Securus Solutions

May 18th, 2007 Drazen Drazic

I kicked off a new company this week….Securus Solutions.

No, I am not selling out.

SA……here’s the plug … www.security-assessment.com is still my baby and it always will be. World’s best security consulting team! Come on….tell me a better one! :-)

Anyway…….the two organisations will be chinese-walled from each other and always will be.

I set up Securus (no stupid play on words….it means “Safe” in Latin… :-)…. because I’ve gotten to know a lot of dudes who had some good product and asked me to front it for them. Security-assessment.com doesn’t do that as you know.

I thought, well do you trust that with your typical reseller? No……thus, Securus Solutions.

More good stuff to come……we’re only starting.

DD

Posted in Uncategorized | 1 Comment »

Security Surveys. Will we miss this?

May 13th, 2007 Drazen Drazic

AusCert takes a stand against budget cutbacks. Related to this post.
Seriously though….I’ve talked about these security surveys before….here. As much as I appreciate the work of fellow security community dudes, we still need to question each other’s work’s relevance, accuracy and what it means in the big picture of improving security practices.

Do these surveys reflect what is happening out there? How accurate are they? AND, my big bug bear, how do the dudes responding know what is actually happening to help provide more accurate stats?…..ie; we see it every day, (as I mention in almost every post)….most companies have no idea what is happening! …so what do the stats really mean? I’ll put it out there and say they are useless and far from accurate stats!

You may say, “Hey Draz, but at least they highlight some of the problems?”…yeah, they do….but I’ve never met one senior decision maker in a company that has even read or heard of the surveys….or rather, I should say, remembers having seen them. So do they preach to the converted? Yeah…they do! Sadly, no one will miss the AusCert Annual Survey in my opinion. They should!

(Aside: SA has a stand at the next AusCert conference next week. Readership here may be small enough for me to feel no repercussions of this post>:-))

Posted in Uncategorized | 3 Comments »

Second Life - Future of eCommerce or Porn…and money laundering?

May 10th, 2007 Drazen Drazic

I’ll leave the latter question for now and look at the first one. Second Life on the face of it, and has been reported widely, opens up a world of e-opportunities for business. Just google it if you haven’t heard about it. It’s getting mainstream press everywhere. You’ll wonder why you haven’t heard about it!

The “Otherland” series of books by Tad Williams gives you the feel for how life may become….and more than likely will. Second Life seems like an early incarnation of what Williams plays out in his stories. This is something our kids or their kids will see as a normal part of their lives. Do I sound like a raving lunatic? Maybe….but marketplaces like this are coming. It is inevitable.

Many large corporates are already investing into the L$ (in Second Life) for marketing purposes, but seriously, is porn and other illegal stuff going to dominate (akin to the Internet)? At present, it looks like it!

Don’t get me wrong….I’m excited by things like this….done right (but how do you manage it?)….. How do you stop it turning into a “dirty” and unregulated society..a place where you can virtually do what you want? A place outside the law? It’s heading that way…..smh story.

Don’t get me wrong. I’m no prude, but I see that games like this (more than a game actually), make it harder for parents to control their kids access to inappropriate material. How can they?

I went into Second Life for the first time last weekend. I had read about it and it sounded interesting. As a businessman, I thought I should stay abreast of new marketing channels for my business. Now some of you that know me may say that I looked for it….but NO…….it wasn’t hard and within a few hours (it takes that long to do your orientation) I was walking into houses and Islands dedicated to porn and virtual sex. NO…I did not look for it. It was there!

I wouldn’t have my kids on this and at present, I surely wouldn’t promote my business in it….but then again…….companies said the same about the Internet.

Posted in Uncategorized | 3 Comments »

Another Australian Government Cybercrime Initiative……

May 9th, 2007 Drazen Drazic

This from the budget as reported in ZDNet. And here.

I’ve been a bit of a cynic in recent posts so nothing more to add from this end, but happy to get thoughts…….

Posted in Uncategorized, news | 1 Comment »

Disclosure Laws - Reality Checks

April 30th, 2007 Drazen Drazic

An article from Peter Benson, Security-Assessment.com on Disclosure Laws.

————————————
So when do you disclose a breach? From what we have seen in Australia and New Zealand, generally only when you are forced into it. The notion of disclosure is starting to raise its profile around Australasia, as a result of breaches occurring, and a general lack of public disclosure being undertaken.

The unfortunate aspect of this, is that within our region, there is nothing to force companies to disclose, and as a result, a number of companies are not taking their information security seriously.

Companies are either burying their heads in the sand, or using obscurity as the weapon whereby they resist letting the public and their customers know of bad stuff happening. Often times, as a lack of this accountability and good corporate citizenship, information security is still being seen as an “IT issue”, or alternatively, something to be avoided. In a number of cases that we are aware of, organizations haven’t even been aware that they have been breached, until such time as “weird things happen”, or it otherwise gets into the public arena.

