Securus Global Roles

Posted on March 12th, 2010 by Drazen Drazic

We’re looking for people again. Check out the role advertisement. If you think you fit the role description and want to join one of the region’s best and fastest growing security companies, give us a yell.

Just a note: while we are open to overseas people applying, and we have recruited OS before, having a work visa or the like for Australia is preferred.

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in Uncategorized | 3 Comments »

Why is “Commander” still allowed to do business?

Posted on March 9th, 2010 by Drazen Drazic

This is a dodgy operation who went bankrupt and did not pay their bills but somehow still exist under the same name?

http://www.commander.com/

Stay away from them. Weird they exist.

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in Bad Stuff, WTF | 2 Comments »

Security Consortium Watch…..

Posted on March 9th, 2010 by Drazen Drazic

I’m not going to go back over all the old posts to try to remember who all these mobs were, but is there a consortium still doing anything? eg; ICASI and SAFECode. etc etc…..

Some previous posts mentioning them: http://beastorbuddha.com/?s=consortium

Not much more to add that I haven’t already said in the link above and links within the posts.

Is there a Cloud one also? Sure there is. :)

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in Bad Stuff, Dumb Security, WTF | 1 Comment »

“Emerging Threats” – Most “emerged” a long time ago….Emerging Responses?

Posted on March 8th, 2010 by Drazen Drazic

A bit quiet lately. Sometimes I wonder if there’s more to say that I haven’t covered in the 500+ posts in Beast or Buddha. (The really interesting stuff, you can’t write about for obvious reasons). What do you do? Continue to rehash the old stuff? Sometimes!….which brings me to an interesting discussion.

We were asked to do a presentation recently on “emerging threats” at a business forum for IT Security and Risk Management professionals. Seems straightforward enough but when looking back over previous such presentations we’ve been doing over the years, nothing much was changing – in particular our recommendations on how organisations should be dealing with “emerging threats”. We could have almost just pulled out “Emerging Threats” presentation, (circa 2002) and done it word for word, (with only a few very minor wording and definition changes, eg; “Cloud”, “APT” etc :) ).

Should we be calling these presentations; “Emerging Responses”? It’s the response part that is in most cases yet to “emerge” effectively! The “threats” (most of them), emerged a long time ago. In many cases, we just call them different things now because we’ve failed to deal with them properly at the time, so it’s easier to rename something – makes it all seem that little bit new, and covers up to a degree for failures in the past.

Am I being unfair? Keen on your thoughts.

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in Bad Stuff, Dumb Security, Research, Risk Management, Vulnerability Management, Web Application Security, cyber crime, governance | 7 Comments »

Recruiters….please don’t purport to represent Securus Global

Posted on March 3rd, 2010 by Drazen Drazic

Dear Recruiters,

Unless we officially approach you to work with us, ie; approve you to go out and look for candidates, please don’t go out and approach people who you think we might like to fullfill roles that we advertise. This doesn’t look good upon you. We don’t support random headhunting of people.

Securus Global Team

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in Uncategorized | 7 Comments »

What’s your “checklist of choice” for an Enterprise State of Security review?

Posted on March 2nd, 2010 by Drazen Drazic

Just wondering how some people would and/or do approach an Enterprise State of Security assessment? Obviously given the plethora of standards, regulatory “guidelines” etc, there’s no right answers. (Including size and scope of such an exercise…assume it is possible of course!). Do you see it as something impossible? Would you use something like PCI DSS? Do you have your own framework/methodology? Keen to hear people’s thoughts.

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in Research, Risk Management, governance | 4 Comments »

Advanced Persistent Threat…APT…WTF!?

Posted on February 28th, 2010 by Drazen Drazic

I know it has taken me a while to catch up, but I relegated it low priority when I first heard of this “APT” business. Bad of me? Who made this stuff up? This is something you’d only make up for a laugh. But, all of the sudden, my industry is talking about it. FFS. Is this an American thing?

:) ….if I had to mention that to a client. “Stand back…..you have an APT!!!”…… “Thanks Draz…awesome we hired you to save us!”

I have nothing! If this makes Wikipedia, (which it may have by now (Ed: yeah, I know it’s there), I’d love to chat (Ed: modified to not scare people), with that genius  who invented the term, (for our industry).

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in Bad Stuff, Disclosure Laws, WTF | 15 Comments »

(Off Topic) Web 2.0 Case Study: How it can work – Jerrys Plains and Coal Mining.

