Pick awesome over boredom. Why Training quality matters.

posted on Mar 31, 2013 by Oliver Ng Comments:0

Whether you’re looking to train staff on OWASP training and/or Security Awareness training, at some point you will need to decide what kind of computer based training product to purchase.  In developing a vendor criteria, it may seem like it makes sense to purchase training with a LOT of  content, but let me tell you…

Your Guide to the HP Cyber Risk Report

posted on Mar 28, 2013 by Geoffrey Vaughan Comments:0

This year at the RSA Conference HP officially released its annual Cyber Risk Report. This report is one among many industry reports that individuals and companies who are concerned about security should pay attention to. By paying attention to these trends your company will be better able to secure your IT assets and more effectively allocate IT…

Avoiding a checklist approach to PCI Compliance Training

posted on Mar 25, 2013 by Oliver Ng Comments:0

It is easy to be skeptical about PCI Compliance and the requirement to deploy Training to satisfy a checklist item. This idea that a checklist approach cannot help with security is not new. But I’d like to propose the idea that if we have an opportunity to educate teams about Security through an audit approach,…

Be a part of our social community!

posted on Mar 22, 2013 by Oliver Ng Comments:0

We love meeting up with security people within the local Toronto community, but there’s a big world out there!  So we’re going a bit more social this year. Follow us, link and share with us your interesting security stories and stay tuned for more exciting tools and resources for the community. Twitter Google+

SC with major contributions to HP Cyber Risk Report 2012

posted on Mar 18, 2013 by Oliver Ng Comments:0

We work on security assessments daily and see common trends on every engagement.  Recognizing these changes helps us keep on the edge of the security assessments and provides us the insight to give back to the community including our research in Mobile tools (ExploitMe Mobile) and NFC. I’m extremely pleased to say that this year,…

Exploiting and Defending Mobile Training @CanSecWest

posted on Feb 4, 2013 by saurabh Comments:0

Salut à tous, We are pleased to announce that we will be presenting our “Exploiting and Defending Mobile” training course @CanSecWest. Our “Exploiting and Defending Mobile” training will provide you with two days of insight into the world of mobile hacking. The course is designed to keep a balance between theoretical knowledge & practical experience….

Assessment Controls in HITRUST CSF

posted on Jan 25, 2013 by Nima Dezhkam Comments:0

By Nish Bhalla and Nima Dezhkam There are many frameworks that industry has and regulations have tried to put together to help organizations follow and succeed in securing their environment. Health Information Trust Alliance (HITRUST) was born out of the belief that information security should be a core pillar of, rather than an obstacle to, the…

What We Learned from 2012 Password Hacks

posted on Sep 20, 2012 by Nima Dezhkam Comments:0

By Ehsan Foroughi and Nima Dezhkam In the past few months we have evidenced frequent news headlines on password breaches at major websites such as LinkedIn, Yahoo! Voices, DropBox, Gamigo, and Phandroid, an Android Forum. The list does not stop there. These incidents motivated us to perform some high-level analysis on the leaked data, review…

The Operational Reality of Opt-In Security Controls

posted on Jul 11, 2012 by Paul O'Grady Comments:0

TL;DR: We thought we found arbitrary command execution due to an absence of class-whitelisting. We actually found several un-hardened Hudson deployments. Hudson/Jenkins CI instances are deployed insecure by default, with opt-into hardening. The operational reality of opt-in hardening is that it doesn’t happen nearly as much as it should.   In broad and liberally scoped…