Sunday, 8 February 2015

The top demographic trends for every major social network

The demographics of who's on what social network are shifting — older social networks are reaching maturity, while newer social messaging apps are gaining younger users fast.

In a report from BI Intelligence, we unpack data from over a dozen sources to understand how social media demographics are still shifting.

Here are a few of the key takeaways from the BI Intelligence report:

Facebook still skews significantly female. Women in the U.S. are more likely to use Facebook than men by about 10 percentage points, according to a 2013 survey of social network adoption.

Facebook remains the top social network for U.S. teens. Nearly half of teen Facebook users say they're using the site more than last year, and Facebook has more daily teen users than any other social network.

That said, Instagram has edged out Facebook and Twitter in terms of prestige among young users. U.S. teens now describe Instagram as "most important," while Facebook and Twitter lost ground on this measure, according to Piper Jaffray's twice yearly teen survey. The survey also found that 83% of U.S. teens in wealthy households were on Instagram.

LinkedIn is actually more popular than Twitter among U.S. adults. LinkedIn's core demographic are those aged between 30 and 49, i.e. those in the prime of their career-rising years. Not surprisingly, LinkedIn also has a pronounced skew toward well-educated users.

Twitter has begun to lean worryingly toward male users, whereas previously it was a more gender-balanced social network. Pew found that 22% of men use Twitter, while only 15% of women do.

YouTube reaches more adults aged 18 to 34 than any single cable TV network. Nearly half of people in this age group visited YouTube between December 2013 and February 2014, according to Nielsen. It was rated by millennials as the top place to watch content, ahead of digital and TV properties like Facebook and ESPN.

Snapchat is the youngest social network of all. More than six out of 10 Snapchat users are in the 18-to-24 age group, compared to 28% of Instagram users, according to a survey by Informate.



Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Tuesday, 27 January 2015

Apple readies another crack at ending Yosemite's Wi-Fi ills

Quickening tempo of 10.10.2 beta releases hints at impending release

Apple is putting the final touches on the next update to OS X Yosemite as it again tries to stamp out Wi-Fi problems customers have experienced -- and reported -- since the operating system launched three months ago.

In a seven-day span, Apple released two iterations of the beta of OS X 10.10.2, the first on Jan. 14, the second on Jan. 21, hinting that the final release is imminent.

Apple, like most developers, typically shortens the interval between builds the closer it comes to a final release.

As they have before, the cryptic release notes for what was pegged as build "14C106a" called out "Wi-Fi" as one of the few areas for testers to focus on, according to numerous online reports and confirmation from registered Apple developers.

On Monday, 9to5Mac.com, citing Apple employee sources, said that an even-newer beta, tagged "14C109," is circulating within the company and comes with a claim of, "Resolves an issue that may cause Wi-Fi to disconnect."

Mac owners who have had trouble connecting to -- and staying connected to -- wireless networks are hoping that 10.10.2 will finally give them relief.

"I suspect Yosemite 10.10.2 [14C106a] is nearly there as to Wi-Fi," wrote an optimistic "hexdiy" in a message last Wednesday on Apple's support forum.

A handful of comments that referenced earlier beta builds said things looked promising. "I installed [Jan. 14's 14C99d] and after several days, the problem seems to have gone away," said kbastian.

Those messages were just two of nearly 2,200 on a massive support thread opened Oct. 17, the day after Apple released Yosemite. The thread has been viewed more than 683,000 times, an extraordinary number for the Cupertino, Calif. company's support discussion forums.

Messages from frustrated, even furious, Mac owners continue to accumulate.

"Yosemite on my machine today is almost unusable," reported ausappleuser last week. "Will it be fixed though? I have ceased to care and will be moving on."

"If I was Apple, I would be totally ashamed and embarrassed," chimed in Gianvito Fanelli. "This is the third month that I CANNOT use the Internet properly. Continuous drops with a few moments of peace."

Apple's first crack at cleaning up the Wi-Fi disconnect mess, Yosemite 10.10.1, which was released Nov. 17, did not cure users' Internet ills, according to reports on the same thread last year.





