Wednesday, November 30, 2016

The Essentials of Information Security Kit: Includes a Free PC Security Handbook - 2nd Edition eBook

Download this kit to learn everything you need to know about Information Security.


The Essentials of Information Security brings together the latest in information, coverage of important developments, and expert commentary to help with your Information Security related decisions.


The following kit contents will help you get the most out of your Information Security research:

  • PC Security Handbook - 2nd Edition 
  • Five Things You Should Know About Insider Threats 
  • Second Edition DDoS Handbook: The Ultimate Guide to Everything You Need to Know About DDoS Attacks

Monday, September 12, 2016

Five Must-Do's for Simple, Certain, Secure Business-to-Business E-Payments

Executive Summary of the CFO.com Webinar.

We recently convened a panel of experts to explore what it would take to make B2B payments simpler, certain, and secure. They came up with five things:

1.Deliver rich remittance information to suppliers.
2.Get out of the business of bank account management.
3.Remove risk and prevent fraud.
4.Provide a simple, self-service supplier interface for payment and information management.
5.Connect settlements to remittance data and bank information.

Okay, so we know what needs to be done, but how can you make these things happen at your company?

Find out by reading this short summary of a recent webinar from CFO.com.

Monday, July 25, 2016

Pokemon Go Security

In one way or another, you’ve definitely heard of Pokémon Go, the latest new app that seems to be taking over smartphones everywhere. 




When I first heard about the app, it piqued my curiosity, given my passion for cyber security. Admittedly, I became addicted immediately, which lead me to research how the game works, how to play it, and what the possible security risks are that come along with the game.

Firstly, it is important to note that this game is not your average smartphone game. It uses a technology known as augmented reality, which is a blend of real life and technology. There are many layers to this game, using real time GPS locations, geocaching technology and the world around you.

What Are the Risks?

This game has literally become an overnight sensation and cybercriminals are looking to cash in on this huge opportunity in a variety of ways.

Malicious Apps:

ince, the App isn’t available in all countries yet, just days after the official Pokémon Go App hit the market, researchers from Proofpoint discovered a Trojanized version of the app. According to Proofpoint’s blog (link is external) "Although we have not observed this malicious APK in the wild, it was uploaded to a malicious file repository service […] less than 72 hours after the game was officially released in New Zealand and Australia” So first thing’s first- when downloading the app, be sure to only download apps from trusted sources such as the Google Play Store and the Apple App Store.

The most recent and most dangerous malicious app was a discovery made by a group of security researchers on July 15th. The first fake lockscreen app, dubbed “Pokémon GO Ultimate,” was found on the Google Play Store. Luckily, the researchers contacted Google quickly, and it has been removed from the app store.


 

Online Scams: With all popular games, users are sure to scour the Internet for cheats and hacks online. Scammers are already on top of this, as fake websites have started popping up offering Pokécoins and other powerups from the game in exchange for filling out surveys or visiting questionable websites. Surveys may seem harmless, however, they can collect a lot of personally identifiable information about you, which could be used in identity theft. Remember, if it sounds too good to be true, it probably is a scam. As of now, there is no legitimate way or “hack” to get Pokécoins except for buying them in the app.

Privacy Risks:

Review App Permissions: It’s always important to evaluate what an app wants to access when it is installed. Sometimes, granting an app permission to areas of your device can leave your personal information exposed as well as that of others. If it doesn’t make sense to you, such as an app requesting permission to access your phone and SMS capabilities, you can always deny the app access to that part of your phone.

Keep in mind however, that it may place limitations on how the app functions, or it may not function at all without the requested access. It’s really up to you to decide how much privacy to give away for a game, but at least be informed.

Currently some iOS users and some Android users do not get asked permission to access anything. If signing in via Google, you are potentially allowing the game full access to your Google account. This means that the app has access to your contacts, e-mail, Google Drive documents, and more. Niantic has released a statement saying that they have fixed the issue.

Here’s the full statement from the developer:

"We recently discovered that the Pokémon GO account creation process on iOS erroneously requests full access permission for the user’s Google account. However, Pokémon GO only accesses basic Google profile information (specifically, your User ID and email address) and no other Google account information is or has been accessed or collected. 

Once we became aware of this error, we began working on a client-side fix to request permission for only basic Google profile information, in line with the data that we actually access. Google has verified that no other information has been received or accessed by Pokémon GO or Niantic. Google will soon reduce Pokémon GO’s permission to only the basic profile data that Pokémon GO needs, and users do not need to take any actions themselves." 





