Managing your network vulnerabilities and identifying the right vulnerability management processes can be complex. Whilst finding and prioritising vulnerabilities are the responsibility of the security leader, the speed at which these vulnerabilities are remediated is dependent on other people in your organisation. System architects and administrators, IT managers and system owners all play a part […]
About Mark Hofman
Mark Hofman is the Chief Technology Officer at Shearwater Solutions and has over 25 years’ experience in ICT Security. He has worked for both private industry and government and has provided a wide range of information security consulting services to numerous organisations, including the financial sector, private sector, and government organisations.
Mark is currently a certified instructor for the SANS Institute. He has had a number of publications, has trained and lectured internationally, and is a handler for the Internet Storm Center. Mark holds professional certifications, including CISSP, GIAC GCFW, CompTIA Security+ and BSI lead auditor accreditations.
Entries by Mark Hofman
As you may be aware the security issues relating to SSL and early TLS prompted the Payment Card Industry Security Standards Council (PCI SSC) to issue a new version of the Payment Card Industry Data Security Standard (PCI DSS) and supporting documents. This release v3.1 (April 2015) included a deadline for moving away from SSL […]
1- Background The Payment Card Industry Security Standards Council (PCI SSC) has issued a bulletin flagging a change in the Payment Card Industry Data Security Standard (PCI DSS) and the Payment Application Data Security Standard (PA DSS). This change will affect all those that are required to implement either standard. As you may be aware […]
By Simon Treadaway [NOTE: All information was gathered from public websites] During the build-up to our recent product launch of “phriendlyphishing.com”, the SEH team conducted hefty amounts of research into phishing attacks, and how they are being used to compromise countless individuals, corporations, and governments every day. SEH have been conducting ‘Client Side’ penetration testing […]
Today I’ll provide an overview of what is often the elephant in the room. The Payment Card Industry Data Security Standard (PCI DSS). Unlike ISO 27001 where shades of grey are acceptable, in PCI DSS things are very much black and white, with some wiggle room although limited and realistically only if you can convince […]