<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ShareFile &#187; cybersecurity</title>
	<atom:link href="http://www.sharefile.com/blog/tag/cybersecurity/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sharefile.com/blog</link>
	<description>Where companies connect</description>
	<lastBuildDate>Wed, 15 May 2013 14:28:54 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>The Latest String of Cyber Attacks</title>
		<link>http://www.sharefile.com/blog/cyber-attacks/</link>
		<comments>http://www.sharefile.com/blog/cyber-attacks/#comments</comments>
		<pubDate>Fri, 10 Jun 2011 14:22:13 +0000</pubDate>
		<dc:creator>Jennifer</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data security]]></category>

		<guid isPermaLink="false">http://www.sharefile.com/blog/?p=668</guid>
		<description><![CDATA[<a href="http://www.sharefile.com/blog/wp-content/uploads/2011/06/comp_lock.png"><img src="http://www.sharefile.com/blog/wp-content/uploads/2011/06/comp_lock.png" alt="" title="cyber-security" width="250" height="150" class="alignleft size-full wp-image-669" /></a>A few weeks ago we blogged about the new proposed cyber security legislation by President Obama.  The proposal highlights voluntary assistance and information sharing framework between government and industry.  Sounds like a good idea considering the recent attacks on major corporations like Sony’s Playstation, PBS, and most recently, banking giant Citibank.  According to a recent article posted by <a href="http://www.ibtimes.com/">International Business Times</a>, Citibank confirmed today that credit card data of 200,000 of its North American customers have been hacked.

However, lawmakers aren’t so certain about the new proposed legislation, arguing that it would give the government unprecedented access to private data.  Critics say that the promotion of shared information about cyber-attacks with the U.S. Department of Homeland Security would violate laws limiting government access to private data.  According to an article in <a href="http://www.networkworld.com/">Network World</a>, the proposal will take away protection found in laws such as the Wiretap Act and the Electronic Communications Privacy Act, in favor of the proposed broad information sharing.]]></description>
				<content:encoded><![CDATA[<p><a href="http://www.sharefile.com/blog/wp-content/uploads/2011/06/comp_lock.png"><img src="http://www.sharefile.com/blog/wp-content/uploads/2011/06/comp_lock.png" alt="" title="cyber-security" width="250" height="150" class="alignleft size-full wp-image-669" /></a>A few weeks ago we blogged about the new proposed cyber security legislation by President Obama.  The proposal highlights voluntary assistance and information sharing framework between government and industry.  Sounds like a good idea considering the recent attacks on major corporations like Sony’s Playstation, PBS, and most recently, banking giant Citibank.  According to a recent article posted by <a href="http://www.ibtimes.com/">International Business Times</a>, Citibank confirmed today that credit card data of 200,000 of its North American customers have been hacked.</p>
<p>However, lawmakers aren’t so certain about the new proposed legislation, arguing that it would give the government unprecedented access to private data.  Critics say that the promotion of shared information about cyber-attacks with the U.S. Department of Homeland Security would violate laws limiting government access to private data.  According to an article in <a href="http://www.networkworld.com/">Network World</a>, the proposal will take away protection found in laws such as the Wiretap Act and the Electronic Communications Privacy Act, in favor of the proposed broad information sharing.</p>
<p><strong><strong>So what should businesses do to protect against cyber security threats?</strong></strong></p>
<p>The best method to use is a proactive approach to data security.  ShareFile’s operational data centers have security measures in place to protect data.  Third party SAS 70 Type II certification verifies that all data center facilities operate with strict security procedures.  ShareFile’s servers are protected with a dedicated firewall, which constantly scans for and protects against malicious threats.  Additionally, encryption technology, password protection, and even the ability to limit the IP addresses that may access a ShareFile account online, keep data secure and available only to authorized parties.  By taking a proactive approach, instead of a reactive approach, to data security, businesses can ensure customer data protection.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sharefile.com/blog/cyber-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Cybersecurity Legislation Proposed</title>
		<link>http://www.sharefile.com/blog/cybersecurity-legislation-proposed/</link>
		<comments>http://www.sharefile.com/blog/cybersecurity-legislation-proposed/#comments</comments>
		<pubDate>Mon, 16 May 2011 18:02:10 +0000</pubDate>
		<dc:creator>Sarah</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data security]]></category>

