<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="http://feeds.feedblitz.com/feedblitz_rss.xslt"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	 xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">
<channel>
	<title>isrisk.net</title>
	<atom:link href="http://www.isrisk.net/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.isrisk.net</link>
	<description>Information security, risk &#38; governance</description>
	<lastBuildDate>Tue, 11 Dec 2012 08:49:46 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5</generator>
<image>
	<url>http://users.feedblitz.com/8cb84d89846f7bdf0dc3059b34d32e0e/isrisk_logo.jpg</url>
	<title>isrisk.net</title>
	<link>http://www.isrisk.net</link>
</image>
<item>
<feedburner:origLink>http://www.isrisk.net/2012/12/security-journalism-bears-repeating/</feedburner:origLink>
		<title>Security journalism: Bears repeating?</title>
		<link>http://feeds.feedblitz.com/~/36334987/0/infosecrisk~Security-journalism-Bears-repeating/</link>
		<comments>http://feeds.feedblitz.com/~/36334987/0/infosecrisk~Security-journalism-Bears-repeating/#comments</comments>
		<pubDate>Tue, 11 Dec 2012 08:49:46 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Comment]]></category>
		<category><![CDATA[Cyber Security & Cyber War]]></category>
		<guid isPermaLink="false">http://www.isrisk.net/?p=1490</guid>
		<description><![CDATA[If practicing information security can be a tough job, security journalism is aguably tougher. You&#8217;re often not an expert, yet to you have to translate between experts and the public, the public and experts, identify a sales pitch and yet still pull out an interesting story that&#8217;s worth the bits and bytes it&#8217;s written on. [...]]]>
&lt;div style=&quot;clear:both;padding-top:0.2em;&quot;&gt;&lt;a title=&quot;Add to Delicious&quot; href=&quot;http://feeds.feedblitz.com/_/3/36334987/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/delicious20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Digg This&quot; href=&quot;http://feeds.feedblitz.com/_/10/36334987/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/digg20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to FaceBook&quot; href=&quot;http://feeds.feedblitz.com/_/2/36334987/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fbshare20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Like on Facebook&quot; href=&quot;http://feeds.feedblitz.com/_/28/36334987/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fblike20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Share on Google+&quot; href=&quot;http://feeds.feedblitz.com/_/30/36334987/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/googleplus20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to LinkedIn&quot; href=&quot;http://feeds.feedblitz.com/_/16/36334987/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/linkedin20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Stumble This&quot; href=&quot;http://feeds.feedblitz.com/_/12/36334987/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/stumble20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Tweet This&quot; href=&quot;http://feeds.feedblitz.com/_/24/36334987/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/twitter20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by email&quot; href=&quot;http://feeds.feedblitz.com/_/19/36334987/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/email20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by RSS&quot; href=&quot;http://feeds.feedblitz.com/_/20/36334987/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/rss20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;View Comments&quot; href=&quot;http://www.isrisk.net/2012/12/security-journalism-bears-repeating/#comments&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/comments20.png&quot;&gt;&lt;/a&gt; &lt;a title=&quot;Follow Comments via RSS&quot; href=&quot;http://www.isrisk.net/2012/12/security-journalism-bears-repeating/feed/&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/commentsrss20.png&quot;&gt;&lt;/a&gt;&lt;h3 style=&quot;clear:left;padding-top:10px&quot;&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/12/case-cyberwar-fear-uncertainty-doubt/&quot;&gt;The case for cyberwar: Fear, Uncertainty and Doubt?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/looking-the-other-way/&quot;&gt;Looking the other way&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/understanding-users-tools/&quot;&gt;Understanding users &amp;#8211; part 2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;</description>
				<content:encoded><![CDATA[<div style="clear:left"><p>If practicing information security can be a tough job, security journalism is aguably tougher. You&#8217;re often not an expert, yet to you have to translate between experts and the public, the public and experts, identify a sales pitch and yet still pull out an interesting story that&#8217;s worth the bits and bytes it&#8217;s written on. Then repeat daily.</p>
<p>However, a healthy dose of cynicism is always in order. Take one article I was discussing the other day &#8211; <a href="http://feeds.feedblitz.com/~/t/0/0/infosecrisk/~www.scmagazineuk.com/cyber-security-strategy-to-introduce-cyber-territorial-army-drawing-on-industry-talent-and-skills/article/271034/">SC Magazine&#8217;s coverage of the UK &#8216;cyber reserve&#8217; forc</a>e. The problem isn&#8217;t the journalism, the problem is that in a specialist field the loudest voices will almost always be those with the biggest agendas.</p>
<p>In particular, reading takes some translation.</p>
<p>Francis Maude says his government is &#8220;&#8221;constantly examining new ways to harness and attract the talents of the cyber security specialists that are needed for critical areas of work&#8221;.</p>
<p><em>Translation? We really don&#8217;t know how to do this, and we&#8217;re still trying to figure it out. We just needed some progress for the annual report so we thought we&#8217;d shout about it anyway.</em></p>
<p>ISC2 says: “Funding new research centres and denoting ‘Centre of Excellence Status&#8217; to universities that are already delivering graduate courses in this space does not begin to address the skills shortage that we all acknowledge is adding to the threat. There are already 55 to 60 graduate level courses in the UK and most students don&#8217;t pursue an education at this level. More is needed at the undergraduate level where awareness of the career opportunities can help reach the numbers required.&#8221;</p>
<p><em>Translation: The government should send more introductory training so people can move on and do CISSP.</em></p>
<p>And Detica says: “When we look back in five years&#8217; time we will see that the government&#8217;s strategy has provided a catalyst for a series of innovative and useful activities, particularly around how industry can respond to and protect itself from cyber incidents – most notably the recent Cyber Incident Response Scheme announced by GCHQ. Nonetheless, there is still a long way to go before we can say that we are successfully countering cyber threats.”</p>
<p><em>Translation: It&#8217;s great that we&#8217;re one of a small number of companies to get privileged access to contracts through CIRS, but we still think there&#8217;s scope to be paid more money.</em></p>
<p>All these agendas are reasonable, understandable, and in the case if ISC2 clearly beneficial to security. The question then has to be &#8211; so what it not being said?</p>
<p>Well, that we don&#8217;t have a clue how to deliver this, for one. What it will do for another. And who will do it. And why.</p>
<p>All questions worthy of an answer.</p>
<Img align="left" border="0" height="1" width="1" style="border:0;float:left;margin:0;padding:0" hspace="0" src="http://feeds.feedblitz.com/~/i/36334987/0/infosecrisk">
</div>]]>
&lt;div style=&quot;clear:both;padding-top:0.2em;&quot;&gt;&lt;a title=&quot;Add to Delicious&quot; href=&quot;http://feeds.feedblitz.com/_/3/36334987/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/delicious20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Digg This&quot; href=&quot;http://feeds.feedblitz.com/_/10/36334987/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/digg20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to FaceBook&quot; href=&quot;http://feeds.feedblitz.com/_/2/36334987/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fbshare20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Like on Facebook&quot; href=&quot;http://feeds.feedblitz.com/_/28/36334987/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fblike20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Share on Google+&quot; href=&quot;http://feeds.feedblitz.com/_/30/36334987/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/googleplus20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to LinkedIn&quot; href=&quot;http://feeds.feedblitz.com/_/16/36334987/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/linkedin20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Stumble This&quot; href=&quot;http://feeds.feedblitz.com/_/12/36334987/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/stumble20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Tweet This&quot; href=&quot;http://feeds.feedblitz.com/_/24/36334987/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/twitter20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by email&quot; href=&quot;http://feeds.feedblitz.com/_/19/36334987/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/email20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by RSS&quot; href=&quot;http://feeds.feedblitz.com/_/20/36334987/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/rss20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;View Comments&quot; href=&quot;http://www.isrisk.net/2012/12/security-journalism-bears-repeating/#comments&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/comments20.png&quot;&gt;&lt;/a&gt; &lt;a title=&quot;Follow Comments via RSS&quot; href=&quot;http://www.isrisk.net/2012/12/security-journalism-bears-repeating/feed/&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/commentsrss20.png&quot;&gt;&lt;/a&gt;&lt;h3 style=&quot;clear:left;padding-top:10px&quot;&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/12/case-cyberwar-fear-uncertainty-doubt/&quot;&gt;The case for cyberwar: Fear, Uncertainty and Doubt?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/looking-the-other-way/&quot;&gt;Looking the other way&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/understanding-users-tools/&quot;&gt;Understanding users &amp;#8211; part 2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;</content:encoded>
			<wfw:commentRss>http://feeds.feedblitz.com/~/36334987/0/infosecrisk~Security-journalism-Bears-repeating/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments></item>
<item>
<feedburner:origLink>http://www.isrisk.net/2012/12/case-cyberwar-fear-uncertainty-doubt/</feedburner:origLink>
		<title>The case for cyberwar: Fear, Uncertainty and Doubt?</title>
		<link>http://feeds.feedblitz.com/~/36143433/0/infosecrisk~The-case-for-cyberwar-Fear-Uncertainty-and-Doubt/</link>
		<comments>http://feeds.feedblitz.com/~/36143433/0/infosecrisk~The-case-for-cyberwar-Fear-Uncertainty-and-Doubt/#comments</comments>
		<pubDate>Tue, 04 Dec 2012 22:24:39 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Comment]]></category>
		<category><![CDATA[Cyber Security & Cyber War]]></category>
		<category><![CDATA[cyber war]]></category>
		<category><![CDATA[Fear]]></category>
		<category><![CDATA[features]]></category>
		<category><![CDATA[organisational change]]></category>
		<category><![CDATA[Uncertainty & Doubt]]></category>
		<guid isPermaLink="false">http://www.isrisk.net/?p=1483</guid>
		<description><![CDATA[Over the last few months, a consistent theme in the media has been the threat posed by Chinese security and network solutions. It&#8217;s unsurprising that the birth of China as a modern post industrial giant strikes fear into the hearts of many &#8211; particularly countries and companies who would see China, or it&#8217;s industry, as [...]]]>
