HALOCK News
The latest HALOCK Updates
Get the scoop, read all the current cyber security news, our services and our team. Or read our latest articles on information security.
TECHOPEDIA – Industry experts discuss cybersecurity predictions for 2021.These are what they identified as likely issues facing enterprises and the IT professionals that must protect them. Measuring Reasonable Security (Duty of Care), Ransomware, Cybersecurity Training & Awareness, Email Vulnerability, Endpoint Protection. Featuring Chris Cronin, Erik Leach, Steve Lawn, Glenn Stout.
A working group of the Sedona Conference has proposed a solid answer to these questions. By its own description, the Sedona Conference is a nonpartisan, nonprofit research and educational institute dedicated to the advanced study of specific law and policy, including privacy and data security law. The Conference has just published a set of commentary on a reasonable security test. The paper is worth reading.
Spirion, a data protection and compliance company based in St. Petersburg, Fla., launched its Global Alliance Partner Program, for data security which spans software developers, technology providers, systems integrators and solution providers. Partners will “extend the functionality” of Spirion’s Data Privacy Management Framework, according to the company. Solution provider members of the program include GuidePoint Security and HALOCK Security Labs, while technology partners include ContextSpace, Seclore and Tonic.
Establishes technology and solution provider partner ecosystem committed to strengthening personal data protection through best-in-class solutions. “Our collaboration with Spirion is one of HALOCK’s most strategic partnerships designed to address some of the most complex challenges related to data protection in large enterprise environments,” said Terry Kurzynski, HALOCK Security Labs Founding Partner. “Our alliance with Spirion extends our reach into understanding, controlling, and protecting what’s most important to our clients, their sensitive data.”
Based on the Duty of Care Risk Analysis (DOCRA) that many regulatory bodies rely on to ensure that organizations are delivering reasonable risk management practices to protect their customers and vendors, the CIS RAM aligns with the CIS Controls specifically and uses a simplified risk statement to benchmark the level of risk associated and determine a viable safeguard to mitigate risk.
The Federal Trade Commission is seeking to ramp up mandated cybersecurity efforts for financial institutions by altering the Gramm-Leach-Bliley Act’s Safeguards Rule, which requires financial institutions to develop, implement and maintain a comprehensive information security program.
“People are not generally doing what we would consider risk assessments,” said Chris Cronin, a partner at HALOCK Security Labs. “Instead, they’ll have an auditor come in and run an audit.”
The Federal Trade Commission (FTC) released the final agenda for a July 13, 2020 virtual workshop that will seek input on proposed changes to the Gramm-Leach-Bliley Act’s Safeguards Rule, which requires financial institutions to develop, implement, and maintain a comprehensive information security program.
HALOCK partner will serve as a panelist during the 9:30am session: The Costs and Benefits of Information Security Programs.
“… tying in other risk measurements with cyber-risk makes good sense, if only to have everyone using similar models, methods, and/or lexicon for risk management… Perhaps best known among these are the NIST risk management resources, cited by many as a basic compliance checklist. There’s also the Center for Internet Security’s Risk Assessment Methodology (RAM), created by Halock Security Labs.”
via DARK READING
Penetration testers are the frontline witnesses on cyber threats and vulnerabilities. They continue to see the same weaknesses and vulnerabilities within the enterprises they examine. Below, is a list of recommendations for you to be aware of in the year ahead.
Chicago Tribune – HALOCK Security Labs is conducting an informative webinar to help establish ‘reasonable’ risk cybersecurity controls, based on the Duty of Care Risk Analysis (DoCRA) standard.
Do you know reasonable?
Enhance your security strategy to address your changing working environment and risk profile due to COVID-19. HALOCK is a trusted cyber security consulting firm and penetration testing company headquartered in Schaumburg, IL in the Chicago area servicing clients throughout the United States.
Insightful discussion with Chicagoland information security experts in Crain’s Roundtable.
A key method that was showcased at the event was the practice of ‘duty of care‘. That is, businesses should assess their security controls to ensure that all parties are protected from potential harm.
HALOCK Security Labs today announced that it has become a Champion of National Cybersecurity Awareness Month (NCSAM) 2018. It will be joining a growing global effort among businesses, government agencies, colleges and universities, associations, nonprofit organizations and individuals to promote the cyber security awareness of online safety and privacy. (more…)
“While accountability starts with the CEO and corporate board, cyber security is a shared responsibility across every function and level of an organization.” – article in Security Magazine. Read more on how information security professionals must be aligned when it comes to security safeguards.
Schaumburg firm HALOCK celebrates over 20 years as an information security firm at the annual outing at Arlington Park. This year is quite special, as HALOCK co-developed with CIS® (Center for Internet Security), CIS RAM, an information security risk assessment method that helps organizations implement and assess their security posture against the CIS Controls cyber security best practices.
The NetDiligence® CyberRisk Summit features leading experts in cyber security and cyber risk management participating in comprehensive panel discussions on hot topics, current issues and evolving trends in the cyber risk management industry. HALOCK partner Chris Cronin moderates an expert panel discussion on reasonable risk.
It was the right thing to do
My employer, HALOCK Security Labs, just gave away our highly valuable intellectual property. For years, we have been developing and improving a method for assessing cyber risk that acts as a universal translator for executives, regulators, judges, attorneys, and subject matter experts. The method, “Duty of Care Risk Analysis” has been very advantageous to us as we described our services to our clients.
CIS® recently released CIS RAM (Center for Internet Security Risk Assessment Method); CIS RAM is an information security risk assessment method that helps organizations implement and assess their security posture against the CIS Controls cybersecurity best practices. Developed by HALOCK Security Labs in partnership with CIS, CIS RAM provides three separate security approaches to support different levels of organizational capability.
A panel including Greg Johnson, Vice President and Assistant General Auditor of the Federal Reserve Bank and Chris Cronin, a partner in HALOCK Security Labs discussed the CIS Controls V7. Learn more about the CIS Controls and risk assessment method, CIS RAM.