<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Information Security Consultants &#124; NCX Group</title>
	<atom:link href="http://www.ncxgroup.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ncxgroup.com</link>
	<description>Information Security Services &#124; Data Protection</description>
	<lastBuildDate>Thu, 16 Feb 2012 01:46:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Cybersecurity Bill Seeks New Regulation</title>
		<link>http://www.ncxgroup.com/2012/02/cybersecurity-bill-seeks-new-regulation/</link>
		<comments>http://www.ncxgroup.com/2012/02/cybersecurity-bill-seeks-new-regulation/#comments</comments>
		<pubDate>Thu, 16 Feb 2012 01:42:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.ncxgroup.com/?p=4004</guid>
		<description><![CDATA[FEBRUARY 15, 2012 A bill introduced by leading U.S. senators yesterday requires the owners and operators of our nation&#8217;s critical computer networks to safeguard against hackers. Essentially, under this bill, the Department of Homeland Security would have the power to identify systems that may cause mass casualties or catastrophic economic damage when attacked. Those identified [...]]]></description>
			<content:encoded><![CDATA[<p><strong>FEBRUARY 15, 2012</strong></p>
<hr />
<p>A bill introduced by leading U.S. senators yesterday requires the owners and operators of our nation&#8217;s critical computer networks to safeguard against hackers.</p>
<p>Essentially, under this bill, the Department of Homeland Security would have the power to identify systems that may cause mass casualties or catastrophic economic damage when attacked. Those identified as a &#8220;Covered Critical Infrastructure&#8221; would be required to prove or improve security according to the set regulations of the sector-specific agency. Companies would have to show that their networks are secure or face penalties.</p>
<blockquote><p>The bill calls for identifying vital information networks and setting security requirements for companies and government agencies. Lawmakers and regulators say rules are needed to fight increasingly sophisticated cyber attacks capable of disrupting power grids, banks and communications networks.<br />
<a href="http://www.bloomberg.com/news/2012-02-14/cybersecurity-bill-in-u-s-senate-seeks-industry-rules-to-thwart-hackers.html" title="Cybersecurity Bill in U.S. Senate Calls for Industry Rules" target="_blank">Read more . . .</a></p>
<p>By Chris Strohm, Bloomberg</p></blockquote>
<p>This bill, called the ‘‘<a href="http://www.ncxgroup.com/wp-content/uploads/2012/02/CYBER_The_Cybersecurity_Act_of_2012_final.pdf" title="Cybersecurity Act of 2012">Cybersecurity Act of 2012</a>’’, is a combination of cybersecurity bills introduced during the past three years. One provision not included is the Internet &#8220;kill switch&#8221; language that caused so much controversy in the past, but there is still a lot of backlash toward this bill because of the burdening cost that it is expected to create on companies. The Homeland Security and Government Affairs Committee, chaired by Joe Lieberman (I-CT), has scheduled a hearing on the ‘Cybersecurity Act of 2012’ on February 16, but surely the debate over this bill will continue so that other committees have a chance to take up the issue.</p>
<p>Whatever the outcome, the bill will include companies taking more responsibility for securing their own networks. This means scheduling the needed <a href="http://www.ncxgroup.com/services/" title="security services"  target="_blank">security services</a> to maintain a secure environment that thwarts off hackers and ensures your computer networks are not vulnerable.</p>
<p>Posted by Mike Fitzpatrick, CRISC, CEO, NCX Group</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ncxgroup.com/2012/02/cybersecurity-bill-seeks-new-regulation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New CA Breach Notification Law In Effect</title>
		<link>http://www.ncxgroup.com/2012/02/new-ca-breach-notification-law-in-effect/</link>
		<comments>http://www.ncxgroup.com/2012/02/new-ca-breach-notification-law-in-effect/#comments</comments>
		<pubDate>Wed, 08 Feb 2012 22:33:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://www.ncxgroup.com/?p=3964</guid>
		<description><![CDATA[FEBRUARY 8, 2012 As a reminder, any business or entity that conducts business within California and collects and holds Personally Identifiable Information (PII) is now subject to Senate Bill 24, which amends the California breach notification law. This new bill aims to strengthen the state’s groundbreaking SB 1386 security breach notification law by mandating how [...]]]></description>
			<content:encoded><![CDATA[<p><strong>FEBRUARY 8, 2012</strong></p>
<hr />
<p>As a reminder, any business or entity that conducts business within California and collects and holds Personally Identifiable Information (PII) is now subject to <a href="http://www.leginfo.ca.gov/pub/11-12/bill/sen/sb_0001-0050/sb_24_bill_20110831_chaptered.html">Senate Bill 24</a>, which amends the California breach notification law.</p>