&lt;div style=&quot;clear:both;padding-top:0.2em;&quot;&gt;&lt;a title=&quot;Add to Delicious&quot; href=&quot;http://feeds.feedblitz.com/_/3/36143433/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/delicious20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Digg This&quot; href=&quot;http://feeds.feedblitz.com/_/10/36143433/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/digg20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to FaceBook&quot; href=&quot;http://feeds.feedblitz.com/_/2/36143433/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fbshare20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Like on Facebook&quot; href=&quot;http://feeds.feedblitz.com/_/28/36143433/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fblike20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Share on Google+&quot; href=&quot;http://feeds.feedblitz.com/_/30/36143433/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/googleplus20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to LinkedIn&quot; href=&quot;http://feeds.feedblitz.com/_/16/36143433/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/linkedin20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Stumble This&quot; href=&quot;http://feeds.feedblitz.com/_/12/36143433/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/stumble20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Tweet This&quot; href=&quot;http://feeds.feedblitz.com/_/24/36143433/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/twitter20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by email&quot; href=&quot;http://feeds.feedblitz.com/_/19/36143433/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/email20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by RSS&quot; href=&quot;http://feeds.feedblitz.com/_/20/36143433/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/rss20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;View Comments&quot; href=&quot;http://www.isrisk.net/2012/12/case-cyberwar-fear-uncertainty-doubt/#comments&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/comments20.png&quot;&gt;&lt;/a&gt; &lt;a title=&quot;Follow Comments via RSS&quot; href=&quot;http://www.isrisk.net/2012/12/case-cyberwar-fear-uncertainty-doubt/feed/&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/commentsrss20.png&quot;&gt;&lt;/a&gt;&lt;h3 style=&quot;clear:left;padding-top:10px&quot;&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/12/security-journalism-bears-repeating/&quot;&gt;Security journalism: Bears repeating?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2011/12/information-security-profession/&quot;&gt;Why Information Security isn&amp;#8217;t a profession&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/looking-the-other-way/&quot;&gt;Looking the other way&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;</description>
				<content:encoded><![CDATA[<div style="clear:left"><p style="float:right; margin:0 0 10px 15px; width:240px;">
		<img src="http://www.isrisk.net/wp-content/uploads/2012/12/12617192_m.jpg" width="240" />
		</p><p>Over the last few months, a consistent theme in the media has been the threat posed by Chinese security and network solutions. It&#8217;s unsurprising that the birth of China as a modern post industrial giant strikes fear into the hearts of many &#8211; particularly countries and companies who would see China, or it&#8217;s industry, as a threat. It&#8217;s also entirely rational to assume that foreign agencies will use all the tricks in the book to obtain a national advantage &#8211; most countries have a long history of doing just that. Minus the trappings of 20th century world leadership, China may well be less reserved about it than others such as the USA or Britain.</p>
<p>There is no doubt whatsoever, that the Cyber Security threat has crept upon us quietly over the last decade, without being noticed.  Only in the last few years have International governments started to acknowledge the systematic nature of the threat and the serious focus it requires.</p>
<p>This is a fair and qualified justification for greater investment in the Cyber Security arena, for public debate, and for reprioritisation of national defence programmes &#8211; not for politicisation, but to serve a very real, tangible defence against what is now an ever present, and current threat.</p>
<p>However, the nature of current headlines makes it reasonable to conclude that too much of the current cyber security agenda is now being sold on Fear, Uncertainty and Doubt – the same ‘FUD’ that the Information Security profession has spent the last few decades trying to shed.</p>
<p>The furore around Huawei is a perfect example – by virtue of its nationality the company has been blocked from bidding for major contracts in several countries, and been subjected to such criticism from the US that picking a Chinese security supplier must now seem to many businesses like an act of treachery. There is no evidence to suggest that they have been anything but open about their technology, and no-one has yet demonstrated that their products demonstrate a threat. Could a rational caution be going too far and closing the door to technology that could offer a competitive advantage? With not all the facts in the public domain it&#8217;s hard to say for certain &#8211; but from the consumer media, it looks that way.</p>
<p>Certainly, any information security manager attempting to build a business case on the back of insubstantial evidence would get a less sympathetic hearing from a corporate board than the world&#8217;s press appears to be giving to current claims.</p>
<p>The worry remains that government agencies are playing on fears that often appear unfounded to the public, or at least unproven. By doing so, we may risk undermining the case for national cyber security when it most matters; just as selling FUD in business has made it harder to sell investment in security today.</p>
<p>Continuous low level espionage attempts have always taken place, and always will, and the only thing that has changed is the means, and ease, of doing it. That does not justify escalating espionage attacks to the status of ‘CyberWar’ simply because they are committed with computers, but nevertheless does need to acknowledge that some systems could, one day be leveraged to underpin Cyber Aggression against a designated target. To access this, we need a more mature debate that moves away from FUD and towards an evidence based approach.</p>
<p>What is required to address the underlying threat is not a focus on fear, but a consistent resolve across governments to build security into the national business model at every step. Unfortunately, this is not an exciting answer. Security, when it works, is like accountancy &#8211; invisible and boring. Responding to cyber threats does not require a global panic, but simply the building of security into how we all operate organisations and live our lives, and the development by governments of high expectations across both government and industry, combined with a security aware culture.</p>
<p>The current inability to protect against cyber threats will not be solved by vast central programmes and costly cyber-weapons; it may be solved by enforcing consistent expectations and by building security awareness and technical competence into primary school curriculums.</p>
<p>Certainly, it will not be solved by FUD.</p>
<Img align="left" border="0" height="1" width="1" style="border:0;float:left;margin:0;padding:0" hspace="0" src="http://feeds.feedblitz.com/~/i/36143433/0/infosecrisk">
</div>]]>
&lt;div style=&quot;clear:both;padding-top:0.2em;&quot;&gt;&lt;a title=&quot;Add to Delicious&quot; href=&quot;http://feeds.feedblitz.com/_/3/36143433/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/delicious20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Digg This&quot; href=&quot;http://feeds.feedblitz.com/_/10/36143433/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/digg20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to FaceBook&quot; href=&quot;http://feeds.feedblitz.com/_/2/36143433/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fbshare20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Like on Facebook&quot; href=&quot;http://feeds.feedblitz.com/_/28/36143433/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fblike20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Share on Google+&quot; href=&quot;http://feeds.feedblitz.com/_/30/36143433/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/googleplus20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to LinkedIn&quot; href=&quot;http://feeds.feedblitz.com/_/16/36143433/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/linkedin20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Stumble This&quot; href=&quot;http://feeds.feedblitz.com/_/12/36143433/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/stumble20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Tweet This&quot; href=&quot;http://feeds.feedblitz.com/_/24/36143433/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/twitter20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by email&quot; href=&quot;http://feeds.feedblitz.com/_/19/36143433/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/email20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by RSS&quot; href=&quot;http://feeds.feedblitz.com/_/20/36143433/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/rss20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;View Comments&quot; href=&quot;http://www.isrisk.net/2012/12/case-cyberwar-fear-uncertainty-doubt/#comments&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/comments20.png&quot;&gt;&lt;/a&gt; &lt;a title=&quot;Follow Comments via RSS&quot; href=&quot;http://www.isrisk.net/2012/12/case-cyberwar-fear-uncertainty-doubt/feed/&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/commentsrss20.png&quot;&gt;&lt;/a&gt;&lt;h3 style=&quot;clear:left;padding-top:10px&quot;&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/12/security-journalism-bears-repeating/&quot;&gt;Security journalism: Bears repeating?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2011/12/information-security-profession/&quot;&gt;Why Information Security isn&amp;#8217;t a profession&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/looking-the-other-way/&quot;&gt;Looking the other way&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;</content:encoded>
			<wfw:commentRss>http://feeds.feedblitz.com/~/36143433/0/infosecrisk~The-case-for-cyberwar-Fear-Uncertainty-and-Doubt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments></item>
<item>
<feedburner:origLink>http://www.isrisk.net/2012/04/security-risk-management-infosec2012-keynote/</feedburner:origLink>
		<title>The oxymoron of security and risk management #infosec12</title>
		<link>http://feeds.feedblitz.com/~/29973368/0/infosecrisk~The-oxymoron-of-security-and-risk-management-infosec/</link>
		<comments>http://feeds.feedblitz.com/~/29973368/0/infosecrisk~The-oxymoron-of-security-and-risk-management-infosec/#comments</comments>
		<pubDate>Sun, 22 Apr 2012 21:25:51 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Confidentiality]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[InfoSec2012]]></category>
		<category><![CDATA[risk]]></category>
		<guid isPermaLink="false">http://www.isrisk.net/?p=1444</guid>
		<description><![CDATA[Information Security exists to manage enterprise risk. Fact. There can be no disputing this simple point. Information Security does not exist to keep all information absolutely secure. It can&#8217;t, even if that was a good idea. Which, incidentally, it isn&#8217;t. Completely secure information is about as much use as that classic beginner&#8217;s programming challenge: &#8220;Design [...]]]>
