The Security Innovation Europe Blog

Alan Pearson

Recent Posts

How Secure Code Reduces The Risk of Inevitable Attacks

Posted by Alan Pearson on Sep 16, 2015


Attacks on your organisation aren’t just possible anymore. They’re inevitable. 

Read More »

7 Common Application Security Problems (and How to Overcome Them)

Posted by Alan Pearson on Sep 9, 2015


Whilst a growing number of organisations are aware of the need for application security, few are tackling the issue in an effective way.

In a survey of over 640 IT professionals, 7 crucial problems were repeatedly identified as recurrent barriers to effective application security. Resolving these problems will help your organisation improve developer security knowledge, and reduce the costs of software vulnerabilities – helping you to improve the maturity of your application security processes, and share in the competencies of high-performing software organisations.

Read More »
how to roll out and effective application security training program

7 Ways to Improve the Efficacy of PCI Compliance Training

Posted by Alan Pearson on Sep 2, 2015


Compliance with PCI Digital Security Standards is a priority for most large organisations. In addition to the legal ramifications of compliance, it’s essential to thwart malicious third-parties, and protect the loss and theft of sensitive data – and safeguard the customers it belongs to.

With that in mind, we’re drawing upon the findings of a global survey into the roles of over 3,000 IT professionals, and the state of PCI compliance in their organisations. The survey’s findings have identified 7 key drivers of effective PCI compliance training – and following each of these principles, you can ensure your own organisation does everything possible to protect card and cardholder data.

Read More »

8 Essential Components of an Effective Security Awareness Curriculum

Posted by Alan Pearson on Aug 27, 2015


A security awareness curriculum is the vital first step in improving your security, helping you to raise organisation-wide awareness of the threats faced by your employees and business on a day-to-day basis.

Read More »

How to Use the SOCIAL System for Employee Security Awareness Training

Posted by Alan Pearson on Aug 26, 2015


A security breach can be devastating to a large organisation, delaying crucial projects, creating massive remediation costs, and negatively impacting the organisation’s reputation.

However, with 40% of data breaches occurring as a result of careless or unwitting insiders, your organisation has a huge opportunity to improve its security. Through simple employee security awareness training, you can dramatically reduce the primary cause of serious security breaches

One of the best frameworks for improving employee security awareness is the SOCIAL system; offering six tenets of effective security awareness that can be taught, quickly and easily, to your organisation’s entire workforce.

Read More »

What to Look for When Selecting a Third-Party Security Training Vendor

Posted by Alan Pearson on Aug 20, 2015


You’ve weighed-up the pros and cons of in-house and outsourced security training, and now, it’s time to choose a third-party training vendor. Your choice of partner will have a far-reaching impact on the efficacy of your security training investment, so it’s essential to choose a vendor capable of rolling out an effective security training program.

To make the right choice, it’s important to ensure that your chosen vendor offers each of these crucial aspects of effective security training.

Read More »
New Call-to-action

What is The Application Security Maturity Model?

Posted by Alan Pearson on Aug 13, 2015


In 2013, the Ponemon Institute carried out a crucial study into the efficacy of security practices in large organisations. 642 executives and engineers were surveyed, in order to gain crucial insights into security in the enterprise. Based on the results, two dangerously common problems were revealed.

The vast majority of executives surveyed believed that their organisations were following stringent and effective security procedures – in contrast to the handful of engineers (the people responsible for executing on security policy) that believed the same. On top of this, most organisations surveyed were found to be taking only minimal steps to address application security throughout the software development lifecycle.

Most organisations were failing to implement adequate security practices, and worse still, those organisations were completely blind to the problem at the executive level. Without any visibility into the need for security, no steps were taken to improve it.

Read More »

Why It’s Important to Keep Security Training Curriculums Up-To-Date

Posted by Alan Pearson on Aug 10, 2015


Security is one of the most fluid challenges faced by organisations.

The computing field is in a constant state of flux, with new technologies and applications appearing on an almost daily basis. This constant process of change and development means that the security threats faced by your organisation change just as regularly.

There’s no guarantee that the secure systems of today will be the same as the secure systems of tomorrow. Without constant vigilance, and a pro-active attitude to security, the best-practices your organisation currently follows will become obsolete in a matter of months, weeks, or even days.

Read More »

Why Most Employees Aren’t Satisfied with Security Training

Posted by Alan Pearson on Aug 6, 2015


Even with a fantastic security training program and full executive support, there’s still a significant barrier for your organisation to overcome: your employees.

Read More »

How to Mitigate the Human Risk to Security

Posted by Alan Pearson on Jul 22, 2015


Last year, IBM conducted a cyber security study looking at over a thousand organisations, ranging from 1,000 to 5,000 employees in size. Over the period of the study, the organisations experienced a combined total of 91 million security events. Of those 91 million events, a staggering 95% involved a single, unifying factor – “human error”.

Read More »
 
New Call-to-action

Subscribe to Email Updates