Archive for category Information Security Management System

Healthcare & Security: A Hacker’s Perspective

by Renee Chronister, CEO, Parameter Security

Here’s another heart-stopper. The latest Ponemon Institute study reveals 60% of healthcare providers had more than 2 security breaches in the last year with the average breach costing them $2 million. Whoa! It then goes on to state that 70% of hospitals say protecting patient data is not a priority.

Healthcare providers in the Ponemon study also say they lack resources, trained personnel, policies and procedures to safeguard patient records. 58% claim they have little or no confidence in their ability to protect records in their possession. Forget WikiLeaks, as a hacker, this is music to my ears.

So what this really means for healthcare is that something has got to change. Specifically, the mindset that data security is not a priority and that all I have to be is HIPAA compliant to be secure. Well, I hate to be the bearer of bad news but I can’t tell you how many times I’ve hacked HIPAA compliant healthcare providers but I guess telling your patients, personnel and anyone else affected by the data breach that “I was HIPAA compliant” is better than “Data security isn’t a priority” but I’m guessing that will still go over like a lead balloon.

Read the rest of this entry »

Tags: , , , , , , , , , , , , , ,

Two factor authentication

What it is, what are the solutions

Today, banks providing internet banking facilities are looking for implementing or have already implemented two factor authentications. This has been done by either identifying risks by the banks themselves or has been mandated by the regulatory authorities. Whatever has initiated this, it is more important to understand what a two factor authentication is, what are the business requirements and how is it going to impact the customers. Read the rest of this entry »

Tags: , , , , ,

CISF Security at Infosys

In the recent news Infosys becomes the first private company to get CISF security. I have also been reading in yet another blog about a organization conducting mocks drills for terrorist’s attacks. It is quite interesting to see that organizations are now taking security as a prime concern. As mentioned in my previous blog about frisking of VIP’s at airports, the exception mentioned there is an age old rule that was implemented when terrorism was a not major concern.

Read the rest of this entry »

Tags: , , , ,