This Week’s [in]Security – Issue 109 | insecurity | Control Gap
9 min read

This Week’s [in]Security – Issue 109 | insecurity | Control Gap

Welcome to This Week’s [in]Security. This week: PCI : Software Security Framework update, contactless hiccups, Breaches: Docker,, Pennsylvania PHI,...

Read More >
This Week’s [in]Security – Issue 108 | insecurity | Control Gap
7 min read

This Week’s [in]Security – Issue 108 | insecurity | Control Gap

Welcome to This Week’s [in]Security. This week: PCI Card Production program updates, Wipro outsourcer supply chain breach,new Equifax regulatory...

Read More >
This Week’s [in]Security – Issue 107 | insecurity | Control Gap
8 min read

This Week’s [in]Security – Issue 107 | insecurity | Control Gap

Welcome to This Week’s [in]Security. This week: PCI in 2019, PCI card production, NIST killing of TDES, hotel breaches, Yahoo settlement, Canadian...

Read More >
NIST is Sunsetting Triple DES - so what will the Financial Industry do?
2 min read

NIST is Sunsetting Triple DES - so what will the Financial Industry do?

NIST recently published a document "Transitioning the Use of Cryptographic Algorithms and Key Lengths" which formalizes the sunset of Triple DES by...

Read More >
This Week’s [in]Security – Issue 106 | insecurity | Control Gap
8 min read

This Week’s [in]Security – Issue 106 | insecurity | Control Gap

Welcome to This Week’s [in]Security. This week: PCI quiet, the future of card numbers, multiple breaches including AeroGrow card data, 500M resumes,...

Read More >
This Week’s [in]Security – Issue 105 - 2nd Anniversary Edition | insecurity | Control Gap
8 min read

This Week’s [in]Security – Issue 105 - 2nd Anniversary Edition | insecurity | Control Gap

Welcome to This Week’s [in]Security. This week: PCI 2019 priorities, Kubernetes and PCI, card breaches at more restaurants, breaches at Toyota,...

Read More >
This Week’s [in]Security – Issue 104 | insecurity | Control Gap
8 min read

This Week’s [in]Security – Issue 104 | insecurity | Control Gap

Welcome to This Week’s [in]Security. This week: NIST FPE update may render some deployed solutions weak, NIST formalizes TDES sunset, Magecart...

Read More >
NIST Update to Format Preserving Encryption Standard affects PCI Use Cases
4 min read

NIST Update to Format Preserving Encryption Standard affects PCI Use Cases

Last month NIST announced they were seeking feedback on a proposed updated guidance for FPE. More formally this is SP 800-38G rev 1 "Recommendation...

Read More >
This Week’s [in]Security – Issue 103 | insecurity | Control Gap
5 min read

This Week’s [in]Security – Issue 103 | insecurity | Control Gap

Welcome to This Week’s [in]Security. This week: Citrix, Ixigo, and a Chinese breach, the "creepy assignment", skepticism over Facebook's privacy...

Read More >