800-810-1885
Home > Blog

Blog

Attorneys: Be Aware When Reviewing Emails in Outlook

Bill Dean

Bill Dean, Director of Computer Forensics

I am well aware that the use of Microsoft Outlook to review email is a perceivably convenient and low cost method to review small volumes of email. However, this method is laced with potential issues that just aren’t worth the risks – and there are risks. This article will address some of these risks to hopefully encourage the use of better technology to review email, or at least educate you enough to understand the risks.

So your client produced his or her email for you to review in a PST format (Microsoft Outlook Email Database). You are already proficient in the use of Microsoft Outlook as it likely already dictates much of your day. Either you already know how to attach this file to Outlook or your “friendly” IT staff will do it for you. You have the email loaded and you are ready to begin, but before you start, let’s talk about keyword searching.

Google has been a great asset to our culture in many ways. For the litigation field, it has inadvertently educated you how to perform Boolean searches. When you search Google for “Trade secret theft” and “Case Law” in the same query, you have performed a powerful Boolean search. However, Boolean search features such as this are not as intuitive in Microsoft Outlook and require extensive effort to execute. Difficulty performing Boolean searches is the good news. The bad news is that Microsoft Outlook, by default, will not search the contents of attachments for the keywords. Your searches will only address the email fields and the contents of an email message, which could potentially omit responsive information. We will visit the danger of attachments later in this article.

The read receipt option on sent emails presents another concern. If an unread email you are reviewing has the read receipt option set, your review of that email could inadvertently send a message to the sender that the email has been read. Consider the implications for that for a moment. There is one instance in which the custodian was deceased and his widow received a read receipt “from beyond the grave”.

Read More »

Posted in Uncategorized | Leave a comment

Information Security: There’s Not an App for That

Vulnerability assessments and exploitation, like so many other areas of technology, have progressed from being understood by a few elite practitioners to being automated for the masses.

Each day information security professionals are releasing new software or improving on existing software to make identifying and exploiting network vulnerabilities easier. Unfortunately, these automated tools have produced a “there’s an app for that” attitude toward information security. Many business owners and managers believe that an automated tool can determine if  their network is secure, which is ridiculous. Information security encompasses not only vulnerability scanning and exploitation but risk management, user management, and other business processes. No automated tool can identify vulnerabilities in business processes – only a qualified information security professional can do that.

Vulnerability scanners are designed to identify specific issues in network services, operating systems, web applications and software but cannot identify vulnerabilities in the underlying vulnerability management and configuration management processes. Exploitation frameworks, like Metasploit and Core Impact, can exploit a machine but have no ability to determine the value of the data on the compromised machine or the affect the loss of that data would have on the business. In other words when it comes to information security there is not an app for that.

Read More »

Posted in Security News | Tagged , , | Leave a comment

Join Us For a Webinar with our New Partner: Prism Microsystems

Sword & Shield will host a webinar Thursday, Dec. 15 at 2 p.m. EST with its new partner, Prism Microsystems, to featuEventTrackerre EventTracker, a comprehensive security information and event management (SIEM).

EventTracker combines log consolidation and log management, real-time threat monitoring and behavioral correlation, incident management with forensic analysis, regulatory compliance and reporting, monitoring of file integrity and USB devices and performs system change audits and management with automatic remediation.

Attend the webinar and see EventTracker in action. Participants are also registered to win a Kindle Fire.

Prism CEO A.N. Ananth will host the event and will demonstrate EventTracker’s real-time log analysis and automated response to:

  • Network Attacks
  • Insider Threats
  • Security Policy Violations
  • Unauthorized Application Useage
  • Managing USB Storate Devices

If you’re an IT professional, financial executive or business manager with responsibility for regulatory compliance, risk management or technology investments, please click here to register.

Posted in Uncategorized | 1 Comment

Join Sword & Shield and Barracuda for Lunch

Sword & Shield and our vendor partner, Barracuda Networks will host a Lunch N’ Learn Thursday, Nov. 10 at Ruth’s Chris Steak House in downtown Knoxville to address the latest trends in content security, data discovery and protection and application delivery solutions to improve your company’s productivity.

Bill Dean, Sword & Shield’s director of computer forensics, will speak about the importance of eDiscovery.  Participants will also learn how to streamline backup strategies by eliminating removable media and how to achieve massive storage reductions by using data deduplication technology.  Whether it’s recovering from a single or lost file, or a hurricane-damaged building,  backups can be simplified and provide quick data recovery.

A Barracuda representative will discuss the Baracuda product line and how it can benefit your company by archiving emails for compliance readiness and how the operational efficiency of your email server can be improved by offloading email messages.  Learn how users can archive calendar items, contacts and tasks from Microsoft Exchange and other email servers, and how to eliminate the need for PST file storage.

