App Security Still Dogs Developers, End-User Organizations

Lots of re-used code, cost pressures and long lead times for application software all lead to porous security where application software is concerned, says Chris Eng, Chief Research Officer for Veracode. But an emerging role he calls a “security champion” can help circumvent those problems and make apps safer for everyone.

from Dark Reading: https://ift.tt/2MzLLm9
via IFTTT

Cloud Services Require a Shift in Security Strategy

End-user organizations have their security management tools, but so do cloud service providers, and that forces some hard questions about whose tools will be used to keep everything locked down, says Jesse Rothstein, CTO and Co-Founder of ExtraHop. And he makes the case that better data hygiene can help decrease the chances of a breach.

from Dark Reading: https://ift.tt/2L5c0O9
via IFTTT

Regular User Training Most Effective Security Antidote

Social engineering remains the top vulnerability organizations face because humans remain the easiest way to access networks or databases, says Stu Sjouwerman, Founder and CEO of KnowBe4. Regular training sessions coupled with creation of a “human firewall” remain the most effective protections against social engineering and phishing, he adds.

from Dark Reading: https://ift.tt/2Zbxa7s
via IFTTT

Analytics and Security Prove Effective Security Hybrid

Against the backdrop of consolidation in the SIEM and SOAR sectors, infosec professionals are deploying some combination of analytics and security, according to Haiyan Song, Senior Vice President & General Manager of Security Markets for Splunk. Analytics helps organizations make better decisions and detect anomalies faster, she adds.

from Dark Reading: https://ift.tt/2KQe123
via IFTTT