Wednesday, 21 January 2015

5 minutes a week to advance your career

Maintain contacts that can keep your career moving by reaching out to people from your past

The New Year is always a good time to reflect on your career: where you’ve been, where you’re heading, and where you’d like to go. It’s also the traditional time for people like me — industry analysts, pundits and consultants — to tell you what hot skills you’ll need to develop to advance your career in the next year. Of course, if developing your career were really that simple, every reader would be the CEO of a company by now.

In reality, simple advice like this is not as universally helpful as we would like to think. Focusing on hot skills may be useful for some, but for many it’s a complete diversion because the paths that people follow through IT careers are remarkably varied. Some pass easily from technical roles to management and back. Some oscillate between employment and contracting. Some even follow the traditional path of staying with one organization and climbing the corporate ladder.

But there is one thing that everyone can benefit from, regardless of what path you choose to follow, and that you can realistically accomplish given the day-to-day demands of work and life. Just take five minutes each week to reach out to someone from your past. Everyone can find five minutes a week — five minutes that would otherwise go to looking at your smartphone, waiting for people to arrive at a meeting, drinking your morning coffee or eating lunch at your desk.

What you do with those five minutes each week is to reconnect. It might be with someone with whom you worked, went to school or set up play dates for your children. All you have to do is think of someone and then call, leave a voice mail, drop an email or even send a physical postcard.

Don’t worry. It won’t be a big commitment, and it won’t take over your life. The people you reach out to are just as busy as you are and don’t have hours to talk on the phone. But those five minutes a week could do more for your career than you can possibly imagine.

Why? Because opportunities are the fundamental building blocks of careers — opportunities for new jobs, contracts or even volunteer work. You can talk in the abstract about building your career all you want, but if no one wants to hire you to do whatever you decide your next step should be, then you’re not translating your intentions into reality.

And where do opportunities come from? Mostly from people who know you. It may have been 15 years since you have spoken to each other, but if the other person remembers you fondly and your work respectfully, she will likely be happy to tell you about opportunities that she’s aware of.

Don’t expect her to do so right away. Don’t call and ask for referrals.

Just check in, person to person. For example, this past week I’ve been upgrading my home audio equipment. It made me think of a guy I worked with 20 years ago who was obsessed with stereo gear. I’ll probably just write a note saying that I was thinking of him and wondering how he is doing. That’s it.

Your greatest career advancement resource is not your résumé. It’s the people who know you. And they will bring opportunities to you if they feel good about you and you are top of mind for them when opportunities cross their path.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Wednesday, 14 January 2015

9 Linux distros to watch in 2015

A list of the most interesting Linux distros to keep up with in 2015.

Looking ahead
Predictions are fun. We all enjoy tech predictions at the beginning of each year. This isn't that. This is a list of the nine Linux Distributions that I feel will be the most interesting to watch during 2015. We're talking both desktop and mobile here because, let's face it, Linux is everywhere. (Note: I say these will be the most "interesting to watch," not necessarily the best or the highest quality. Just the most interesting and entertaining to keep tabs on.)

Ubuntu Touch
It was first announced that phones powered by Ubuntu Touch were set to ship way back in 2013. Then again in 2014. It is now 2015 and it looks as though the wait may finally be over, with actual devices set to ship this February (in limited markets outside of North America). My very soul wants this to succeed like gangbusters...but my gut tells me this isn't going to go well. Will 2015 end with Ubuntu Touch being anything other than a weird, orange blip on the radar? Who knows? But it promises to be rather exciting to watch.

Ubuntu
With the recent release of Ubuntu MATE (a community-built version of Ubuntu using MATE, a fork of the old GNOME 2, as the desktop environment) there is now a version of Ubuntu out there that looks and feels a lot like the pre-Unity days of Ubuntu (aka "what Ubuntu was like back when it catapulted to stardom and grabbed huge market share in the Linux world"). I'm not sure how this will actually impact Ubuntu proper (the Unity-powered version), but with yet another re-written version of Unity set to be released (along with a brand-new display server with Mir), having Ubuntu MATE around will serve to remind Ubuntu users where they came from. Which could prove very interesting.

elementary OS
elementary OS currently sits at the No. 9 spot on the Distrowatch list (up from No. 19 in 2013). While Distrowatch is not the best way to track actual numbers of users of any given Distro – heck, it's not even the second best – this certainly shows the upward momentum of this little system with a focus on design. They've also been putting a heavy focus on developers and designers getting paid to work on elementary OS-related projects via Bountysource.com (an approach I find highly interesting).

