Jump to content

Coverage

Featured Coverage

Cyberthreats Evolve, Start-ups Responding

Dow Jones – VentureWire – Syndicated

"Everybody agrees that this is the right thing," said Mike Lloyd, chief technology officer of RedSeal Networks, which sponsored the survey in which some 64 percent of respondents said that continuous monitoring and the security metrics it provides will improve IT security status. 'This clearly is a technical problem.'"

Recent Coverage

2012

Is CIO Confidence on FISMA Compliance Waning?

Government Computer News – Hot Topics

"Everybody agrees that this is the right thing," said Dr. Mike Lloyd, chief technology officer at RedSeal Networks, with 64 percent of respondents saying that continuous monitoring and the security metrics it provides will improve IT security status. "This clearly is a technical problem."

Five Principles To Improve Your Security Monitoring

Dark Reading – Tech Center – Security monitoring

"Security is the absence of something, and that is hard to measure," said Dr. Mike Lloyd, chief technology officer at RedSeal Networks. "So what you have to measure is posture -- how far you are ahead of the next threat." Instead, companies should measure metrics that improve security, such as the number of vulnerabilities remediated. "The trick then is to make it quantifiable and repeatable," he says.

Symantec Source Code Scattered to the Winds

TechNewsWorld – Network Intrusions

"Anyone who faces risk due to assets in someone else's control needs to establish a yardstick that the outside entity can use to show they have taken due care," said Dr. Mike Lloyd, chief technology officer at RedSeal Networks. The yardstick needs to be quantifiable objectively, must maintain some privacy for the organization being studied, and "must actually measure security posture, not just busy-ness," Lloyd concluded.

Stratfor, Facebook Worm, Fujitsu Virus Lead Week's Security News

eWeek – IT Security & Network Security News

Security experts were more concerned about the fact that Symantec lost its data through no fault of its own, since the code was on a third-party server. "It is not enough to ensure you follow best practices; in an interconnected world, you have to worry about the security of other organizations," Dr. Mike Lloyd, CTO of RedSeal Networks, told eWEEK.

Hackers Claim Breach Of Norton Antivirus Source Code; Experts Say Claims Are Exaggerated

Dark Reading – Tech Centers – Attacks/Breaches

"It is not enough to ensure you follow best practices; in an interconnected world, you have to worry about the security of other organizations," said Dr. Mike Lloyd, chief technology officer at RedSeal Networks. "Your business partners and strategic customers may be friendly, but they are not going to expose specifics to you about how well they protect themselves."

Security roundup: DOD revving up cyber-defense; Microsoft to have big January Patch Tuesday

PCAdvisor – News – Security

However, Mike Lloyd, chief technology officer at RedSeal Networks, points out the breach does raises questions about addressing security of your own corporate data in the networks of business partners and others. "The fact that Symantec suffered a breach due to lax protections in someone else's network is a significant wake-up call," he said.

Symantec Source Code Theft: Threat is Low to Current Products, Vendor Says

SearchSecurity – Information Security Threats – Emerging Threats

It's difficult for organizations to "understand the risk of a network you cannot see," said Mike Lloyd, CTO of Santa Clara, Calif.-based vendor RedSeal Networks. "As we steadily lose control of our own critical assets, and as attackers increasingly automate their attacks, we will need more baselines like this so that one organization can show another that it is well run."

Pessimism over FISMA Deadline Starts at the Top, Survey Finds

Government Computer News – Most Popular Articles

"Other companies to watch in this sector include website vulnerability company WhiteHat Security Inc. and RedSeal Networks Inc. which combines vulnerability data with network access data to provide a picture of the overall health of a network, rather than pinpointing particular holes."

2011

Agencies Struggle with Continuous Monitoring Mandate

Federal News Radio – CyberSecurity Stories – CyberSecurity News

"People are aware of the objectives, but when you map it down to practical technical concerns, people don't even agree on which technologies they will do the continuous monitoring in," said Mike Lloyd, CTO of RedSeal Networks. "There doesn't seem to be agreement that what we need to do is get, what those with a military background would call, situational awareness. We understand we need the situational awareness, but it is not a well settled question how to do that. These environments are extremely complex."