<p>This new bill aims to strengthen the state’s groundbreaking SB 1386 security breach notification law by mandating how and what content to include when notifying affected individuals after January 1, 2012.</p>
<p>To begin, SB 24 requires that the notice to California residents be written in plain language. I believe this to mean at a level easy to understand without the legalese.</p>
<p>Additional content required must include the following:</p>
<ul>
<li>The types of information breached.</li>
<li>When the breach occurred or a range of suspected dates.</li>
<li>The name and contact of the person or business reporting the breach.</li>
<li>Whether the notification was delayed as a result of a law enforcement investigation.</li>
<li>A general description of the breach incident.</li>
<li>The toll-free telephone numbers and addresses of the major credit reporting agencies, if the breach exposed a social security number or a driver&#8217;s license or California identification card number.</li>
</ul>
<p>At the discretion of the business, the security breach notification may also include what is being done to protect the individual whose information was compromised.  We urge businesses to add this because it can restore trust and may reduce customer churn.</p>
<p>In addition, SB 24 now requires businesses and state agencies notifying more than 500 California residents in a single breach to submit an <a href="https://oag.ca.gov/ecrime/databreach/report-a-breach">electronic reporting form</a> online and upload a sample copy of the notification letter being sent to affected individual.</p>
<p>HIPAA-covered entities are deemed to have complied with the notice requirements if they have complied with the similar breach notification requirements of the HITECH Act.  This means that a HITECH Act notification satisfies the content requirements of SB24, but nothing more.  HIPAA-covered entities must still notify the Attorney General if more than 500 California residents need to be notified.</p>
<p>NCX encourages all organizations to establish a comprehensive information security program that includes a thorough <a href="../services/incident-response/">incident response program</a>.  Don’t forget to review SB24 and update your notification policies to include the new requirements.</p>
<p><em>Posted by Mike Fitzpatrick, CRISC, CEO, NCX Group</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ncxgroup.com/2012/02/new-ca-breach-notification-law-in-effect/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Defend Your Data &#8211; 2012 to Challenge Profits</title>
		<link>http://www.ncxgroup.com/2012/01/defend-your-data-2012-to-challenge-profits/</link>
		<comments>http://www.ncxgroup.com/2012/01/defend-your-data-2012-to-challenge-profits/#comments</comments>
		<pubDate>Sun, 15 Jan 2012 23:29:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[Secure24]]></category>
		<category><![CDATA[security assessment]]></category>
		<category><![CDATA[security review]]></category>

		<guid isPermaLink="false">http://www.ncxgroup.com/?p=3922</guid>
		<description><![CDATA[NCX SECURITY INSIGHTS / JANUARY 2012 &#8211; #2 As CEO of NCX Group, I wish you and your company a prosperous new year. It is sure to be a challenging one for all of us due to the economy and smaller budgets, and with the 2012 data threat predictions calling for an increase of very [...]]]></description>
			<content:encoded><![CDATA[<p><strong>NCX SECURITY INSIGHTS / JANUARY 2012 &#8211; #2</strong></p>
<hr />
<p><img class="alignright size-full wp-image-3936" style="margin: 0px 10px 5px; padding: 0px; border: 0pt none;" title="Profit or Loss" src="http://www.ncxgroup.com/wp-content/uploads/2012/01/profit.png" alt="Profit or Loss" width="137" height="180" />As CEO of NCX Group, I wish you and your company a prosperous new year. It is sure to be a challenging one for all of us due to the economy and smaller budgets, and with the 2012 data threat predictions calling for an increase of very sophisticated breach attacks, profitability becomes even more challenging.</p>
<p>It only takes one attack to change the hope of a prosperous year. Our goal is to prevent that from happening by helping businesses and organizations, regardless of size, identify their current data security vulnerabilities and prepare them against oncoming threats.</p>
<p>A thorough <a title="Secure24 Comprehensive Security Review" href="http://www.ncxgroup.com/services/information-security/information-security-assessment/">Secure24 security review</a> identifies high and medium data risk, explains remediation solutions, and enables organizations to build an effective data security and privacy program that mitigates risk and meets compliance regulations. Most information security reviews we conduct find vulnerabilities due to misconfiguration of assets, lack of processes and controls, insecure web applications or misguided procedures. It is critical that you don’t take your eyes off of the “basics” in securing your information assets when the stakes are so high. Even a simple, cost effective network <a title="Vulnerability Assessment" href="http://www.ncxgroup.com/services/information-security/vulnerability-assessment/">Vulnerability Assessment</a> or a <a title="Web Application Test" href="http://www.ncxgroup.com/services/information-security/web-application-testing/">Web Application Test</a> will go a long way in meeting most of your information risk management needs during these difficult times.</p>