SteamOS
SteamOS was set to shake up the console gaming world in 2014. New boxes ("Steam Machines") were set to ship from multiple vendors. We were talking high-end PCs running a version of Linux that hooked up to your TV and were filled with games from Valve (and other companies). It was going to be glorious. But, as with the Linux-powered Ubuntu Phones, it just never shipped. The failure to launch in 2014 (as planned) isn't the end of the world, though – Valve (the company behind SteamOS) has a long and glorious track record of taking its sweet time in order to get its products just right. The current ETA is sometime in 2015.

ChromeOS
Chromebooks absolutely dominated laptop sales on Amazon for the second straight holiday season in a row. If there was any doubt that the Gentoo-based ChromeOS was here to stay, that doubt should now be completely erased. Add to that the growing list of Android applications that run on ChromeOS and the imagination can't help but run a bit wild about what the future has in store for this system. Just speculating here, but imagine if Google made all Android apps available on ChromeOS via a full version of the Google Play App store. This system would be an even bigger force to be reckoned with.

Android
Speaking of Android... did you realize that you can currently get Adobe Photoshop and Microsoft Office (in Beta) that run natively on Android? I've got an Android-powered laptop here running both, which means I'm running Photoshop and MS Office natively on my Linux-powered computer. Ever heard anyone say something like "I would use Linux... but I need Microsoft Office"? Well, it's here. On Linux. Look out your window. Go ahead. Stand up, walk over to your window, and take a look out. Those pink things in the sky? Yeah. Those are pigs. And, boy howdy, are they flying.

Fedora
I'll be honest – usually, I'm not terribly interested in Fedora. For years I've struggled to find reasons to convince myself to install the latest versions (because it always ended up either being rather dull or half-broken). But the Fedora Project shook things up this past year with the Fedora Next initiative. The first result of which being that Fedora is now broken into three distinct versions: Workstation, Server, and Cloud. And you know what? The first iteration of "Fedora Workstation" is actually quite nice. What will be truly interesting is where the Fedora team will go from here. 2015 could be rather interesting for these chaps.

Sailfish and Firefox
Ubuntu Touch may have a hard time shipping, but there are two Linux-based systems that have been shipping on actual hardware all throughout 2014 – Sailfish OS and Firefox OS, two (very different) systems that are moving mobile Linux forward. What will be fascinating is how these two systems strive to gain market share in 2015, with the possibly soon-to-be-released, Ubuntu-powered phones along with the continuing dominance of Android in the market.

Debian and Devuan
Debian has been around for 21 years now. But the controversy over systemd has caused a group of Debian users to fork and create a systemd-free version that they now call "Devuan." Disagreements and controversy around systemd don't show any signs of ending soon, making Debian and Devuan an interesting set of projects to watch, even if just for the reality TV-style entertainment of it all.


Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Monday, 5 January 2015

IT 2015 predictions

If I am right, this will be a tough year for tech and everyone else.

With the year coming to a close, a lot of people are making their predictions for 2015. So naturally I had to join the party. A whole lot of issues seem to be coming to a head and will need to be addressed in the next year, and I think it will happen all at once. So heed the words of Patridamus.

1) Wearables continue to tank
This is yet another case of the industry looking for new growth opportunities and a chance to expand by driving something the public doesn't really want. People don't want another device to carry or remember to wear, they are often inaccurate, and the newness wears off quickly and they get tossed in the drawer.

2) IoT proves a hard sell
Take what I said above and multiply it by 10. I don't know anyone screaming for an Internet-connected refrigerator. Then again, Steve Jobs did famously say “A lot of times, people don’t know what they want until you show it to them.” But with concerns about privacy by government and corporate snooping, security from all the hacks and general public tech illiteracy (the Silicon Valley is so myopic about this), IoT will be a hard sell.

3) BYOD chickens come home to roost

Many firms established BYOD rules when the trend first began, and they never revisited them. Eventually, there will be a reckoning where companies have to set down rules concerning data security and loss prevention, not to mention who pays the bills. It's only a matter of time before we get stories of employees giving up on BYOD and telling their boss to just provide a device.

