Sign In
Akshay on the business of security
A blog about the business implications of information security
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
About
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Tags
Application Security
BlueHat
Business
Conference
Conflicts
Consulting
Customer Support
Education
Facebook
Financial Analysis
Governance Series
Innovation
Leadership
Management
Performance
Privacy
Process
Risk Management
SDL
SDLC
Security
Speaking
Strategy
Threat Modeling
Tools
Archive
Archives
February 2011
(2)
January 2011
(2)
April 2010
(1)
April 2009
(1)
March 2009
(2)
February 2009
(3)
January 2009
(2)
July 2008
(3)
June 2008
(3)
May 2008
(4)
April 2008
(4)
October 2007
(1)
July 2007
(1)
June 2007
(2)
May 2007
(1)
MSDN Blogs
>
Akshay on the business of security
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Akshay on the business of security
Two Security Startups To Keep An Eye On
Posted
over 1 year ago
by
akshay_aggarwal
0
Comments
The security market has been heating up. With the acquisition of McAfee by Intel Corp for $7.68 billion and ArcSight by Hewlett-Packard for $1.5 billion. Now its time to start looking for new startups. Two companies have caught my eye as they focus on...
Akshay on the business of security
Conflicting Approaches: 2 different approaches to enforcing privacy
Posted
over 1 year ago
by
akshay_aggarwal
0
Comments
Enforcing information security & privacy laws and policies has become a priority for a myriad of law enforcement agencies. This reflects the growing importance that information plays in our lives. However many laws and policies are unclear. The punishment...
Akshay on the business of security
Secure your Facebook password
Posted
over 1 year ago
by
akshay_aggarwal
0
Comments
Ok. I’m going to make an exception from my general rule of focusing on deep analysis and not providing technology–specific security how-to’s. Some of my friends and family could definitely benefit from securing their Facebook accounts. The Change...
Akshay on the business of security
Advanced Persistent Threat (APT): Real or just hype?
Posted
over 1 year ago
by
akshay_aggarwal
0
Comments
Put four CSOs together and sooner or later they’ll start talking about Advanced Persistent Threat (APT). Now imagine the conversation with 20 CSOs together. I recently hosted a session at a security event at Microsoft and the two dozen security executives...
Akshay on the business of security
The McAfee Way: Don’t follow it!!
Posted
over 2 years ago
by
akshay_aggarwal
0
Comments
The chronicles of McAfee’s shoddy security updates have been well chronicled . If you haven’t been following this, let me summarize the situation for you. McAfee sent out a security update that led millions of uninfected machines to think they were...
Akshay on the business of security
Shrinking Budgets: Application Security Tools vs Process Tradeoff
Posted
over 3 years ago
by
akshay_aggarwal
1
Comments
An all too familiar scene repeated itself two weeks ago. My good friend & CISO of a mid-sized technology company, lets call him Alok, went into a budget planning meeting and came out as a shadow of his former self. To be more precise a 85% version...
Akshay on the business of security
Akshay’s Uncertainty Principle: Observing Some Metrics Changes Them
Posted
over 3 years ago
by
akshay_aggarwal
1
Comments
You’ve probably heard of the famous Heisenberg Uncertainty Principle in Quantum physics. It states “The more precisely the position is determined, the less precisely the momentum is known in this instant, and vice versa.” --Heisenberg, uncertainty...
Akshay on the business of security
Response to InfoSec X Prize Part 1
Posted
over 3 years ago
by
akshay_aggarwal
1
Comments
So I’ve been quite amazed by the amount of discussion and feedback i have received from colleagues and peers on my original post on creating fundamental change through competition. I will be posting some of the written replies that I received and which...
Akshay on the business of security
Baking Security In: A Comic Strip View of SDL
Posted
over 3 years ago
by
akshay_aggarwal
1
Comments
So how do you t ake your average developer who scoffs at security from the careless and brash aka Kevin, to the poster child for good development practices aka Kevlarr. Well, the Microsoft SDL team has the answer for you. The team recently...
Akshay on the business of security
Microsoft IT Solutions: Full Drive Encryption using BitLocker
Posted
over 3 years ago
by
akshay_aggarwal
1
Comments
One of the challenges that I have been focusing my team on this fiscal year has been creating new solutions that leverage the learning that Microsoft IT has had in deploying technology or solving problems. Microsoft IT generally has to deploy new technologies...
Akshay on the business of security
Note to Fannie Mae: Dealing with Logic Bombs
Posted
over 3 years ago
by
akshay_aggarwal
1
Comments
Today, it was revealed that a departing contractor left Fannie Mae with a parting gift – a Logic Bomb designed to take 4000 of the financial giants servers & their data. Since this news broke, a number of concerned CIOs have requested my team for...