<p>Many organizations are demanding that departments affecting security, IT and compliance groups do more with less. Your approach to obtaining the right services and expertise has never been more important than it is right now.</p>
<p>For more information on how NCX Group can assist you in meeting your company&#8217;s information risk management goals for 2012, please contact us for a free consultation. We look forward to helping you stay profitable.</p>
<p>Best Regards,</p>
<p>Michael Fitzpatrick, CEO<br />
NCX Group, Inc.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ncxgroup.com/2012/01/defend-your-data-2012-to-challenge-profits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Avoid a Security Breach</title>
		<link>http://www.ncxgroup.com/2012/01/how-to-avoid-a-security-breach/</link>
		<comments>http://www.ncxgroup.com/2012/01/how-to-avoid-a-security-breach/#comments</comments>
		<pubDate>Wed, 04 Jan 2012 23:42:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[security assessment]]></category>
		<category><![CDATA[security review]]></category>

		<guid isPermaLink="false">http://www.ncxgroup.com/?p=3891</guid>
		<description><![CDATA[NCX SECURITY INSIGHTS / JANUARY 2012 &#8211; #1 It would be the ultimate buzzkill to learn that data breaches you hear happening to other companies has now happened to yours, especially when your company’s security measures were strong, or so you thought. There’s a dangerous disconnect between perception and reality when it comes to data [...]]]></description>
			<content:encoded><![CDATA[<p><strong>NCX SECURITY INSIGHTS / JANUARY 2012 &#8211; #1</strong></p>
<hr />
<p><img class="alignright size-full wp-image-3905" style="margin: 0px 10px 5px; padding: 0px; border: 0pt none;" title="Surprised Businessman" src="http://www.ncxgroup.com/wp-content/uploads/2012/01/surprisedman.png" alt="Surprised Businessman" width="150" height="166" />It would be the ultimate buzzkill to learn that data breaches you hear happening to other companies has now happened to yours, especially when your company’s security measures were strong, or so you thought.</p>
<p>There’s a dangerous disconnect between perception and reality when it comes to data security and that disconnect can come back to bite. It slowly begins when those responsible for their company’s data security become complacent or have a false sense of security, simply because a breach hasn’t happened yet. Many who thought their critical information was secure were surprised to discover it was not. How do we know? We only need to read the news. It’s alarming to learn that simple fixes and better due diligence could have kept most hackers at bay.</p>
<p>The key is to know if your critical data is vulnerable and if policies and processes are in place to head off an attacker. This is accomplished by identifying the state of your company’s security posture. A comprehensive <a href="../services/information-security/information-security-assessment/">security review</a> can save you hundreds of thousands in data breach exposure costs and quickly identify areas requiring risk mitigation.</p>
<p>Remember, a secure environment can change unexpectedly with newly added equipment, mergers, or even conducting downsizing activities. Performing periodic network vulnerability scans from experts with the right tools will also help confirm that your critical information is protected from overlooked configurations or undocumented changes.</p>
<p>You probably already know that security threats have skyrocketed this year and data breaches are climbing to an all time high. This means it’s a risky time to have a wait and see attitude. Businesses with fewer than 500 employees, or even 100 employees, are proving to be more popular targets as hackers are finding them to be “low-hanging fruit” and “ripe for the pickins”. Why? Because they typically have weaker security measures in place and hackers view them as opportunistic. The end result can have significant repercussions to the business while the hacker exhibits little effort for a good payout. You can prove them wrong, and we can help.</p>
<p>Contact us for a free consultation on how we can help secure your critical information assets at a price that will fit your budget, or <a href="mailto:info@ncxgroup.com?subject=Contact%20me%20regarding%20NCX%20Services&amp;body=Please%20have%20a%20representative%20call%20me.">email</a> us to have a representative call you.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ncxgroup.com/2012/01/how-to-avoid-a-security-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Calif. Amends Data Breach Notification Law</title>