&lt;div style=&quot;clear:both;padding-top:0.2em;&quot;&gt;&lt;a title=&quot;Add to Delicious&quot; href=&quot;http://feeds.feedblitz.com/_/3/29973368/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/delicious20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Digg This&quot; href=&quot;http://feeds.feedblitz.com/_/10/29973368/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/digg20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to FaceBook&quot; href=&quot;http://feeds.feedblitz.com/_/2/29973368/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fbshare20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Like on Facebook&quot; href=&quot;http://feeds.feedblitz.com/_/28/29973368/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fblike20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Share on Google+&quot; href=&quot;http://feeds.feedblitz.com/_/30/29973368/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/googleplus20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to LinkedIn&quot; href=&quot;http://feeds.feedblitz.com/_/16/29973368/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/linkedin20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Stumble This&quot; href=&quot;http://feeds.feedblitz.com/_/12/29973368/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/stumble20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Tweet This&quot; href=&quot;http://feeds.feedblitz.com/_/24/29973368/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/twitter20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by email&quot; href=&quot;http://feeds.feedblitz.com/_/19/29973368/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/email20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by RSS&quot; href=&quot;http://feeds.feedblitz.com/_/20/29973368/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/rss20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;View Comments&quot; href=&quot;http://www.isrisk.net/2012/04/security-risk-management-infosec2012-keynote/#comments&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/comments20.png&quot;&gt;&lt;/a&gt; &lt;a title=&quot;Follow Comments via RSS&quot; href=&quot;http://www.isrisk.net/2012/04/security-risk-management-infosec2012-keynote/feed/&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/commentsrss20.png&quot;&gt;&lt;/a&gt;&lt;h3 style=&quot;clear:left;padding-top:10px&quot;&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/understand-infosecurity-risk/&quot;&gt;When will we understand infosecurity risk?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/looking-the-other-way/&quot;&gt;Looking the other way&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/03/infosecurity-budgets-austerity/&quot;&gt;Austerity is here to stay&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;</description>
				<content:encoded><![CDATA[<div style="clear:left"><p style="float:right; margin:0 0 10px 15px; width:240px;">
		<img src="http://www.isrisk.net/wp-content/uploads/2012/04/t-Infosec-Europe-logo-rev.png" width="240" />
		</p><p><a href="http://feeds.feedblitz.com/~/t/0/0/infosecrisk/~www.infosec.co.uk/page.cfm/Action=Seminars/SeminarID=71"><img class="size-full wp-image-1445 alignright" title="t-Infosec-Europe-logo-rev" src="http://www.isrisk.net/wp-content/uploads/2012/04/t-Infosec-Europe-logo-rev.png" alt="" width="241" height="120" /></a>Information Security exists to manage enterprise risk. Fact.</p>
<p>There can be no disputing this simple point. Information Security does not exist to keep all information absolutely secure. It can&#8217;t, even if that was a good idea.</p>
<p>Which, incidentally, it isn&#8217;t.</p>
<p>Completely secure information is about as much use as that classic beginner&#8217;s programming challenge: &#8220;Design me a useful program with no inputs and outputs&#8221;. The answer of course is that it can&#8217;t be done. Information, like a computer program, has to do something useful.</p>
<p>Of course somewhere out there, someone is thinking that&#8217;s not true. OK, it&#8217;s not. You <em>can</em> have useless information (like this blog, that same person is thinking&#8230;), however in a business context if you have information you&#8217;re not using, it&#8217;s time to bin it. Information has to be useful or we might as well not have it. Fact.</p>
<p>So, if absolute security is an absolutely rotten idea, we must all be in it for something else. That&#8217;s risk management then &#8211; keeping information as secure as it&#8217;s sensible to do so whilst allowing the business to operate &#8211; even whilst <em>helping</em> the business to operate.</p>
<p>So, some questions:</p>
<ol>
<li>Why are we so bad at explaining the business consequences of security threats and vulnerabilities?</li>
<li>Why are so few security metrics risk orientated?</li>
<li>Why is security so often seen as a hindrance to achieving business objectives, rather than an enabler?</li>
<li>Why is information security theory and practice so divergent from operational risk theory and practice?</li>
<li>How do we fix it?</li>
<li>And finally, accepting that we can&#8217;t achieve perfect security, how do we deal with the fact that at some point, it will go wrong?</li>
</ol>
<p>If you&#8217;re interested in the answers, let me know when you find them. If you&#8217;re interested in discussing some of these issues, join me at <a href="http://feeds.feedblitz.com/~/t/0/0/infosecrisk/~www.infosec.co.uk/">InfoSecurity Europe</a> at Earls Court, London this Tuesday for the keynote debate &#8220;<a href="http://feeds.feedblitz.com/~/t/0/0/infosecrisk/~www.infosec.co.uk/page.cfm/Action=Seminars/SeminarID=71">RISK: Defining &#8216;Risk Management&#8217; &amp; What It Means In The Context Of Information Security</a>&#8221; with myself, Prof. Paul Dorey of the <a href="http://feeds.feedblitz.com/~/t/0/0/infosecrisk/~https://www.instisp.org/">IISP</a>, Boris Goncharov of G4S and Matthew Lord of Steria UK.</p>
<ul>
<li><a href="http://feeds.feedblitz.com/~/t/0/0/infosecrisk/~www.infosec.co.uk/page.cfm/Action=Seminars/SeminarID=71">RISK: Defining &#8216;Risk Management&#8217; &amp; What It Means In The Context Of Information Security, Keynote Theatre, 24th April 14.30 &#8211; 15.30</a></li>
</ul>
<Img align="left" border="0" height="1" width="1" style="border:0;float:left;margin:0;padding:0" hspace="0" src="http://feeds.feedblitz.com/~/i/29973368/0/infosecrisk">
</div>]]>
&lt;div style=&quot;clear:both;padding-top:0.2em;&quot;&gt;&lt;a title=&quot;Add to Delicious&quot; href=&quot;http://feeds.feedblitz.com/_/3/29973368/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/delicious20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Digg This&quot; href=&quot;http://feeds.feedblitz.com/_/10/29973368/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/digg20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to FaceBook&quot; href=&quot;http://feeds.feedblitz.com/_/2/29973368/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fbshare20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Like on Facebook&quot; href=&quot;http://feeds.feedblitz.com/_/28/29973368/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fblike20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Share on Google+&quot; href=&quot;http://feeds.feedblitz.com/_/30/29973368/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/googleplus20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to LinkedIn&quot; href=&quot;http://feeds.feedblitz.com/_/16/29973368/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/linkedin20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Stumble This&quot; href=&quot;http://feeds.feedblitz.com/_/12/29973368/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/stumble20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Tweet This&quot; href=&quot;http://feeds.feedblitz.com/_/24/29973368/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/twitter20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by email&quot; href=&quot;http://feeds.feedblitz.com/_/19/29973368/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/email20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by RSS&quot; href=&quot;http://feeds.feedblitz.com/_/20/29973368/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/rss20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;View Comments&quot; href=&quot;http://www.isrisk.net/2012/04/security-risk-management-infosec2012-keynote/#comments&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/comments20.png&quot;&gt;&lt;/a&gt; &lt;a title=&quot;Follow Comments via RSS&quot; href=&quot;http://www.isrisk.net/2012/04/security-risk-management-infosec2012-keynote/feed/&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/commentsrss20.png&quot;&gt;&lt;/a&gt;&lt;h3 style=&quot;clear:left;padding-top:10px&quot;&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/understand-infosecurity-risk/&quot;&gt;When will we understand infosecurity risk?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/looking-the-other-way/&quot;&gt;Looking the other way&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/03/infosecurity-budgets-austerity/&quot;&gt;Austerity is here to stay&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;</content:encoded>
			<wfw:commentRss>http://feeds.feedblitz.com/~/29973368/0/infosecrisk~The-oxymoron-of-security-and-risk-management-infosec/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments></item>
<item>
<feedburner:origLink>http://www.isrisk.net/2012/04/looking-the-other-way/</feedburner:origLink>
		<title>Looking the other way</title>
		<link>http://feeds.feedblitz.com/~/29919333/0/infosecrisk~Looking-the-other-way/</link>
		<comments>http://feeds.feedblitz.com/~/29919333/0/infosecrisk~Looking-the-other-way/#comments</comments>
		<pubDate>Tue, 17 Apr 2012 11:15:58 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Comment]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Human Behaviour & Social Engineering]]></category>
		<category><![CDATA[Risk]]></category>
		<guid isPermaLink="false">http://www.isrisk.net/?p=1371</guid>
		<description><![CDATA[Are we at risk of looking away and missing the action? Legal and regulatory pressure is risking turning security into a tick-box exercise. Boards rely on security professionals to deliver on corporate issues such as compliance without forgetting the underlying risks. Changes such as the European Commission proposals on Data Protection will only increase the [...]]]>
&lt;div style=&quot;clear:both;padding-top:0.2em;&quot;&gt;&lt;a title=&quot;Add to Delicious&quot; href=&quot;http://feeds.feedblitz.com/_/3/29919333/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/delicious20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Digg This&quot; href=&quot;http://feeds.feedblitz.com/_/10/29919333/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/digg20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to FaceBook&quot; href=&quot;http://feeds.feedblitz.com/_/2/29919333/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fbshare20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Like on Facebook&quot; href=&quot;http://feeds.feedblitz.com/_/28/29919333/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fblike20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Share on Google+&quot; href=&quot;http://feeds.feedblitz.com/_/30/29919333/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/googleplus20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to LinkedIn&quot; href=&quot;http://feeds.feedblitz.com/_/16/29919333/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/linkedin20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Stumble This&quot; href=&quot;http://feeds.feedblitz.com/_/12/29919333/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/stumble20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Tweet This&quot; href=&quot;http://feeds.feedblitz.com/_/24/29919333/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/twitter20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by email&quot; href=&quot;http://feeds.feedblitz.com/_/19/29919333/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/email20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by RSS&quot; href=&quot;http://feeds.feedblitz.com/_/20/29919333/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/rss20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;View Comments&quot; href=&quot;http://www.isrisk.net/2012/04/looking-the-other-way/#comments&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/comments20.png&quot;&gt;&lt;/a&gt; &lt;a title=&quot;Follow Comments via RSS&quot; href=&quot;http://www.isrisk.net/2012/04/looking-the-other-way/feed/&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/commentsrss20.png&quot;&gt;&lt;/a&gt;&lt;h3 style=&quot;clear:left;padding-top:10px&quot;&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/understanding-users-tools/&quot;&gt;Understanding users &amp;#8211; part 2&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/understanding-system-users/&quot;&gt;Know your users, know yourself&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/12/security-journalism-bears-repeating/&quot;&gt;Security journalism: Bears repeating?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;</description>