4) Stock market crash and burn
The stock market has been going gangbusters, but it won't last. Every seven years, the stock market melts down like Chernobyl. We all remember 2008, and the recent "Cromnibus" budget deal in Washington has set us up for a repeat. In 2001, it hit the skids due to the Dot Bomb crash and 9/11. In 1994, the bond market went into the toilet. And in 1987 we had Black Monday with the massive sell-off. And if you don't believe me, maybe this guy's words will carry weight.

5) AMD finally bottoms out, Qualcomm acquires it for IP protection
AMD is in a real tough spot. Its CEO change caused a collapse in confidence and stock, neither of which has bounced back. Nvidia is gaining market share and is now over 70%, according to Jon Peddie Research. There are hints of big things to come but nothing concrete, and the company has been through endless rounds of layoffs.

Nvidia wouldn't be allowed to buy the company, unless it was torn in half and it got the x86 business (and CEO Jen-Hsun Huang has repeatedly said he doesn't want an x86 business), with the GPU side going to Intel. A more likely outcome is Qualcomm grabbing the company primarily for IP protection against Intel.

6) IT continues to dump its own data centers in favor of the cloud
The trend of shutting down an on-premises data center in favor of a cloud solution has been going on for some time, but it will take off in 2015 for one very good reason – Windows Server 2003 is reaching its end of life and there are 10 million 2003 server installations out there that need upgrading. Many companies may decide it's easier to move to the cloud than buy new servers and go through a rip-and-replace routine.

7) Windows 10 is a hit, mostly
Windows 10 seems to have a lot of warm and fuzzy feelings around it, and it will likely revive PC sales, especially in the enterprise. The only thing that will mute Windows 10 at this point is declining interest in PCs. If the trend toward tablets as PC replacements continues, well, there's nothing Microsoft can do about that except get the tablet experience right, which it seems to have done with Surface 3.

8) Big Data's growth will be hampered by talent shortages
Big Data is an important new trend in tech, but it's also a significant change in how computer science is done. It requires people with specialized, advanced degrees, and there are not a lot of them on the market. In fact, there have been repeated predictions of talent shortages of data scientists and other people to make Big Data work. The people who have that kind of experience, however, will make some serious money.

9) Tablets will crash and burn
Tablet sales are already slowing down and the trend likely won't reverse in 2015. Some experiments have failed, like the Los Angeles Unified School District's $1.3 billion tablet boondoggle. I expect as the batteries start to die on these things and they are not replaceable, that will also hurt. The main problem, though, is that tablets don't have an advocate. Steve Jobs was the big champion of the tablet and no one has stepped forward to take up the mantle.

10) MMOs start dying off
My one consumer prediction. For some time now, every game company and a whole bunch of startups had massively multiplayer online games in the works. Then they all started failing. "Star Wars: The Old Republic," "Final Fantasy XIV," and "Elder Scrolls Online" all bombed recently, and when an "Elder Scrolls" game bombs, that's a big warning. Many other MMOs have faded into nothing. And Blizzard killed its MMO codenamed "Titan" after seven years of R&D. The reality is these games demand too much time and people who play them frequently suffer from health problems for their addictions.



Best Microsoft MCTS Training – Microsoft MCITP Training at Certkingdom.com

Tuesday, 23 December 2014

Cool Yule Tools: Best techie gifts for 2014

The National Santa Agency has a handle on what everyone wants.

Sonos Play:1 $199
This portable speaker lets you experience the joy of the Sonos Music system without the additional equipment (a wireless bridge, for example) needed with other parts of their gear. Control music through the wonderful Sonos app on your phone or tablet and you'll be hearing lovely music all season long.

KEF X300A Wireless Digital Hi-Fi Speaker System $799.99
When you think of wireless speakers, you think of smaller, Bluetooth-enabled devices (such as the Jambox Jawbone, or the Sonos Play:1, etc.), aimed a providing some good sound for music stored on tablets, phones, etc. These speakers are not like those systems.