		<link>http://www.ncxgroup.com/2011/09/calif-amends-data-breach-notification-law/</link>
		<comments>http://www.ncxgroup.com/2011/09/calif-amends-data-breach-notification-law/#comments</comments>
		<pubDate>Wed, 07 Sep 2011 00:39:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://www.ncxgroup.com/?p=3328</guid>
		<description><![CDATA[California Amends Data Breach Notification Law California has one of the toughest breach notification laws in the country.  Although it is strong on notification, the current law lacks direction on what information to include when issuing a data breach notification.  Senate Bill 24, which was signed by Governor Brown on August 31, 2011 and goes [...]]]></description>
			<content:encoded><![CDATA[<div style="line-height: 1.4em; font-size: 14pt;">California Amends Data Breach Notification Law</div>
<p>California has one of the toughest breach notification laws in the country.  Although it is strong on notification, the current law lacks direction on what information to include when issuing a data breach notification.  <a href="http://leginfo.ca.gov/pub/11-12/bill/sen/sb_0001-0050/sb_24_bill_20110831_chaptered.html">Senate Bill 24</a>, which was signed by Governor Brown on August 31, 2011 and goes into effect January 1, 2012, amends SB 1386 to include standard, core content when notifying individuals of a data breach.</p>
<p>SB 24 requires certain content in data breach notifications, including a general description of the incident; the type of information breached; the date or date range of the breach; the name and contact information of the reporting agency; and the toll-free telephone numbers and addresses of the major credit reporting agencies, if the breach exposed a Social Security number or a driver&#8217;s license.</p>
<p>In addition, SB 24 also mandates the breached agency send an electronic copy of the notification to the California Attorney General if a single breach affects more than 500 Californians.</p>
<p>We have seen many vague and unhelpful notification letters in the news.  I believe the requirements of SB 24 aim to help consumers gain a greater understanding of how to respond and protect themselves against identity theft.</p>
<p><em>Posted by Mike Fitzpatrick, CEO, NCX Group</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ncxgroup.com/2011/09/calif-amends-data-breach-notification-law/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Are CIOs Making Isolated Decisions?</title>
		<link>http://www.ncxgroup.com/2011/07/are-cios-making-isolated-decisions/</link>
		<comments>http://www.ncxgroup.com/2011/07/are-cios-making-isolated-decisions/#comments</comments>
		<pubDate>Thu, 07 Jul 2011 19:07:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://www.ncxgroup.com/?p=3105</guid>
		<description><![CDATA[Are CIOs Making Isolated Decisions? Results of a recent survey by Financial Executives International (FEI) and Gartner posted on CIO states CIOs and IT teams are falling short of CFO expectations. CFOs, who appear to be having a greater influence over IT, don’t have the confidence that their own IT organization can muster the flexibility [...]]]></description>
			<content:encoded><![CDATA[<div style="line-height: 1.4em; font-size: 14pt;">Are CIOs Making Isolated Decisions?</div>
<p>Results of a recent survey by Financial Executives International (FEI) and Gartner posted on <a href="http://www.cio.com/article/684964/CFOs_Lack_Faith_in_CIOs_and_IT_Teams_Survey_Shows" target="blank">CIO</a> states CIOs and IT teams are falling short of CFO expectations. CFOs, who appear to be having a greater influence over IT, don’t have the confidence that their own IT organization can muster the flexibility to respond to changing business priorities.</p>
<p>As I read this article, I thought of how this sentiment also ties to the security of information assets. With all the breaches in the news lately, it stands to reason that doubts of IT security capabilities are coming into question as well. Today’s CIO and IT teams must be able to bridge information technology and business requirements to meet company business objectives, all while making sure security is not an impediment to growth.</p>
<p>We all know that new technology and the thought of building new systems usually puts a gleam of excitement in the eyes of IT folks. Unfortunately, information security is not the primary focus of these new technology implementations. Too many times, I’ve seen companies spend a lot of money on hardware and software without verifying the current state of information security and how it relates to the business environment or forward strategy. The end result is money spent in the wrong areas. In many cases, IT can actually hamper business growth by only focusing on technology. I can understand why CFOs loose confidence. IT must consider how information security plays into business objectives to create a competitive advantage over other businesses.</p>
