800-810-1885
Home > Blog

The Sword & Shield Blog

LanceNews about the company, views from our security staff.

Subscribe to our blog's RSS feed to get site updates


Cyber Group Offers Special Update on Chinese Threats on May 29

Image for Our Feedburner FeedSword & Shield Director of Computer Forensics and Security Assessments Bill Dean and Betsy Woudenberg, founder of Intelligence Arts, LLC, will be the featured speakers at a special session Wednesday, May 29.

The session, presented by the 2013 East Tennessee Cyber Security Summit Planning Committee, will discuss new information regarding Chinese hacking.

The committee is offering this session to members of the local cyber practitioner community for free if the member attended the 2012 Cyber Security Summit. Those who did not attend the summit, but who want to attend this session will be charged a $10 cash fee.

Dean and Wouldenberg will present the updated information at the Fountainhead College of Technology West campus at 10208 Technology Drive from 1 to 4:30 p.m.

Dean will discuss detailed forensics from actual cases.  He will concentrate on discovering the intrusion, preventing data loss, and effective remediation.

Woudenberg will cover China’s cyber “hacking” programs and concentrate on motivation, organization, activity, and techniques.  She is a former CIA Case Officer with years of relevant experience, and speaks to audiences around the globe about the vulnerability of SCADA systems.

The presentations are unclassified and were initially being offered exclusively to 2012 Summit attendees.  This program is NOT open to the general public. You must be invited or be a member of the cyber security community. Seating is limited for this event, so an RSVP is required.  Please email your request to attend to Pat Payne, paynepw@ornl.gov.  Your confirmation and directions will be emailed once your place is assigned.

Posted in Company News, Events | Leave a comment


Assume the Enemy is Already on Your Network and Look for Them

Bill Dean

Bill Dean

With little modification to their malicious code, Chinese hackers are back in business and U.S. companies need to assume this code is already on their IT networks.

As the information security industry is well aware, the cyber security company, Mandiant, published a paper in February detailing cyber-espionage involving the compromise and intellectual property theft of hundreds of U.S.-based companies.

Not only did the report disclose the origin of the attacks as originating from China, but actually pinpointed the Peoples Liberation Army (PLA), in detail, as the culprit. The Chinese government, with very careful wording, disputed these accusations.

Is there additional information supporting these claims of Chinese cyber-espionage on U.S. companies? As an organization that provides incident response services, our answer is, “Yes.”

When the Mandiant report was published on the heels of President Barack Obama’s executive order for “Improving Critical infrastructure Cybersecurity”,” incident responders applauded the disclosure of what was common knowledge in the incident response community.

This report brought to light to what incident response organizations have been reporting to their clients for years: China is infiltrating your computer networks for long durations of time and obtaining your valued intellectual property. The report also did a great job of simplifying the situation for the needed executive understanding from a business impact perspective.

Once the admiration of the needed disclosure was realized, the incident response community then became somewhat concerned. Over time, incident response organizations had developed successful tools and techniques for identifying this specific threat for our clients. Now that the adversary has been “ousted”, will they raise their game and change their methods making the identification more difficult?

Read More »

Posted in Security News | Tagged | Leave a comment


Caswell to Speak at Healthcare Security Summit in Los Angeles on May 21

Michelle Caswell

Michelle Caswell

Sword & Shield Risk and Compliance Consultant Michelle Caswell is among an “all-star cast” of healthcare privacy and security experts scheduled to speak at the Healthcare HITECH Privacy and Security Summit on Tuesday, May 21 at the Hilton Universal City Hotel in Los Angeles.

The Los Angeles Chapter of the Information Systems Security Association (ISSA-LA) and the Healthcare Information and Management Systems Society (HIMSS) Southern California, have partnered to hold the summit, as part of the ISSA-LA Fifth Annual Information Security Summit, The Growing Cyber Threat: Protect Your Business. The events advance ISSA-LA’s core belief that, “It takes the village to secure the village.”

According to a press release issued by the groups, the Healthcare HITECH Privacy and Security Summit will bring together leaders in privacy and security within government and private industry for a day of collaboration, networking and presentations by leading privacy and security professionals. Attendees will learn from experts what they need to know to comply with new HIPAA/HITECH rules and OCR investigations.

The U.S. Department of Health and Human Services (HHS) published the rule January 17, which modifies the privacy and security, breach notification, and enforcement regulations, now a part of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) . Covered Entities and Business Associates must be in compliance with the final rule by Sept. 23.

Read More »

Posted in Company News, Compliance, Events | Leave a comment


When Your High Walls and Wide Moats Fail

For years, organizations were instructed to diligently protect their perimeter from attackers, but this approach no longer works.

Bill Dean

Bill Dean

Sword & Shield Director of Computer Forensics and Security Assessments Bill Dean says that after many high-profile breaches, most organizations are likely already breached and must make the effort to detect the threats that are already inside.

He will present information on these advanced threats at the Middle Tennessee Cyber Summit on Wednesday, May 8 from 2:30 to 3:30 p.m. The event, held at the Middle Tennessee State University (MTSU) campus May 7-8, will address criminal, intelligence, disruptive, and information cyber threats and is scheduled to include presentations from U.S. Department of Homeland Security, the Tennessee Department of Safety and Homeland Security, the FBI, the United States Secret Service, and private sector cyber security organizations.