				<content:encoded><![CDATA[<div style="clear:left"><p>Are we at risk of looking away and missing the action?</p>
<p>Legal and regulatory pressure is risking turning security into a tick-box exercise. Boards rely on security professionals to deliver on corporate issues such as compliance without forgetting the underlying risks. Changes such as the European Commission proposals on Data Protection will only increase the focus on regulatory risk. From a security standpoint, it’s the wrong focus.</p>
<p>If we’re actually going to reduce data loss incidents we need to change the way people behave. That’s about convincing directors that security isn’t just a compliance issue, which will be hard to do when compliance is the easiest way to build a business case for investment.  It also means getting beyond ‘tick box’ awareness exercises and influencing corporate culture in order to embed security into the way staff think on the job.</p>
<p>A shame then that so much of the current focus is on legislation.</p>
<Img align="left" border="0" height="1" width="1" style="border:0;float:left;margin:0;padding:0" hspace="0" src="http://feeds.feedblitz.com/~/i/29919333/0/infosecrisk">
</div>]]>
&lt;div style=&quot;clear:both;padding-top:0.2em;&quot;&gt;&lt;a title=&quot;Add to Delicious&quot; href=&quot;http://feeds.feedblitz.com/_/3/29919333/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/delicious20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Digg This&quot; href=&quot;http://feeds.feedblitz.com/_/10/29919333/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/digg20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to FaceBook&quot; href=&quot;http://feeds.feedblitz.com/_/2/29919333/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fbshare20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Like on Facebook&quot; href=&quot;http://feeds.feedblitz.com/_/28/29919333/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fblike20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Share on Google+&quot; href=&quot;http://feeds.feedblitz.com/_/30/29919333/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/googleplus20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to LinkedIn&quot; href=&quot;http://feeds.feedblitz.com/_/16/29919333/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/linkedin20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Stumble This&quot; href=&quot;http://feeds.feedblitz.com/_/12/29919333/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/stumble20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Tweet This&quot; href=&quot;http://feeds.feedblitz.com/_/24/29919333/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/twitter20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by email&quot; href=&quot;http://feeds.feedblitz.com/_/19/29919333/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/email20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by RSS&quot; href=&quot;http://feeds.feedblitz.com/_/20/29919333/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/rss20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;View Comments&quot; href=&quot;http://www.isrisk.net/2012/04/looking-the-other-way/#comments&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/comments20.png&quot;&gt;&lt;/a&gt; &lt;a title=&quot;Follow Comments via RSS&quot; href=&quot;http://www.isrisk.net/2012/04/looking-the-other-way/feed/&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/commentsrss20.png&quot;&gt;&lt;/a&gt;&lt;h3 style=&quot;clear:left;padding-top:10px&quot;&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/understanding-users-tools/&quot;&gt;Understanding users &amp;#8211; part 2&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/understanding-system-users/&quot;&gt;Know your users, know yourself&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/12/security-journalism-bears-repeating/&quot;&gt;Security journalism: Bears repeating?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;</content:encoded>
			<wfw:commentRss>http://feeds.feedblitz.com/~/29919333/0/infosecrisk~Looking-the-other-way/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments></item>
<item>
<feedburner:origLink>http://www.isrisk.net/2012/04/understanding-users-tools/</feedburner:origLink>
		<title>Understanding users &#8211; part 2</title>
		<link>http://feeds.feedblitz.com/~/29880442/0/infosecrisk~Understanding-users-part/</link>
		<comments>http://feeds.feedblitz.com/~/29880442/0/infosecrisk~Understanding-users-part/#comments</comments>
		<pubDate>Fri, 13 Apr 2012 11:09:54 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Comment]]></category>
		<category><![CDATA[Human Behaviour & Social Engineering]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[user behaviour]]></category>
		<guid isPermaLink="false">http://www.isrisk.net/?p=1368</guid>
		<description><![CDATA[A fe days ago I suggested that understanding a user base starts with ourselves. Of course, that doesn&#8217;t mean ignoring tools that allow you to build on that understanding, after all, politicians are customers of the state but still use polling every day. Fortunately, there is no shortage of good tools available to bring security [...]]]>
&lt;div style=&quot;clear:both;padding-top:0.2em;&quot;&gt;&lt;a title=&quot;Add to Delicious&quot; href=&quot;http://feeds.feedblitz.com/_/3/29880442/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/delicious20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Digg This&quot; href=&quot;http://feeds.feedblitz.com/_/10/29880442/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/digg20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to FaceBook&quot; href=&quot;http://feeds.feedblitz.com/_/2/29880442/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fbshare20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Like on Facebook&quot; href=&quot;http://feeds.feedblitz.com/_/28/29880442/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fblike20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Share on Google+&quot; href=&quot;http://feeds.feedblitz.com/_/30/29880442/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/googleplus20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to LinkedIn&quot; href=&quot;http://feeds.feedblitz.com/_/16/29880442/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/linkedin20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Stumble This&quot; href=&quot;http://feeds.feedblitz.com/_/12/29880442/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/stumble20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Tweet This&quot; href=&quot;http://feeds.feedblitz.com/_/24/29880442/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/twitter20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by email&quot; href=&quot;http://feeds.feedblitz.com/_/19/29880442/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/email20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by RSS&quot; href=&quot;http://feeds.feedblitz.com/_/20/29880442/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/rss20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;View Comments&quot; href=&quot;http://www.isrisk.net/2012/04/understanding-users-tools/#comments&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/comments20.png&quot;&gt;&lt;/a&gt; &lt;a title=&quot;Follow Comments via RSS&quot; href=&quot;http://www.isrisk.net/2012/04/understanding-users-tools/feed/&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/commentsrss20.png&quot;&gt;&lt;/a&gt;&lt;h3 style=&quot;clear:left;padding-top:10px&quot;&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/understanding-system-users/&quot;&gt;Know your users, know yourself&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/looking-the-other-way/&quot;&gt;Looking the other way&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/12/security-journalism-bears-repeating/&quot;&gt;Security journalism: Bears repeating?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;</description>
				<content:encoded><![CDATA[<div style="clear:left"><p>A fe days ago I suggested that <a href="http://feeds.feedblitz.com/~/t/0/0/infosecrisk/~www.isrisk.net/2012/04/understanding-system-users">understanding a user base starts with ourselves</a>. Of course, that doesn&#8217;t mean ignoring tools that allow you to build on that understanding, after all, politicians are customers of the state but still use polling every day.</p>
<p>Fortunately, there is no shortage of good tools available to bring security closer to the user base, and which ones you use will depend on the audience. Directors and non-executives might benefit from dedicated seminars to drive engagement with security risks facing the business. For most staff however, it’s about getting beyond annual CBT exercises and scary posters to actually engage with people in a two-way conversation – for example, offering a prize in exchange for feedback, or providing advice on home IT security that people will connect with. It means taking people’s ideas and concerns on board and providing feedback to show that you’ve listened.</p>
<Img align="left" border="0" height="1" width="1" style="border:0;float:left;margin:0;padding:0" hspace="0" src="http://feeds.feedblitz.com/~/i/29880442/0/infosecrisk">
</div>]]>
&lt;div style=&quot;clear:both;padding-top:0.2em;&quot;&gt;&lt;a title=&quot;Add to Delicious&quot; href=&quot;http://feeds.feedblitz.com/_/3/29880442/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/delicious20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Digg This&quot; href=&quot;http://feeds.feedblitz.com/_/10/29880442/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/digg20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to FaceBook&quot; href=&quot;http://feeds.feedblitz.com/_/2/29880442/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fbshare20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Like on Facebook&quot; href=&quot;http://feeds.feedblitz.com/_/28/29880442/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fblike20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Share on Google+&quot; href=&quot;http://feeds.feedblitz.com/_/30/29880442/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/googleplus20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to LinkedIn&quot; href=&quot;http://feeds.feedblitz.com/_/16/29880442/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/linkedin20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Stumble This&quot; href=&quot;http://feeds.feedblitz.com/_/12/29880442/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/stumble20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Tweet This&quot; href=&quot;http://feeds.feedblitz.com/_/24/29880442/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/twitter20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by email&quot; href=&quot;http://feeds.feedblitz.com/_/19/29880442/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/email20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by RSS&quot; href=&quot;http://feeds.feedblitz.com/_/20/29880442/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/rss20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;View Comments&quot; href=&quot;http://www.isrisk.net/2012/04/understanding-users-tools/#comments&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/comments20.png&quot;&gt;&lt;/a&gt; &lt;a title=&quot;Follow Comments via RSS&quot; href=&quot;http://www.isrisk.net/2012/04/understanding-users-tools/feed/&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/commentsrss20.png&quot;&gt;&lt;/a&gt;&lt;h3 style=&quot;clear:left;padding-top:10px&quot;&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/understanding-system-users/&quot;&gt;Know your users, know yourself&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/looking-the-other-way/&quot;&gt;Looking the other way&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/12/security-journalism-bears-repeating/&quot;&gt;Security journalism: Bears repeating?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;</content:encoded>
