<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Brightfly, Inc. &#187; Low Tech Data Leakage Protection</title>
	<atom:link href="http://brightfly.com/category/analysis_and_commentary/feed/" rel="self" type="application/rss+xml" />
	<link>http://brightfly.com</link>
	<description>Enlighten Your Enterprise</description>
	<lastBuildDate>Wed, 15 Jun 2011 20:19:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Low Tech Data Leakage Protection</title>
		<link>http://brightfly.com/low-tech-data-leakage-protection/</link>
		<comments>http://brightfly.com/low-tech-data-leakage-protection/#comments</comments>
		<pubDate>Tue, 31 May 2011 21:21:58 +0000</pubDate>
		<dc:creator>bsdunlap</dc:creator>
				<category><![CDATA[Analysis and Commentary]]></category>
		<category><![CDATA[Broadcast]]></category>
		<category><![CDATA[data leakage]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[information security and privacy]]></category>
		<category><![CDATA[isc2]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://brightfly.com/?p=1646</guid>
		<description><![CDATA[Simple Ideas For Protecting Against Data Leakage On the last (ISC)2 ThinkT@nk Roundtable webcast (link to the archive is below), I had the good fortune to moderate a very interesting panel about low tech methods for securing your data. Our panelists ranged from the academic to the pragmatist. Dr. Hugh Thompson, Chief Security Strategist of [...]
<b>Related articles:</b><ol>
<li><a href='http://brightfly.com/identity-aware-data-protection-and-control/' rel='bookmark' title='Identity Aware Data Protection and Control'>Identity Aware Data Protection and Control</a> <small>Abstract: Enterprise data classification has always been a difficult task,...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<h3>Simple Ideas For Protecting Against Data Leakage</h3>
<p>On the last (ISC)<sup>2</sup> ThinkT@nk Roundtable webcast (link to the archive is below), I had the good fortune to moderate a very interesting panel about low tech methods for securing your data. Our panelists ranged from the academic to the pragmatist.</p>
<ul>
<li><a title="Hugh thompson's LinkedIn profile" href="    http://www.linkedin.com/pub/herbert-hugh-thompson-ph-d/2/1bb/3b5" target="_blank">Dr. Hugh Thompson</a>, Chief Security Strategist of <a title="People Security's Homepage" href="http://www.peoplesecurity.com" target="_blank">People Security</a></li>
<li><a title="Chris Trautwein's LinkedIn profile" href="http://www.linkedin.com/in/christrautwein" target="_blank">Chris Trautwein</a>, Information Security Officer at <a title="(ISC)2's Homepage" href="http://www.isc2.org" target="_blank">(ISC)<sup>2</sup></a></li>
<li><a title="Joe Sechman's LinkedIn profile" href="http://www.linkedin.com/in/sechman" target="_blank">Joe Sechman</a>, Director of <a title="Sunera's Homepage" href="http://www.sunera.com" target="_blank">Sunera</a>&#8216;s Attack &amp; Penetration Testing Practice</li>
</ul>
<p>What I found most exciting about the event was the sheer number of ideas being offered by the audience members. While I usually have little trouble keeping up with audience questions during these types of events, we had over 400 people in attendance and the ideas were coming at me so fast that we ran out time before getting to all of them. I want to take a minute to share more of what was going on &#8220;behind the scenes&#8221; and see if this sort of recap is useful to you. Let&#8217;s keep the discussion going. Just add your own ideas and thoughts on the roundtable in the comments section below.</p>
<ol>
<li>Being a supporter of the (ISC)<sup>2</sup> Security Leadership Program, and the sponsor of this event, it was no surprise that <a title="Link to 3M's privacy filter page" href="www.3mprivacyfilters.com/" target="_blank">3M&#8217;s privacy filters</a> were discussed as a means of guarding against &#8220;shoulder surfing&#8221;. These filters are now available for just about every mobile device on the market now and seem like a good starting point.</li>
<li>Within just a few minutes of the call, <a title="Robert Curee's LinkedIn profile" href="http://www.linkedin.com/in/robcuree" target="_blank">Robert Curee</a> from Rite-Solutions, Inc. brought up another obvious choice: laptop cable locks. I can&#8217;t even count the number of times someone at a coffee shop has asked me to keep an eye on their new MacBook while they scurried off to the bathroom. This just seems like a no-brainer for the mobile worker.</li>
<li>Martin Linda, from Siemens, then quickly added that they issue laptop bags that don&#8217;t look so much like laptop bags. Being able to hide the fact that you are even carrying a mobile device, makes you less likely to be targeted. He went on to add that at Siemens, they issue backpacks and other alternatives to traditional laptop bags with each new laptop going out.</li>
<li>Just a couple of minutes later, <a title="Jospeh Valinotti's LinkedIn profile" href="http://www.linkedin.com/pub/joseph-valinotti/5/279/552" target="_blank">Jospeh Valinotti</a> of <a title="Valdor Homepage" href="http://www.valador.com/" target="_blank">Valador</a> piped up that he encourages larger bags for travelers so that they put their personal affects in with their laptops. His theory being that this helps raise awareness because the user is also thinking about their own &#8220;stuff&#8221;, not just company assets.</li>
<li>In a spark of creativity, <a title="David Nelson's LinkedIn profile" href="http://www.linkedin.com/pub/david-nelson/b/34b/606" target="_blank">David Nelson</a> from the FDIC started attaching a small cat bell to his own laptop bag. This simple idea let&#8217;s him know when his bag is being  tampered with, even when out of sight such as when going through airport security.</li>
</ol>
<p>These first few items seem like an easy way to mitigate data theft, but the questions soon shifted toward how to implement these and other controls. Here are some of the key items we captured on the discussion.</p>
<ul>
<li>For physical security controls, such as cable locks and laptop bags, integrate with the purchasing department to ensure that every new mobile device getting released to the field comes with these basic protections.</li>
<li>Train your users on the proper use of these tools and direct them to your company policy regarding their responsibility for protecting company assets, both physical and ephemeral.</li>
<li>Not only should you reach out to purchasing, but while we were on the topic of policies, <a title="Larry Chu's LinkedIn profile" href="http://www.linkedin.com/pub/larry-chu/0/113/7ba" target="_blank">Larry Chu</a> from RS Investments reminded us of the need to include HR in the policy making decision. Especially if you use language around penalties the user could face, such as termination.</li>
<li>While we are on the topic of HR enforcement of policies, Petr McAllister mentioned a policy of &#8220;lose your laptop, lose your job&#8221; that he recalled from the CSO of Visa who imparted these words of wisdom at RSA back in 2007 or 2008 (if anyone has a link to the presentation, please send it along).</li>
</ul>
<p>Keep the ideas coming, we had a great discussion and some of the comments on the live were very encouraging.</p>
<blockquote><p>Very interesting discussion with a variety of relevant viewpoints</p>
<p>Learned a lot of new ideas to help me in preventing mobile data breaches.</p>
<p>Good presentation. Covered a wide range of issues and potential solutions.</p>
<p>Jam-packed with practical real-world tips, this was an excellent presentation!</p></blockquote>
<p>In case you wanted to watch it again, or pass it along to your colleagues, the archived event is below.</p>
<p><span id="more-1646"></span></p>
<p><object width="560" height="524" type="application/x-shockwave-flash" data="http://www.brighttalk.com/clients/flashplatform/viewer/no_channel/loader.swf"><param name="movie" value="http://www.brighttalk.com/clients/flashplatform/viewer/no_channel/loader.swf" /><param name="allowscriptaccess" value="always" /><param name="allowfullscreen" value="true" /><param name="wmode" value="transparent" /><param name="flashvars" value="channelid=5385&amp;commid=28833&amp;autoStart=false&amp;fromdc=false&amp;css=" /><a href="http://www.brighttalk.com/channel/5385">A BrightTALK Channel</a></object></p>
<p><b>Related articles:</b><ol>
<li><a href='http://brightfly.com/identity-aware-data-protection-and-control/' rel='bookmark' title='Identity Aware Data Protection and Control'>Identity Aware Data Protection and Control</a> <small>Abstract: Enterprise data classification has always been a difficult task,...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://brightfly.com/low-tech-data-leakage-protection/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>(ISC)2 Secure Metro New York</title>
		<link>http://brightfly.com/isc2-secure-metro-new-york/</link>
		<comments>http://brightfly.com/isc2-secure-metro-new-york/#comments</comments>
		<pubDate>Wed, 04 May 2011 17:28:59 +0000</pubDate>
		<dc:creator>newsdesk</dc:creator>
				<category><![CDATA[Analysis and Commentary]]></category>
		<category><![CDATA[Field Notes and Research]]></category>
		<category><![CDATA[Newsflashes]]></category>
		<category><![CDATA[Brandon Dunlap]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[IAPP]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[information security and privacy]]></category>
		<category><![CDATA[isc2]]></category>
		<category><![CDATA[Newsflash]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Security Leadership Series]]></category>

		<guid isPermaLink="false">http://brightfly.com/?p=1619</guid>
		<description><![CDATA[The CISO/CPO Partnership: Addressing Online Risks Brightfly is pleased to announce that Managing Director of Research, Brandon Dunlap will be presenting at this exciting event brought to you jointly by (ISC)² and the International Association of Privacy Professionals (IAPP) on May 10th, 2011. This event promises to be a day packed full of discussions on [...]
