<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CounterMeasures -  A Security Blog » Shameless plug</title>
	<atom:link href="http://countermeasures.trendmicro.eu/category/shameless-plug/feed/" rel="self" type="application/rss+xml" />
	<link>http://countermeasures.trendmicro.eu</link>
	<description>Rik Ferguson blogs about current security issues.</description>
	<lastBuildDate>Wed, 28 Jul 2010 17:12:49 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Don&#8217;t care &#8211; Shouldn&#8217;t have to care</title>
		<link>http://countermeasures.trendmicro.eu/dont-care-shouldnt-have-to-care/</link>
		<comments>http://countermeasures.trendmicro.eu/dont-care-shouldnt-have-to-care/#comments</comments>
		<pubDate>Tue, 06 Jul 2010 20:42:30 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Shameless plug]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=2235</guid>
		<description><![CDATA[My colleague Jon Collins from Freeform Dynamics posted a really interesting question over on The Register: â€œDoes business really care about security?â€ &#160; Like all the big, crunchy questions, the answer is a lot more complex than initially seems possible. &#160; You could take some sort of statistical approach â€“ what proportion of businesses deploy [...]]]></description>
			<content:encoded><![CDATA[<p>My colleague Jon Collins from Freeform Dynamics posted a really interesting question over on <a href="http://www.theregister.co.uk/2010/06/28/biz_care_about_security/">The Register</a>: â€œDoes business really care about security?â€<br />
&nbsp;</p>
<p>Like all the big, crunchy questions, the answer is a lot more complex than initially seems possible.<br />
&nbsp;<br />
You could take some sort of statistical approach â€“ what proportion of businesses deploy antivirus software to their desktops? â€“ and come up with a big number that implies â€˜<em>yes, it does</em>â€™. (Or <a href="http://www.news.com.au/technology/biz/more-than-half-of-small-bussinesses-hit-by-security-threat-survey/story-fn5lic6c-1225877514805">maybe not</a>).<br />
&nbsp;<br />
You could interview the CTOs of a representative sample of large organisations and ask them for more in-depth examples and views. Again, itâ€™s pretty likely that youâ€™ll come up with a positive picture.<br />
&nbsp;<br />
However, those results are misleading in some respects. And I think thatâ€™s because the question involves two big abstract terms. â€˜Businessâ€™ is an idea, not a person, so it doesnâ€™t care about anything much. Security doesnâ€™t appear on the mission statement, Iâ€™d be willing to wager. Nor would it be appropriate for it to be there. Alongside things like Health and Safety, environmentalism and equality of opportunities, itâ€™s the sort of thing we expect businesses to care about, but we know itâ€™s not their primary function. And does â€˜businessâ€™ mean the board, the IT department or every single member of the organisation?<br />
&nbsp;<br />
Similarly, â€˜securityâ€™ is extremely slippery as an idea: weâ€™re talking about systems, software, attitudes, processes and policy.<br />
&nbsp;<br />
So to break it down: does Jon in logistics make sure his internet browser is <a href="http://www.mywot.com/en/blog/226-have-you-updated-your-browser-lately">patched*</a> to the currently advised levels? No, he couldnâ€™t care less. Heâ€™s got a big shipment that needs to be in Paris tomorrow â€“ so donâ€™t start messing with his machine right now, thank-you very much. But he does <a href="http://www.mckeay.net/2010/05/28/its-frustrating-being-a-qsa-but-sometimes-its-rewarding/">care</a> â€“a lot â€“ that his system works and that he doesnâ€™t get in trouble.<br />
&nbsp;<br />
What we keep arguing for is an holistic approach to security. That doesnâ€™t mean that we need to persuade Jon that his patch levels need to be up-to-date. That isnâ€™t going to happen. Sorry.<br />
&nbsp;<br />
What it does mean is that the security and IT department are able to manage his security for him â€“ all the time. Itâ€™s pretty much impossible for Jon to screw-up or for his machine to get compromised because the policies are baked into the processes and the technology.<br />
&nbsp;<br />
What are your views on this? Voice your opinions on the Registerâ€™s <a href="http://www.theregister.co.uk/security/security_that_fits/">Security That Fits</a> Workshop before it closes later this month.<br />
&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/dont-care-shouldnt-have-to-care/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Countermeasures shortlisted for award</title>
		<link>http://countermeasures.trendmicro.eu/countermeasures-shortlisted-for-award/</link>
		<comments>http://countermeasures.trendmicro.eu/countermeasures-shortlisted-for-award/#comments</comments>
		<pubDate>Tue, 03 Nov 2009 21:36:55 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Shameless plug]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1494</guid>
		<description><![CDATA[UPDATE: The Computer Weekly 2009 IT Blog awards took place on the 25th November in London. I wanted to add this short update to thank all of you that voted, because CounterMeasures was named Runner-Up in the IT Security category! This is a fantastic achievement for us as we have only been blogging for 9 [...]]]></description>
			<content:encoded><![CDATA[<p><strong>UPDATE</strong>: The Computer Weekly 2009 IT Blog awards took place on the 25th November in London. I wanted to add this short update to thank all of you that voted, because CounterMeasures was named Runner-Up in the IT Security category! This is a fantastic achievement for us as we have only been blogging for 9 months.</p>
<p>Â </p>
<p>So once again many many thanks, and here&#8217;s to next year!</p>
<p>___________________________________________________________________________________________</p>
<p>I am very proud to be able to say that Countermeasures has been shortlisted for the Computer Weekly IT blog awards 2009 in the IT Security category.</p>
<p>Â </p>
<p>So firstly, many thanks to all of you who felt motivated enough to nominate the blog in the first place.</p>
<p>Â </p>
