“Working on the right thing is probably more important than working hard.”

—Caterina Fake


Houston Astros hacked, trade conversations posted online http://www.scmagazine.com/houston-astros-hacked-trade-conversations-posted-online/article/358952/

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that is capable of block incoming attempts from bad reputation IP addresses from countries on the watch list.
  2. Verify your security appliances are reporting to a Security Information and Event Management tool (SIEM) that correlates events and displays intelligible information to security analysts.
  3. Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
  4. Verify your company has an effective and enforced data classification standard which requires data owners to seriously assess data sensitivity and requires data custodians to properly secure the information to need-to-know only basis.
  5. Ensure your organization has a solid data storage policy which requires confidential data to be stored in secure, encrypted locations
  6. Perform periodic access reviews for data stores and applications housing highly classified or confidential information to ensure appropriate access is enforced. Any users or groups who are discovered to have access and don’t have a need to have access should be immediately removed.
  7. Confirm network segmentation in your environment so that only required devices are able to access networks where highly classified or confidential data resides.

Article Resources

Houston Astros Exposed Conversations

http://anonbin.com/753432515

http://anonbin.com/2412624498

Houston Chronicle Article: Astros GM Jeff Luhnow addresses trade leaks, Deadspin

http://blog.chron.com/ultimateastros/2014/06/30/astros-gm-jeff-luhnow-addresses-trade-leaks-deadspin/#22102101=0


P.F. Chang’s Hit With Class Action Lawsuit Over Data Breach http://www.securityweek.com/pf-changs-hit-class-action-lawsuit-over-data-breach

http://www.scmagazine.com/pf-changs-hit-with-class-action-lawsuit-following-breach/article/358909/

C-IT Recommendations

  1. Ensure your organization has an incident response plan in the case of a data breach
    1. Incident Response Team
    2. Public Relations Strategy
    3. Legal Team
    4. Possibly Data Breach Insurance

Article Resources

P.F. Chang’s Lawsuit Courtroom Paperwork

http://media.scmagazine.com/documents/83/13186094-0–21770_20721.pdf

Definition of injunction

http://www.law.cornell.edu/wex/injunction

Definition of Declaratory judgment

http://www.law.cornell.edu/wex/declaratory_judgment

Experian Data Breach Response Guide

http://www.experian.com/assets/data-breach/brochures/response-guide.pdf


Payment Services, Financial Industry Top List of Phishing Targets http://www.securityweek.com/payment-services-financial-industry-top-list-phishing-targets-research

C-IT Recommendation

  1. Ensure your company has an effective spam gateway or email content filter solution that quarantines junk mail, detects viruses.
  2. Consult with your email security team to validate the email security solution is running on the latest stable version with the latest signature updates.
  3. Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
  4. Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
  5. Thoroughly educate your end users on phishing attacks and how to avoid them.
  6. Encourage your end users through your information security policy not to give their company email out for non-business related purposes
  7. Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes

Article Resources

Phishlabs Data Analysis of Phishing Targets

http://blog.phishlabs.com/banks-epayment-top-list-of-phishing-kit-targets