<b>Related articles:</b><ol>
<li><a href='http://brightfly.com/isc2-secure-san-diego-2011/' rel='bookmark' title='(ISC)2 Secure San Diego 2011'>(ISC)2 Secure San Diego 2011</a> <small>Based upon the fantastic feedback on the Competitive Compliance material...</small></li>
<li><a href='http://brightfly.com/isc2-secure-chicago-2010/' rel='bookmark' title='(ISC)2 Secure Chicago 2010'>(ISC)2 Secure Chicago 2010</a> <small>Please join Brightfly&#8217;s Managing Director of Research, Brandon Dunlap, on...</small></li>
<li><a href='http://brightfly.com/isc2-secure-chicago-2011/' rel='bookmark' title='(ISC)2 Secure Chicago 2011'>(ISC)2 Secure Chicago 2011</a> <small>The Business Model of Security: Competitive Compliance v2.0 Built  upon...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<h4>The CISO/CPO Partnership: Addressing Online Risks</h4>
<p>Brightfly is pleased to announce that Managing Director of Research, <a title="Brandon Dunlap" href="http://brightfly.com/about/brandon-dunlap/">Brandon Dunlap </a>will be presenting at this exciting event brought to you jointly by <strong>(ISC)²</strong> and the <strong>International Association of Privacy  Professionals (IAPP)</strong> on <strong>May 10th, 2011</strong>.</p>
<p>This event promises to be a day packed full of discussions on common threats and  risks to online security and privacy.</p>
<p>In addition to Brightfly&#8217;s perspective on building <strong><em>&#8220;Guardrails on the Road to the Cloud&#8221;</em></strong>, you&#8217;ll also  hear from leading members of the security community as they address recent  developments across a number of areas that include mobile  communications and social media with a focus on effective techniques for ensuring online security and privacy.</p>
<p>This event will be held at the Sheraton Newark Airport:</p>
<div id="ctl00_MainContentRegion_uxMainContentBlock">128 Frontage Road</div>
<div>Newark, NJ</div>
<div>07114&nbsp;</p>
</div>
<div>Like all Security Leadership Series events, this is a free member benefit (only $99 for non-members) and is a fantastic opportunity to   connect with your peers from the metro area.&nbsp;</p>
<p>A special thanks goes out   to all of the sponsors who make this valuable learning experience   possible through their continued support and contributions.</p>
</div>
<p>Just click the button below to register for the event. Hurry, they fill up quickly!</p>
<p><a href="https://www.cvent.com/events/securemetronewyork2011/registration-3631fc0c9858496385e37304302fcfb7.aspx" target="_blank"><img style="border: 0pt none;" title="registration_button.png" src="http://brightfly.com/wp-content/uploads/2010/01/registration_button.png.png" alt="Register Here" width="100" height="60" /></a></p>
<p><b>Related articles:</b><ol>
<li><a href='http://brightfly.com/isc2-secure-san-diego-2011/' rel='bookmark' title='(ISC)2 Secure San Diego 2011'>(ISC)2 Secure San Diego 2011</a> <small>Based upon the fantastic feedback on the Competitive Compliance material...</small></li>
<li><a href='http://brightfly.com/isc2-secure-chicago-2010/' rel='bookmark' title='(ISC)2 Secure Chicago 2010'>(ISC)2 Secure Chicago 2010</a> <small>Please join Brightfly&#8217;s Managing Director of Research, Brandon Dunlap, on...</small></li>
<li><a href='http://brightfly.com/isc2-secure-chicago-2011/' rel='bookmark' title='(ISC)2 Secure Chicago 2011'>(ISC)2 Secure Chicago 2011</a> <small>The Business Model of Security: Competitive Compliance v2.0 Built  upon...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://brightfly.com/isc2-secure-metro-new-york/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Introducing the Energy Sector Security Consortium</title>
		<link>http://brightfly.com/introducing-the-energy-sector-security-consortium/</link>
		<comments>http://brightfly.com/introducing-the-energy-sector-security-consortium/#comments</comments>
		<pubDate>Fri, 18 Feb 2011 20:07:13 +0000</pubDate>
		<dc:creator>bsdunlap</dc:creator>
				<category><![CDATA[Analysis and Commentary]]></category>
		<category><![CDATA[Brandon Dunlap]]></category>
		<category><![CDATA[EnergySec]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[NESCO]]></category>
		<category><![CDATA[Newsflash]]></category>
		<category><![CDATA[Patrick Miller]]></category>
		<category><![CDATA[SCADA]]></category>

		<guid isPermaLink="false">http://brightfly.com/?p=1549</guid>
		<description><![CDATA[Recently, I had the opportunity to sit down with Patrick Miller and some of his colleagues from EnergySec to see where they are headed and what big plans they have in store for the coming months. This interview followed shortly after and gives some terrific insights into how his team is moving forward and bridging [...]