The KEF X300A speakers are huge speakers – they look more like giant audio system speakers you’d have connected to your older audio system (if you still had a receiver, record player, cassette deck, etc.) They’re very heavy – when you get these, decide quickly where you want them and keep them there – portable speakers these are not.

iHome iDL100 – Triple Charging FM Clock Radio Stereo System $149.99
With the integration of alarm clock functions (clock, alarm, snooze button, etc.), you’ll most likely want to have this unit sitting on your nightstand. The Lightning Connector dock at the top lets you place your iPhone 5/5S (or the new 6 models) as well as your iPad to recharge it. If you’re so motivated, you can even set your alarm clock to wake up to a favorite song instead of an annoying buzzer or beep.

But leaving this on a bedroom nightstand isn’t the only thing you’ll want to do with the iDL100 – The system allows for three devices to be recharged (the two Lightning-based devices at the top, as well as a USB charging port in the back), and the speakers are good enough to place in a kitchen or other small room for additional audio entertainment. If you have a video that you’d like to watch on your phone or tablet, for example, the system provides excellent audio to accompany the video. An AUX in jack lets you connect any other older audio device (or an old iPod that doesn’t have the Lightning connector).

Pure Evoke F4 with Bluetooth $220
Pure continues to impress us with its Internet-radio-themed devices – this Evoke F4 is a very old-school, classic look-and-feel device that can access a variety of different music streaming sources from around the world. But also realizing that customers may already have a bunch of music either stored on computers, storage devices or even phones/tablets, they’ve added Bluetooth connectivity to play music from those devices to the Evoke F4 system.

In addition to the Internet radio services (connecting through Pure’s Connect service), the Evoke F4 can connect to Sirius XM satellite radio (a separate subscription would be required) and FM radio (hence the old-school metal antenna). Connecting to the Internet is done through Wi-Fi (interestingly, no Ethernet port on the unit). Volume control and menu control are handled through nice metal dials, but there’s also some touch-enabled buttons on the display for making other menu choices.

Star Wars Street by 50 on-ear wired headphones (SMS Audio) $199.95
If you’re a Star Wars fan and you love music, and - more importantly - you want others to know about your love of the movie, then these headphones are ones that you’ll want to sport when you’re out and about. These high-performance headphones provide pretty good sound quality for your music, movies or if you want to use when video gaming, and come in different Star Wars themes and colors (we tried the white Stormtrooper model, but there’s also some other cool colors/themes such as Rebel Alliance, Boba Fett and Galactic Empire). The on-ear wired headphones include 40mm drivers, passive noise cancellation (non-powered) and can fold up for putting into your travel bag.

Icon Q Boundless E1 Bluetooth earphones $65
These small and light earbuds/earphones will wirelessly connect you with your music device (phone, MP3 player, tablet) without a tangled cord getting in the way. This can be good if you want to use these while working out (although I prefer the Plantronics BackBeat Fit earbuds for that purpose), or if you just don’t like the extra bulk of a connection cord. The earbuds provide good, but not stellar, sound for your music or movies -you are using Bluetooth, after all. Pairing can be done via Bluetooth (an in-ear prompt helps you determine whether the earphones are powered on or off, or whether you’re in pairing mode), or NFC if you have an NFC-compatible phone or tablet.

Polk Audio Ultrafocus 8000LE noise cancelling headphones $250
For comfort and sound quality, these noise-cancelling headphones are pretty impressive. We've tried other brands and they always felt heavy and clunky on the head. They were the kind where your wife says, “You’re not really going out of the house wearing those are you?”

The Ultrafocus 800LE is Star-Wars-white plastic on the outside and chocolate brown on the inside – which means the ear cups themselves are brown along with the padding on the inside of the headband. On the outside of the left ear cup is the battery cover for the two AAA batteries you need to run the headphones. On the outside of the right is a circular control panel.

Plantronics BackBeat Fit headphones $129.99
These super comfortable, around-the-ear earbuds use Bluetooth wireless to connect to your phone/music player, and provide an outstanding listening experience for when you're jogging, running or generally working out and building up a sweat. The headphones are sweatproof and have a long-lasting battery, so the tunes won't cut out on Heartbreak Hill.