			<wfw:commentRss>http://feeds.feedblitz.com/~/29880442/0/infosecrisk~Understanding-users-part/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments></item>
<item>
<feedburner:origLink>http://www.isrisk.net/2012/04/understanding-system-users/</feedburner:origLink>
		<title>Know your users, know yourself</title>
		<link>http://feeds.feedblitz.com/~/29843344/0/infosecrisk~Know-your-users-know-yourself/</link>
		<comments>http://feeds.feedblitz.com/~/29843344/0/infosecrisk~Know-your-users-know-yourself/#comments</comments>
		<pubDate>Tue, 10 Apr 2012 11:04:18 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Comment]]></category>
		<category><![CDATA[Human Behaviour & Social Engineering]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[users]]></category>
		<guid isPermaLink="false">http://www.isrisk.net/?p=1365</guid>
		<description><![CDATA[Why does understanding users seem to require a science of its own? We have to remember that we’re users too, so the starting point is to understand our own needs and frustrations with the systems we use. If we’re irritated by inflexible systems, complex password requirements, an inability to use new technology in the office, [...]]]>
&lt;div style=&quot;clear:both;padding-top:0.2em;&quot;&gt;&lt;a title=&quot;Add to Delicious&quot; href=&quot;http://feeds.feedblitz.com/_/3/29843344/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/delicious20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Digg This&quot; href=&quot;http://feeds.feedblitz.com/_/10/29843344/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/digg20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to FaceBook&quot; href=&quot;http://feeds.feedblitz.com/_/2/29843344/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fbshare20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Like on Facebook&quot; href=&quot;http://feeds.feedblitz.com/_/28/29843344/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fblike20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Share on Google+&quot; href=&quot;http://feeds.feedblitz.com/_/30/29843344/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/googleplus20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to LinkedIn&quot; href=&quot;http://feeds.feedblitz.com/_/16/29843344/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/linkedin20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Stumble This&quot; href=&quot;http://feeds.feedblitz.com/_/12/29843344/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/stumble20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Tweet This&quot; href=&quot;http://feeds.feedblitz.com/_/24/29843344/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/twitter20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by email&quot; href=&quot;http://feeds.feedblitz.com/_/19/29843344/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/email20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by RSS&quot; href=&quot;http://feeds.feedblitz.com/_/20/29843344/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/rss20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;View Comments&quot; href=&quot;http://www.isrisk.net/2012/04/understanding-system-users/#comments&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/comments20.png&quot;&gt;&lt;/a&gt; &lt;a title=&quot;Follow Comments via RSS&quot; href=&quot;http://www.isrisk.net/2012/04/understanding-system-users/feed/&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/commentsrss20.png&quot;&gt;&lt;/a&gt;&lt;h3 style=&quot;clear:left;padding-top:10px&quot;&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/understanding-users-tools/&quot;&gt;Understanding users &amp;#8211; part 2&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/looking-the-other-way/&quot;&gt;Looking the other way&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/12/security-journalism-bears-repeating/&quot;&gt;Security journalism: Bears repeating?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;</description>
				<content:encoded><![CDATA[<div style="clear:left"><p>Why does understanding users seem to require a science of its own? We have to remember that we’re users too, so the starting point is to understand our own needs and frustrations with the systems we use. If we’re irritated by inflexible systems, complex password requirements, an inability to use new technology in the office, or network connectivity issues, then it’s a fair bet that our colleagues feel the same. The difference is that we are closer to the issues and understand why corporate security isn’t as responsive as we’d like it to be. Your average user doesn’t have a clue and frankly doesn’t care – they just want work systems to be as good as the ones they use at home. It’s not an unreasonable demand.</p>
<Img align="left" border="0" height="1" width="1" style="border:0;float:left;margin:0;padding:0" hspace="0" src="http://feeds.feedblitz.com/~/i/29843344/0/infosecrisk">
</div>]]>
&lt;div style=&quot;clear:both;padding-top:0.2em;&quot;&gt;&lt;a title=&quot;Add to Delicious&quot; href=&quot;http://feeds.feedblitz.com/_/3/29843344/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/delicious20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Digg This&quot; href=&quot;http://feeds.feedblitz.com/_/10/29843344/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/digg20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to FaceBook&quot; href=&quot;http://feeds.feedblitz.com/_/2/29843344/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fbshare20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Like on Facebook&quot; href=&quot;http://feeds.feedblitz.com/_/28/29843344/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fblike20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Share on Google+&quot; href=&quot;http://feeds.feedblitz.com/_/30/29843344/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/googleplus20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to LinkedIn&quot; href=&quot;http://feeds.feedblitz.com/_/16/29843344/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/linkedin20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Stumble This&quot; href=&quot;http://feeds.feedblitz.com/_/12/29843344/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/stumble20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Tweet This&quot; href=&quot;http://feeds.feedblitz.com/_/24/29843344/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/twitter20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by email&quot; href=&quot;http://feeds.feedblitz.com/_/19/29843344/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/email20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by RSS&quot; href=&quot;http://feeds.feedblitz.com/_/20/29843344/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/rss20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;View Comments&quot; href=&quot;http://www.isrisk.net/2012/04/understanding-system-users/#comments&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/comments20.png&quot;&gt;&lt;/a&gt; &lt;a title=&quot;Follow Comments via RSS&quot; href=&quot;http://www.isrisk.net/2012/04/understanding-system-users/feed/&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/commentsrss20.png&quot;&gt;&lt;/a&gt;&lt;h3 style=&quot;clear:left;padding-top:10px&quot;&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/understanding-users-tools/&quot;&gt;Understanding users &amp;#8211; part 2&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/looking-the-other-way/&quot;&gt;Looking the other way&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/12/security-journalism-bears-repeating/&quot;&gt;Security journalism: Bears repeating?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;</content:encoded>
			<wfw:commentRss>http://feeds.feedblitz.com/~/29843344/0/infosecrisk~Know-your-users-know-yourself/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments></item>
<item>
<feedburner:origLink>http://www.isrisk.net/2012/04/understand-infosecurity-risk/</feedburner:origLink>
		<title>When will we understand infosecurity risk?</title>
		<link>http://feeds.feedblitz.com/~/29773966/0/infosecrisk~When-will-we-understand-infosecurity-risk/</link>
		<comments>http://feeds.feedblitz.com/~/29773966/0/infosecrisk~When-will-we-understand-infosecurity-risk/#comments</comments>
		<pubDate>Tue, 03 Apr 2012 10:48:46 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Information Security Management]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[information risk management]]></category>
		<category><![CDATA[security metrics]]></category>
		<guid isPermaLink="false">http://www.isrisk.net/?p=1362</guid>
		<description><![CDATA[After all the focus of the last few decades, it should be surprising that information risk is still one of the least well understood risks most organisations have to deal with. Mature industries are used to looking at issues like capital, finance and operations as business risks, but information security is still often seen as [...]]]>
&lt;div style=&quot;clear:both;padding-top:0.2em;&quot;&gt;&lt;a title=&quot;Add to Delicious&quot; href=&quot;http://feeds.feedblitz.com/_/3/29773966/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/delicious20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Digg This&quot; href=&quot;http://feeds.feedblitz.com/_/10/29773966/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/digg20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to FaceBook&quot; href=&quot;http://feeds.feedblitz.com/_/2/29773966/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fbshare20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Like on Facebook&quot; href=&quot;http://feeds.feedblitz.com/_/28/29773966/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fblike20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Share on Google+&quot; href=&quot;http://feeds.feedblitz.com/_/30/29773966/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/googleplus20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to LinkedIn&quot; href=&quot;http://feeds.feedblitz.com/_/16/29773966/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/linkedin20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Stumble This&quot; href=&quot;http://feeds.feedblitz.com/_/12/29773966/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/stumble20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Tweet This&quot; href=&quot;http://feeds.feedblitz.com/_/24/29773966/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/twitter20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by email&quot; href=&quot;http://feeds.feedblitz.com/_/19/29773966/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/email20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by RSS&quot; href=&quot;http://feeds.feedblitz.com/_/20/29773966/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/rss20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;View Comments&quot; href=&quot;http://www.isrisk.net/2012/04/understand-infosecurity-risk/#comments&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/comments20.png&quot;&gt;&lt;/a&gt; &lt;a title=&quot;Follow Comments via RSS&quot; href=&quot;http://www.isrisk.net/2012/04/understand-infosecurity-risk/feed/&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/commentsrss20.png&quot;&gt;&lt;/a&gt;&lt;h3 style=&quot;clear:left;padding-top:10px&quot;&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/security-risk-management-infosec2012-keynote/&quot;&gt;The oxymoron of security and risk management #infosec12&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/looking-the-other-way/&quot;&gt;Looking the other way&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/03/infosecurity-budgets-austerity/&quot;&gt;Austerity is here to stay&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;</description>