No related articles.]]></description>
			<content:encoded><![CDATA[<p>Recently, I had the opportunity to sit down with Patrick Miller and some of his colleagues from EnergySec to see where they are headed and what big plans they have in store for the coming months. This interview followed shortly after and gives some terrific insights into how his team is moving forward and bridging the gaps in knowledge and cooperation across the various silos in IT and Information Security.</p>
<p>[Brandon Dunlap] What is “EnergySec ,“ the Energy Sector Security Consortium, chartered to do?</p>
<p>[Patrick Miller] EnergySec spawned from a group of security professionals in the electric power business in the Pacific Northwest. The group met for professional lunches and shared security information with their trusted peers. No vendors and no regulators were allowed, it was strictly limited to utility personnel. Due to the interconnected nature of the power grid, more peers from further connected utilities began showing up until we outgrew the restaurant model and had to shift to quarterly meetings. This all-volunteer army of security practitioners (including folks from physical security, information security, disaster recovery, business continuity, audit, regulatory, operations, engineering, etc) ultimately grew into a nation-wide non-profit in late 2008. The mission never changed and it is still intact today: security information sharing between trusted peers in the energy sector.</p>
<p>[BD] How are EnergySec and “NESCO,” National Electric Sector Cybersecurity Organization working together?</p>
<p>[PM] EnergySec is the parent non-profit 501(c)(3) organization, and NESCO is a DOE funded program under the EnergySec umbrella. NESCO&#8217;s mission is to lead a broad-based, public-private partnership to improve electric sector energy systems cyber security; become the security voice of the electric industry. I think is it easy to see the natural fit for NESCO under EnergySec.</p>
<p>[BD] A lot of folks from the utility sector would disagree with you about the uniqueness of their security needs. How is EnergySec fostering this collaboration and helping to bring down some of the barriers that have plagued this industry historically?</p>
<p>[PM] I think many industries suffer from the &#8220;not invented here&#8221; syndrome, but the electric sector is notorious for this. SCADA is SCADA, whether it is power, water, oil, gas, manufacturing etc. Sure, there are uniquenesses to how you manage a live industrial control system (from the management application environments to the endpoint field devices) so that you minimize potential impacts to the always-up reliability expectations but this is not unique to the electric sector.</p>
<p>[BD] How can the broader information security community lend a hand to either or both of these two organizations?</p>
<p>[PM] Security isn&#8217;t unique to the energy sector. Great security ideas, architectures and approaches are happening every day. The cross-pollination and interdisciplinary discussions are really where the value is realized. We have much to share from our experience securing both business systems as well as industrial/process control systems (SCADA), and we are open to good security ideas from anyone.</p>
<p>If you are interested, then you can join Patrick on February 22nd to learn more about the NESCO project and what it means for the electric industry.  In this informative webinar Patrick Miller, as both CEO of EnergySec and the Principal Investigator on the NESCO project, will discuss in depth:</p>
<ul>
<li>what NESCO is</li>
<li>why NESCO was created</li>
<li>NESCO&#8217;s mission and goals</li>
<li>the differences between NESCO and EnergySec</li>
<li>and the supporting role of NESCOR, funding structure, the critical role of industry, our partnerships, outreach efforts and more.</li>
</ul>
<p><strong>Date and Time:</strong> February 22, 2011 10:00 am PST</p>
<p><strong>Event number:</strong> 921 850 714</p>
<p><strong>Event password:</strong> nesco<strong> </strong></p>
<p><strong>Event address for attendees:</strong><a title="EnergySec Webinar" href="http://bit.ly/EnergySecWebinar " target="_blank"> http://bit.ly/EnergySecWebinar</a></p>
<p><strong>Call-in toll number (US/Canada):</strong> +1-408-600-3600<strong><br />
</strong></p>
<p><strong> Access code:</strong> 921 850 714</p>
<p>No related articles.</p>]]></content:encoded>
			<wfw:commentRss>http://brightfly.com/introducing-the-energy-sector-security-consortium/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Identity Aware Data Protection and Control</title>
		<link>http://brightfly.com/identity-aware-data-protection-and-control/</link>
		<comments>http://brightfly.com/identity-aware-data-protection-and-control/#comments</comments>
		<pubDate>Mon, 31 Jan 2011 22:25:33 +0000</pubDate>
		<dc:creator>newsdesk</dc:creator>
				<category><![CDATA[Broadcast]]></category>
		<category><![CDATA[access control]]></category>
		<category><![CDATA[Brandon Dunlap]]></category>
		<category><![CDATA[CA]]></category>
		<category><![CDATA[Charlie McClain]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[Gijo Mathew]]></category>
		<category><![CDATA[identity management]]></category>
		<category><![CDATA[isc2]]></category>
		<category><![CDATA[jared thorkelson]]></category>
		<category><![CDATA[Security Leadership Series]]></category>

		<guid isPermaLink="false">http://brightfly.com/?p=1541</guid>
		<description><![CDATA[Abstract: Enterprise data classification has always been a difficult task, but it has also not been enough to ensure data protection. Once classified, the appropriate controls must be in place to govern the appropriate access and use of that data. In this archived event, the last (ISC)2 ThinkT@nk Roundtable webcast of 2010, we explore the [...]
<b>Related articles:</b><ol>
<li><a href='http://brightfly.com/low-tech-data-leakage-protection/' rel='bookmark' title='Low Tech Data Leakage Protection'>Low Tech Data Leakage Protection</a> <small>Simple Ideas For Protecting Against Data Leakage On the last...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<h3>Abstract:</h3>
<p>Enterprise data classification has always been a difficult task, but it has also not been enough to ensure data protection. Once classified, the appropriate controls must be in place to govern the appropriate access and use of that data. In this archived event, the last (ISC)<sup>2</sup> ThinkT@nk Roundtable webcast of 2010, we explore the touchpoints between identity and access management with data protection and how to craft an identity aware data protection strategy.</p>
<h3>Panel of Experts:</h3>
<p>This roundtable, moderated by Brightfly Managing Director Research, Brandon Dunlap, plays host to the following security industry experts:</p>
<ul>
<li>Charlie McClain, CISSP, PhD, Professional Curriculum Vitae, Information Technology Management, <a title="Capela University Homepage" href="http://www.capella.edu/" target="_blank">Capella University</a></li>
<li>Jared Thorkelson, Principal, <a title="DLPExperts Homepage" href="http://www.dlpexperts.com" target="_blank">DLPExperts</a> and a <a title="DLP Expert Jared Thorkelson Joins As Guest Researcher" href="http://brightfly.com/dlp-expert-jared-thorkelson-joins-as-guest-researcher/" target="_self">Guest Researcher for us here at Brightfly</a></li>
<li>Gijo Mathew, Vice President, Security, <a title="CA Technologies Homepage" href="http://www.ca.com" target="_blank">CA Technologies</a></li>
</ul>
<p><object id="myChannel_1296155247" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="560" height="524" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowscriptaccess" value="always" /><param name="allowfullscreen" value="true" /><param name="flashvars" value="channelid=5385&amp;commid=24273&amp;autoStart=false&amp;fromdc=false&amp;isViewer=true" /><param name="src" value="http://www.brighttalk.com/clients/flashplatform/viewerdefault/loader.swf?" /><param name="wmode" value="transparent" /><embed id="myChannel_1296155247" type="application/x-shockwave-flash" width="560" height="524" src="http://www.brighttalk.com/clients/flashplatform/viewerdefault/loader.swf?" wmode="transparent" flashvars="channelid=5385&amp;commid=24273&amp;autoStart=false&amp;fromdc=false&amp;isViewer=true" allowfullscreen="true" allowscriptaccess="always"></embed></object></p>
<p><b>Related articles:</b><ol>
<li><a href='http://brightfly.com/low-tech-data-leakage-protection/' rel='bookmark' title='Low Tech Data Leakage Protection'>Low Tech Data Leakage Protection</a> <small>Simple Ideas For Protecting Against Data Leakage On the last...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://brightfly.com/identity-aware-data-protection-and-control/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISACA PCI Compliance Symposium</title>
		<link>http://brightfly.com/isaca-pci-compliance-symposium/</link>
		<comments>http://brightfly.com/isaca-pci-compliance-symposium/#comments</comments>
		<pubDate>Mon, 24 Jan 2011 13:00:11 +0000</pubDate>
		<dc:creator>newsdesk</dc:creator>
				<category><![CDATA[Analysis and Commentary]]></category>
		<category><![CDATA[Newsflashes]]></category>
		<category><![CDATA[blake dournaee]]></category>
		<category><![CDATA[Brandon Dunlap]]></category>
		<category><![CDATA[isaca]]></category>
		<category><![CDATA[jeff casazza]]></category>
		<category><![CDATA[jeffery sanchez]]></category>
		<category><![CDATA[Newsflash]]></category>
		<category><![CDATA[pci]]></category>
		<category><![CDATA[tim wright]]></category>

		<guid isPermaLink="false">http://brightfly.com/?p=1424</guid>
		<description><![CDATA[Please join Brightfly&#8217;s Managing Director of Research, Brandon Dunlap, as he hosts and moderates &#8220;Taking a New Look at PCI Compliance at the Start of a New Year&#8221;, a half-day virtual symposium from ISACA. This highly interactive event is being held on January 25th, 2011 and starts at 8:00am PST / 11:00pm EST. Tim Wright, [...]