Plantronics BackBeat Pro headphones $249.99
These over-the-head headphones include active noise cancellation and a superior battery life, making it a great gift for anyone looking for great-sounding music and quiet while they’re in a noisy environment (aka planes, room full of kids, etc.) Additional features, such as multipoint connections (connecting to a phone and tablet, for example), an “OpenMic” button that reduces the volume so you can hear outside noise without removing the headphones, and a nice comfortable fit make this an excellent choice to give or receive as a gift this year.

iHome iBN26 Bluetooth speaker/speaker phone $79.99
If you're looking for a small and stylish wireless speaker for casual use around the house, iHome's iBN26 should be on your list. This compact system can connect to your mobile device using Bluetooth or NFC. After pairing, all you have to do is start playing music on your mobile device and your songs will be streamed wirelessly to the iBN26. Sound quality is good, albeit light on bass and a little muddy on higher notes. But for the price, it's more than enough to fill a room with whatever tunes you fancy.

Boom Swap headphones $69.99
Hey kids, having a hard time deciding whether you want on-ear or over-the-ear headphones? Can’t decide what color to make your headband or earcups? Then check out The Boom Swap headphones, a modular headphone system that allows you to make changes depending on your mood and situation. It’s like a “build your own headphone” system! The headphones are made out of a flexible plastic and come with several components, including two foam over-the-ear earcups that you can easily slide onto the on-ear parts. The flexible headband can be removed and replaced with a second one of a different color (ours came with black and blue headbands). On the outside of the earcups, another two options for colors. The headphones come with three color options (black/blue, white/black and mint/orange), but unfortunately you can’t buy different colored headbands or earcaps separately.

Polk Audio Hinge headphones $97 (Newegg) to $129 (Best Buy and Nordstrom)
These headphones have an old-school, over-the-ear style, but in a compact form that’s also more comfortable. The aluminum frame make them lightweight, yet still very sturdy, adding the additional comfort.

These were a lot more comfortable than most on-ear sets we’ve tried - there’s a good seal, but not a lot of tight pressure. Music quality was surprisingly good bass and treble for headphone sin this price range - it gave out some nice deep and clear tones.

REPORT 3: Office gadgets and other work gear
Why should your family members have all the cool gifts at home? Here are some picks of some great technology gift ideas that will make you more productive when you're working in your cubicle or office.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Wednesday, 10 December 2014

The top infosec issues of 2014

Security experts spot the trends of the year almost past

There is still time for any list of the “top information security issues of 2014” to be rendered obsolete. The holiday shopping season is just getting into high gear, after all, and everybody knows it was from late November to mid-December last year when the catastrophic Target breach occurred.

But this list is about more than attacks and breaches – it is about broader infosec issues or trends that are likely to shape the future of the industry.

Several experts offered CSO some thoughts on their top picks, what can be learned from them and whether that knowledge can help organizations improve their security posture in the coming year.

Cyber threats trump terrorism
An Associated Press story this past week on the federal government’s $10-billion annual effort to secure its multiple agencies noted, almost in passing, that, “intelligence officials say cybersecurity now trumps terrorism as the No. 1 threat to the U.S.”

That makes sense to Sarah Isaacs, managing partner at Conventus. While cyber attacks have been expanding and evolving for decades, Isaacs said there has been a qualitative change: It is not just criminals trying to steal money – it is nation states using it for espionage and even military advantage.

Be sure not to miss:

Free security tools you should try

In May, “the Department of Justice indicted five members of China’s People’s Liberation Army on felony hacking charges for stealing industrial secrets,” she said. “We’ve never seen that before.”

Then in September, “NATO agreed that a cyber-attack could trigger a military event,” she said. “This is about more than protecting credit cards. This is escalating to new levels.”
"Everyone is oversharing everything. The threats are broad and potentially catastrophic."
sarah isaacs

Sarah Isaacs, managing partner, Conventus
Author, security guru and Co3 Systems CTO Bruce Schneier, would likely agree. In a recent blog post, he wrote that increasingly sophisticated attacks, especially advanced persistent threats (APT) that are not about financial theft, are coming from, “a new sort of attacker, which requires a new threat model.”

There is evidence of that in a recent study by ISACA on APTs. CEO Rob Clyde said 92% of respondents, “feel APTs are a serious threat and have the ability to impact national security and economic stability.”