				<content:encoded><![CDATA[<div style="clear:left"><p>After all the focus of the last few decades, it should be surprising that information risk is still one of the least well understood risks most organisations have to deal with. Mature industries are used to looking at issues like capital, finance and operations as business risks, but information security is still often seen as an issue for the IT department. Alternatively, it’s seen a regulatory issue with compliance, rather than customers, in the driving seat. Reputations take a long time to build but companies like Sony have proved that a security incident can cost you that reputation overnight. Despite this, few business understand what security breaches really cost.</p>
<p><a href="http://feeds.feedblitz.com/~/t/0/0/infosecrisk/~www.isrisk.net/2012/03/mcafee-cost-of-data-loss-incidents/">McAfee’s 2012 security report</a> suggests that incidents cost on average $0.5 &#8211; $1m, but also reveals that only a third of respondents had any idea what the cost was to them, and that a quarter of respondent’s didn’t feel they knew what security risks their controls were protecting them against. Until we can make an accurate quantitative assessment of security risk Boards and security professionals alike will find it hard to decide what level of resource to deploy, or how best to deploy it.</p>
<Img align="left" border="0" height="1" width="1" style="border:0;float:left;margin:0;padding:0" hspace="0" src="http://feeds.feedblitz.com/~/i/29773966/0/infosecrisk">
</div>]]>
&lt;div style=&quot;clear:both;padding-top:0.2em;&quot;&gt;&lt;a title=&quot;Add to Delicious&quot; href=&quot;http://feeds.feedblitz.com/_/3/29773966/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/delicious20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Digg This&quot; href=&quot;http://feeds.feedblitz.com/_/10/29773966/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/digg20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to FaceBook&quot; href=&quot;http://feeds.feedblitz.com/_/2/29773966/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fbshare20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Like on Facebook&quot; href=&quot;http://feeds.feedblitz.com/_/28/29773966/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fblike20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Share on Google+&quot; href=&quot;http://feeds.feedblitz.com/_/30/29773966/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/googleplus20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to LinkedIn&quot; href=&quot;http://feeds.feedblitz.com/_/16/29773966/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/linkedin20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Stumble This&quot; href=&quot;http://feeds.feedblitz.com/_/12/29773966/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/stumble20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Tweet This&quot; href=&quot;http://feeds.feedblitz.com/_/24/29773966/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/twitter20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by email&quot; href=&quot;http://feeds.feedblitz.com/_/19/29773966/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/email20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by RSS&quot; href=&quot;http://feeds.feedblitz.com/_/20/29773966/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/rss20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;View Comments&quot; href=&quot;http://www.isrisk.net/2012/04/understand-infosecurity-risk/#comments&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/comments20.png&quot;&gt;&lt;/a&gt; &lt;a title=&quot;Follow Comments via RSS&quot; href=&quot;http://www.isrisk.net/2012/04/understand-infosecurity-risk/feed/&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/commentsrss20.png&quot;&gt;&lt;/a&gt;&lt;h3 style=&quot;clear:left;padding-top:10px&quot;&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/security-risk-management-infosec2012-keynote/&quot;&gt;The oxymoron of security and risk management #infosec12&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/looking-the-other-way/&quot;&gt;Looking the other way&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/03/infosecurity-budgets-austerity/&quot;&gt;Austerity is here to stay&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;</content:encoded>
			<wfw:commentRss>http://feeds.feedblitz.com/~/29773966/0/infosecrisk~When-will-we-understand-infosecurity-risk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments></item>
<item>
<feedburner:origLink>http://www.isrisk.net/2012/03/infosecurity-budgets-austerity/</feedburner:origLink>
		<title>Austerity is here to stay</title>
		<link>http://feeds.feedblitz.com/~/29691876/0/infosecrisk~Austerity-is-here-to-stay/</link>
		<comments>http://feeds.feedblitz.com/~/29691876/0/infosecrisk~Austerity-is-here-to-stay/#comments</comments>
		<pubDate>Tue, 27 Mar 2012 10:22:02 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Comment]]></category>
		<category><![CDATA[Information Security Management]]></category>
		<category><![CDATA[Jobs and Careers]]></category>
		<category><![CDATA[budgets]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[recruitment]]></category>
		<guid isPermaLink="false">http://www.isrisk.net/?p=1360</guid>
		<description><![CDATA[Security departments can no longer count on increasing resources when organizations are stretched. Over the next few years, that stretch should become a little less. But will security feel it? Security risks still have to be addressed but the expectation is that organizations will save money at the same time. That puts the focus on [...]]]>
&lt;div style=&quot;clear:both;padding-top:0.2em;&quot;&gt;&lt;a title=&quot;Add to Delicious&quot; href=&quot;http://feeds.feedblitz.com/_/3/29691876/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/delicious20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Digg This&quot; href=&quot;http://feeds.feedblitz.com/_/10/29691876/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/digg20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to FaceBook&quot; href=&quot;http://feeds.feedblitz.com/_/2/29691876/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fbshare20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Like on Facebook&quot; href=&quot;http://feeds.feedblitz.com/_/28/29691876/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fblike20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Share on Google+&quot; href=&quot;http://feeds.feedblitz.com/_/30/29691876/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/googleplus20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to LinkedIn&quot; href=&quot;http://feeds.feedblitz.com/_/16/29691876/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/linkedin20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Stumble This&quot; href=&quot;http://feeds.feedblitz.com/_/12/29691876/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/stumble20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Tweet This&quot; href=&quot;http://feeds.feedblitz.com/_/24/29691876/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/twitter20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by email&quot; href=&quot;http://feeds.feedblitz.com/_/19/29691876/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/email20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by RSS&quot; href=&quot;http://feeds.feedblitz.com/_/20/29691876/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/rss20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;View Comments&quot; href=&quot;http://www.isrisk.net/2012/03/infosecurity-budgets-austerity/#comments&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/comments20.png&quot;&gt;&lt;/a&gt; &lt;a title=&quot;Follow Comments via RSS&quot; href=&quot;http://www.isrisk.net/2012/03/infosecurity-budgets-austerity/feed/&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/commentsrss20.png&quot;&gt;&lt;/a&gt;&lt;h3 style=&quot;clear:left;padding-top:10px&quot;&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/understand-infosecurity-risk/&quot;&gt;When will we understand infosecurity risk?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2011/12/information-security-profession/&quot;&gt;Why Information Security isn&amp;#8217;t a profession&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/12/security-journalism-bears-repeating/&quot;&gt;Security journalism: Bears repeating?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;</description>
				<content:encoded><![CDATA[<div style="clear:left"><p>Security departments can no longer count on increasing resources when organizations are stretched. Over the next few years, that stretch should become a little less. But will security feel it?</p>
<p>Security risks still have to be addressed but the expectation is that organizations will save money at the same time. That puts the focus on projects that reduce, for example, complexity and device proliferation in data centers, improve flexibility and support changes to business processes. Any investment in staffing or equipment needs a sound business case that demonstrated better risk management and bottom-line impact. Organisations now understand that security functions can deliver on this, so these expectations will be here to stay.</p>
<p>The poor economic conditions have also not made it any easier to recruit. There is still a skills shortage in the industry, particularly for technical specialists with a business perspective &#8211; in application security, for example. What has happened is that the number of companies looking to recruit has fallen, as has the number of people looking to move. Obtaining the budget may not get any easier, but at least recruitment should.</p>
<Img align="left" border="0" height="1" width="1" style="border:0;float:left;margin:0;padding:0" hspace="0" src="http://feeds.feedblitz.com/~/i/29691876/0/infosecrisk">
</div>]]>