<b>Related articles:</b><ol>
<li><a href='http://brightfly.com/esymposium-implementing-a-dlp-solution/' rel='bookmark' title='e-Symposium: Implementing a DLP Solution'>e-Symposium: Implementing a DLP Solution</a> <small>Please join Brightfly&#8217;s Managing Director of Research, Brandon Dunlap, as...</small></li>
<li><a href='http://brightfly.com/36th-isaca-international-conference/' rel='bookmark' title='36th ISACA International Conference'>36th ISACA International Conference</a> <small>I&#39;m in lovely downtown Toronto, ON enjoying poutine and the...</small></li>
<li><a href='http://brightfly.com/virtualization-compliance-roundtable/' rel='bookmark' title='Virtualization Compliance Roundtable'>Virtualization Compliance Roundtable</a> <small>Please join Brightfly&#8217;s Managing Director of Research, Brandon Dunlap, as...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Please join Brightfly&#8217;s Managing Director of Research, Brandon  Dunlap, as he hosts and moderates &#8220;Taking a New Look at PCI Compliance at the Start of a New Year&#8221;, a half-day virtual symposium from <a title="ISACA Homepage" href="http://www.isaca.org" target="_blank">ISACA</a>.  This highly interactive event is being held on  January 25th, 2011 and starts at 8:00am PST / 11:00pm EST.</p>
<p>Tim Wright, Senior Manager at Kingston Smith Consulting, kicks off the day with <em>&#8220;Plastic Security: An Overview of PCI DSS v2.0</em><em>&#8220;</em> where he will cover the evolution of PCI DSS from v1.2 to  v2.0, highlighting all the changes included in the new version.</p>
<p>Following the Q&amp;A with Tim, we&#8217;ll have Blake Dournaee, Product Manager from Intel, this event&#8217;s sponsor. He&#8217;ll be leading a talk titled &#8220;<em>Address PCI Compliance with Tokenization&#8221;</em>.  In this presentation, Blake will explore the benefits of leveraging tokenization as a means of reducing PCI scope.</p>
<p>Up after Blake,  we&#8217;ll have Jeffery Sanchez, a Managing Director from Protiviti. Jeffery will be presenting on the myriad of rule interpretations and the way they have changed over time in his session, <em>&#8220;Beyond 2.0, What Else is New&#8221;</em>.</p>
<p>Closing out the day&#8217;s event is an interactive roundtable discussion on <em>&#8220;Data Encryption and Trusted Execution Technology&#8221;</em>.We&#8217;ll bring Tim Wright and Jeffery Sanchez back on the line, along with Jaff Casazza, the Director of Security Technology from Intel&#8217;s Data Center Group.</p>
<p>To register your attendance to this enlightening and informative event, just click the button below.</p>
<div>
<div>
<div><a href="http://isaca.brighttalk.com/user/register" target="_blank"><img style="border: 0pt none;" title="registration_button.png" src="http://brightfly.com/wp-content/uploads/2010/01/registration_button.png.png" alt="Register Here" width="100" height="60" /></a></div>
</div>
</div>
<p><b>Related articles:</b><ol>
<li><a href='http://brightfly.com/esymposium-implementing-a-dlp-solution/' rel='bookmark' title='e-Symposium: Implementing a DLP Solution'>e-Symposium: Implementing a DLP Solution</a> <small>Please join Brightfly&#8217;s Managing Director of Research, Brandon Dunlap, as...</small></li>
<li><a href='http://brightfly.com/36th-isaca-international-conference/' rel='bookmark' title='36th ISACA International Conference'>36th ISACA International Conference</a> <small>I&#39;m in lovely downtown Toronto, ON enjoying poutine and the...</small></li>
<li><a href='http://brightfly.com/virtualization-compliance-roundtable/' rel='bookmark' title='Virtualization Compliance Roundtable'>Virtualization Compliance Roundtable</a> <small>Please join Brightfly&#8217;s Managing Director of Research, Brandon Dunlap, as...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://brightfly.com/isaca-pci-compliance-symposium/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>e-Discovery and Social Media Privacy</title>
		<link>http://brightfly.com/e-discovery-and-social-media-privacy/</link>
		<comments>http://brightfly.com/e-discovery-and-social-media-privacy/#comments</comments>
		<pubDate>Wed, 19 Jan 2011 16:57:12 +0000</pubDate>
		<dc:creator>bsdunlap</dc:creator>
				<category><![CDATA[Analysis and Commentary]]></category>
		<category><![CDATA[Prosecutions]]></category>
		<category><![CDATA[e-discovery]]></category>
		<category><![CDATA[expectation of privacy]]></category>
		<category><![CDATA[gibson dunn]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[social media]]></category>

		<guid isPermaLink="false">http://brightfly.com/?p=1385</guid>
		<description><![CDATA[Gibson Dunn have released their analysis of the state of e-discovery for 2010. It&#8217;s a lengthy read, but well worth the time invested if you are worried about e-discovery, social media, or working on a big document management project. You can download a copy of the report from Gibson Dunn&#8217;s website here. One of the [...]