Privacy Policy and Terms of Service: In this day and age, it’s important to take a look at these documents in order to see what the app plans to do with your personal information. One notable issue in the terms of service located inside of the app is that the links to the privacy policy, and the Pokémon GO Trainer guidelines were not hyperlinked, and you have to agree to all three of them before gameplay.

Pokémon GO Terms of Service 



 


In the terms of service, it is emphasized throughout the risks of danger during gameplay. The line that really caught my eye was: “You agree that your use of the App and play of the game is at your own risk, and it is your responsibility to maintain such health, liability, hazard, personal injury, medical, life, and other insurance policies as you deem reasonably necessary for any injuries that you may incur while using the Services.” I’ve never seen a Terms Of Service recommend that you get an insurance policy as a result of any injuries that may occur during gameplay, but this just reinforces how dangerous this game can become if you’re not paying attention to what you’re doing.

Pokémon GO Trainer Guidelines 

According to the terms of service, users must adhere to the Trainer Guidelines. Since you can’t access these URLs in the application before agreeing them, it’s a good idea to go over all of these documents just to know exactly what you’re agreeing to.


 

Pokémon GO Privacy Policy 



 

At the time of writing this article, Niantic and The Pokémon Company International issued this statement to us:

"We encourage all people playing Pokémon GO to be aware of their surroundings and to play with friends when going to new or unfamiliar places. Please remember to be safe and alert at all times. We are humbled by the overwhelmingly positive response to Pokemon GO and greatly appreciate the support of our fans."

The fact that there are risks should not encourage users to shy away from new things. The most important thing is to educate yourself on the risks and be aware. Once you’re empowered with this knowledge, you can embrace this new technology and go catch that Mewtwo!


Be Sure to protect your devices today while playing! 


Wednesday, May 18, 2016

How to Connect Workforce Training with Millenials

Ever Heard of "Death by PowerPoint"

Attracting great young talent is hard enough. Keeping and growing that talent in a competitive market-space is also a challenging proposition. After you've hired millennials, what are you doing to make sure that your organization is delivering on the promise of a new career?

Growing talent with great training is a huge part of this, and critical to demonstrating the investment in talent development that millennials expect.

If you want to get it right, this is your playbook for shrinking the gap between stale workforce training from the 1990's, and meeting the training expectations of the younger generation today.

Click here for more

Tuesday, March 29, 2016

Putting Contextual Marketing in Context

Learn how marketing leaders are redefining context in their organizations.

As the customer becomes more savvy about what experiences should exist, marketers must start to redefine what context is and differentiate a contextual experience from a clever campaign.

This on-demand webinar includes discussion by marketing experts on the advancement of the contextual customer experience. Beyond campaigns and beyond CRM, this discussion will focus on the new meaning of context as it relates to the customer and the business.

Hear expert insights from:

  • Liz Miller, SVP of Marketing - CMO Council 
  • Bernard Chung, Senior Director of Solution Marketing – SAP 
  • Amy Jackson, Senior Director of Brand Strategy & Consumer Marketing - TripIt

Sunday, February 21, 2016

Modern HR for Dummies - Plus additional FREE resources!

Explore the challenges that Modern HR Organizations are facing, and learn the right processes and technologies for your organization.

Use this eKit to learn what a modern HR organization is, and how to transform your organization to
achieve a competitive advantage.

You'll learn to:


  • Create a talent-centric business strategy 
  • Build a collaborative culture 
  • Deliver engaging HR applications for your employees 


Download this FREE eKit today and you'll have access to Modern HR for Dummies as well as The Myth of Human Resources Best Practices.

Wednesday, January 27, 2016

How To Balance The Pros And Cons Of Gating Premium Content

You need to ask yourself some questions: What content format is it? Does the topic qualify your audience? Can you bring enough traffic to it to compensate for its lacking virality?

While the dust hasn't quite yet settled when it comes to the "gate debate", one thing is for certain:
gating your premium content needs to be determined on a case-by-case basis. You need to weigh your losses and your potential gains when you gate a piece of content. Aside from the obvious lead generation benefits, you also get more accurate insights into the motivations of leads that convert on that particular piece of content.

But you need to ask yourself some questions: What content format is it? Does the topic qualify your audience? Can you bring enough traffic to it to compensate for its lacking virality? Furthermore, you need to understand how you can still retain some of the benefits of public content when you gate your premium content.

In this eBook you'll learn: 

  • How to weigh your options before you gate a piece of content 
  • The kinds of gates that you can use 
  • A strategy to reap the benefits of both gated and ungated content

Your premium content can be a lead gen magnet if you gate it. Learn how in our eBook How to Gate Premium Content and Generate Leads.