Online registration is closed, but walk-up registration will be available at 7.30 a.m.

Read More »

Posted in Company News, Security News, Training | Tagged , , | Leave a comment


Discovery of Confidential Records are Potential Identity Theft Danger

Sword & Shield Director of Enterprise Sales Chris Bevil tells WBIR that if confidential medical records that were found outside the now-closed Lakeshore Mental Institute were used for identity theft, it could have serious consequences.

At this point, it’s too soon to tell if this is in fact a security breach.

“We don’t actually know what happened with the information at Lakeshore. If it was actually breached and someone did take that information. There are several things per the HIPAA Breach Notification that would have to occur,” Bevil said.

Posted in Compliance, Security News | Leave a comment


Compliance and Forensics Experts Talk to Two Nashville Groups Thursday

Bill Dean

Bill Dean

Bill Dean, Sword & Shield’s director of computer forensics and security assessments, wants Nashville-area attorneys to understand how computer investigations work so that they know what information to request and how to obtain it, while Michelle Caswell, the company’s risk and compliance consultant, gives healthcare professionals the latest information on the new HIPAA Omnibus Rule on Thursday.

Dean will speak with attorneys in the Nashville Bar Association’s conference room from noon to 1:30 p.m. CST on Thursday, April 18. Registration begins at 11:30 a.m. and CLE credits are available.

“Electronic data can make or break a litigation case,” he said.

Dean will provide information regarding:

  • The value that digital forensics can provide
  • The  basics of cloud computing
  • The facts about Metadata: What is it? What information is and is not available from Metadata?
  • Why the delete key only entertains you; and,
  • The answers to key questions about cell phone forensics: What information is available? Where is it?
Caswell Headshot

Michelle Caswell

Caswell will discuss the U.S. Department of Health and Human Services’ major modifications to the Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, and Breach Notification Rules at the Cool Springs Marriott in Franklin, TN from 11 a.m. to 1 p.m. CST on April 18.Topics to be discussed include:

  • Major changes in the Breach Notification standard
  • What policies and procedures need to be revisited based on the revised Rule
  • Amending your organization’s Notice of Privacy practices
  • Training workforce and promoting an overall sense of security
  • Forms that should be updated pursuant to the revised Rule
  • Ensuring that an updated risk assessment is in place
  • Revising Business Associate contracts
  • Direct liability of Business Associates
  • Civil monetary penalties

Register here.

Posted in Company News, Compliance, Computer Forensics, Events | Leave a comment


BYOD Is Great for Business, But Is It Secure?

Law firms around the country are embracing Bring-Your-Own-Device (BYOD) programs because it allows attorneys to share information with clients quickly on their mobile devices; however, the benefits of using BYOD programs bring with them the risk of confidential client data breaches.

Sword & Shield Director of Computer Forensics and Security Assessments Bill Dean and Catherine Shuck, a senior associate with Wimberly, Lawson, Wright, Davies and Jones, PLLC, will speak to these benefits and challenges at the Knoxville Bar Association’s Law Practice Today Expo on Friday, April 12. Dean and Shuck are scheduled to speak in Room 400A at the University of Tennessee Conference Center from 10:15 to 11:15 a.m.

Dean points out that one of the biggest challenges facing legal IT is the accessing of firm data by personal applications, such as Dropbox-style transfers used to synchronize client data on everyone’s mobile devices. Legal IT must outfit mobile devices with technology that allows encrypted and secure downloads and the storage of client data accessed on the devices via email, legal applications or document repositories.

The legal and financial consequences of data breaches can be profound for a law firm and can include both a loss of reputation and a hit to the firm’s pocketbook.

Dean’s research indicates that 70 million mobile devices are lost or stolen each year and 43 percent of all mobile devices are not password protected. In his speech, Dean will provide information on how to “control the mayhem.” Sword & Shield also offers solutions to help businesses secure their mobile connectivity.

 

 

Posted in Company News, Events, Security News | Leave a comment


The New HIPAA Omnibus Rule and Your Business

Image for Our Feedburner FeedDo you know how the major amendments and additions to the HIPAA Omnibus Rule will affect your business?

Sword & Shield Risk and Compliance Consultant Michelle Caswell will tell you all you need to know at a complimentary lunch on Thursday, April 18 from 11 a.m. to 1 p.m. at the Franklin Marriott Cool Springs in Franklin, TN.

Register to learn about the U.S. Department of Health and Human Services’ major modifications to the Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, and Breach Notification Rules.

Topics to be discussed include:

  • Major changes in the Breach Notification standard
  • What policies and procedures need to be revisited based on the revised Rule
  • Amending your organization’s Notice of Privacy practices
  • Training workforce and promoting an overall sense of security
  • Forms that should be updated pursuant to the revised Rule
  • Ensuring that an updated risk assessment is in place
  • Revising Business Associate contracts
  • Direct liability of Business Associates
  • Civil monetary penalties

Your registration also provides you with a chance to win one of two $50 gift certificates to the City House restaurant in Nashville. Sword & Shield is sponsoring the lunch and the presentation at no cost to the registrants.

Free Registration

An asterisk (*) indicates a required field.







Spam Protection – Enter this word: captcha

   Contact Form Powered By Best Contact Form







Posted in Company News, Compliance, Events | 1 Comment