<b>Related articles:</b><ol>
<li><a href='http://brightfly.com/isc2-secure-metro-new-york/' rel='bookmark' title='(ISC)2 Secure Metro New York'>(ISC)2 Secure Metro New York</a> <small>The CISO/CPO Partnership: Addressing Online Risks Brightfly is pleased to...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><a title="Gibson Dunn homepage" href="http://www.gibsondunn.com/" target="_blank">Gibson Dunn</a> have released their analysis of the state of e-discovery for 2010. It&#8217;s a lengthy read, but well worth the time invested if you are worried about e-discovery, social media, or working on a big document management project.</p>
<p>You can <a title="2010 Year End e-Discovery Report" href="http://www.gibsondunn.com/publications/Documents/2010YearEndE-Discovery-InformationLawUpdate.pdf" target="_blank">download a copy of the report from Gibson Dunn&#8217;s website here</a>.</p>
<p>One of the more interesting pieces that I gleaned from this report was the various state bar associations issuing ethics opinions on the use of social media &#8220;trickery&#8221; to gain additional information. The example cited in the report, from the New York State Bar Association, states that attorneys may view public profile pages, etc., but may not &#8220;friend&#8221; the person, nor direct a 3rd party to do so.</p>
<p>Chiling perhaps, but nothing sends as clear of a message about your online life as this quote from the report (emphasis mine):</p>
<p>&#8220;Another trend last year saw courts holding that <strong>there is no expectation of privacy or confidentiality for social networking communications</strong>. In <em>Romano</em>, for example, the court held that <strong>the production of information from social networking sites did not violate the plaintiff&#8217;s right to privacy, regardless of her chosen privacy settings</strong>, because the social networks&#8217; terms of use and their inherent nature provide no expectation of privacy.&#8221;</p>
<p>Based on a review of 323 decisions (all of which are listed in the report for your reference), this is perhaps the most comprehensive anylsis of the current state of e-discovery available.</p>
<p><b>Related articles:</b><ol>
<li><a href='http://brightfly.com/isc2-secure-metro-new-york/' rel='bookmark' title='(ISC)2 Secure Metro New York'>(ISC)2 Secure Metro New York</a> <small>The CISO/CPO Partnership: Addressing Online Risks Brightfly is pleased to...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://brightfly.com/e-discovery-and-social-media-privacy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>State of Cybersecurity from the Federal CISOs</title>
		<link>http://brightfly.com/state-of-cybersecurity-from-the-federal-cisos/</link>
		<comments>http://brightfly.com/state-of-cybersecurity-from-the-federal-cisos/#comments</comments>
		<pubDate>Wed, 05 May 2010 17:21:20 +0000</pubDate>
		<dc:creator>newsdesk</dc:creator>
				<category><![CDATA[Broadcast]]></category>
		<category><![CDATA[Newsflashes]]></category>
		<category><![CDATA[Barack Obama]]></category>
		<category><![CDATA[Brandon Dunlap]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[CISO]]></category>
		<category><![CDATA[Greg Garcia]]></category>
		<category><![CDATA[isc2]]></category>
		<category><![CDATA[John N. Stewart]]></category>
		<category><![CDATA[Michael Castagna]]></category>
		<category><![CDATA[Newsflash]]></category>
		<category><![CDATA[Security Leadership Series]]></category>
		<category><![CDATA[W. Hord Tipton]]></category>

		<guid isPermaLink="false">http://brightfly.com/?p=1156</guid>
		<description><![CDATA[This time last year, President Barack Obama, delivered the first-ever presidential speech dedicated entirely to cybersecurity. In this speech, he proclaimed that the nation’s digital infrastructure should be considered a “strategic national asset.” The fact that those words were uttered by the President of the United States have cast a new light on the ongoing [...]
<b>Related articles:</b><ol>
<li><a href='http://brightfly.com/brightfly-welcomes-john-petruzzi/' rel='bookmark' title='Brightfly Welcomes John Petruzzi'>Brightfly Welcomes John Petruzzi</a> <small>Outspoken industry veteran, John Petruzzi, joins us as Managing Director...</small></li>
<li><a href='http://brightfly.com/esymposium-implementing-a-dlp-solution/' rel='bookmark' title='e-Symposium: Implementing a DLP Solution'>e-Symposium: Implementing a DLP Solution</a> <small>Please join Brightfly&#8217;s Managing Director of Research, Brandon Dunlap, as...</small></li>
<li><a href='http://brightfly.com/isc2-secure-metro-new-york/' rel='bookmark' title='(ISC)2 Secure Metro New York'>(ISC)2 Secure Metro New York</a> <small>The CISO/CPO Partnership: Addressing Online Risks Brightfly is pleased to...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>This time last year, President Barack Obama, delivered the first-ever  presidential speech dedicated entirely to cybersecurity. In this speech,  he proclaimed that the nation’s digital infrastructure should be  considered a “strategic national asset.” The fact that those words were  uttered by the President of the United States have cast a new light on  the ongoing and pervasive risks that government, business, academic and  personal users face in the digital world.</p>
<p>Please join Brightfly&#8217;s Managing Director of Research, Brandon  Dunlap, as he moderates the latest in (ISC)<sup>2</sup>&#8216;s ThinkT@nk series: &#8220;State of Cybersecurity from the Federal CISOs-A New Perspective.&#8221; This one hour online roundtable, based on the findings of (ISC)<sup>2</sup>&#8216;s latest survey of the Government CISO community promises to be an enlightening event.</p>
<p>The live webcast is being held Thursday, May 6th, 2010 at 12:00pm EST/9:00am PST, and includes the following security luminaries on the panel:</p>
<ul>
<li><a title="Greg Carcia's LinkedIn profile" href="http://www.linkedin.com/in/gregorytgarcia" target="_blank">Greg Garcia</a>, President of <a title="Homepage of Garcia Strategies, LLC" href="http://garcia-strategies.com/default.aspx" target="_blank">Garcia Strategies</a>, LLC</li>
<li><a title="W. Hord Tipton's LinkedIn profile" href="http://www.linkedin.com/pub/w-hord-tipton-cissp-issep-cap-cisa/5/5aa/89" target="_blank">W. Hord Tipton</a>, Executive Director &amp; member of the Board of Directors (ISC)²</li>
<li>John N. Stewart, Vice President and Chief Security Officer, <a title="Homepage of Cisco Systems" href="http://www.cisco.com" target="_blank">Cisco</a></li>
<li>Michael Castagna, Vice President of Corporate Information Security, Sallie Mae</li>
</ul>
<p>To learn more about this event and to register your attendance, just click the button below.</p>
<div>
<div>
<div><a title="ThinkT@nk Registration" href="http://mediazone.brighttalk.com/event/ISC2/4ecb679fd3-3792-intro" target="_blank"><img title="registration_button.png" src="http://brightfly.com/wp-content/uploads/2010/01/registration_button.png.png" alt="Register Here" width="100" height="60" /></a></div>
</div>
</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 114px; width: 1px; height: 1px; overflow: hidden;">
<table style="height: 309px;" border="0" width="472" align="left">
<tbody>
<tr align="left">
<td style="padding-left: 5px;" valign="top">Greg Garcia<br />
President<br />
Garcia Strategies<br />
LLC</td>
<td style="padding-left: 5px;" valign="top">W. Hord Tipton<br />
Executive Director<br />
and member of the<br />
Board of Directors<br />
(ISC)²</td>
<td style="padding-left: 5px;" valign="top">John N. Stewart<br />
Vice President<br />
and<br />
Chief Security<br />
Officer<br />
Cisco</td>
<td style="padding-left: 5px;" valign="top">Micahel Castagna<br />
Vice President<br />
of Corporate<br />
Information<br />
Security<br />
Sallie Mae</td>
</tr>
</tbody>
</table>
</div>
<p><b>Related articles:</b><ol>
<li><a href='http://brightfly.com/brightfly-welcomes-john-petruzzi/' rel='bookmark' title='Brightfly Welcomes John Petruzzi'>Brightfly Welcomes John Petruzzi</a> <small>Outspoken industry veteran, John Petruzzi, joins us as Managing Director...</small></li>
<li><a href='http://brightfly.com/esymposium-implementing-a-dlp-solution/' rel='bookmark' title='e-Symposium: Implementing a DLP Solution'>e-Symposium: Implementing a DLP Solution</a> <small>Please join Brightfly&#8217;s Managing Director of Research, Brandon Dunlap, as...</small></li>
<li><a href='http://brightfly.com/isc2-secure-metro-new-york/' rel='bookmark' title='(ISC)2 Secure Metro New York'>(ISC)2 Secure Metro New York</a> <small>The CISO/CPO Partnership: Addressing Online Risks Brightfly is pleased to...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://brightfly.com/state-of-cybersecurity-from-the-federal-cisos/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Is IFRS All About Greed?</title>
		<link>http://brightfly.com/is-ifrs-all-about-greed/</link>
		<comments>http://brightfly.com/is-ifrs-all-about-greed/#comments</comments>
		<pubDate>Mon, 25 Jan 2010 16:04:12 +0000</pubDate>
		<dc:creator>bsdunlap</dc:creator>
				<category><![CDATA[Analysis and Commentary]]></category>
		<category><![CDATA[Audits and Auditors]]></category>
		<category><![CDATA[Frameworks]]></category>
		<category><![CDATA[arthur andersen]]></category>
		<category><![CDATA[arthur wyatt]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[auditors]]></category>
		<category><![CDATA[Big 4]]></category>
		<category><![CDATA[david albrecht]]></category>
		<category><![CDATA[ifrs]]></category>
		<category><![CDATA[international financial reporting standards]]></category>
		<category><![CDATA[mark adams]]></category>
		<category><![CDATA[tracy coenen]]></category>

		<guid isPermaLink="false">http://brightfly.com/?p=1118</guid>
		<description><![CDATA[Once again, our hat goes off to Tracy Coenen for her coverage over at The Fraud Files Blog. Way back in November of 2008, Brightfly Researcher Mark Adams wrote a short piece on IFRS as the new Cash Cow for the Big 4. This was a follow-on piece to his insights into the Grant Thornton [...]