<p>Because most structural IT purchases must now tightly integrate with information security, it is critical that IT not perform in a vacuum. As head of an information security consulting company, I have for years advocated that information security should not be the sole responsibility of your an IT organization; after all, &#8216;it takes a village.&#8217; While I hate this phrase, it&#8217;s true in this case. An effective and successful information security program requires the involvement of the entire organization; Everyone on the same page and moving in the same direction to deliver on the business objectives of the company.</p>
<p>To this point, NCX strongly recommends the formation of an Information Security Steering Committee (ISSC). This committee not only provides leadership in protecting information assets and technology, they also prioritize the development of security initiatives and provide guidance on IT infrastructure and investments that affect the confidentiality, integrity and availability of critical information. The committee should include someone from executive leadership (CEO, CFO, COO), HR, IT and legal. No more than you can feed with a large pizza.</p>
<p>Establishing such a body will give CFOs and upper management the confidence their company’s critical information assets, desired growth path, and business priorities are being considered to achieve success.</p>
<p>Let me know what think.</p>
<p><em>Posted by Mike Fitzpatrick, CEO, NCX Group</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ncxgroup.com/2011/07/are-cios-making-isolated-decisions/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Don’t Trust Your Security to the Cloud</title>
		<link>http://www.ncxgroup.com/2011/05/don%e2%80%99t-trust-your-security-to-the-cloud/</link>
		<comments>http://www.ncxgroup.com/2011/05/don%e2%80%99t-trust-your-security-to-the-cloud/#comments</comments>
		<pubDate>Fri, 20 May 2011 21:54:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://www.ncxgroup.com/?p=2772</guid>
		<description><![CDATA[Don’t Trust Your Security to the Cloud – At Least Not Yet Companies that have launched their data into the cloud might be doing so at a greater cost than what they hope to save. The lure of IT cost savings provided by cloud computing becomes a strong incentive in this economy, but many organizations [...]]]></description>
			<content:encoded><![CDATA[<div style="line-height: 1.4em; font-size: 14pt;">Don’t Trust Your Security to the Cloud – At Least Not Yet</div>
<p>Companies that have launched their data into the cloud might be doing so at a greater cost than what they hope to save. The lure of IT cost savings provided by cloud computing becomes a strong incentive in this economy, but many organizations are overlooking security and privacy, and a breach could destroy the savings they intend to gain.</p>
<p>I have read many surveys lately highlighting the adoption of cloud computing along with the pros and cons. No doubt, more and more companies are migrating to this technology, but what is now coming to light is the misconception of who’s responsible for securing customer data. In a recent study released by the Ponemon Institute, &#8220;<a href="http://www.ca.com/%7E/media/Files/IndustryResearch/security-of-cloud-computing-providers-final-april-2011.pdf" target="_blank">Security of Cloud Computing Providers</a>,” the majority of cloud providers (79%) allocate 10% or less of IT resources to security or control-related activities. They found that most providers believe their cloud services do not include the protection of sensitive data. Instead of security, cloud providers focus on cost and speed of deployment, the survey states.</p>
<p>As with any outsourced service, it’s important to vet the service provider to ensure their security framework supports your standards of access control and authentication. Qualify that the SLA meets your level of security and thoroughly understand the controls and testing of the provider. Attempting to achieve your required mandates of security later may be complex and more costly.</p>
<p>With that said, I strongly urge companies considering cloud computing to assess their security risks before they make the move. This will identify and close any gaps that might put them at risk.</p>
<p>NCX Group includes assessing clients’ cloud computing information risks as a part of our <a href="http://www.ncxgroup.com/services/information-security/information-security-assessment/" target="_blank">Secure24 security review</a> to help identify any security issues or potential impact to their security architecture. As a standard, cloud computing services need to be mapped to a model of compensating security and operational controls, risk assessment and management frameworks, all while adhering to security compliance guidelines. NCX Group can help you achieve this goal.</p>