Click Here to For More Details and to Register

Read More »

Posted in Uncategorized | Leave a comment

Job Posting: Senior Consultant, PCI Risk & Compliance

Join Sword & Shield, one of the most trusted and fastest-growing security consulting firms in the United States!Send Resumes as a Word or PDF   Attachment

Position Title: Senior Consultant, PCI Risk & Compliance

Skills: PCI Risk Assessments/Gap Analysis/Remediation Plans

Tax Term: Full Time

Pay Range: $80-$110k commensurate with experience

Length: Indefinite

Travel Required: < 50%

Telecommute: Negotiable

POSITION DESCRIPTION

Read More »

Posted in Hiring Notices | Leave a comment

Job Posting: Senior Consultant, HIPAA Risk & Compliance

Join Sword & Shield, one of the most trusted and fastest-growing security consulting firms in the United States!Send Resumes as a Word or PDF   Attachment

Position Title: Senior Consultant, HIPAA Risk & Compliance

Skills: HIPAA Risk Assessments/Gap Analysis/Remediation Plans

Location: Negotiable

Tax Term: Full Time

Pay Range: $80-$110k commensurate with experience

Length: Indefinite

Travel Required: < 50%

Telecommute: Negotiable

POSITION DESCRIPTION

Read More »

Posted in Hiring Notices, Uncategorized | Tagged | Leave a comment

Lunch at Club LeConte; Learn About Advanced Threats

Sword & Shield Director of Computer Forensics Bill Dean will discuss how both industry and government can better understand today’s advancForensic Discoveriesed threats at a Lunch N’ Learn, Friday Nov. 4 from 11:30 a.m. to 1:30 p.m. at Club LeConte.

Today’s cyber attacks are more stealthy and malicious than ever before and are programmed to remain unnoticed for as long as possible until an opportune time in the future to inflict damage. In addition, data breaches can mean the loss of reputation and revenue and result in legal expenses.

Sword & Shield analysts have discovered that many computer security breaches occur today because of the time lag between discovery of a vulnerability and installation of security patches. Simply stated: traditional anti-virus vendors continue to lag behind online criminals when it comes to detecting and protecting against new and quickly evolving Internet threats. Add this time lag to the patching schedules of diligent IT administrators, you have approximately a three month vulnerability window through which malware can be injected into the network.

“A network vulnerability assessment/penetration test determines the vulnerabilities that may be exploited in the future, while a Data Breach Threat Analysis works to determine whether or not your systems have already been compromised,” Dean said.

To reserve your seat for the Lunch N’ Learn, please RSVP by emailing forensics@swordshield.com. Space is limited and registration must be approved by Tuesday, Nov. 1.

Posted in Computer Forensics, Events | Leave a comment

Sword & Shield to Partner with MAD Security

MAD Security to Offer Security Solutions for US Government on Sword & Shield’s NASA SEWP IV Contract

Henderson, NV – October 10, 2011 – MAD Security, an information security firm that provides full-service information security solutions, services and training, announced today that it has partnered with Sword & Shield Enterprise Security to offer and implement security solutions and training for government agencies through Sword & Shield’s NASA SEWP IV contract.

Providing industry-leading customized training offerings – including The Hacker Academy, a cloud-based training system for information security professionals – and security awareness programs, in addition to MAD Security’s leading solution implementation and architecture services on SEWP IV allow agencies to learn, practice and stay up to date on the latest in information security.

“MAD Security’s comprehensive security services and training offerings have been helping government agencies reduce overall security risk and improve technology infrastructure security for years,”, said Mad Security Managing Partner Dean Pace.  “Provisioning MAD Security training and solutions on SEWP will greatly simplify the process for agencies that want to find the right methods to enhance the  protection of their critical business assets”.

“While Sword & Shield maintains core competencies in Network Security services and products, we engage in strategic partnerships with industry leading companies. Our new partnership with MAD Security will allow us to provide an even greater depth and breadth of offerings across the Federal IT landscape,” said Sword & Shield President and CEO John McNeely.

Read More »

Posted in Company News | Tagged , | Leave a comment

Sword & Shield Makes 2011 CRN Fast Growth 100 List

Sword & Shield has again been recognized as one of the top 100 fastest growing companies in the United States by Computer Reseller News (CRN) – climbing from number 72 in 2010 to No. 20 in 2011.

 With a two-year growth rate of 206 percent and a net sales revenue of $135 million, Sword & Shield secured a position on the CRN Fast Growth 100 List for the fifth time.

 CRN’s measuring stick was a company’s average percent of revenue growth between 2008 and 2010. Companies on the 2011 Fast Growth list grew in percentages that were not measured in double or even triple digits, but by the thousands.

 ”We are honored to be listed once again on the CRN Fast Growth list,” said Sword & Shield President and CEO John McNeely. “Making the list for the fifth time in a row highlights the hard work and talents of our associates. At Sword & Shield we have been focused on bringing innovative and effective security solutions to our customers for dealing with the increasing pressures of regulatory/compliance issues and the rising threat of targeted attacks to corporate networks. This recognition by CRN helps to underscore our track record of success in helping our customers deal with their IT security challenges.”

The CRN Fast Growth list is based on the financial performance of both private and publicly-held companies, including IT solution providers, system integrators, IT consultants and service providers. The selection process measures revenue generated by the sale of IT hardware and software, software licensing, custom software sales, and professional services and managed services.

Posted in Company News | Tagged | Leave a comment

Data Breach Threat Analysis Service Showcased at CyberSummit

Do you know if hidden malware is siphoning off your organization’s trade secrets, market intelligence or military defense information?

Sword & Shield Enterprise Security provides a field-tested Data Breach Threat Analysis service that can find and detect this malware with proven results. The company will showcase this service and its uses against advanced threats at the 7th Annual East Tennessee CyberSecurity Summit on Oct. 12 – 13 at the Hilton Hotel in downtown Knoxville, Tenn.

Today’s cyber attacks are more stealthy and malicious than ever before. Many attacks sneak through the traditional security defenses of Intrusion Detection Systems (IDS), Intrusion Detection Prevention (IDP) and firewalls. They are designed to remain unnoticed for as long as possible until an opportune time to inflict damage. Many of these sophisticated evasion techniques are defined as Advanced Persistent Threats (APT).

Read More »

Posted in Computer Forensics, Events | Tagged , , | Leave a comment