<b>Related articles:</b><ol>
<li><a href='http://brightfly.com/aicpa-comes-out-in-favor-of-ifrs/' rel='bookmark' title='AICPA Comes out in Favor of IFRS'>AICPA Comes out in Favor of IFRS</a> <small>Ok, I was going to leave IFRS alone for a...</small></li>
<li><a href='http://brightfly.com/ifrs-the-new-cash-cow/' rel='bookmark' title='IFRS: The New Cash Cow'>IFRS: The New Cash Cow</a> <small>Last Friday the SEC released its new roadmap for migrating...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Once again, our hat goes off to Tracy Coenen for her coverage over at <a title="The Fraud Files Blog" href="http://www.sequenceinc.com/fraudfiles" target="_blank">The Fraud Files Blog</a>. Way back in November of 2008, <a title="Welcome Mark Adams!" href="http://brightfly.com/welcome-mark-adams/" target="_self">Brightfly Researcher Mark Adams</a> wrote a short piece on <a title="IFRS: The New Cash Cow" href="http://brightfly.com/ifrs-the-new-cash-cow/" target="_self">IFRS as the new Cash Cow for the Big 4</a>. This was a follow-on piece to his insights into the Grant Thornton survey which indicated <a title="Grant Thornton Survey Says CFOs Don't Like IFRS" href="http://brightfly.com/grant-thornton-survey-says-cfos-dont-like-ifrs/" target="_self">broad disapproval among CFO&#8217;s with IFRS</a> and a reluctance to change. You see, even back then we were debating internally as to why the big push for IFRS seemed to get so much press, despite widespread community support. Mark indicated how the push to this new standard would prop up revenues that were were slipping for SOX work as those efforts matured in Big 4 clients. We all nodded and thought it was plausible and a highly likely Astroturf campaign, then moved on.</p>
<p>Thankfully, via The Fraud Files Blog, Tracy has pointed us to a recent piece by Professor David Albrecht on how <a title="They Still Don't Get It" href="http://profalbrecht.wordpress.com/2010/01/22/they-still-dont-get-it/" target="_blank">the push to IFRS is being driven by the Big 4</a> (and the lesser firms as well). His hypothesis is that since the only organizations embracing the move seem to be the large audit firms, and that they stand in  the best position to profit from the move, that it their greed that propels this change. He goes on to quote Arthur R. Wyatt&#8217;s analysis of Arthur Andersen&#8217;s implosion as one fueled by greed, and as a canary in the coal mine perhaps, for the future for this industry. A great read, and one that lays many of pieces out in the open for deeper inspection.</p>
<p>Thanks Tracy! Keep up the good work.</p>
<p><b>Related articles:</b><ol>
<li><a href='http://brightfly.com/aicpa-comes-out-in-favor-of-ifrs/' rel='bookmark' title='AICPA Comes out in Favor of IFRS'>AICPA Comes out in Favor of IFRS</a> <small>Ok, I was going to leave IFRS alone for a...</small></li>
<li><a href='http://brightfly.com/ifrs-the-new-cash-cow/' rel='bookmark' title='IFRS: The New Cash Cow'>IFRS: The New Cash Cow</a> <small>Last Friday the SEC released its new roadmap for migrating...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://brightfly.com/is-ifrs-all-about-greed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Archer and EMC: More To The Story</title>
		<link>http://brightfly.com/archer-and-emc-more-to-the-story/</link>
		<comments>http://brightfly.com/archer-and-emc-more-to-the-story/#comments</comments>
		<pubDate>Thu, 07 Jan 2010 21:18:10 +0000</pubDate>
		<dc:creator>bsdunlap</dc:creator>
				<category><![CDATA[Analysis and Commentary]]></category>
		<category><![CDATA[Mergers and Acquisitions]]></category>
		<category><![CDATA[acquisition]]></category>
		<category><![CDATA[agiliance]]></category>
		<category><![CDATA[archer]]></category>
		<category><![CDATA[bain capital ventures]]></category>
		<category><![CDATA[ben holzman]]></category>
		<category><![CDATA[ben nye]]></category>
		<category><![CDATA[brabeion]]></category>
		<category><![CDATA[castile ventures]]></category>
		<category><![CDATA[chris caldwell]]></category>
		<category><![CDATA[chris goodwin]]></category>
		<category><![CDATA[configuresoft]]></category>
		<category><![CDATA[emc]]></category>
		<category><![CDATA[it grc]]></category>
		<category><![CDATA[itgrc]]></category>
		<category><![CDATA[jon darbyshire]]></category>
		<category><![CDATA[lockpath]]></category>
		<category><![CDATA[mcafee]]></category>
		<category><![CDATA[network intelligence]]></category>
		<category><![CDATA[openpages]]></category>
		<category><![CDATA[paisley]]></category>
		<category><![CDATA[PWC]]></category>
		<category><![CDATA[rapid7]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[yo delmar]]></category>

		<guid isPermaLink="false">http://brightfly.com/?p=1009</guid>
		<description><![CDATA[A number of people have wondered why we have been silent on EMC&#8217;s intent to purchase Archer Technologies. Well, we&#8217;ve been waiting to see what kind of vector this story developed over the coming days. Having followed Jon Darbyshire and Archer since the beginning, we wanted to take the time to look past the press [...]
