BeyondTrust

Security In Context

BeyondTrust’s blog tackles important issues for your company including network and data security.
Learn more and protect your company!

Intentional Harm

Cutting Pay? Think Least Privilege First

There was a big story in Network World about an IT staffer who sold his own company pirated software, used corporate servers for his own purposes and even downloaded credit card information.

Post by admin February 4, 2011
eye in the sky_smaller-resized-600.jpg

Monitoring Your Change Control Processes

I have responded to a number of RFPs (Request For Proposal) in my day and recently I have seen a trend in some of the questions. While the question varies between requests, there seems to be a growing trend that users want vulnerability assessment tools to not only identify vulnerabilities, but to also track changes to…

Post by Morey Haber February 3, 2011
Tags:
, , , ,
stolen

Stolen Fruit is the Sweetest (Especially for Hackers)

I’m sure you’ve heard the saying, “stolen fruit is the sweetest.” It’s a phrase that gets thrown around lightly, but it’s time to take it to heart. In a day when information and sensitive data are being stolen, manipulated, and blasted for the world to read, this is a saying we all need to look at twice. Hackers, inside security leakers, and thieves all agree: that which is stolen is the sweetest. You don’t want to find out how sweet the information in your enterprise will be to them. Steps should to be taken to secure the sensitive information and data in enterprises across the world.

Post by admin February 3, 2011
broken chain

Least Privilege Legacy Apps and the Desktop “Wild West”: Part 4

This week we report the conclusions of our recent survey of 185 IT Administrators and Help Desk Operatives, in a report Legacy Applications and Least Privilege Access Management’ – which reveals the way legacy apps leave Windows desktop environments unnecessarily exposed to attack from malware, as well as providing an open door to insider threats.

Post by admin February 2, 2011
hands

Prevent Security Storms by Eliminating Admin Rights

How many times have you heard the old proverb, “after the storm comes the calm?” And how many times have you just accepted “storms” as part of life? From my point of view, these downpours aren’t actually necessary.

Post by admin February 1, 2011
pillars

Prioritizing Vulnerability Assessment and Remediation Steps: A New Users Guide to Getting Started – Part 1

New users to vulnerability assessment often ask the same question: “How do I get started”? While this may sound incredibly generic for a security engineer, many companies have never had a vulnerability management process in place and are trying to comprehend the problems of missing patches, remediation prioritization, and risk acceptance. As a basic recommendation,…

Post by Morey Haber January 31, 2011
Tags:
, , ,
The Duke

Least Privilege Legacy Apps and the Desktop “Wild West”: Part 3

This week we report the conclusions of our recent survey of 185 IT Administrators and Help Desk Operatives, in a report ‘Legacy Applications and Least Privilege Access Management’ which reveals the way legacy apps leave Windows desktop environments unnecessarily exposed to attack from malware, as well as providing an open door to insider threats.

Post by admin January 31, 2011
Win 7

Microsoft Vulnerabilities & Admin Privileges

Some of you may have already seen the annual report we do each year on vulnerabilities in Microsoft products. Our last report found that in 90% of critical vulnerabilities could be mitigated with the removal of administrative rights.

Post by admin January 28, 2011
The Duke

Least Privilege Legacy Apps and the Desktop “Wild West”: Part 2

This week we report the conclusions of our recent survey of 185 IT Administrators and Help Desk Operatives, in a report Legacy Applications and Least Privilege Access Management’ which reveals the way legacy apps leave Windows desktop environments unnecessarily exposed to attack from malware, as well as providing an open door to insider threats.

Post by admin January 27, 2011
Team

Password Rotation, Phishing and Authentication Limitations, Oh My!

As we have pointed out in several recent blog posts, getting users to choose effective passwords is hard. This is particularly important to us at BeyondTrust since for our PIM solutions to function correctly we need to accurately authenticate a user to know what access privileges to grant them While new technologies for user authentication are on the way, they aren’t here just yet.

Post by admin January 26, 2011