Contain Data Leakage by Raising Your Security IQ

Luke LeBoeuf, Principal Security Consultant, HP Enterprise Security
Headlines about compromised enterprises seem to be a weekly occurrence lately, if not daily. Whether data leakage incidents are driven by the likes of botnets, malware, viruses, etc., or non-malicious insiders, organizations’ bottom line and reputations are being severely affected.

From published internal emails to entire customer lists, intellectual property theft is often the result of a simple security program oversight. This webinar has been designed to help companies better comprehend the scope of data leakage and IP theft and, more importantly, how you can glean better security intelligence by:

· Considering the focus areas your company needs to encompass in your security program, from devices to education

· Understanding what use cases to look for and which Primary Data Sources to gather and monitor to gain the most visibility into the security and threats both internal and external

· Reviewing best practices for handling SIEM events and reducing Mean Time to Resolution (MTTR) for any detected breaches
Apr 5 2012
49 mins
Contain Data Leakage by Raising Your Security IQ
More from this community:

IT Security

Webinars and videos

  • Live 1 and recorded (2601)
  • Upcoming (171)
  • Date
  • Rating
  • Views
  • How do you monitor and assess performance in the cloud? Do you need more visibility and control over your managed cloud environments? Learn how HOSTING 360° Report™ delivers a level of visibility to cloud performance that has historically been unavailable to cloud customers. Aggregating key performance and operational data in a concise and usable format provides full visibility into the availability, performance, recovery, security and capacity (AppRisk™) of HOSTING’s cloud services.
  • The explosion of social media in recent years means that there are millions of users or ‘fans’ to reach and add to your customer base. While there are clear benefits to end-users and the organizations that accept their social identities for account creation and authentication, there are important risk factors that have to be considered as well.

    Please join CA and ISACA for this webinar, where we will review the pros and cons of social media login and Bring Your Own Identity (BYOI), and provide guidance and best practices based on real use cases to help guide organizations to a model that meets their risk profile.
  • BYOD is inevitable and unstoppable. Maybe even uncontrollable and unmanageable. But is it the real issue? We seem to be very interested in mobile device management and security risks and data breaches, as, of course, we should be. But, isn’t the real issue the fact that traditional IT is fast becoming irrelevant. Nearly all of us use our personal devices for work and have multiple personal clouds full of data – personal and business. Today’s users believe that they need traditional IT less than before. Crowdsourcing is replacing the Service Desk while Web self-service is replacing live people. But, there’s more to running IT than mobile device buzz words and doom & gloom blogs and tweets. Check out this webinar with CA Technologies & Pink Elephant to find out what’s really happening and what IT can do to embrace this new world. 1 PriSM CPD.
  • For the IT employer utilizing contingent or contract worker(s) services there are best practices and considerations that need to be made in order to protect yourself and your employees.

    - Do you know how to discuss pay rates, increases or bonuses?
    - Do you know how to deal with full-time employment queries, how to properly deal with timecards or forms?
    - How do you deal with punctuality, attendance, dress code etc?
    - What do you do when you want to terminate or suspend a contingent worker?

    These are the common questions we receive and we will provide tangible tools and information that can help protect you as an employer.
  • For the IT employer utilizing contingent or contract worker(s) services there are best practices and considerations that need to be made in order to protect yourself and your employees.

    - Do you know how to discuss pay rates, increases or bonuses?
    - Do you know how to deal with full-time employment queries, how to properly deal with timecards or forms?
    - How do you deal with punctuality, attendance, dress code etc?
    - What do you do when you want to terminate or suspend a contingent worker?

    These are the common questions we receive and we will provide tangible tools and information that can help protect you as an employer.
  • By 2014, 60% of global companies are expected to pilot, deploy or expand their BYOD programs (RainKing). As BYOD has become a fixture in the workplace, with 72% of employees clamoring to have their personal devices work-enabled, the IT industry has watched as the familiar “perimeter" model has become untenable. Data is going to more places, and ending up on a wider variety of devices, than ever before. A new model for protecting data has become a necessity. Organizations have tried to do so in a multitude of ways: extending policies to cover mobile devices, monitoring usage, MDM solutions, and even NAC; all have been methods used to try and create the most stable environment for mobile technology. Let Integralis security expert Mike Gabriel explain how to best balance mobile productivity and security in this Security Talks installment.

    Why Attend?

    1.Discover how your peers are trying to protect mobile data.
    2.See how the perimeter is being sculpted (or not) by the IT industry.
    3.Find out what the future holds for BYOD in the workplace.
  • Over the years true MSPs have had to work diligently to differentiate themselves from companies that are at best, not true MSPs and at worst, are shady fly-by-night operators. This is where the Unified Certification Standard or (UCS) for Cloud & Managed Service Providers comes in.

    The UCS was created by a team of dedicated MSPs to address the shortfalls of existing standards like ISO 27001, ITIL, CoBIT, SSAE 16, which were never intended for managed services organizations and offered little in the way of consumer protection.

    CASE IN POINT: Many MSPs do NOT fail because of technical deficiencies, but due to financial risk. Because of this, customers have very little insight into the service provider's business practices and financial strengths and capabilities.

