Sign in
Roger's Security Blog
As Chief Security Advisor of Microsoft EMEA - lets share interesting security information
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
About
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Blog - News
Chat directly with me if you want. Go to my
Chat
page to find a web messenger!
Search Blogs
Blog - Link List
Links to other blogs
Roger's Blog on Security
This is my other blog I just started. It will be similar content but over time more org and business focused
CSA Switzerland
The Blog of the Swiss Chief Security Advisor
CSA Russia
The Blog of the Russian Chief Securty Advisor
CSA Finland
The Blog of the Finish Chief Security Advisor
CSA Italy
The Blog of the Italian Chief Security Advisor
MS Security Response Center
Microsoft Malware Portal
Microsoft's Security Blog
Security by Numbers
Jeff's Blog on Security and Numbers
Shoaib Yousuf
One of my readers
ts/sci security
Gerhard's Marktbeobachtungen
Trustworthy Computing
Tags
Cloud
Cloud Computing
Competition
Consumer
Crime
Critical Infrastructure Protection
Cybercrime
Events/Training
Fun
Incident Response
Incidents
Industry Associations
Law Enforcement
Microsoft
Microsoft Products
Patch Management
Policies
Policy
Politics
Privacy
Processes
Security
Technology
Terrorism
Trends
Archive
Archives
June 2013
(3)
May 2013
(3)
April 2013
(2)
March 2013
(1)
February 2013
(2)
January 2013
(5)
December 2012
(1)
November 2012
(1)
October 2012
(4)
September 2012
(4)
August 2012
(4)
July 2012
(1)
June 2012
(3)
May 2012
(2)
April 2012
(9)
March 2012
(2)
February 2012
(2)
January 2012
(1)
December 2011
(3)
November 2011
(6)
October 2011
(11)
September 2011
(8)
August 2011
(3)
July 2011
(4)
June 2011
(8)
May 2011
(7)
April 2011
(7)
March 2011
(13)
February 2011
(18)
January 2011
(15)
December 2010
(6)
November 2010
(15)
October 2010
(15)
September 2010
(32)
August 2010
(10)
July 2010
(14)
June 2010
(18)
May 2010
(8)
April 2010
(6)
March 2010
(22)
February 2010
(5)
January 2010
(12)
December 2009
(8)
November 2009
(7)
October 2009
(11)
September 2009
(17)
August 2009
(12)
July 2009
(12)
June 2009
(13)
May 2009
(14)
April 2009
(16)
March 2009
(11)
February 2009
(12)
January 2009
(14)
December 2008
(22)
November 2008
(13)
October 2008
(22)
September 2008
(8)
August 2008
(14)
July 2008
(4)
June 2008
(16)
May 2008
(30)
April 2008
(29)
March 2008
(19)
February 2008
(16)
January 2008
(26)
December 2007
(18)
November 2007
(23)
October 2007
(11)
September 2007
(10)
August 2007
(7)
July 2007
(11)
June 2007
(11)
May 2007
(4)
April 2007
(9)
March 2007
(8)
February 2007
(8)
January 2007
(6)
TechNet Blogs
>
Roger's Security Blog
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Roger's Security Blog
Targeted Attacks – a Video Series
Posted
16 hours ago
by
rhalbheer
0
Comments
Trustworthy Computing in partnership with Microsoft IT, Microsoft Consulting and the product groups just released a series of videos on targeted attacked and how to defend. I would definitely urge you to listen to them and make sure you implement the...
Roger's Security Blog
Are we sitting on a time bomb?
Posted
14 days ago
by
rhalbheer
0
Comments
I just read another of these studies: Enterprises sitting on security time bomb as office workers compromise company data . Let's briefly look at the findings first: 38% of U.S. office workers admit to storing work documents on personal cloud tools...
Roger's Security Blog
The Moscow Rules in the Cyberspace
Posted
15 days ago
by
rhalbheer
0
Comments
Doing your basics is a natural given, when you defend your assets. Basics like updating your computers, staying on latest versions, dynamic network zones, incident response, identity management, monitoring etc. etc. – last but not least (or probably first...
Roger's Security Blog
Enabling the Hybrid Cloud with Microsoft Technology
Posted
25 days ago
by
rhalbheer
0
Comments
When I talk with customers about the Cloud, we always talk about a few key themes: Identity: I am convinced that you need to be able to federate your identity from your on premise solutions to the cloud. You will want to control the process of decommissioning...
Roger's Security Blog
Is there a future for Product Certifications?
Posted
1 month ago
by
rhalbheer
0
Comments
Often, when I talk to customers, product certification is one of the key themes they want to address. Especially they want to know about our commitment to Common Criteria and whether our products are certified. Typically we certify an operating system...
Roger's Security Blog
Will the user define security policies in the future?
Posted
1 month ago
by
rhalbheer
0
Comments
I think, I blogged about this event already earlier: Years ago I was meeting a customer and was talking about the future of IT. I was telling the audience (about 10 people including the Security Officer) that there is a good chance that IT will not define...
Roger's Security Blog
Some Windows XP Users Can't Afford To Upgrade
Posted
1 month ago
by
rhalbheer
9
Comments
I just read a post on slashdot : During a recent trip to an eye doctor, I noticed that she was still using Windows XP. After I suggested that she might need to upgrade soon, she said she couldn't because she couldn't afford the $10,000 fee involved...
Roger's Security Blog
Microsoft Account: Enable Two-Step Verification
Posted
1 month ago
by
rhalbheer
0
Comments
We could even talk about two-factor authentication in my opinion. The idea is, that whenever you logon from an untrusted PC, you will be asked to use a second factor (or step). In my case, which I show below, I use the Authenticator app on my phone, which...