		<guid isPermaLink="false">http://www.sharefile.com/blog/?p=565</guid>
		<description><![CDATA[Following recent attacks on major corporations, including the breach of Sony’s PlayStation system, the Obama administration has submitted a proposal to Congress for new cybersecurity legislation for companies. The announcement of this proposal highlights a renewed focus for the White House on computer and data security as a matter of national and financial stability, although there are still many questions as to how any laws regarding corporate network security could be written or implemented.

]]></description>
				<content:encoded><![CDATA[<p>Following recent attacks on major corporations, including the breach of Sony’s PlayStation system, the Obama administration has submitted a proposal to Congress for new cybersecurity legislation for companies. The announcement of this proposal highlights a renewed focus for the White House on computer and data security as a matter of national and financial stability, although there are still many questions as to how any laws regarding corporate network security could be written or implemented.</p>
<p>Some concerns involve the possibility of actually limiting progress by writing any specific methods or requirements for protecting data and network systems into law. Any explicit stipulations may force businesses to keep dated measures in place after they have become obsolete, potentially driving resources away from the implementation of newer and more sophisticated security technology. In acknowledgement of these issues, the proposal introduced on May 12th does not recommend specific requirements but instead offers potential incentives to companies for meeting or exceeding standard expectations for security that the Department of Homeland Security will decide.</p>
<p>The reach of the Department of Homeland Security, and even the White House itself, is also a matter of discussion here. CNET reported the following regarding a comment from an unnamed Department of Homeland Security official: “If ‘industry does not come forward’ with an ‘appropriate’ standard, the draft legislation would give the government the power to ‘pick one, to create one, to modify one and choose that one. We believe that won’t be necessary.’” If this line of thinking is incorporated into law, this would leave open the possibility for the Department of Homeland Security to create and promote a standard that the Department determines to be appropriate for corporate information security.</p>
<p>Further, the New York Times reports that the Obama administration announced that under the proposed law, the Department of Homeland Security would be able to identify private organizations that are considered important to national stability and to have increased control over the computer system and networks of these companies, so that federal government could intervene in case of a security breach to prevent the spread of damage.</p>
<p>In this environment, a proactive approach to data security is best.  The ShareFile service offers a hosted solution to protect information using the same encryption technology used by online banking and ecommerce companies. Further, SAS 70 type II servers, password protection, and even the ability to limit the IP addresses that may access a ShareFile account online keep account data secure and available only to authorized parties.</p>
<p>ShareFile has recently been able to offer consistent, secure file transfer and storage where other services have failed because of our focus on infrastructure and staying up to date with changes in data protection and migration. The recent interruption in Amazon Web Services which affected many companies did not affect ShareFile clients although our servers are hosted by Amazon, because our worldwide network of servers is designed to allow data to be migrated to the healthiest server on short notice. Further, data is backed up in real time to alternate server locations to allow ShareFile to restore client data as quickly as possible in case of server failure.</p>
<p>European researchers also recently released a report on how some file transfer services compromise information security by using unique ids for files stored on their service which can be predicted and exploited to gain access to files. The method used by the services cited in the report creates ids by making incremental changes from id to id, which makes it possible to determine the pattern used. The ShareFile service employs a random string of characters too long to guess to identify and store each file, and there is always the option to require login to access any files or links created, preventing access to the file by unauthorized users even if they had a file id. If an IP address attempts 20 wrong ‘guesses’ at a file id to try to access a file, the system will lock out any attempts by that IP address to access the account or any stored files for 10 minutes.</p>
<p>For more information on how our world-class <a href="http://www.sharefile.com/ftp/large-file-transfer.aspx">large file transfer</a> and storage service can help you keep your confidential files safe, please see our website at www.sharefile.com.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sharefile.com/blog/cybersecurity-legislation-proposed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