Akshay on the business of security
The InfoSec X Prize: Fundamental Change Through Competition
Posted
over 3 years ago
by
akshay_aggarwal
1
Comments
Today I had a thought provoking conversation with Dr. Peter Diamandis , Chairman and CEO of Zero Gravity Corporation & X Prize Foundation, on radical & fundamental change. Change that advances the status quo rather than relying on incremental...
Akshay on the business of security
Business During Downturn: The Chain Of Trust
Posted
over 3 years ago
by
akshay_aggarwal
1
Comments
Business during economic downturns brings to the surface the tiny fractures that were unnoticeable during the good times. It is a fertile ground to relearn some of the lessons of the past & form wisdom for the future. I am going to try and capture...
Akshay on the business of security
Meter This: Practical Application Of Power drain Attack
Posted
over 4 years ago
by
akshay_aggarwal
2
Comments
Last week while feeding my caffeine addiction I came across an article in the New York Times titled Can’t Find a Parking Spot? Check Smartphone . In order to reduce traffic congestion and fuel consumption, the city of San Francisco is implementing a new...
Akshay on the business of security
My BlueHat Talk
Posted
over 4 years ago
by
akshay_aggarwal
0
Comments
Just got word that my talk Suddenly Psychic: Knowing everything about everyone was accepted at Microsoft's BlueHat Security Conference on October 16-17th. Sometimes when you go blue... you really go blue. Over the course of the next few months my buddy...
Akshay on the business of security
Towards enabling secure infrastructure outsourcing
Posted
over 4 years ago
by
akshay_aggarwal
1
Comments
Many enterprise customers are increasingly evaluating the benefits of infrastructure outsourcing (ITO) to their businesses. In the past year, several CIOs have expressed concerns around the impact to the security and privacy of digital assets resulting...
Akshay on the business of security
Application Security Development Lifecycle 5A: Is Threat Modeling Right For You?
Posted
over 4 years ago
by
akshay_aggarwal
6
Comments
Several enterprises are increasingly investing time and money in building application security tasks into their existing SDLCs. Some of them have also reached the conclusion that proactive approaches , like threat modeling, have more ROI than reactive...
Akshay on the business of security
OWASP Conference Update
Posted
over 4 years ago
by
akshay_aggarwal
1
Comments
I will be presenting at the OWASP conference in Denver, CO this Tuesday, June 10th. The presentation will focus on the value that organizations especially ISVs can derive from threat modeling of line of business applications. For some time now, I've been...
Akshay on the business of security
Application Security development Lifecycle 4: Finding the right security talent
Posted
over 4 years ago
by
akshay_aggarwal
1
Comments
After about an hour of nodding his head vigorously in agreement with some of our lessons learnt, my customer jumped up and exclaimed, " Great!! Now where do I find another 20 people like these?" (pointing to my team)... I thought about it a while and...
Akshay on the business of security
How Microsoft IT does Secure Application Development: Webcast
Posted
over 4 years ago
by
akshay_aggarwal
1
Comments
Technorati Tags: Conference , SDLC , SDL , IT , ISV I will be discussing Microsoft IT's approach to secure application development, with a special focus on how we integrate security into the IT line-of-business SDLC, in a webcast this Thursday May...
Akshay on the business of security
Increase the TCO, kill the project: An ad-hoc analogy
Posted
over 4 years ago
by
akshay_aggarwal
1
Comments
The other day I was subject to the assertion that the only asset an IT security organizations should care about is data. Now being in the application security business, I should have been jumping at this validation but couldn't. The IT security org...
Akshay on the business of security
Application Security Development Lifecycle 3: Funding Models
Posted
over 4 years ago
by
akshay_aggarwal
2
Comments
Now that you've decided (or battled) to set up an application security program you realize that it actually needs to get funded. You must master the art of delicately drinking from the fire hydrant of line of business applications. In my experience helping...
Akshay on the business of security
Front Range web application security summit in Denver
Posted
over 4 years ago
by
akshay_aggarwal
0
Comments
I will be speaking at the Front Range OWASP Conference (FROCo8) in Denver on June 10th. The focus of the conference to share the experiences that the speakers had around solving technical and management issues surrounding application security. I'll be...
Akshay on the business of security
Connecting a Global team: the power of 30 seconds
Posted
over 4 years ago
by
akshay_aggarwal
1
Comments
Technorati Tags: Leadership , Business One of the challenges I constantly grapple with is leading a large yet mostly remote team. Managing across 5 time zones posting I wrote about it earlier generated a lot of discussion and loads of ideas. Recently...
Akshay on the business of security
Application Security Development Lifecycle 2: Mandatory or Not?
Posted
over 4 years ago
by
akshay_aggarwal
2
Comments
Large enterprises tend to have a number of line of business (LOB) applications supporting business operations. It becomes key for an application security program to help the organization manage the risk posed by each of these applications. Applications...
Page 1 of 2 (32 items)
1
2