<b>Related articles:</b><ol>
<li><a href='http://brightfly.com/details-on-bluelane-acquisition/' rel='bookmark' title='Details on BlueLane Acquisition'>Details on BlueLane Acquisition</a> <small>While Hoff called this one on October 10th, by linking...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>A number of people have wondered why we have been silent on <a title="Press Release-EMC to Acuire Archer Technologies" href="http://www.prnewswire.com/news-releases/emc-to-acquire-archer-technologies-leading-provider-of-it-governance-risk-and-compliance-software-80630982.html" target="_blank">EMC&#8217;s <em>intent</em> to purchase Archer Technologies</a>. Well, we&#8217;ve been waiting to see what kind of vector this story developed over the coming days. Having followed <a title="Jon darbyshire's LinkedIn profile" href="http://www.linkedin.com/pub/jon-darbyshire/3/704/179" target="_blank">Jon Darbyshire</a> and <a title="Archer Technologies Homepage" href="http://www.archer.com/" target="_blank">Archer</a> since the beginning, we wanted to take the time to look past the press releases and dig a little deeper into how this acquisition might play out for all parties involved, and specifically, what <a title="Bain Capital Ventures Homepage" href="http://www.baincapitalventures.com/" target="_blank">Bain Capital Venture</a>&#8216;s involvement may spell for the future.<span id="more-1009"></span></p>
<h3>A Timeline of Events</h3>
<p>Back in early 2005, Bain Capital Ventures and <a title="Castile Ventures Homepage" href="http://www.castileventures.com/" target="_blank">Castile Ventures</a> joined existing investors in an oversubscribed C round for Network Intelligence. The $12 million injection brought the total invested up to the $25 million mark. As part of the deal, Bain&#8217;s <a title="Ben Nye's LinkedIn profile" href="http://www.linkedin.com/in/benjaminnye" target="_blank">Benjamin Nye</a> joined the board. Just over a year later, in June of 2006, E<a title="Press Release-EMC to Acquire RSA" href="http://www.rsa.com/press_release.aspx?id=6983" target="_blank">MC announces a definitive agreement to buy RSA for around $2 billion</a>, which RSA shareholders approve on September 14, 2006. Two days later, on September 16th, <a title="Press Release-EMC Completes RSA Acquistion, Announces Acquistion of Network Intelligence" href="http://www.rsa.com/press_release.aspx?id=7317" target="_blank">EMC announces (in the same press release!) that they had a definitive agreement to purchase Network Intelligence</a> and expected to close in the next 2 days.</p>
<p>Fast forward a year and we find Ben Nye taking another board seat, this time at <a title="Rapid7 Homepage" href="http://www.rapid7.com/" target="_blank">Rapid7</a>, after Bain Capital Ventures tosses them $7 million in growth funding on September 17th. Ben Holzman, also of BCV, joined the board as well. On September 8th, <a title="Press Release-Darbyshire Joins Rapid7's Board of Directors" href="http://www.rapid7.com/news-events/press-releases/2009/2009-darbyshire.jsp" target="_blank">Jon Darbyshire also secures a place at the big boy&#8217;s table</a>. A month later, in a what appears to be a growing trend for open source security tools, <a title="Press release-Rapid7 Acquires Metasploit" href="http://www.rapid7.com/news-events/press-releases/2009/2009-rapid7-acquire-metasploit.jsp" target="_blank">Rapid7 swoops in and buys Metasploit</a>, effectively underwriting its continued development.</p>
<p>By the second week of November we see <a title="Sramma Mitra Deal Radar: Archer Technologies Nov 2008" href="http://www.sramanamitra.com/2008/11/18/4568/" target="_blank">Bain Capital Ventures form a &#8220;strategic partnership with Archer Technologies which includes an estimated $29 million infusion</a> (we&#8217;ve heard numbers as high as $42 million), netting them a 40% stake in the Overland Park, KS firm. As part of the deal, <a title="Press Release-Archer Announces Strategic Partnership with Bain Capital Ventures" href="http://www.archer.com/company/pressreleases/2008/baincapitalventures.html" target="_blank">Ben Nye secures a seat on Archer&#8217;s board</a>. Shortly after the ink on the deal dries, <a title="Press Release-Archer Announces Acquistion of Brabeion Software" href="http://www.archer.com/company/pressreleases/2009/acquisition.html" target="_blank">Archer announces that they are taking out ailing  PwC spin-off and GRC player Brabeion</a> at a fire sale price (around the $10 million invested by <a title="Longworth Venture Partners Homepage" href="http://www.longworth.com/" target="_blank">Longworth</a> and <a title="Fairhaven Capital Homepage" href="http://www.fairhavencapital.com" target="_blank">Fairhaven</a>), closing the deal on January 22nd, 2009. This deal is largely seen as a content play by Archer to roll Braebion&#8217;s ESAS-based controls library into the SmartSuite Framework. Braebion CEO <a title="Julian waits LinkedIn Profile" href="http://www.linkedin.com/pub/julian-waits/0/6a/497" target="_blank">Julian Waits</a>, along with about 25% of his employees, joins Archer. Interestingly, <a title="Yo Delmar's LinkedIn profile" href="http://www.linkedin.com/pub/yo-delmar-mcdonald/1/277/b50" target="_blank">Yo Delmar</a>, Braebion&#8217;s CMO, doesn&#8217;t take the bait and moves on to EMC within a few months as their Director of Strategic Offer Marketing.</p>
<p>By the end of the quarter, <a title="Press Release-Acher Announces Rapid7 As An Integration Partner" href="http://www.archer.com/company/pressreleases/2009/archer-gains-market-momentum.html" target="_blank">Archer announces that Rapid7 has joined as an integration partner</a>, further deepening the ties between the two organizations. At around the same time, <a title="Press Release-Archer Announces UCF Integration" href="http://www.unifiedcompliance.com/what_is_ucf/press/archer.html" target="_blank">Network Frontiers and Archer announce the integration of the Unified Compliance Framework into the SmartSuite Framework</a>, which leads us to question Archer&#8217;s content strategy as they are still struggling to choke down the 6000+ controls they inherited in the Brabeion deal.</p>
<p>By May of 2009, <a title="Press release-EMC Acquires Configuresoft" href="http://www.emc.com/about/news/press/2009/20090527-01.htm" target="_blank">EMC has announced the purchase of Configuresoft</a>. Configuresoft had hitched their wagon to the virtualization engine prior to the acquisition,  a smart move as traditional configuration management vendors began to follow suit. Configuresoft was then folded into the Resource Management Software Group at EMC, quite a distance from the RSA side of the house, firmly ensconcing the products in the management, not security and compliance, side of the business.</p>
<p>Still nursing a hangover from the 2010 New Year and we see EMC&#8217;s announcement to buy Archer. While we knew that this was brewing for a while, we thought the hurdles that EMC had placed in front of Archer would cause the deal to drag out a bit longer. Rumor has it that the deal was supposed to be announced and closed prior to the 2009 year end. Obviously, this is one of the facets of the deal that points to the &#8220;definitive agreement to acquire&#8221; as opposed to an outright acquisition announcement but is a press relations tactic employed by EMC regularly so is of little insight on its own.</p>
<h3>What Does All of This This Mean?</h3>
<p>We think that EMC/RSA might have difficulty with this acquisition. By placing the Configuresoft product line where they did, we think the silos in a company of their size will make any hope of integration between those products and the Archer SmartSuite Framework more difficult, if not impossible (<a title="Chuck Hollis' Blog-EMC to Acquire Archer" href="http://chucksblog.emc.com/chucks_blog/2010/01/emc-to-acquire-archer.html" target="_blank">depiste what Chuck Hollis says</a>). This is further exacerbated by the existing relationships that Archer has with security configuration (nCircle and NetIQ) and vulnerability scanning vendors (Qualys and rapid7 to name just a couple)  where integration has already happened.</p>