Clouds – private, public and hybrid – are not new. But the steady increase in the use of cloud storage services is posing larger risks to businesses.

Schneier, in his blog post, said the continuing migration to clouds means, “we've lost control of our computing environment. More of our data is held in the cloud by other companies …”

While experts say cloud service providers frequently provide better security, that may not be true of so-called “shadow” or “rogue” use of clouds by workers who believe that is an easier way to do their jobs than going through IT.

Internet of Everything (IoE) – a hacker frontier

The Internet of Things (IoT) is so last year. It is now the IoE. Smart, embedded devices in homes, cars, electronics, machines, and worn by individuals are now mainstream. They already number in the billions, and estimates of their growth range from 50 billion by 2020 to more than a trillion within the next decade.

And that means a growing tsunami of data flowing to the Internet, where it can be sold for marketing purposes or stolen for more malicious means.

Isaacs, who says she is among those who uses an exercise wearable, said she used “dummy data” to register it. “So nobody knows it’s my data,” she said. “It can’t be mapped directly to me.”

In general, however, she said, “everyone is oversharing everything. The threats are broad and potentially catastrophic. I’m very nervous about the smart cars I see.

There does seem to be an increasing awareness of the privacy implications of smart cars. The AP reported this week that 19 automakers that make most of the cars and trucks sold in the U.S. signed on to a set of principles, delivered to the Federal Trade Commission (FTC), that seek to reassure vehicle owners that the information gathered by those vehicles, “won't be handed over to authorities without a court order, sold to insurance companies or used to bombard them with ads … without their permission.”

The vulnerabilities of “smart” devices to hacking have been demonstrated numerous times, prompting Phil Montgomery, senior vice president of Identiv to call for, “a more regimented standards-based security approach that relies less on outdates processes around username/password technology and more on stronger forms of authentication.”

No parties for third parties
This was the year that the risks of breaches through third-party contractors made it into mainstream consciousness. The Target breach, which exposed 70 million records, was just one of many that came through outside vendors.

Regulatory agencies are trying to maintain that awareness. Stephen Orfei, the new general manager of the Payment Card Industry Security Standards Council (PCI SSC) noted in a recent interview that, “security is only as good as your weakest link – which means the security practices of your business partners should be as high a priority as the integrity of your own systems.”
"Employee negligence was at an all-time high in 2014."
christine marciano

Christine Marciano, president, Cyber Data-Risk Managers
Christine Marciano, president of Cyber Data-Risk Managers, said that in addition to vetting vendors for rigorous security standards, companies should, “require their vendors to carry and purchase cyber/data breach insurance, to indemnify them for any costs associated with a data breach caused by the vendor’s negligence.”

The porous, sometimes malicious, human OS
While third parties may be a weak link in the security chain, that is less likely due to technology and more due to the human factor.

It was former National Security Agency contractor Edward Snowden who brought the risks of malicious insiders to international attention in 2013, but the danger to enterprises can be just as great from loyal insiders who are simply "clueless or careless," and fall for social engineering scams.

Joseph Loomis, founder and CEO of CyberSponse, said he is, “sure there are major companies out there with little controls over their employees and their access rights. Who is watching who and what they’re doing?”

It is also about employees controlling themselves when presented with ever-more persuasive social engineering attacks.

The federal government reported earlier this year that 63 percent of the breaches of its systems in 2013 were due to human error.

According to Marciano, “employee negligence was at an all-time high in 2014,” with the problems ranging from, “failure to perform routine security procedures to lack of security awareness, routine mistakes and misconduct.”

Eldon Sprickerhoff, cofounder and chief security strategist at eSentire, noted that, “phishing emails are getting better and better. I’ve seen some that were so well targeted, so well done that I could not tell the difference.”

And it is not just the average worker who is a problem. Identity Finder CEO Todd Feinman said the problem goes all the way to the top. “Many executives don’t know where their sensitive data is so they don’t know how to protect it,” he said.

Ubiquitous BYOD
While BYOD is now mainstream in the workplace, Isaacs calls the increased focus on mobile computing, “very scary, and it’s going to get even worse.”