Posted on February 25th, 2010 by Drazen Drazic

In my day to day, I read blog after blog and most of the ones that I have bookmarked are all I need to keep up with the latest in IT Security news. I rarely now ever read an IT news site unless it’s linked from a blog I read (or to be fair…..Twitter). This Web 2.0 business has substance. I hate the term but love the delivery. (FFS most IT news sites are not worth it anymore (not that many were before), when the bloggers and twitters provide the news quicker!). Anyway, back to the off topic:

The Protect Jerrys Plains blog is one of the best examples of Web 2.0 in action I have come across. Yes, it is run by a friend, Big Galoot, Craig Chapman, and yes, probably the only reason I know about it. But, it’s a gem!

I highly recommend the read. There’s not many entries but if you want to see Australia’s version of Erin Brockovich in action, this is it. It is a soap opera of big business and NSW government games at their best. Read how some make millions from nothing and how a community is spun on the concept of “supporting” individuals and big business making squillions. It reads like a daytime drama, but it is what a community and NSW taxpayers are copping while at the same time being convinced they’re getting something! It’s still going on…..keep reading….logic tells you that someone will someday soon get into trouble!

Web 2.0 – If the Jerrys Plains community did not have this, you have to wonder where they may be?! It still may end bad but at least there will be a record of how it got there and one day, someone may decide to make the players accountable. Go Big Galoot!

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in Uncategorized | 3 Comments »

Symantec Customers Immune to Rising Security Threats! (Late Update: Maybe Not!)

Posted on February 23rd, 2010 by Drazen Drazic

Symantec Press Release 22 February, 2010: Symantec 2010 State of Enterprise Security Study……

(Time to pump out another piece of marketing to get people thinking about buying Symantec. Here’s the report if you are interested in wasting a few minutes).

Just reading this now…….wooo…..hang on……what I don’t see anywhere in this report is a proud statement that Symantec customers are the lucky few that are safe from malicious attacks that other businesses are facing.

Why is this not in there Symantec? Surely you should be beating your own drums given you so proudly told us all some time ago that your product(s), and I quote; will provide “…proactive protection against unknown and zero-day threats”. It’s the Symantec Guarantee!

As such, surely Symantec customers do not have the same concerns as those poor businesses you mention in your study. Let us know if this was just an error on your part, or Symantec just not wanting to show off here because, surely you would not use bullshit marketing in the past?! :)

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in Bad Stuff, Dumb Security, Too cool, Vulnerability Management, WTF, cyber crime | 20 Comments »

Door to Door Spam Chaser Style

Posted on February 21st, 2010 by Drazen Drazic

Classic Chaser work:

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in Too cool, cyber crime | No Comments »

The best business books…..What?

Posted on February 20th, 2010 by Drazen Drazic

Thanks D: http://bsdosx.blogspot.com/

This guy wasn’t “consulting” with me when he did this :) :
http://personalmba.com/best-business-books/

The greatest and all time best management book is: “The Dilbert Principle” by Scott Adams. Since its release, it has been mandatory reading for all staff!….It is the only one worth reading!

As a business dude, that is 99 books I will not read…when the greatest is snubbed! :)

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in Uncategorized | 3 Comments »

Australian IT Security Blogger Roundup

Posted on February 14th, 2010 by Drazen Drazic

From the Australian IT Security Blog Directory:

- Jarrod Loidl at /dev/null has a couple of good recent posts; one on web application scanners and the other on “How to get a start in Information Security.
- Chris Gatford at http://www.penetrationtester.com/ talks about his recent radio interview and then presents “7 Tips for Small Business IT Security”.
- Over at Infamous Agenda, Matthew’s latest post is on Incident Response and what he believe works. Have a read and respond to Matt if you disagree with anything.
- Eldar at Just Another Hacker has changed the look of his site. A heap of topics in recent times from Internet Filtering, theories on hacking, XSS Bank of Queensland and ING plus more.
- Donal at Ockham’s Razor is as always thinking outside the square and presenting theories to question the established ways. He’s also busy with Nodecity and this is definitely worth a look. For more information, contact Donal.
- Fifth.Sentinel in his latest post is talking about research on Windows Registry and time time analysis. Worth a read.
- Christian, the main man from Perth at un-excogitate.org has covered quite a few topics in recent times; BeEF, Sandboxing, new ISACA certification, discussion on “Trust”.

I haven’t covered everyone here. If you want to be added to the list, let me know.

Busiest Blog post of the week; Once again, anything to do with the ACS gets people worked up, and this one here has been no different.

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in news | 1 Comment »

APRA releases “guidance on the management of security risk in information and information technology “

Posted on February 5th, 2010 by Drazen Drazic

APRA has released what they dub as a “prudential practice guide” – “on the management of security risk in information and information technology (IT) by institutions supervised by APRA”. Press release and document here.

It will be interesting to see how the “guideline” adoption will go. Similar to the Monetary Authority of Singapore’s “Internet Banking and Technology Risk Management Guidelines“, but a decade behind, and packing what seems to be no real regulatory push nor enforcement like that in Singapore.