<p>We’re beginning to see hackers hit the cloud hard to capture easy data. Businesses will soon be forced into more heightened security measures as more critical data gets pushed to the cloud. Stay vigilant, stay aware.</p>
<p><em>Posted by Mike Fitzpatrick, CEO, NCX Group</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ncxgroup.com/2011/05/don%e2%80%99t-trust-your-security-to-the-cloud/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nasdaq Breach – Another Warning to CEOs</title>
		<link>http://www.ncxgroup.com/2011/02/nasdaq-breach-another-warning-to-ceos/</link>
		<comments>http://www.ncxgroup.com/2011/02/nasdaq-breach-another-warning-to-ceos/#comments</comments>
		<pubDate>Sat, 12 Feb 2011 01:04:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://www.ncxgroup.com/?p=2623</guid>
		<description><![CDATA[Nasdaq Breach – Another Warning to CEOs to Enhance Security Although there are some breaches companies can’t prepare for, this breach appears to be a case of lapsed security. The breached system at Nasdaq, so far, was tied to Directors Desk, a web-based service tool used by directors of companies, including board members, to share [...]]]></description>
			<content:encoded><![CDATA[<div style="line-height: 1.4em; font-size: 14pt;">Nasdaq Breach – Another Warning to CEOs to Enhance Security</div>
<p>Although there are some breaches companies can’t prepare for, this breach appears to be a case of lapsed security.</p>
<p>The breached system at Nasdaq, so far, was tied to Directors Desk, a web-based service tool used by directors of companies, including board members, to share confidential documents.  One would think that if Nasdaq were acquiring a company for their portal service, as they did Directors Desk in 2007, the web application would have been thoroughly tested for flaws based on the highly sensitive information that flows through and is housed in its system.  For all you CEOs out there, take note!  Have ALL your web-based applications tested!</p>
<p>What’s so concerning about this breach is that it became known through “routine computer security checks” revealing that hackers had installed malware files inside Directors Desk.  The Wall Street Journal reported the computer network had been repeatedly penetrated during the past year.  So the real question is why the system was only routinely monitored and not continually monitored?  This went on for a full year before it was discovered, despite the files left on the system by the hack!  Web-based services like this are highly vulnerable and require constant monitoring.</p>
<p>There are other board portals out there and these services don’t come cheap.  It would be interesting to see if companies jump to other board management systems because of the lack of security discovered by this breach.</p>
<p>The latest development from this breach is to <a href="../2011/02/nasdaq-hack-prompts-cybersecurity-bill/" target="_blank">revive the Cybersecurity Enhancement Act</a>.  To investigate the cause of this breach is certainly required, but to initiate a bill that funds scholarships and grants for security research through the National Science Foundation to the tune of $639 million over four years is truly alarming.</p>
<p>It’s said that these systems are complicated, but really?  With a thorough information security program in place, the chance of this type of breach is minimal. According to the reports, the files in question were removed and Nasdaq made modifications to the system as a deterrent.  Gee, guess it wasn’t all that complicated.</p>
<p><em>Posted by Mike Fitzpatrick, CEO, NCX Group</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ncxgroup.com/2011/02/nasdaq-breach-another-warning-to-ceos/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NCX Group</title>
		<link>http://www.ncxgroup.com/2010/01/post7/</link>
		<comments>http://www.ncxgroup.com/2010/01/post7/#comments</comments>
		<pubDate>Sun, 31 Jan 2010 01:07:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Featured Articles]]></category>

		<guid isPermaLink="false">http://site5.fore3.com/?p=985</guid>
		<description><![CDATA[NCX is committed to helping our clients achieve the confidentiality, integrity and availability of their critical business systems.]]></description>
			<content:encoded><![CDATA[<p>NCX is committed to helping our clients achieve the confidentiality, integrity and availability of their critical business systems.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ncxgroup.com/2010/01/post7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>December 2008</title>
		<link>http://www.ncxgroup.com/2010/01/december-2008/</link>
		<comments>http://www.ncxgroup.com/2010/01/december-2008/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 01:21:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Newsletters]]></category>

		<guid isPermaLink="false">http://site5.fore3.com/?p=731</guid>
		<description><![CDATA[If your Internet provider filters incoming e-mail, please add ncxgroup.com to your list of approved senders to make sure you receive NCX Group Security Updates. TIS THE SEASON  FOR SCRUTINIZING INFORMATION SECURITY As CEO of NCX Group, I wish you and your family a joyful Holiday Season and a Happy New Year. Today’s economic environment [...]]]></description>