<p>Now the contest heats up as voting has opened, so if you&#8217;re a regular reader, or are simply coming here for the first time and like what you see please head over to the <a title="Vote in the Computer Weekly IT Blog Awards 2009" href="http://www.computerweekly.com/Articles/2009/11/03/238190/vote-in-the-computer-weekly-it-blog-awards-2009.htm#1" target="_blank">voting page </a>at Computer Weekly and vote for Countermeasures in section 9: IT Security.</p>
<p>Â </p>
<p>Thanks again for reading and now back to your regular program.</p>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/countermeasures-shortlisted-for-award/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>In Security, Reputation Is Key</title>
		<link>http://countermeasures.trendmicro.eu/in-security-reputation-is-key/</link>
		<comments>http://countermeasures.trendmicro.eu/in-security-reputation-is-key/#comments</comments>
		<pubDate>Mon, 28 Sep 2009 10:37:19 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Shameless plug]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[NSS Labs]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[testing]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1382</guid>
		<description><![CDATA[That appears to be the conclusion of a pair of independent tests recently released by NSS Labs. Back in June of 2008 you may remember there was some noise in the IT press, as Trend Micro was declining to participate in some of the well known anti-malware tests, such as VB100. Our argument at the [...]]]></description>
			<content:encoded><![CDATA[<p>That appears to be the conclusion of a pair of independent tests recently released by NSS Labs.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="480" height="295" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/1j17l1kvHio&amp;hl=en&amp;fs=1&amp;rel=0" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="480" height="295" src="http://www.youtube.com/v/1j17l1kvHio&amp;hl=en&amp;fs=1&amp;rel=0" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>Back in June of 2008 you may remember there was some <a title="Trend withdraws from 'irrelevant' VB100 anti-virus test" href="http://www.channelregister.co.uk/2008/06/09/trend_vb_test_criticism/" target="_blank">noise in the IT press</a>, as Trend Micro was declining to participate in some of the well known anti-malware tests, such as VB100. Our argument at the time, and this still stands today, was that those tests simply do not accurately reflect the threat as our customers encounter it, and as such the results may offer a false sense of security.</p>
<p>The internet has emerged as the <a title="Most Abused Attack Vector - TrendLabs" href="http://blog.trendmicro.com/most-abused-infection-vector/" target="_blank">most abused attack vector</a>, attacks are multi-variant, multi-protocol, distributed in source (botnets), often targeted in nature and can no longer be defeated by the pattern-matching techniques that have been at the core of security software for so long.</p>
<p>Traditional security product testing has mostly been conducted in an isolated lab environment with a selected list of malware and this does not allow modern security software to perform to the best of its abilities. Trend Micro uses the internet based capabilities of the <a title="Trend Micro Smart Protection Network" href="http://uk.trendmicro.com/uk/technology/smart-protection-network/" target="_blank">Smart Protection Network</a> to provide real-time dynamic protection, focusing not just on the malicious file, but the malicious email and web site as well, creating smart correlated rule-sets designed to thwart malicious activity.</p>
<p>This is a threat-centric philosophy not a file-centric one. The aim is to break the chain of infection, or block the threat, as early as possible; looking first at the &#8220;exposure layer&#8221; or where threats come from and subsequently at the infection layer, or &#8220;what the threat does when it arrives&#8221;.</p>
<p><strong>Independent</strong> and importantly <strong>unsponsored</strong> testing, from <a title="NSS Labs | Independent security product testing and certification" href="http://nsslabs.com/" target="_blank">NSS Labs</a>, has just been released that underlines the importance of this new approach. In July and August of this year NSS Labs performed 17 days of 24&#215;7 testing on 9 consumer and 10 enterprise products.</p>
<p>Is Trend Micro&#8217;s cloud-client Smart Protection Network ready for prime time? I think the results speak for themselves&#8230;</p>
<div id="attachment_1383" class="wp-caption alignleft" style="width: 518px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/09/catch-rate.png"><img class="size-full wp-image-1383  " title="NSS Labs Consumer Report, September 2009" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/09/catch-rate.png" alt="NSS Labs Consumer Report, September 2009" width="508" height="227" /></a><p class="wp-caption-text">&quot;Trend Micro achieved the best download and execution protection with 96.4% overall&quot; - Source: NSS Labs Consumer Report, September 2009</p></div>
<div id="attachment_1384" class="wp-caption alignleft" style="width: 571px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/09/over-time.png"><img class="size-full wp-image-1384" title="NSS Labs Consumer Report, September 2009" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/09/over-time.png" alt="NSS Labs Consumer Report, September 2009" width="510" height="279" /></a><p class="wp-caption-text">NSS Labs Consumer Report, September 2009</p></div>
<div id="attachment_1385" class="wp-caption alignleft" style="width: 585px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/09/time-to-block.png"><img class="size-full wp-image-1385" title="NSS Labs Consumer Report, September 2009" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/09/time-to-block.png" alt="NSS Labs Consumer Report, September 2009" width="510" height="235" /></a><p class="wp-caption-text">NSS Labs Consumer Report, September 2009</p></div>
<p>Download the full reports from NSS Labs <a title="Anti-malware Test Report of endpoint products" href="http://nsslabs.com/reprints/9b/EndpointProtection-3Q2009" target="_blank">here</a></p>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/in-security-reputation-is-key/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