&lt;div style=&quot;clear:both;padding-top:0.2em;&quot;&gt;&lt;a title=&quot;Add to Delicious&quot; href=&quot;http://feeds.feedblitz.com/_/3/29691876/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/delicious20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Digg This&quot; href=&quot;http://feeds.feedblitz.com/_/10/29691876/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/digg20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to FaceBook&quot; href=&quot;http://feeds.feedblitz.com/_/2/29691876/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fbshare20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Like on Facebook&quot; href=&quot;http://feeds.feedblitz.com/_/28/29691876/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fblike20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Share on Google+&quot; href=&quot;http://feeds.feedblitz.com/_/30/29691876/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/googleplus20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to LinkedIn&quot; href=&quot;http://feeds.feedblitz.com/_/16/29691876/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/linkedin20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Stumble This&quot; href=&quot;http://feeds.feedblitz.com/_/12/29691876/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/stumble20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Tweet This&quot; href=&quot;http://feeds.feedblitz.com/_/24/29691876/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/twitter20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by email&quot; href=&quot;http://feeds.feedblitz.com/_/19/29691876/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/email20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by RSS&quot; href=&quot;http://feeds.feedblitz.com/_/20/29691876/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/rss20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;View Comments&quot; href=&quot;http://www.isrisk.net/2012/03/infosecurity-budgets-austerity/#comments&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/comments20.png&quot;&gt;&lt;/a&gt; &lt;a title=&quot;Follow Comments via RSS&quot; href=&quot;http://www.isrisk.net/2012/03/infosecurity-budgets-austerity/feed/&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/commentsrss20.png&quot;&gt;&lt;/a&gt;&lt;h3 style=&quot;clear:left;padding-top:10px&quot;&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/understand-infosecurity-risk/&quot;&gt;When will we understand infosecurity risk?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2011/12/information-security-profession/&quot;&gt;Why Information Security isn&amp;#8217;t a profession&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/12/security-journalism-bears-repeating/&quot;&gt;Security journalism: Bears repeating?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;</content:encoded>
			<wfw:commentRss>http://feeds.feedblitz.com/~/29691876/0/infosecrisk~Austerity-is-here-to-stay/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments></item>
<item>
<feedburner:origLink>http://www.isrisk.net/2012/03/mcafee-cost-of-data-loss-incidents/</feedburner:origLink>
		<title>Knowing the unknown</title>
		<link>http://feeds.feedblitz.com/~/29475831/0/infosecrisk~Knowing-the-unknown/</link>
		<comments>http://feeds.feedblitz.com/~/29475831/0/infosecrisk~Knowing-the-unknown/#comments</comments>
		<pubDate>Wed, 07 Mar 2012 16:00:24 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Comment]]></category>
		<category><![CDATA[Goverance]]></category>
		<category><![CDATA[Profession]]></category>
		<category><![CDATA[data loss]]></category>
		<guid isPermaLink="false">http://www.isrisk.net/?p=1341</guid>
		<description><![CDATA[McAfee today released their report on the ‘state of security’ 2012. 19 pages of interesting reading is let down by one thing: the inevitably low quality of the quantitative information they obtained. Highlighted in their report is one critical statement that should, if it stacks up, demonstrate the value we in the information security profession [...]]]>
&lt;div style=&quot;clear:both;padding-top:0.2em;&quot;&gt;&lt;a title=&quot;Add to Delicious&quot; href=&quot;http://feeds.feedblitz.com/_/3/29475831/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/delicious20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Digg This&quot; href=&quot;http://feeds.feedblitz.com/_/10/29475831/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/digg20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to FaceBook&quot; href=&quot;http://feeds.feedblitz.com/_/2/29475831/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fbshare20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Like on Facebook&quot; href=&quot;http://feeds.feedblitz.com/_/28/29475831/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fblike20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Share on Google+&quot; href=&quot;http://feeds.feedblitz.com/_/30/29475831/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/googleplus20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to LinkedIn&quot; href=&quot;http://feeds.feedblitz.com/_/16/29475831/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/linkedin20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Stumble This&quot; href=&quot;http://feeds.feedblitz.com/_/12/29475831/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/stumble20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Tweet This&quot; href=&quot;http://feeds.feedblitz.com/_/24/29475831/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/twitter20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by email&quot; href=&quot;http://feeds.feedblitz.com/_/19/29475831/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/email20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by RSS&quot; href=&quot;http://feeds.feedblitz.com/_/20/29475831/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/rss20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;View Comments&quot; href=&quot;http://www.isrisk.net/2012/03/mcafee-cost-of-data-loss-incidents/#comments&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/comments20.png&quot;&gt;&lt;/a&gt; &lt;a title=&quot;Follow Comments via RSS&quot; href=&quot;http://www.isrisk.net/2012/03/mcafee-cost-of-data-loss-incidents/feed/&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/commentsrss20.png&quot;&gt;&lt;/a&gt;&amp;nbsp;
&lt;div style=&quot;clear:left;&quot;&gt;&lt;h3&gt;&lt;a href=&quot;http://www.isrisk.net/2012/03/mcafee-cost-of-data-loss-incidents/#comments&quot;&gt;Comments&lt;/a&gt;&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/03/mcafee-cost-of-data-loss-incidents/#comments&quot;&gt;Comments&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style=&quot;clear:left;padding-top:10px&quot;&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2011/12/information-security-profession/&quot;&gt;Why Information Security isn&amp;#8217;t a profession&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/12/security-journalism-bears-repeating/&quot;&gt;Security journalism: Bears repeating?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/12/case-cyberwar-fear-uncertainty-doubt/&quot;&gt;The case for cyberwar: Fear, Uncertainty and Doubt?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;</description>
				<content:encoded><![CDATA[<div style="clear:left"><p>McAfee today released their report on the <a href="http://feeds.feedblitz.com/~/t/0/0/infosecrisk/~www.mcafee.com/us/resources/white-papers/wp-state-of-security.pdf" target="_blank">‘state of security’ 2012</a>. 19 pages of interesting reading is let down by one thing: the inevitably low quality of the quantitative information they obtained.</p>
<p>Highlighted in their report is one critical statement that should, if it stacks up, demonstrate the value we in the information security profession bring to our organisations. The statement? That organisations with a mature security stance face costs of a data breach just half that of their less mature competitors. Instant value to the tune of $0.5m per incident.</p>
<p>Before we all pat ourselves on the back however, it’s worth taking a moment to consider the quality of their information, and the report gives us all the information we need to do that.</p>
<p>Firstly, it tells us that only around a third of respondents were confident they were able to assess this financial impact. When you consider that those companies who can quantity this are unlikely to have the same security profile as the other two thirds, you are already left wondering whether their calculation is of much merit.</p>
<p>Later in the report, McAfee reveal that again only around a third of respondents felt they were both aware of their security risks and protected against them (a worrying 38% said they were aware of the risks but didn’t feel they were protected against them, and a scary quarter of respondents felt adequately protected but didn’t know what their risks were).</p>
<p>What does this mean? Quite simply, that in addition to not really being able to assess how much incidents that were managed and detected actually cost, it’s quite likely that most incidents simply went under the radar because either the company didn’t know to look for them, or didn’t have the controls in place to detect them.</p>
<p>Overall, it’s a pretty fair reflection of where we are as an industry. But there’s nothing worse than misinformation, and so far attempts like this to quantify the costs of data loss and the value of security are sailing very close to the wind.</p>
<Img align="left" border="0" height="1" width="1" style="border:0;float:left;margin:0;padding:0" hspace="0" src="http://feeds.feedblitz.com/~/i/29475831/0/infosecrisk">
</div>]]>
&lt;div style=&quot;clear:both;padding-top:0.2em;&quot;&gt;&lt;a title=&quot;Add to Delicious&quot; href=&quot;http://feeds.feedblitz.com/_/3/29475831/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/delicious20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Digg This&quot; href=&quot;http://feeds.feedblitz.com/_/10/29475831/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/digg20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to FaceBook&quot; href=&quot;http://feeds.feedblitz.com/_/2/29475831/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fbshare20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Like on Facebook&quot; href=&quot;http://feeds.feedblitz.com/_/28/29475831/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fblike20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Share on Google+&quot; href=&quot;http://feeds.feedblitz.com/_/30/29475831/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/googleplus20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to LinkedIn&quot; href=&quot;http://feeds.feedblitz.com/_/16/29475831/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/linkedin20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Stumble This&quot; href=&quot;http://feeds.feedblitz.com/_/12/29475831/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/stumble20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Tweet This&quot; href=&quot;http://feeds.feedblitz.com/_/24/29475831/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/twitter20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by email&quot; href=&quot;http://feeds.feedblitz.com/_/19/29475831/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/email20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by RSS&quot; href=&quot;http://feeds.feedblitz.com/_/20/29475831/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/rss20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;View Comments&quot; href=&quot;http://www.isrisk.net/2012/03/mcafee-cost-of-data-loss-incidents/#comments&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/comments20.png&quot;&gt;&lt;/a&gt; &lt;a title=&quot;Follow Comments via RSS&quot; href=&quot;http://www.isrisk.net/2012/03/mcafee-cost-of-data-loss-incidents/feed/&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/commentsrss20.png&quot;&gt;&lt;/a&gt;&lt;h3 style=&quot;clear:left;padding-top:10px&quot;&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2011/12/information-security-profession/&quot;&gt;Why Information Security isn&amp;#8217;t a profession&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/12/security-journalism-bears-repeating/&quot;&gt;Security journalism: Bears repeating?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/12/case-cyberwar-fear-uncertainty-doubt/&quot;&gt;The case for cyberwar: Fear, Uncertainty and Doubt?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;</content:encoded>
			<wfw:commentRss>http://feeds.feedblitz.com/~/29475831/0/infosecrisk~Knowing-the-unknown/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments></item>
<item>
<feedburner:origLink>http://www.isrisk.net/2012/02/local-councils-fined-1m-information-commissioner/</feedburner:origLink>
		<title>Council data loss fines hit £1M</title>
