shows how it works...

...

Published Thursday, June 07, 2012 8:29 PM by Jason Clark
Yesterday’s LinkedIn breach made headlines, but I want to go deeper and provide practical advice for organizations on how they can anticipate any DLP consequences and tighten their network security. As the world’s largest professional social...

Published Tuesday, April 17, 2012 3:37 PM by Andrew Forgie

 

Before we begin, I recommended reading Getting Ready For Data Loss Prevention (DLP). Go ahead, I’ll wait for you…

Back? OK, now let’s talk what comes after; the “How” to implement DLP part.

As a next step, and at the risk of blowing my own horn, consider watching the recording of a webcast I did on April 5 here. You’ll get recommendations on how to deal with issues that are often overlooked in DLP deployments as well as some critical “how to” advice. This I position as an antidote to the all-too-common and none-too-helpful “just do it” approach to DLP advice. Because, on the path to DLP success, there are two deadly pitfalls to watch out for: 

The first is in understanding where to start your data protection strategy using DLP (and why). Where to start influences your program’s effectiveness compared to how much risk you are hoping to eliminate from the business.

The second pitfall is in understanding how to execute. The "how" may be the most important  part as it ultimately determines how soon you will benefit from DLP and determines the amount of resources that are required.

Surviving one of the pitfalls is hard enough, but trying to get through both on your own is nearly impossible.

Unfortunately, much of the historical “how” started with massive data-discovery projects, which usually meant at least six-months of project consulting before any data is protected.

Not every DLP vendor has the same vision for how to make DLP work, so make sure that you understand your vendor’s approach and agree with it.

Have a listen and let me know what you think.

 

...

Published Tuesday, February 07, 2012 4:25 PM by Jason Clark

 

Do you think data breaches are up or down in 2011 compared to 2007 or 2008? The official answer may surprise you. According to DatalossDB and the 2011 Data Breach Investigations Report by Verizon, the number of records compromised per year has been decreasing since its 2008 peak. But these reports are missing something very important. It all comes down to what is reported. Last year I met with more than 450 CIOs and CSOs, and almost all of them said that incidents are way up. New breaches are constantly making headlines, so why is there a discrepancy between our perception and what these reports are finding?

Many industry reports focus on the never-ending stream of leaked or stolen personally identifiable information (PII). Most laws and industry standards, such as PCI DSS, also concentrate on PII. But there is something that could be more dangerous to lose than PII and that isn't getting enough attention in data breach reports—intellectual property (IP).

 

(More)

 

...

Published Thursday, September 15, 2011 12:32 AM by Farley Stewart

 

I think there is a need for industries to first admit a problem – a problem with data. A huge volume of new content is being created, shared and moved inside and outside our walls every second. The challenge is that much of this data is sensitive and is a major governance and data theft concern. In order to prevent both accidental data loss and malicious data theft organizations need to be able to identify what is and is not sensitive information and be able to accurately categorize sensitive information as it is created without a massive process that intrudes or adds additional steps to content creator.

We’ve seen this is a real challenge for organizations, so we have been working closely with Microsoft to accurately monitor, identify, categorize, and ensure protection and proper use of sensitive information— as it is being authored. It’s a big challenge and a huge technology hurdle. That said, at the recent Microsoft® BUILD developer conference we demonstrated accurate real-time file classification and data security policy application done automatically, without manual intervention from the author.

 

 

...

More Posts Next page »