NetWorks Group Blog

Cisco UCS Central Software - Critical Vulnerability Advisory

Posted by NetWorks Group on May 8, 2015 9:08:00 AM

Affected Product
Cisco UCS Central Software versions 1.2 and earlier

If you are currently running Cisco UCS Central Software you should update the software immediately.

Read More

Topics: Device Management, Information Security, Threat Advisory

PCI's Bold Move to Define Penetration Testing

Posted by Mike Stailey on Apr 7, 2015 11:14:00 AM

In March 2015, the PCI Council released their Information Supplement for Penetration Testing Guidance.  This is a fantastic move as previous guidelines were centered on the completion of penetration tests and left the methodology for completing those up to the auditor.  With this guidance in place, we now have a clear definition to what qualifies as a penetration test in the eyes of the Council.  There isn’t a need to rehash the document for you here, and I encourage everyone to read it.  I would like to focus on a few key highlights that I’m happy to see added.

Read More

Topics: Ethical Hacking, Compliance, Penetration Testing

Nails in the Coffin: What put SSL in the grave?

Posted by Aaron Pohl on Mar 19, 2015 2:09:00 PM

In light of new PCI-DSS requirements stating that SSLv3 no longer meets the specification for “strong cryptography” prescribed by PCI standards, we wanted to give you a brief history of how the industry got here and why SSLv3 is no longer considered secure.

Read More

Topics: Ethical Hacking, Information Security, Security Architecture Review, Penetration Testing

Red Teaming - Is it right for you?

Posted by Michael Walker on Jan 28, 2015 4:17:00 PM

In this post, I'd like to talk about how to actually apply the concept of “red teams” in your enterprise.  First, and foremost, red teaming for cyber security refers to the concept of a small team of hackers reviewing an organization to determine if they can gain access to critical assets.  This may not sound much different than a penetration test, but one crucial piece is almost non-existent in a red team exercise:  scope.  A red team will utilize a web application, mobile platform, physical, social engineer, and network tester as part of a team whose goal is to profile the organization and gain access.

Read More

Topics: Security Monitoring, Managed Detection & Response, Ethical Hacking, Penetration Testing

Vulnerability Management - A Call to Arms

Posted by Aaron Pohl on Jan 13, 2015 11:09:00 AM

I had a completely different article typed up, however after catching up on my morning news and seeing a huge amount of controversy regarding Coordinated Vulnerability Disclosure (CVD) from Microsoft, I decided to reach out to the NetWorks Group Community and help our customers (past, current, and prospective) understand what that means to them.

Read More

Topics: Managed Detection & Response, Ethical Hacking, Vulnerability Management, Threat Management

Penetration Testing for the Executive

Posted by NetWorks Group on Dec 16, 2014 10:19:00 AM

Whether you are a veteran security executive who has received hundreds of penetration testing reports, or a part-time security manager whose primary roles lay in traditional business management, it can be difficult to decipher the encrypted text held within some penetration testing reports.  The problem exists because there is not a standard for penetration testing reporting inside of the industry.  I’ve seen literary works that range anywhere from Dr. Seuss to William Shakespeare.  I have peer reviewed reports for associates whose bad grammar could make a first grader wince.  The goal here is to identify what makes a penetration test report good, how to interpret the results, and finally how to put them to use in your strategic planning to improve organizational security.

Read More

Topics: Ethical Hacking, Penetration Testing

NetWorks Group is Proud to be Sponsoring BSides Detroit 2013

Posted by NetWorks Group on Jun 6, 2013 9:48:00 AM

IT Security is thriving in the Detroit Metro area and we're proud to be sponsoring BSides Detroit 2013 this year!  Security BSides is an innovative new un-conference style meetup that brings local security professionals together to share experiences, knowledge, and network.

Read More

Topics: Information Security, Events

Twitter Adds Two-Factor Authentication for Users

Posted by NetWorks Group on May 24, 2013 9:57:00 AM

After a string of high-profile account compromises that included the Associated Press and Burger King, Twitter has added an additional (but optional) layer of authentication to help protect users from being the next big-name account that's compromised.

Read More

Topics: Information Security, Security Architecture Review

Failing Gracefully: Using AWS for Web Site Failover

Posted by NetWorks Group on May 13, 2013 1:42:00 PM

When it comes to the Internet, keeping your organization's presence online is crucial to the accessibility of resources for customers, potential and existing. At NetWorks Group, we understand that despite the best of intentions and planning, downtime will likely still occur, at least a few minutes per year. Many teams put forth a goal of 100% uptime for their web site, but often get a dose of reality when a large storm hits their data center or other issues pop-up that may be out of their direct control. To this end, we wanted a way to minimize full-downtime so that our presence on the Internet would only be down as minimally as possible, without going over-the-top on infrastructure to do so.

Read More

Topics: Information Security

NetWorks Group is Hiring: Come Join Our Team!

Posted by NetWorks Group on May 6, 2013 9:17:00 AM

If you're a fan of delicious restaurants, awesome concert venues, Big 10 sports, or just a bike-friendly city, then you should probably be working with us in beautiful downtown Ann Arbor, Michigan. The team at NetWorks Group works at the corner of Main and Huron, a central-point to blocks of great places to shop, eat, and relax at. Located a short distance from the University of Michigan, NetWorks Group benefits from the feeling of both a college-town and an active business hub for southeastern Michigan. For a vibrant mixture of cultures, architecture, and activities, Ann Arbor is hard to beat!

Read More

Topics: Security Monitoring, Managed Detection & Response, Ethical Hacking, Device Management, Information Security, Threat Hunting, Vulnerability Management, Security Architecture Review, Compliance, Penetration Testing, Incident Response, Threat Management

Subscribe to our blog!