    Attend this webcast and you will hear from real MSP executives on how the UCS certification and audit has helped them to:

    - Win new business
    - Provide needed transparency to customers
    - Achieve compliance objectives
    - Quickly develop trust with customers and prospects
    - Provide documentation on how those MSPs deliver their services
    - And much more...

    Both Cloud and Managed Service Providers should attend this webcast and at least begin to follow the standards necessary to achieve managed services and cloud computing excellence.
  • Doug Turner, CEO of Mantis Technology Group, talks about how his team built Pulse Analytics, a sentiment analysis solution using text analytics tool running on SAP HANA One. Hear how his team strengthened the capabilities of this solution while simplifying their data architecture by replacing 20 servers with only 1 SAP HANA One instance.
  • Most SMB's use a single point product for each of the different perceived security threats. This has worked in the past, but a far better approach is layering multiple products in a stouter defense.
  • APIs are a hot topic in all sectors of IT - they have gone from being niche solutions provided by big players like Amazon and Google, to being almost as ubiquitous as corporate websites. Ad hoc API development & evangelism without a formal program can leave real revenue on the table, can unintentionally leak sensitive data, and can tarnish the corporate brand with the development community. Today, developers and partners expect to be engaged with first class API programs, while businesses expect real insights to know which APIs are profitable and which APIs to bring to market next. In this webinar, Intel & Mashery outline the baseline enterprise pillars for constructing a first class API program. Learn from CapitalOne how they strategized to build an API program grounded in core business objectives. All attendees to receive a new Mobile API Buyers Guide that presents how to optimize APIs for mobile apps.
  • Channel
  • Channel profile
Up Down
  • Gaining Threat Intelligence and Combating the Four Most Common Attack Vectors Jun 12 2013 5:00 pm UTC 45 mins
    The HP Security Research team (HPSR) is hard at work monitoring the threat landscape for new campaigns, profiling actors to understand their motivations, identifying the tools they use and determining how credible certain threats might be. It’s part of a long-term strategy for developing a new threat intelligence-sharing model. Why is that important? It will provide real-time info from the larger security community-- enterprises like yours, industry security organizations and security vendors-- that can be used to automate and catch these breaches immediately.

    Learn about HP’s findings, including these culprits: injection flaws, DDoS, various phishing techniques and zero day vulnerabilities. How can you address the inevitable breaches that will occur?
  • Enhance Your Security Operations with Big Data Recorded: Mar 13 2013 37 mins
    More and more security operations centers are transforming their operations from being reactive, to proactive and even predictive. Hear how big data technologies like Autonomy IDOL can be leveraged with traditional security monitoring tools for Social Network Monitoring and Data Loss Prevention (data in motion) to drive value and empower a “next generation SOC.”
  • Top 10 Tips to be Compliant and Secure Together Recorded: Jan 17 2013 45 mins
    Compliance and security are better together. Through these ten tips, discover the tools and resources you need to implement now in order to achieve both. Learn some of the best practices such as continuous monitoring, assessing the controls, cost-effective audit logs, and others to understand and implement best practices of compliance and security together.
  • Secure your Enterprise with Big Data Recorded: Jan 16 2013 46 mins
    While organizations continue to battle cyber criminals, it seems that security professions are always fighting a losing war. However, a new weapon has been building up within the domain of most organizations, one that can help tip the balance in favor of the good guys. Find out how we can take the massive amounts of information we are generating and turn it to help bring valuable intelligence that can stop cyber-attacks from compromising your enterprise.
  • How secure is your IT operations? Making SOC/NOC integration work for you Recorded: Sep 20 2012 58 mins
    The emergence of Enterprise 2.0 with social, mobile, local, and cloud applications within the enterprise has increased IT infrastructure management challenges with an increasing number of IT assets. Bring your own device (BYOD) is no longer an option for the enterprise. Your business needs an open IT architecture to facilitate collaboration between customers and employees, but your IT operations cannot fully support it due to security issues. How do you align business and IT needs while keeping your enterprise secure? This webcast talks about how to seamlessly integrate the Network Operations Center (NOC) and the Security Operations Center (SOC) to secure your IT infrastructure and empower your organization to collaborate with your ecosystem effectively.

    Speaker Bio:
    Sridhar Karnam, Product Marketing Manager, HP Enterprise Security Products. Sri Karnam is a subject matter expert on IT operations and security challenges, and has over 10 years of experience managing IT and security software products through their entire lifecycle. He has an MBA from Wigan & Leigh College in the UK, and an MS in Engineering Management from Santa Clara University. In his spare time, Sri enjoys building robots.
  • Security Intelligence for a Faster World Recorded: Aug 8 2012 49 mins
    The amount of digital data is exploding exponentially. It is being generated, transmitted and exchanged much faster, by more sources and in different formats than ever before. At the same time, the number of attempts to infiltrate organizations to steal and profit from the unauthorized use of critical data is skyrocketing. Not only are financially motivated criminals conducting more attacks on organizations, there has also been a dramatic increase in the number of data theft attempts by nation states and politically motivated hacking groups. We will discuss new technological innovation that enables HP ArcSight SIEM solutions to maintain the security of organizational IT assets by detecting more incidents and addressing larger sets of log data.
  • Hacktivists Declare War Against All Organizations – What Can YOU Do About It? Recorded: Jun 20 2012 44 mins
    Are you wondering what you should do to fight cyber terrorism? Hacktivist groups like Lulzsec and Anonymous are encouraging fellow hackers to open fire on any organization or agency that crosses their path. That adds a lot of pressure on all security professionals. Join cyber security expert Narayan Makaram, Director of Solutions Marketing, Enterprise Security at Hewlett-Packard, to learn:

    · Why hackers are going after big and small organizations worldwide

    · What you should do… and NOT do

    · How to prepare for The Day should things go south

    We will also cover the best practices organizations worldwide have implemented to better prepare themselves against cyber terrorism.
  • Securing the Cloud with SIEM Recorded: May 24 2012 39 mins
    Organizations are adopting cloud services at a very fast pace, driven by the cost effectiveness, speed/time to market and better performance and availability cloud adoption provides. However the security of data and access in the cloud is still a major cause for concern. Even if the organization is comfortable with a cloud service provider’s security posture, they are often surprised to find they are ultimately responsible for securing their own data. Fortunately security event and information management (SIEM) solutions are able to extend information and access controls to cloud in addition to physical and virtual environments. This webinar will dive into the various options available to organizations to help them ensure a secure cloud services environment.
  • Centralizing Compliance Controls: Achieving Scale and Cutting Costs Recorded: May 22 2012 44 mins
    Organizations often approach regulatory compliance with one-off projects, deploying a set of controls for each regulation. This approach to enterprise-wide management of compliance can become expensive and difficult to sustain, let alone develop and expand to meet growing demands. This presentation will address how a centralized system coupled with an IT governance framework may be used to achieve multiple compliance regulations and manage them efficiently with a consolidated view across an entire organization.
  • Contain Data Leakage by Raising Your Security IQ Recorded: Apr 5 2012 49 mins
    Headlines about compromised enterprises seem to be a weekly occurrence lately, if not daily. Whether data leakage incidents are driven by the likes of botnets, malware, viruses, etc., or non-malicious insiders, organizations’ bottom line and reputations are being severely affected.

    From published internal emails to entire customer lists, intellectual property theft is often the result of a simple security program oversight. This webinar has been designed to help companies better comprehend the scope of data leakage and IP theft and, more importantly, how you can glean better security intelligence by:

    · Considering the focus areas your company needs to encompass in your security program, from devices to education

    · Understanding what use cases to look for and which Primary Data Sources to gather and monitor to gain the most visibility into the security and threats both internal and external

    · Reviewing best practices for handling SIEM events and reducing Mean Time to Resolution (MTTR) for any detected breaches
  • When Insiders Go Rogue: Tactics for Monitoring and Containing Breaches Recorded: Mar 15 2012 49 mins
    If today’s headlines about compromised enterprises are any indication, an insider data breach can cost a single organization as much as tens of millions of dollars. Another significant financial impact to an organization is the remediation cost that follows breach detection. This highly relevant Webinar that has been designed to help companies better understand the scope of insider threats and glean best practices for monitoring and containing breaches.

    You will learn:
    · The sources of insider threats, both careless employee behavior or malicious actions, and how to recognize them in your organization.

    · Best practices for monitoring high-risk users and anomalous behavior to identify possible breaches before they become large scale.

    · Reporting metrics to monitor the business threats and ensuring incident response processes are in place to quickly remediate any breach.
  • Top 5 Security Threats for 2012 Recorded: Feb 9 2012 61 mins
    In 2011, we saw many examples of organizations falling victim to hackers and malicious insiders – from major cyberattacks like Sony, malware like Stuxnet to massive data breaches like Epsilon Interactive. As you begin making improvements to your security programs in 2012, it is critical to review these breaches to betting prepare for the trends taking place in the information security arena.

    In this webinar, we will take a close look at the security risks you should expect to face in 2012 and how you can prevent a major security incident from occurring in your organization. You will gain valuable insight into:

    • Notable security incidents in 2011
    • Top security threats to watch for in 2012
    • The steps you can take to secure your organization NOW

    You will also hear about case studies illustrating how organizations have successfully prevented security attacks and improved their security and compliance posture.
Preventing Threats & Securing Information Across the Enterprise
HP is a leading global provider of security and compliance management solutions that intelligently identify and mitigate cyber threat and risk for businesses and government agencies. HP Enterprise Security helps protect enterprises and government agencies by providing complete visibility and critical insights into their IT infrastructure across all users, networks, datacenters and applications. The market-leading Information Security platform enables organizations to proactively safeguard their digital assets, control the risks associated with cybertheft, cyberfraud, cyberwarfare and cyberespionage and comply with corporate and regulatory policy.

Embed in website or blog

Successfully added emails: 0
Remove all
  • Title: Contain Data Leakage by Raising Your Security IQ
  • Live at: Apr 5 2012 7:00 pm
  • Presented by: Luke LeBoeuf, Principal Security Consultant, HP Enterprise Security
  • From:
Your email has been sent.
or close
You must be logged in to email this