7 Housekeeping Duties For Better Database Security In 2012

Dark Reading - Tech Center - Database Security

"The databases that exist today have ultimately been designed to allow the easiest access from a multitude of devices and places. In many people's minds, they think you need to access a server with an application running on that, and that there is a measure of safety for the data sitting underneath the application because the application is secure," says Dr. Mike Lloyd, CTO of RedSeal Systems. "But your database is sitting out there, and, in many cases, when it came out of the box, it came configured to be connected to the Internet."

Hackers Stole Emails From Employees in Chamber of Commerce Breach

eWeek - IT Security & Network Security News

Modern IT infrastructure can be very "porous" and it's difficult for security teams to "understand it all," Mike Lloyd, CTO of RedSeal Networks, told eWEEK. The Journal report highlighted "significant out-bound holes" as it appears the infiltrators were able to "exfiltrate" the data they found, Lloyd said. Most organizations build some defenses against in-bound attacks, but very few effectively know how to control out-bound traffic, he said.

Power Grid Cybersecurity: Who's In Charge?

TechNewsWorld - Security - CyberSecurity

"When it came to protecting clients in a number of instances, the advice from vendors was to unplug the SCADA solution from anything connected to the Internet or any public network," said Parveen Jain, President and CEO of RedSeal Networks. Still, "it's a big problem where you have old systems, sometimes unresponsive vendors, limited resources and yet [a technology that's] a tremendous source of risk to almost everyone."

Study: Most Federal Agencies Uncertain About Meeting FISMA Security Monitoring Deadlines

Dark Reading - Tech Center - Security Monitoring

"Interestingly, the senior people that we surveyed -- the people who have the broadest view of the problem -- were the most pessimistic," says Mike Lloyd, CTO at RedSeal, which makes security monitoring solutions. "The people who can see the whole picture are realizing how difficult continuous monitoring is and how much more is still to be done."

RedSeal Nabs Insider Round To Ward Off Network Hackers

Dow Jones - VentureWire - Top Stories

"If you look at (vendors like) McAfee or Symantec, they provide medicines or prescriptions, while we are a full health check," Jain said. "We conduct a CAT scan or a blood test and tell customers the best way to deploy technology or medications for the problems they have. We give them this intelligence before the bad guys can get it."

RedSeal Networks Raises $10 Million in Funding

Wall Street Journal - VentureWire - Daily Start-Up

RedSeal Networks has raised $10 million in additional funding from insiders to help companies and government agencies protect their networks against hackers, VentureWire has learned.

RedSeal Networks Raises $10 Million from Investors

TMCnet - Feature - Security

"RedSeal is one of the most strategic and influential providers on the global security market based on its ability to solve the most acute challenges faced by every large enterprise security organization today, complexity and change," Ray Rothrock, chairman and Partner of Venrock, said. "The constant evolution of security infrastructure makes it nearly impossible for even the best professionals in any organization to maintain the visibility necessary to ensure compliance and critical asset protection, or measure their progress over time."

RedSeal Networks Upgrades Security Intelligence Software Offering

Network Computing - Tech Center - WAN Security

"It's a count of activity, of all the processes that your people run that they record. How many times did you change the firewall? How many patches did you deploy? How many times did you update your antivirus signatures?" says Mike Lloyd, CTO for RedSeal. "The problem with this approach is that you're measuring your busy-ness, not your business."

Despite Stiffer Reporting Requirements Many Agencies Still Slow To Implement Continuous Monitoring

Dark Reading - Tech Center: Compliance

"The move to monthly reporting was [former federal CIO] Vivek Kundra's effort to make it impossible to do security reporting as a bureaucratic exercise," says Mike Lloyd, chief scientist at RedSeal Systems, which makes security monitoring tools. "If you're doing it monthly, you can't do it with people pushing paper. He was trying to make reporting difficult enough to force agencies to move to automation."

Security Teams Left in the Dark by Current Technologies and Practices

Tech Herald - Security

Can anyone be blamed for feeling like this? It seems like there is a new breach or incident reported in the news each week. Yet, most of the automated attacks are preventable. Technologies and policies that assess code development, user and process enforcement, and traffic analysis are all helpful when addressing these types of threats.

