Latest news

In mid Septeber, the 1st NIS Summer School jointly organized by the European Network and Information Security Agency (ENISA) and the Institute of Computer Science of the Foundation for Research and Technology - Hellas (FORTH-ICS) took place in Heraklion, Greece. The purpose of this gathering was to discuss multi-dimensional issues related to network and information security (NIS), the advances made in the recent past, along with emerging threats, critical compliance and legal issues. The attendees enjoyed the presentations of numerous outstanding speakers from all over the world.
ENISA representatives have a clear idea about the complexity of the problem they're dealing with. Rather than bombarding us with surveys, they simply say they don't know how big the problem is. Nobody does really, statistics differ and companies still under-report security breaches which makes it impossible to see the big picture. We can only accept the fact that we live in uncertainty but at the same time we need to get an understanding of the risks and vulnerabilities since that's the only way we can protect our networks. It's worth noting that ENISA wants the mandatory reporting of security breaches despite this not being popular with all organizations.
Working together
One of the hot topics at the event was data protection. It's essential for an organization to set a clear set of goals if it wants to achieve an acceptable level of security. What organizations need to realize when discussing the question of security return on investment (ROI) is the fact that good regulation guarantees trust. Naturally, trust brings forward more users and eventually more services. Thus, it's of the essence to work on issues related to the regulatory framework.
Some member states of the European Union are more equipped than others when it comes to developing NIS. One of the roles of ENISA is to broker the way knowledge is exchanged between countries. Fine examples of cooperation are Hungary working with Bulgaria in setting up a government Computer Emergency Response Team (CERT) and Finland supporting Slovenia in organizing awareness raising activities.
You are probably wondering how effective ENISA's work is. A survey showed that the work is influential and of high quality, but it still has to reach its full potential. With a yearly budget of 8 million Euros and so much on their plate, the agency has to choose their research carefully.
Dr. Jorgo Chatzimarkakis, a Member of the European Parliament, emphasized the importance of having politicians acquainted with matters related to computer security. It was refreshing to hear a politician with a significant amount of IT knowledge discuss crucial security issues and their impact on the European Union.
Spotlight

Cyber espionage campaign uses professionally-made malware
Posted on 20 May 2013. | A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.

Ransomware adds password stealing to its arsenal
Posted on 17 May 2013. | Microsoft researchers are warning about a new variant of the well-known Reveton ransomware doing rounds.

Application vulnerabilities still a top security concern
Posted on 16 May 2013. | Respondents to a new (ISC)2 study identified application vulnerabilities as their top security concern. A significant gap persists between software developers’ priorities and security professionals’ concerns.

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Hacking charge stations for electric cars
Posted on 15 May 2013. | Ofer Shezaf talks about what charge stations really are, why they have to be ‘smart’ and the potential risks created to the grid, to the car and most importantly to its owner’s privacy and safety.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.