Lets be real about this; while there are emerging standards such as the Payment Card Industry and banking regulations that bring in mandatory compliance in some organizations, the reality is that it is simply just good and responsible practice to at least let your customers know that you have had a breach, and that their information may have been impacted!. What is better…. covering up a breach and having the media find out about it first (then catch up with media controls), or to demonstrate an ethical responsibility to customers where their information has been put at risk? The old school notions of “not telling anyone” just dosen’t cut it any more, and is likely to result in a higher impact over time if issues become disclosed by third parties.

So lets look at bringing back a level of responsibility and accountability to the customer. If we don’t, it is likely that disclosure laws will be enforced sooner rather than later, which will force the issue, and potentially have a much higher impact than if we take a proactive stance on this.

Lets make no mistake, accountability is there, and while there are some courses of action available to enforce accountability around protection of information, the reality is that these will largely be superceded in the not too distant future through disclosure laws. Protection for customers interests and privacy is something that a lot of us have not really addressed seriously as yet, and we still give lip service to this as an “IT issue”. It is not; it is the ethical and responsible protection of our customer’ (and implicitly our shareholders) in behaving in ways that are socially and ethically responsible. To say that this doesn’t exist, or is not a risk, is simply untrue, and we will see changes coming in the near future. Watch this space!
——————————————–
Peter was recently quoted in Computerworld on this topic. He will be presenting on this topic in New Zealand and possibly Australia. Watch this space also.

Peter raises a good comment about organisations not even knowing if they have been breached. We see this all the time as I have noted in a few entries; Botnets, Zero Days, Tell me I’m not owned. How will this play out when disclosure laws come out? 3 monkey approach? I hope not!

Posted in Uncategorized | 5 Comments »

Wow…exciting news…..

March 18th, 2007 Drazen Drazic

Running Vista “legally”:

www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9013258

Posted in Uncategorized | No Comments »

Security Surveys……..

March 18th, 2007 Drazen Drazic

Is there one security survey (from the plethora of “surveys” produced each year eg; Big 4, FBI, IDC etc etc) that from the outset states: “the information contained here cannot be verified and in most cases, should not be taken as fact……….because we can’t verify the information and we have no idea on what basis the company we asked has based their response upon?”

Can anyone surprise me and find one?

MTC………………. And they’ll be rolling them out again soon for 2006, telling us how it is.

Posted in Uncategorized | 1 Comment »

Dec on passwords ……

March 12th, 2007 Drazen Drazic

www.security-assessment.com/newsletter/march_2007/passwords/

Posted in Uncategorized | 1 Comment »

A new notebook arrived with Vista on it ……..

February 15th, 2007 Drazen Drazic

Never have a I seen such a reaction ….. …..A certain techo in the team backed away like he had seen a spider…..really.

I convinced him that it wouldn’t bite, and after a while, he even booted it up, looked around, showed me how cool it was to view open windows in a 3d like view and just as I thought things were okay, he proceeded to trash the operating system and install something else. :-)

Posted in Uncategorized | 1 Comment »

In fear of Obi, Luke and the boys……………

February 5th, 2007 Drazen Drazic

The Star Wars brigade has united as one in defence of their nerdism. Seems even nerds want to distance themselves from the vista fanboys.

The Brain of Wade has led the charge - http://blog.wi.id.au/2007/02/03/are-vista-fanboys-starwars-nerds-leave-a-comment/.

And who could blame them! I have been taught a valuable lesson in all this experience, and never again shall I lump all nerds into one basket.

Posted in Uncategorized | 1 Comment »

Shameless Plug for Security-Assessment.com

February 1st, 2007 Drazen Drazic

Just to prove most pundits and analysts are correct….another dude who’s decided to write about our small, little company:

http://www.demo.com/demoletter/report_from_down_under.php
http://wistechnology.com/article.php?id=3316

But then again, those who matter, know this already……. :-)

Send POs at your pleasure………………………

Posted in Uncategorized | 1 Comment »

Sleepless Nights Waiting for Vista

February 1st, 2007 Drazen Drazic

Why Why Why would anyone line up at a department store at midnight to be one of the first to buy an operating system?

http://www.computerworld.com.au/index.php/id;295073968

Should the cops have been hanging outside to book these geeks as they speed home to install it? Then again, I reckon mum and dad were in the car outside waiting to take their 30 year old computer “guru” home so maybe not. Same dudes who probably lined up for Star Wars movie tickets while the rest of us just booked them on the net or over the phone. Maybe I’m just getting old or maybe I’m just still too cool for all this stuff……. :-)

That’s all …………

Posted in Uncategorized | 4 Comments »