Many Security Pros In The Dark About Their Own Environments, Study Says

Dark Reading - Tech Center: Security Monitoring

"On the one hand, it shows that, as an industry, we are growing up -- we're willing to admit we don't have all the answers," said RedSeal CTO Dr. Mike Lloyd. "On the other hand, it also shows that it's time for many organizations to wake up and smell the coffee -- they don't have some of the information they need to build a comprehensive defense."

You Just Can't Win When The Bad Guys Have Cooler Toys

CSO - Salted Hash Blog

"Consistent application of network security controls across even medium sized networks has transcended human ability," RedSeal CTO Dr. Mike Lloyd said. "For many years there's been the notion of an arms race between IT security professionals and attackers; what this survey proves is that the good guys understand they're facing a truly daunting task to keep up."

Sound Database Security Starts With Segmentation

Dark Reading - Tech Center: Database Security

"If you cannot keep the "crown jewel" servers up to the minute with the latest patches, then you have to put these most critical assets inside a "zone" to defend them," said Dr. Mike Lloyd, CTO of RedSeal Systems. "This can be called the 'Boy in the Bubble' security model -- you have to secure these most sensitive machines, using an internal perimeter because patching frequently isn't an option."

Unifying Compliance Initiatives To Make Budgets Last

Dark Reading - Tech Center: Compliance

"Of course the response to that is to unify your controls. Look at the set of audits you have in place, about what they have in common, pass that once, and use the same report over and over," says Dr. Mike Lloyd, CTO of RedSeal Systems. "This doesn't come cheap, it takes effort to do this but it can be done."

Web-Searchable Databases An Increasing Security Risk

Dark Reading - Tech Center: Database Security

"Blaming Google for this is really getting it all backwards," said Dr. Mike Lloyd, chief technology officer at RedSeal Systems. "Google just makes it clear that there is a problem. If you left the door unlocked on a store room for years and then Google Maps came along and put a photograph showing there was no lock on the door, the fact that the photograph went up isn't the problem. The problem was that the door was unlocked for years."

Hacking exposes large caches of personal data

USA Today - Technology Live Blog

"With the addition of indexing data that is accessible via FTP, hackers can now identify wide-open FTP sites that may contain sensitive data or can be used to leapfrog to other machines on the company's internal network," says Tom Rabaut, RedSeal analyst. "Also, Google offers the ability to restrict searches to a single domain which will make it easier for hackers to limit their data mining to only target companies."

RedSeal Systems Names Parveen Jain as CEO

Security Week - IT Security News Headlines

"Security professionals in organizations of all sizes are tasked to defend against escalating threats despite shrinking budgets. Addressing the complexity of today's networks and attacks requires the intelligence and operational insights that RedSeal uniquely delivers, along with the opportunity to optimize security spending," said Ray Rothrock, Chairman of RedSeal's Board of Directors. "Parveen will drive RedSeal to even greater success by providing organizations with the products they need to improve their network defenses and prevent the data breaches that dominate today's headlines."

Enemy At The Loading Dock: Defending Your Enterprise From Threats In The Supply Chain

Dark Reading - Cover Story

"It's been about: I need to connect to this business partner, then that business partner, then that business partner, and then all the sudden, your great castle of defenses has a whole wall missing, because you have this wide path out to all these extranet partners," said Dr. Mike Lloyd, Chief Scientist at RedSeal Systems.

Marine General Calls for Stronger Offense in U.S. Cyber-Security Strategy

eWeek - IT & Network Infrastructure News

"The government agencies haven't gotten to that point of awareness yet," said Major General John Casciano. "We keep saying the same old things, senior officials are giving the same old briefings and we are not further along solving the problem."

U.S. Congress Wants to Make Hacking Government Networks a Felony

eWeek - IT Security and Network Security

“The “emphasis on cyber-security by the Administration and Congress is commendable,” but progress has been practically non-existent, as the country hasn’t really moved forward towards enacting a comprehensive cyber-security law, said Major General John Casciano, an adviser on government security issues to security software producer RedSeal Systems. “We are not further along solving the problem than we were 20 or 25 years ago,” Casciano said.”