<p>The ITGRC space has seen it&#8217;s fair share of acquisitions that bring together <a title="Brightfly-Event vs. State Driven Security" href="http://brightfly.com/event-vs-state-driven-security/" target="_blank">state-based security and IT GRC reporting, much as we have seen the SEIM market do with event-based security</a>. We saw McAfee pick-up Preventsys (R.I.P.), an integration partner of Foundstone&#8217;s when they closed that deal and we have watched Symantec&#8217;s Control Compliance Suite do a reasonable job of making good on their BindView acquisition. Most recently, we watched <a title="Press Release-Lumension Acquires Security Works" href="http://www.lumension.com/Press---Events/Press-Releases/Lumension-Acquires-Securityworks-to-Deliver-an-Int.aspx" target="_blank">Lumension climb up the stack by acquiring Dallas-based Security Works</a> to layer onto their vulnerability and endpoint solutions.</p>
<p>Another contributing factor in the hot mess of post-acquisition integration is around Documentum. A number of large organizations are still storing audit testing and controls information in document-centric systems such as SharePoint or even the purpose built solutions such as those from Paisley (now <a title="Pasiley Homepage of ThompsonReuters" href="http://paisley.thomsonreuters.com/" target="_blank">ThompsonReuters</a>) and <a title="OpenPages Homepage" href="http://www.openpages.com" target="_blank">OpenPages</a> (built on PwC&#8217;s Internal Controls Workbench) which have historically shown little to no integration with compliance automation products.</p>
<p>Considering the deep involvement of Bain Capital Ventures in this deal, along with the cross-pollination of board seats and personal/professional history among the players, it would come as no surprise to see RSA pick up Rapid7 in a wired deal to accelerate the automation of state-based device compliance reporting while they figure out the rest of the integration story.</p>
<p><a title="Rook Blog-EMC &amp; Archer Pave Way for 2010 Consolidation" href="http://www.rookconsulting.com/insight/emc-archer-pave-way-for-2010-consolidation" target="_blank">We also agree with the guys over at Rook that this might mark a bit of a thaw in security deals.</a> The  price tag (rumored to be anywhere from $120 million to <a title="TechCrunch Coverage and Comments" href="http://www.techcrunch.com/2010/01/04/emc-to-acquire-it-risk-and-compliance-software-developer-archer-technologies/" target="_blank">$225 million</a>) has woken the sleeping VC giants which have started sniffing around this space for interesting start-ups to fund. Specifically, <a title="Thomas Weisel venture Partners Homepage" href="http://www.twvp.com" target="_blank">Thomas Weisel Venture Partners</a>, who has a good bit wrapped up in <a title="BigFix Homepage" href="http://www.bigfix.com" target="_blank">BigFix</a> could arrange a marriage with an up-and-coming IT GRC player or maybe even an established one such as <a title="Agiliance Homepage" href="http://www.agiliance.com/" target="_blank">Agiliance</a> who already has an integration story. Speaking of Agiliance, with their partnership with McAfee, and McAfee&#8217;s churn around IT GRC we think that their integration story holds some weight in the context of state-based security and compliance management and could be picked up fairly easily. A start-up in the space that bears mention is <a title="Lockpath Homepage" href="http://www.lockpath.com" target="_blank">Lockpath</a>. Founded by two early members of the Archer team, <a title="Chris Caldwell's LinkedIn profile" href="http://www.linkedin.com/pub/chris-caldwell/13/177/4a0" target="_blank">Chris Caldwell</a> and <a title="Chris Goodwin's LinkedIn profile" href="http://www.linkedin.com/in/hicmndr" target="_blank">Chris Goodwin</a> have deep experience in this market and were recently named <a title="Lockpath Named Microsoft Startup of the Day" href="http://www.microsoftstartupzone.com/Blogs/Microspark-BizSpark-Startup-of-the-Day/Lists/Posts/Post.aspx?ID=130" target="_blank">Microsoft Start-up of the Day</a>.</p>
<p>From the client side of the equation, you rest assured that this has put a chilling effect on burgeoning integration Symantec was working on whereby they were pumping CCS data into the Archer SmartSuite Platform, bypassing their own dashboard. We also think that Archer&#8217;s fragmented content strategy will create some issues as RSA figures out how and what to pile into the platform which could drive some simplification in the long term but some pain in the here and now.</p>
<p><b>Related articles:</b><ol>
<li><a href='http://brightfly.com/details-on-bluelane-acquisition/' rel='bookmark' title='Details on BlueLane Acquisition'>Details on BlueLane Acquisition</a> <small>While Hoff called this one on October 10th, by linking...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://brightfly.com/archer-and-emc-more-to-the-story/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Overstock.com CEO Backhands Grant Thornton</title>
		<link>http://brightfly.com/overstock-ceo-backhands-grant-thornton/</link>
		<comments>http://brightfly.com/overstock-ceo-backhands-grant-thornton/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 20:07:11 +0000</pubDate>
		<dc:creator>bsdunlap</dc:creator>
				<category><![CDATA[Audits and Auditors]]></category>
		<category><![CDATA[Defections]]></category>
		<category><![CDATA[black friday]]></category>
		<category><![CDATA[Grant Thornton]]></category>
		<category><![CDATA[henry blodget]]></category>
		<category><![CDATA[OSTK]]></category>
		<category><![CDATA[Overstock.com]]></category>
		<category><![CDATA[patrick byrne]]></category>

		<guid isPermaLink="false">http://brightfly.com/?p=980</guid>
		<description><![CDATA[In a blow-by-blow rebuttal to Grant Thornton&#8217;s letter to the SEC last week, Overstock.com&#8216;s Chairman &#38; CEO, Patrick Byrne, laid it all out in a very public way via a press release. A bit on the ugly side, but a fascinating look inside the interaction between a board and their auditor. It has devolved into [...]
No related articles.]]></description>
			<content:encoded><![CDATA[<p>In a blow-by-blow rebuttal to <a title="Grant Thornton's Letter to the SEC" href="http://sec.gov/Archives/edgar/data/1130713/000110465909066580/a09-34089_2ex16d1.htm" target="_blank">Grant Thornton&#8217;s letter to the SEC</a> last week, <a title="Overstock.com's Stock Price via Google Finance" href="http://www.google.com/finance?chdnp=1&amp;chdd=1&amp;chds=1&amp;chdv=1&amp;chvs=maximized&amp;chdeh=0&amp;chdet=1259614800000&amp;chddm=1173&amp;chls=IntervalBasedLine&amp;q=NASDAQ:OSTK&amp;ntsp=0" target="_blank">Overstock.com</a>&#8216;s Chairman &amp; CEO, Patrick Byrne, laid it all out in a very public way via a <a title="Overstock.com Chairman and CEO Corrects Misstatements in Grant Thornton Letter to SEC" href="http://finance.yahoo.com/news/Overstockcom-Chairman-and-CEO-prnews-2353150509.html?x=0&amp;.v=1" target="_blank">press release</a>. A bit on the ugly side, but a fascinating look inside the interaction between a board and their auditor. It has devolved into an outright pissing match (<a title="Overstock: Actually, Grant Thornton Is Lying" href="http://finance.yahoo.com/news/Overstock-Actually-Grant-siliconalley-774766593.html?x=0&amp;.v=3" target="_blank">Henry Blodget</a>&#8216;s term) between the two companies, with both sides accusing the other of lying.</p>
<p>What is particularly alarming about this whole affair (other than the openness of the mudslinging), is the size of the drop in OSTK&#8217;s value on Friday the 30th. Gapping up on Monday the 23rd and hitting a high that day of $16.37, it has since given up over $2.00 in two sharp drops. The first was in the early hours of trading on Tuesday (from $16.18 to $15.50), after Mr. Byrne&#8217;s press release hit the wires. Just before the markets closed for the Thanksgiving holiday, OSTK was at $15.30. However, on Friday, the 27th, it opened down at $14.42 and has continued to hover below $14.50 today. Black Friday will forever mean something else within the walls of Overstock.com I suspect. All of this, despite their marketing engine churning out multiple releases regarding holiday promotions.</p>
<p>Perhaps airing your audit issues so openly, and through press releases, should be reconsidered as a strategy.</p>
<p>No related articles.</p>]]></content:encoded>
			<wfw:commentRss>http://brightfly.com/overstock-ceo-backhands-grant-thornton/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
<!-- This Quick Cache file was built for (  brightfly.com/category/analysis_and_commentary/feed/ ) in 1.56757 seconds, on May 18th, 2012 at 8:34 am GMT+7. -->
<!-- This Quick Cache file will automatically expire ( and be re-built automatically ) on May 18th, 2012 at 9:34 am GMT+7 -->