Roger's Security Blog
Internet Accessible SCADA Systems
Posted
2 months ago
by
rhalbheer
1
Comments
This is a fairly scary view of the world…. Freie Universität Freiburg mapped the Internet accessible SCADA systems. Have a look on your own: https://www.scadacs.org/projects.html Roger
Roger's Security Blog
Cyber Espionage and Targeted Attacks
Posted
4 months ago
by
rhalbheer
1
Comments
This morning I read an article on Infoworld: Why you should care about cyber espionage which – to me – is a strange question. First of all, most companies have to protect some sort of intellectual property. It is not new for the Internet, that state-driven...
Roger's Security Blog
The Challenge of Patch Management
Posted
4 months ago
by
rhalbheer
2
Comments
Depending on where I travel and with which customers I talk, patch management is still the number 1 issue coming up. Not only is the challenge to deploy the updates – much worse, there is still an awareness issue in a lot of markets. People know that...
Roger's Security Blog
Try Office 365 Home Premium
Posted
4 months ago
by
rhalbheer
2
Comments
Today is the day we launched Office 2013 officially to the broad market. This is a real cool step forward you should look at: Go to http://office.microsoft.com and give it a try. For only $8/year you get the ability to have it on up to 5 PCs or Macs...
Roger's Security Blog
Security in 2013 – the way forward?
Posted
4 months ago
by
rhalbheer
3
Comments
Typically January is the month where we are asked to make predictions on the trends for the New Year. I do not like this as I am an engineer and not a fortune teller J . But there are things we know and things we definitely need to drive this year. I...
Roger's Security Blog
An Attack via VPN – Really?
Posted
4 months ago
by
rhalbheer
0
Comments
I was just made aware of a case study, which is a really interesting "attack" on a US company via VPN. It is sometimes not like it seems… You should read this: Case Study: Pro-active Log Review Might Be A Good Idea Roger
Roger's Security Blog
The Directory in the Cloud?
Posted
5 months ago
by
rhalbheer
0
Comments
It seems that it is an eternity ago – and it is. Pretty much three years ago, Doug Cavit and me published a paper called the Cloud Computing Security Considerations . Even though it is three years, the paper is still worth reading as the content still...
Roger's Security Blog
New book on Direct Access
Posted
5 months ago
by
rhalbheer
0
Comments
A lot of customers are asking us about Direct Access and how you can implement it. Erez Ben Ari (a Senior Support Escalation Engineer at Microsoft) and Bala Natarajan (a Program Manager in our Windows division) wrote a book on that called Windows Server...
Roger's Security Blog
Mitigating Pass the Hash Attacks
Posted
6 months ago
by
rhalbheer
0
Comments
In the recent months, we have seen more and more targeted attacks towards our customers. A lot of them use a technique called Pass the Hash. This made us publishing a paper, which explains Pass the Hash but much more important shows some fairly simple...
Roger's Security Blog
Kaspersky Lab: Microsoft software products pretty darn secure
Posted
7 months ago
by
rhalbheer
0
Comments
What a statement! The last time I was on a panel with Eugene Kaspersky, he told us that the world will end and the only way to prevent this from happening is a new really secure OS (and they have one…). And now, I read such statement: Microsoft products...
Roger's Security Blog
Two Papers on Current Issues
Posted
7 months ago
by
rhalbheer
0
Comments
Trustworthy Computing just released two papers on current issues: Determined Adversaries and Targeted Attacks Whitepaper This paper shares Microsoft's insights into the threat that Determined Adversaries and Targeted Attacks pose, identifies challenges...
Roger's Security Blog
The Future of Crime
Posted
7 months ago
by
rhalbheer
0
Comments
You should spend 15 minutes on this TED talk – really worth it!! http://youtu.be/7_OcyWcNi_Y Roger
Roger's Security Blog
Security Lessons from Star Wars
Posted
7 months ago
by
rhalbheer
0
Comments
Exactly the right article for a weekend: May the (En)Force(ment) Be With You – Security Lessons from Star Wars From applying security policies to DLP and effective user authentication, there are many infosecurity lessons to be learned from the classic...
Roger's Security Blog
New Consumerization of IT Test Lab Guide: Hyper-V Windows 8 corporate virtual machine on personal computer"
Posted
8 months ago
by
rhalbheer
0
Comments
Out friends in France are currently working intensively on Test Lab Guides for Consumerization of IT. The next one was just released: New Consumerization of IT Test Lab Guide: Hyper-V Windows 8 corporate virtual machine on personal computer" This...
Roger's Security Blog
Paper: Information Protection and Control (IPC) in Office 365 Preview with Windows Azure AD Rights Management
Posted
8 months ago
by
rhalbheer
1
Comments
As you know, protecting your information in the cloud is key. We just published a paper called Information Protection and Control (IPC) in Office 365 Preview with Windows Azure AD Rights Management . Here is the summary: Due to increased regulation...
Roger's Security Blog
Security Implications of Pirated Software
Posted
8 months ago
by
rhalbheer
2
Comments
A while ago, when I was travelling a journalist told me that he never pays for our software as he can easily download a tool to crack Windows XP (he was still running XP). We had an interesting discussion afterwards (besides the fact that he showed me...
Roger's Security Blog
How to secure your Facebook account
Posted
9 months ago
by
rhalbheer
0
Comments
I think that this is actually a fairly good overview of the privacy settings on Facebook and how you should set them: How to secure your Facebook account Roger
Page 1 of 33 (808 items)
1
2
3
4
5
»