BYOD is now bringing, “extremely unreliable business applications inside the walls of corporations,” she said. “There are a lot of software vulnerabilities. Every app that is free or 99 cents, probably doesn’t have great level of security. And people don’t install patches either.”

According to Clyde, “there are now many times more mobile devices than PCs in the world. In fact, in many regions of the world, mobile devices are the only way most users connect to the Internet,” yet security remains a relative afterthought.

ISACA found that, “fewer than half (45%) have changed an online password or PIN code.

And now, connected wearable devices (BYOW) are becoming common in the workplace, yet, “a majority of professionals say their BYOD policy does not address wearable tech, and some do not even have a BYOD policy,” Clyde said.

The age of Incident Response (IR)
All of the above issues have led to an increased focus on IR. According to Schneier, this is not just the year but the decade of IR, following a decade of protection products and another of detection products.

In his blog post, he cited three trends: More data held in the cloud and more networks outsourced; more APTs by nation states and; a continuing lack of investment in protection and detection, leaving the bulk of the burden on response.

But IR has been more on everybody’s lips in 2014 than even a couple of years ago. The mantra of security experts is that it is not a matter of if, but when, an organization will be breached, and that an effective IR plan (combined with detection) can make attacks more of a nuisance than a disaster.

Getting IR right is crucial, but Tom Bain, vice president of CounterTack, calls it, “the hardest job in security. You can have all the technology in place to detect, prevent and analyze, but if your workflow is broken, or the team is so inundated with incident investigation, you are still vulnerable,” he said.

More regulation, please
An industry that generally decries government regulation – retail – is now singing the opposite tune when it comes to cyber security.

A Nov. 6 letter signed by 44 state and national organizations representing retailers, addressed to the leaders of both houses of Congress, called for, “a single federal law applying to all breached entities (to) ensure clear, concise and consistent notices to all affected consumers regardless of where they live or where the breach occurs.”

Sprickerhoff said such a law would be, “a good first step. There are 38 states with different definitions of what is a breach, so things are getting a bit out of hand,” he said. “If you had unifying description of what needs to be done, that’s not a bad thing.”

Richard Bejtlich, chief security strategist, FireEye
“I worry that ‘compliance with frameworks’ attracts a lot of attention,” said Richard Bejtlich, chief security strategist at FireEye. “I would prefer that organizations focus on results or outputs, like what was the time from detection to containment?

“Until organizations track those metrics, based on results, they will not really know if their security posture is improving,” he said.

What to do?
There are, of course, no magic bullets in security. Isaacs said, noting that it’s almost impossible to say what is the biggest threat. “I heard a speech where it was described as, “death by a thousand cuts,” she said.

But experts do have suggestions. Sprickerhoff said more training is crucial, not just the security awareness of employees, but the next generation of IT security experts.

“I don’t think it’s ever been harder to find good people in IT security,” he said. “There’s not much in course work at the college level.”

Eyal Firstenberg, vice president research, LightCyber, said improving security is going to take a combination of technology and training.

“There is a need for fast and accurate alerts and notifications, which ultimately determine the outcome of these cyber engagements,” he said, but added that, “organizations need more professional diagnosticians on staff who are trained to know what threats are real and need to be addressed, and which ones aren’t.”

Ashley Hernandez, an instructor for Guidance Software, calls for more communication among organizations. “Security professionals need to have a way to share intelligence about patterns or attack types to others in their industry or trusted security groups,” she said.

Clyde notes that ISACA, “has a number of programs, from risk governance frameworks like COBIT 5 to the Cybersecurity Nexus (CSX), to ensure cybersecurity professionals have the skills they need to defend enterprises from the plethora of threats.”

Finally, Loomis offers a short list:
Improve procurement processes. “It takes too long to buy new tools,” he said.
Start educating your staff on what the DHS and NIST Frameworks really are. Read the MITRE book on the 10 strategies to a world-class SOC.
Stop believing the marketing and get real-world feedback on tools. “Security has put a lot of money into marketing, but that doesn’t mean the solution is right for the organization,” he said.
Run simulations. “When was the last time a company ran a real cyber drill?” he asked.
Stop following paper policy, “Militarizing your team, running drills, making it second nature is what will help the response process, not following a check list,” he said.



Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com