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in Risk Management, governance | 3 Comments »

Big Best Congrats to iiNet……..

Posted on February 4th, 2010 by Drazen Drazic

Made my day when I heard iiNet won their case against the Film Industry! Here reported by itnews. Awesome. Hoping some common sense will prevail and workable collaborative efforts can happen now. Well done iiNet.

Some of our previous posts on this topic…worth a read:
http://beastorbuddha.com/?s=iinet

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in Dumb Security, Internet Filtering, WTF | No Comments »

Securus Global about to get an ACS Member…no joke. :)

Posted on February 2nd, 2010 by Drazen Drazic

Amazingly, one of our own…a Securus Global person is about to become a member, (we hope…..) of the Australian Computer Society.

“We hope”..because that is the only way he can work as an IT person in Australia and get his visa approved. (I hope this post does not delay him). With all the posts here regarding the ACS, I never clicked that a new “Australian” IT person, MUST ALSO, become a member of the ACS, as part of visa acceptance. (My fault…I just did not assume that that stupidity would extend to mandatory “membership”).

So now, we will have a member of the ACS as part of Securus Global……if they accept his credentials to be good enough to work here with us. Who knows, we may learn some things. :)

Phil Argy, who I find a good bloke to chat with and who, to his credit, will respond here, will probably/hopefully present a case as to why all new Australians must become a member of the ACS….but I cannot see it ACS myself and you know me Phil.

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in Uncategorized | 118 Comments »

Internet Censorship – Taking the Power Back (REPOST)

Posted on January 30th, 2010 by Drazen Drazic

This video was put together by Donal and Wade at the recent RSA Conference in San Francisco (April 2009).

Dan Kaminsky, Pete Lindstrom and Marcus Ranum put forward their thoughts on Australia’s plan to censor the Internet. Dan talks about many of the issues that Securus Global’s Matthew Strahan talked about in his interview with ban.this.url. Surprising that these concerns have barely rated a mention here. Marcus certainly adds some interesting analogies and angles to the whole debate.

Related Posts on Internet Filtering. Thanks to Donal and Wade for representing BorB at the Blogger Meetup at the conference.

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in Bad Stuff, Dumb Security, Internet Filtering, WTF | 4 Comments »

Obama position on Internet Censorship

Posted on January 30th, 2010 by Drazen Drazic

Thanks to Wade for this one (and @Wadeis on Twitter). A bit late on my part, but worth a read.

Obama position on; “…right to a free internet….and unshackled internet” – article from The AGE: White House steps into China-Google row.

I wonder how that marries up to Stephen Conroy’s position and thoughts? Yes, I know he’ll “sell” his “project” as a different beast but is it really? We know the implications. More here: http://beastorbuddha.com/category/internet-filtering/

Can you have shades of grey here and spin to suit the occasion/scenario? Keep the fire burning people.

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in Bad Stuff, Dumb Security, Internet Filtering, WTF | No Comments »

“The Great Australian Internet Blackout” Information

Posted on January 29th, 2010 by Drazen Drazic

Run by Electronic Frontiers Australia (EFA), “The Great Australian Internet Blackout” is on.

Some background on this from our perspective can be found here. This is important.

We’ve been against this Government “initiative” from the outset. It is flawed on so many levels, so please, have a read and pass this information onto your colleagues, family and friends, if you haven’t already.

We need critical thinkers to push this information out into the broader community who may not understand the real issues outside of the Government spin on it. We need to wake up our fellow Australians!

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in Uncategorized | 2 Comments »

Apple Don’t Care……

Posted on January 28th, 2010 by Drazen Drazic

I love my Mac. Unlike a PC, it still works the same as the day I bought it! Same speed and can work with it for months without a re-boot other than having to reboot for an update. (Happy to get Windows 7 people responses…..does Windows 7?). Apple formula: you never go back.

iPod, iPhone; so locked in with music and apps – you never go back to anything else.

Fillers like Macbook Air and iPad are just that, “fillers” – perception of innovation to keep the “standards” like Mac Notebooks and iPods going. They all know that.

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in news | 7 Comments »

China, Google, Marketing etc etc…..

Posted on January 25th, 2010 by Drazen Drazic

Random thoughts: News?, OMG really?….nah!, Awesome marketing move Google!, Using the Net for spying…you naughty boys China…you’re the only ones and need to be punished :) , Hang on, he who controls the pipes…controls it all? It’s okay as long as it’s not someone other than us doing it!, yawn…..news?, Great marketing….I’m pulling out of China too! Write it up journos, I need more business!

———————————————————————————————-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.

Posted in Bad Stuff, Dumb Security, WTF, cyber crime | 1 Comment »