		<link>http://feeds.feedblitz.com/~/29370952/0/infosecrisk~Council-data-loss-fines-hit-%c2%a3M/</link>
		<comments>http://feeds.feedblitz.com/~/29370952/0/infosecrisk~Council-data-loss-fines-hit-%c2%a3M/#comments</comments>
		<pubDate>Sun, 26 Feb 2012 09:07:29 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Confidentiality]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[Data Protection Act 1998]]></category>
		<category><![CDATA[features]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[local government]]></category>
		<category><![CDATA[Monetary penalty notices]]></category>
		<guid isPermaLink="false">http://www.isrisk.net/?p=1324</guid>
		<description><![CDATA[Monetary penalties for local authorities issued by the Information Commissioners&#8217; Office have officially hit £1m, isrisk.net is first to reveal. Our analysis of ICO penalties for local authorities (click to download pdf) confirms the total as £1.040m as of 15th February 2012 when the latest penalty was issued to Cheshire East Council. The eleven notices issued [...]]]>
&lt;div style=&quot;clear:both;padding-top:0.2em;&quot;&gt;&lt;a title=&quot;Add to Delicious&quot; href=&quot;http://feeds.feedblitz.com/_/3/29370952/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/delicious20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Digg This&quot; href=&quot;http://feeds.feedblitz.com/_/10/29370952/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/digg20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to FaceBook&quot; href=&quot;http://feeds.feedblitz.com/_/2/29370952/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fbshare20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Like on Facebook&quot; href=&quot;http://feeds.feedblitz.com/_/28/29370952/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fblike20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Share on Google+&quot; href=&quot;http://feeds.feedblitz.com/_/30/29370952/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/googleplus20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to LinkedIn&quot; href=&quot;http://feeds.feedblitz.com/_/16/29370952/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/linkedin20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Stumble This&quot; href=&quot;http://feeds.feedblitz.com/_/12/29370952/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/stumble20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Tweet This&quot; href=&quot;http://feeds.feedblitz.com/_/24/29370952/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/twitter20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by email&quot; href=&quot;http://feeds.feedblitz.com/_/19/29370952/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/email20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by RSS&quot; href=&quot;http://feeds.feedblitz.com/_/20/29370952/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/rss20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;View Comments&quot; href=&quot;http://www.isrisk.net/2012/02/local-councils-fined-1m-information-commissioner/#comments&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/comments20.png&quot;&gt;&lt;/a&gt; &lt;a title=&quot;Follow Comments via RSS&quot; href=&quot;http://www.isrisk.net/2012/02/local-councils-fined-1m-information-commissioner/feed/&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/commentsrss20.png&quot;&gt;&lt;/a&gt;&lt;h3 style=&quot;clear:left;padding-top:10px&quot;&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/12/case-cyberwar-fear-uncertainty-doubt/&quot;&gt;The case for cyberwar: Fear, Uncertainty and Doubt?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/security-risk-management-infosec2012-keynote/&quot;&gt;The oxymoron of security and risk management #infosec12&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/looking-the-other-way/&quot;&gt;Looking the other way&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;</description>
				<content:encoded><![CDATA[<div style="clear:left"><p style="float:right; margin:0 0 10px 15px; width:240px;">
		<img src="http://www.isrisk.net/wp-content/uploads/2012/02/Leeds_town-hall.jpg" width="240" />
		</p><p>Monetary penalties for local authorities issued by the Information Commissioners&#8217; Office have officially hit £1m, isrisk.net is first to reveal.</p>
<p>Our <a href="http://feeds.feedblitz.com/~/t/0/0/infosecrisk/~www.isrisk.net/wp-content/uploads/2012/02/ICO-penalties-for-local-authorities.pdf">analysis of ICO penalties for local authorities</a> (click to download pdf) confirms the total as £1.040m as of 15th February 2012 when the latest penalty was issued to Cheshire East Council.</p>
<p>The eleven notices issued covered the loss of at least 1,914 records to a total 730 unauthorised recipients.</p>
<p>The analysis reveals a number of interesting trends:</p>
<h3>Frequency</h3>
<p>Fines are becoming more frequent. During 2011 there were gaps of several months between fines, towards the end of last year and in the first two months of this year, penalties were issued every few weeks. We can expect many more penalties in 2012.</p>
<h3>Highly sensitive data</h3>
<p>All the penalty notices issued were for loss of highly sensitive data, specifically child or adult care records. Whether this reflects a conscious focus for the ICO or simply where the losses have taken  place is hard to say, however it is clear that the ICO are reserving their power to issue financial penalties for those cases where the information at risk is sensitive and the data subjects are vulnerable.</p>
<h3>Just one record lost is enough for a fine</h3>
<p>45% of penalties were issued for the loss of just one record. This calls in to question the common view that only the loss of multiple records would be of interest to the Commissioner. Clearly the Commissioner considers that even one record can justify a penalty where the data lost would have a signficant impact on the data subject.</p>
<h3>Data in transit</h3>
<p>Every single fine related to data in transit. Four were for email sent to the wrong recipients, five were for paper documents sent to the wrong person or address, one to a fax sent to the wrong number, two Ealing and Hounslow) for the loss of an unencrypted laptop, and one was caused by a Council officer leaving documents in a pub on the way home from work, None were the result of third parties obtaining access to Council networks, however whether that reflects a lack of interest by hackers or Councils&#8217; lack of capability to identify such attacks is a matter for speculation.</p>
<h3>Human error</h3>
<p>The most revealing aspect of these penalties however is that every single one was the result of human error. All could have been avoided if the individuals concerned had been properly trained and were conscious of their obligations. Equally, many could have been avoided if manual processes had been replaced with more efficient automated ones, or data sent in a more secure manner.</p>
<h2>Lessons for the future</h2>
<p>There is s strong message here for local authorities and other public sector bodies: securing your network is not going to be enough. Instead, the focus should be on investing in better processes and staff training and awareness.</p>
<p>The tokenistic approach many organisations have deployed in the past of annual refresher training on organisational policies does little to embed the importance of security in the minds of staff on a daily basis. Instead, Councils and others need to foster a security culture where everyone understands the contribution made by their activities.</p>
<p>Just as importantly however, the penalties reveal an opportunity to build a stronger business case for developing processes that are inherently more secure. There can be no excuse for sending bulk personal data be email, storing records on laptops rather than in enterprise systems, and sending highly sensitive data using obsolete and inefficient faxes.</p>
<p>Ultimately, we&#8217;re paying twice for these mistakes: once in high taxation driven by poor processes, and a second time in monetary penalties for data losses. The monetary penalties are, therefore, the tip of the iceberg.</p>
<p>Any local authority getting to grips with the process issues highlighted will surely make their budget savings and improve services at the same time.</p>
<p>You can download the <a href="http://feeds.feedblitz.com/~/t/0/0/infosecrisk/~www.isrisk.net/wp-content/uploads/2012/02/ICO-penalties-for-local-authorities.pdf">analysis of ICO penalties for local authorities</a> here.</p>
<Img align="left" border="0" height="1" width="1" style="border:0;float:left;margin:0;padding:0" hspace="0" src="http://feeds.feedblitz.com/~/i/29370952/0/infosecrisk">
</div>]]>
&lt;div style=&quot;clear:both;padding-top:0.2em;&quot;&gt;&lt;a title=&quot;Add to Delicious&quot; href=&quot;http://feeds.feedblitz.com/_/3/29370952/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/delicious20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Digg This&quot; href=&quot;http://feeds.feedblitz.com/_/10/29370952/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/digg20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to FaceBook&quot; href=&quot;http://feeds.feedblitz.com/_/2/29370952/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fbshare20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Like on Facebook&quot; href=&quot;http://feeds.feedblitz.com/_/28/29370952/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/fblike20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Share on Google+&quot; href=&quot;http://feeds.feedblitz.com/_/30/29370952/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/googleplus20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Add to LinkedIn&quot; href=&quot;http://feeds.feedblitz.com/_/16/29370952/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/linkedin20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Stumble This&quot; href=&quot;http://feeds.feedblitz.com/_/12/29370952/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/stumble20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Tweet This&quot; href=&quot;http://feeds.feedblitz.com/_/24/29370952/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/twitter20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by email&quot; href=&quot;http://feeds.feedblitz.com/_/19/29370952/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/email20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;Subscribe by RSS&quot; href=&quot;http://feeds.feedblitz.com/_/20/29370952/infosecrisk&quot;&gt;&lt;img height=&quot;20&quot; src=&quot;http://assets.feedblitz.com/i/rss20.png&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot;&gt;&lt;/a&gt;  &lt;a title=&quot;View Comments&quot; href=&quot;http://www.isrisk.net/2012/02/local-councils-fined-1m-information-commissioner/#comments&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/comments20.png&quot;&gt;&lt;/a&gt; &lt;a title=&quot;Follow Comments via RSS&quot; href=&quot;http://www.isrisk.net/2012/02/local-councils-fined-1m-information-commissioner/feed/&quot;&gt;&lt;img height=&quot;20&quot; style=&quot;border:0;float:left;margin:0px 3px 0px;padding:0&quot; src=&quot;http://assets.feedblitz.com/i/commentsrss20.png&quot;&gt;&lt;/a&gt;&lt;h3 style=&quot;clear:left;padding-top:10px&quot;&gt;Related Stories&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/12/case-cyberwar-fear-uncertainty-doubt/&quot;&gt;The case for cyberwar: Fear, Uncertainty and Doubt?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/security-risk-management-infosec2012-keynote/&quot;&gt;The oxymoron of security and risk management #infosec12&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.isrisk.net/2012/04/looking-the-other-way/&quot;&gt;Looking the other way&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;/div&gt;</content:encoded>
			<wfw:commentRss>http://feeds.feedblitz.com/~/29370952/0/infosecrisk~Council-data-loss-fines-hit-%c2%a3M/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments></item>
</channel></rss>

