Securosis Blog

I was fortunate enough to be invited by TechTarget to put together their, “Database Security School”. It’s a compilation of four online educational components: a webcast, podcast, article, and online quiz.

VMware: Please Hire The Hoff

Rich · April 17, 2008

Do you care about virtualization security?

No?

Then get out of the security or virtualization biz.

Yes?

Then go read this.

Ah, RSA. Not much more to say, but we managed to squeeze out a good 30 minutes of recap and conclusions. We spent most of our time on a few issues, especially some of the lessons from our Security Groundhog Day panel, and tried to avoid too many frat-boyish, “I was so drunk at that party dude!”-isms.

Someone call the Guinness records people- I’m actually posting the next part of this series when I said I would!

Debix Contest Ending This Week

Rich · April 15, 2008

I really owe you readers (and Debix) an apology. My shoulder knocked me back more than expected, and I let the contest to win a year’s subscription to Debix for identity theft prevention linger.

‘Boy, RSA was sure a blur this year. No, not because of the alcohol, and not because the event was any more hectic than usual. My schedule, on the other hand, was more packed than ever. I barely walked the show floor and was only able to wave in passing to people I fully intended on sitting down with over a beer or coffee and having deep philosophical conversations with.

Today, in cooperation with SANS, Securosis is releasing Understanding and Selecting a Database Activity Monitoring Solution. This is a compilation of my multipart series on DAM, fully edited with expanded content.

Nothing. Nada. Zip.

While we’ve seen themes emerge most years at RSA; such as DLP, PKI, and compliance; there really doesn’t seem to be any particular preference this year. Sure, we see data security and PCI on every booth, but I don’t see any particular technology or theme consistently highlighted. This could indicate a maturation, or simply that market demands are so all over the place that vendors are using either shotguns or lasers to target buyers.

An Inconvenient Lack Of Truth

Rich · April 6, 2008

On Tuesday morning I’ll be giving a breakfast session at RSA sponsored by Vericept entitled Understanding and Preventing Data Breaches. This is the latest update to my keynote presentation where I dig into all things data breaches to make a best effort at determining what’s really going on out there. Since the system itself is essentially designed to hide the truth and shift risk like a token ring network, digging to the heart of the matter is no easy task.

This morning Dr. Rothman was kind enough to set me up for my last pre-RSA blog post with his Top 3 RSA Themes. It seems that every year there’s some big theme among the show floor vendors. I also can’t make it through a call, especially with VCs, without someone asking, “What’s exciting?”