			<content:encoded><![CDATA[<table border="0" cellspacing="0" cellpadding="0" width="586" align="center" bgcolor="#ffffff"><!--DWLayoutTable--></p>
<tbody>
<tr>
<td colspan="3" height="1" bgcolor="#cccccc"><img src="spacer.gif" border="0" alt="" width="1" /></td>
<td rowspan="64" width="1" align="right" valign="top" bgcolor="#cccccc"><img src="spacer.gif" border="0" alt="" width="1" /></td>
</tr>
<tr>
<td rowspan="12" width="1" align="top" valign="top" bgcolor="#cccccc"><img src="spacer.gif" border="0" alt="" width="1" /></td>
<td colspan="2" height="70" valign="top"><img style="border: 0pt none; margin: 0px;" title="NCX Newsletter Banner" src="http://www.ncxgroup.com/Newsletter/newsletterbanner.jpg" alt="NCX Group  Security Update" width="584" height="70" /></td>
</tr>
<tr>
<td width="398" height="564" valign="top">
<table border="0" cellspacing="0" cellpadding="0" width="100%"><!--DWLayoutTable--></p>
<tbody>
<tr>
<td width="8" height="58"></td>
<td class="em_arial10" style="color: #5f5f5f;" width="381" align="left" valign="middle">If your Internet provider filters incoming e-mail, please add ncxgroup.com to your list of approved senders to make sure you receive NCX Group Security Updates.</td>
<td width="9"></td>
</tr>
<tr>
<td height="286"></td>
<td class="em_arial13" rowspan="3" valign="top"><strong>TIS THE SEASON  FOR SCRUTINIZING INFORMATION SECURITY</strong><br />
As CEO of NCX Group, I wish you and your family a joyful Holiday Season and a Happy New Year.</p>
<p>Today’s economic environment has businesses and organizations facing some very difficult challenges and decisions regarding their budget and direction. Information Risk Management must be a top priority, more so today than ever before. After all, one breach today, coupled with the expenses incurred from notification, legal activities and mitigation, might be a company-ending event. You can’t afford to make a mistake.</p>
<p>As a result of necessary cuts, many organizations are demanding that departments affecting security, IT and compliance groups do more with less. Your approach to obtaining the right services and expertise has never been more important than it is right now.</p>
<p>So the $64,000,000 question is, “How do I meet security compliance requirements and protect my information assets?” Most information security reviews we conduct find vulnerabilities due to misconfiguration of assets, lack of processes and controls, insecure web applications or misguided procedures. It is critical that you don&#8217;t take your eyes off of the “basics” in securing your information during these times. A simple, cost effective network vulnerability assessment or a web application test will go a long way in meeting most of your information risk management needs during these difficult times.</p>
<p>As you plan ahead for 2009, I would like to offer you an hour of our time to discuss your information risk management goals and compliance challenges. I know my team of professionals can assist you in meeting these goals and can provide the expertise you need for these projects. One of our specialties is getting more done with less.</td>
<td></td>
</tr>
<tr>
<td height="50" valign="top"><img src="spacer.gif" alt="" width="8" height="1" /></td>
<td></td>
</tr>
<tr>
<td height="223"></td>
<td></td>
</tr>
<tr>
<td height="2"></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
</td>
<td width="186" valign="top">
<table border="0" cellspacing="0" cellpadding="0" width="100%"><!--DWLayoutTable--></p>
<tbody>
<tr>
<td width="7" height="38"></td>
<td class="em_arial13" width="179" align="left" valign="middle"><strong><span style="color: #5f5f5f;">ISSUE:</span> December 2008</strong></td>
</tr>
<tr>
<td colspan="2" height="360" valign="top">
<table border="0" cellspacing="0" cellpadding="0" width="100%"><!--DWLayoutTable--></p>
<tbody>
<tr>
<td rowspan="15" width="1" align="left" valign="top" bgcolor="#cccccc"><img src="spacer.gif" border="0" alt="" width="1" /></td>
<td colspan="3" height="1" bgcolor="#cccccc"><img src="spacer.gif" border="0" alt="" width="1" /></td>
</tr>
<tr>
<td width="7" height="46"></td>
<td class="em_arial13" width="115" valign="middle"><strong>Subscribe to Security Update</strong></td>
<td width="63" align="left" valign="middle" bgcolor="#ffffff"><img class="size-full wp-image-625 alignleft" style="border: 0pt none; margin: 0px;" title="Newsletter Signup" src="http://www.ncxgroup.com/wordpress/wp-content/uploads/2010/01/env.gif" alt="Envelope Graphic" width="38" height="38" /></td>
</tr>
<tr>
<td colspan="3" height="1" bgcolor="#cccccc"><img src="spacer.gif" border="0" alt="" width="1" /></td>
</tr>
<tr>
<td class="em_arial13" colspan="3" height="53" align="center" valign="middle"><a style="text-decoration: underline;" title="http://www.ncxgroup.com/data_breaches_2008.htm" href="http://www.ncxgroup.com/data_breaches_2008.htm" target="_blank">2008 Reported Data Breaches</a><br />
