Thought Leader

Martin Trzaskalik, CIO, cleverbridge

Q: How are you dealing with the current spam and security threats within your organization, such as botnets, phishing, spoofing, spyware and the like?

A: " Cleverbridge employs two strategies to protect both its internal office environment and its service platform from attacks. First, we have securely configured our infrastructure, making sure that all of our systems are hardened, all the latest available patches and up-to-date anti-malware tools have been run or installed, and we only grant access rights that are absolutely necessary. Equally important, or perhaps more so, is our second strategy: user education. Phishing attacks initially were successful because they hit an unprepared and uneducated audience. This is essentially true for every emerging threat. Ensuring that the technical staff, as well as all company employees, is familiar with new threats is a key to successfully thwarting attacks. It's about being proactive versus reactive. "

More Features

Minimizing PII Exposure and Loss

The shift to e-government -- and all that comes with it, including high-speed networks, mobile computing and better information sharing -- has introduced new risks to PII.

Is Web-Hosted Software Safe for Compliance?

The latest frontier for Software as a Service (SaaS) -- software solutions hosted over the Web by another company -- is financial governance, risk management and compliance solutions. Is this safe for large organizations?

The Importance of Assessment Services and Penetration Testing

Learn how the current threat environment makes assessment services and penetration testing essential for network operators seeking to ensure that their infrastructure investment is protected.

ADVERTISEMENT

Podcast Audio Content

CIO Strategy Center is now available in audio format.

This week's feature topic is:

CIO Interview: CIO of Port of Portland, Michelle Gaines

Playtime: 7 min 59 sec

Poll

What is your No. 1 obstacle to better information security?

Corporate culture

Budgetary constraints

Incompatible legacy systems

Regulatory obstacles

Untrained IT professionals