Continuous Monitoring Still A Long Way Off For The Feds

Dark Reading - Security Monitoring

"With a federal agency deadline for Federal Information Security Management Act (FISMA) compliance reporting through the new automated CyberScope tool already five months past, many security experts believe the government still has a long way to go in its quest to establish standards and implement continuous monitoring across the board."

Verizon Data Breach Report: Bad Guys Target Low-Hanging Fruit

Dark Reading - Protect The Business

"If you look at the [Verizon report], you see that most attacks were not targeted at a specific company, but were designed to find the enterprises that were most vulnerable. Ninety-seven percent of the breaches could have been avoided by using simple controls."

Searching For Security's Yardstick

Dark Reading - Security Monitoring

“If security is about prevention of leaks and attacks, then, what metrics should security departments show their bosses to prove that they are doing their jobs well?”

Common Security Mistakes Can Lead to Major Compromises

Threatpost - B-Sides talk by Dr. Mike Lloyd

“Security is hard and getting it right all the time is nearly impossible. But many of the mistakes that people make are simple, avoidable ones that can lead to serious intrusions and major network compromises.”

Telecom infrastructure faces daunting risks, TATA CSO says

CSO Online - Security and Risk

"Finding every potential configuration problem and vulnerability on our network is simply too big a job for human efforts alone. RedSeal took that whole process out of the equation and automated everything."

2010

Why Don't Firewalls Work?

Dark Reading - Security Management

"Even the best firewalls might fail an audit -- or get hacked -- if your enterprise doesn't follow proper change and configuration management practices."

Analysis: Cybersecurity's Double-Edged Sword

nextgov.com

"In the dynamic and ever-changing networks in which agencies operate, continuous monitoring simply can't be performed manually; it must be supported by software that provides powerful new weapons for defending against and thwarting attacks."

Does this audit make me look fat?

Federal News Radio

"It's that time of the year for audits under the Federal Information Security Management Act (FISMA). But will your audit make your agency appear bloated with risks?"

Security's Risk And Change Management Tools: Drawing A Picture Of Security Posture

Dark Reading - Security Monitoring

"It's a question that business executives love to ask -- and IT people hate to answer. "What's our security status?" If you've been around IT security for more than a week, then you know there's no definitive, empirical way to answer that question. Recently, however, some large enterprises have been getting a little closer to providing some metrics for security posture, using an emerging class of products that is coming into its own."

Firewall Operations Management

Network World Review

"Overall, we were most impressed with RedSeal and Skybox, which cover all the basics, plus have the added benefits of being able to support multiple vendor vulnerability scanning products, which can calculate the network's risk scores and run vulnerability analyses on your whole network."

SC Magazine Product Review - 5 Stars

RedSeal Network Advisor 4.1 & Vulnerability Advisor 4.1

"A very nice operational risk solution that has everything needed to take control of security posture management."

Navigating the fog of cyberwarfare

The Armed Forces Journal: The silent infiltrator, by Mike Lloyd

"The only hope for clearing the fog of cyberwarfare is to bring to bear automated systems that continuously monitor security posture and provide risk-based situational awareness to decision makers."

2009

Cyber Security Strategies

American Public Power Association

"The way to provide security is to put the whole system in a ‘bubble’ that restricts access, and then be very careful about who is allowed into the ‘bubble’."

In The Zone

Security Products Magazine

"A delicate balance exists in the retail world as businesses try to ensure easy and seamless customer experiences while maintaining high security."

First look: RedSeal

SANS Security Leadership Blog by Stephen Northcut

"I spent about an hour with Dr. Mike Lloyd, Chief Scientist at RedSeal today. It was fascinating."

Getting Firewalls to Play Nice With One Another

Tech News World

"People no longer access networks through one or two points. Now we have multiple DMZs (demilitarized zones), remote users, partners, access from around the world, etc. Everything is interconnected."

2008

M&A Surge Jeopardizes Sensitive Data

Bank Technology News

A wave of mergers makes protecting data all the more difficult. IT personnel are under incredible pressure to "parachute in" and act fast. They must assess the risk, do it quickly, often examining an unfamiliar structure.

New PCI Security Standards

E-Commerce Times

The Payment Card Industry (PCI) regulation changes that take affect October 1 will mean some additional work by IT departments — and some new spending.