<span class="em_arial10">Keep yourself updated on the latest security breach disclosures</span></td>
</tr>
<tr>
<td colspan="3" height="1" bgcolor="#cccccc"><img src="spacer.gif" border="0" alt="" width="1" /></td>
</tr>
<tr>
<td colspan="3" height="104" valign="top"><img class="aligncenter size-full wp-image-628" style="border: 0pt none; margin: 0px;" title="NCX Vision Network Attack Map" src="/wp-content/uploads/2010/01/Vision_AttackSmpl.jpg" alt="Network Attack Map" width="185" height="102" /></td>
</tr>
<tr>
<td class="em_arial13" colspan="3" height="61" align="center" valign="middle"><strong>NCX Vision</strong><br />
<span class="em_arial10">See What You&#8217;ve Been Missing</span><br />
<a style="text-decoration: underline;" title="http://www.ncxgroup.com/services/information-security/vulnerability-assessment" href="http://www.ncxgroup.com/services/information-security/vulnerability-assessment" target="_blank">Learn more here &gt;&gt; </a></td>
</tr>
<tr>
<td colspan="3" height="1" bgcolor="#cccccc"><img src="spacer.gif" border="0" alt="" width="1" /></td>
</tr>
<tr>
<td colspan="3" height="111" valign="top"><img class="aligncenter size-full wp-image-629" style="border: 0pt none; margin: 0px;" title="Picture of SOC" src="/wp-content/uploads/2010/01/emsoc.jpg" alt="Picture of SOC" width="185" height="111" /></td>
</tr>
<tr>
<td colspan="3" height="1" bgcolor="#cccccc"><img src="spacer.gif" border="0" alt="" width="1" /></td>
</tr>
<tr>
<td class="em_arial13" colspan="3" height="84" align="center" valign="top"><strong>Looking for<br />
Managed Security Services?</strong><strong> </strong></p>
<p><strong>Call us at 888-448-5451 or contact us below</strong></td>
</tr>
<tr>
<td colspan="3" height="1" bgcolor="#cccccc"><img src="spacer.gif" border="0" alt="" width="1" /></td>
</tr>
<tr>
<td class="em_arial13" colspan="3" height="57" align="center" valign="top"><strong>To have an NCX Group Representative Contact You</strong><br />
<a style="text-decoration: underline;" title="http://www.ncxgroup.com/conrequest.htm" href="http://www.ncxgroup.com/conrequest.htm" target="_blank">Email us here</a></td>
</tr>
<tr>
<td colspan="4" height="2" valign="top" bgcolor="#cccccc"><img src="spacer.gif" border="0" alt="" width="1" /></td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr>
<td height="2" valign="top"><img src="spacer.gif" alt="" width="1" height="1" /></td>
<td></td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr>
<td colspan="2" height="382" valign="top">
<table border="0" cellspacing="0" cellpadding="0" width="100%"><!--DWLayoutTable--></p>
<tbody>
<tr>
<td width="8"></td>
<td class="em_arial13" width="567" valign="top">I invite you to call NCX Group and schedule your “Free” hour-long consultation with one of our industry and compliance experts. I look forward to having you as part of the NCX Group family of satisfied clients in 2009.</p>
<p>Again, Happy Holidays and a Happy New Year!</p>
<p>Mike Fitzpatrick, CEO<br />
NCX Group, Inc.</p>
<p>For more information about our services or for a free consultation on how our experts can help you secure your data at a price that will fit your budget, call us at 888-448-5451 or <a style="text-decoration: underline;" title="http://www.ncxgroup.com/conrequest.htm" href="http://www.ncxgroup.com/conrequest.htm" target="_blank">request a representative to call you</a>.</p>
<p>NCX Group, Inc. is a leading information risk management firm specializing in the assessment and mitigation of risk associated with today&#8217;s technologies and business processes.</p>
<hr /></td>
<td width="9"></td>
</tr>
<tr>
<td colspan="3" height="120" valign="top">
<table border="0" cellspacing="0" cellpadding="0" width="100%"><!--DWLayoutTable--></p>
<tbody>
<tr>
<td class="em_arial10" style="color: #000080;" width="584" height="52" align="center" valign="top">NCX Group, Inc.<br />
5000 Birch Street, West Tower, Suite 3000<br />
Newport Beach, CA 92660<br />
888-448-5451<br />
<a style="text-decoration: underline;" title="http://www.ncxgroup.com" href="http://www.ncxgroup.com" target="_blank">www.ncxgroup.com</a></td>
</tr>
<tr>
<td class="em_arial9" style="color: #000080;" height="50" align="center" valign="bottom">Copyright ©2008 NCX Group, Inc. All rights reserved.<br />
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .<br />
If you do not wish to receive future NCX Group Security Updates, please <a href="mailto:unsubscribe@ncxgroup.com?subject=Unsubscribe to NCX Group Security Update">email us here</a></td>
</tr>
</tbody>
</table>
</td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr>
<td colspan="2" height="2" valign="top" bgcolor="#cccccc"><img src="spacer.gif" border="0" alt="" width="1" /></td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.ncxgroup.com/2010/01/december-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic page generated in 1.920 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2012-02-16 15:59:35 -->
<!-- Compression = gzip -->
