Showing posts with label IT security. Show all posts
Showing posts with label IT security. Show all posts

Wednesday, December 18, 2019

Kaspersky’s IT Security Calculator reveals budgets lower than average in 45% of SMBs and 50% of enterprises

Data released by the Kaspersky IT Security Calculator shows that budgets at 45 percent of SMBs and 50 percent of enterprises are below the average spend at US$205,000 for small to medium, and $8 million for enterprise businesses. This is despite a Gartner report announcing cybersecurity spending is growing year-on-year with almost 9 percent growth this year.


The Kaspersky IT Security Calculator is a free web tool that allows IT security managers to view the average budget for cybersecurity in their region and industry, as well as to compare budgets within their organization. The tool is becoming increasingly important as it allows companies to understand their position in the market and also gives them the ability to compare their budget with competitors and improve planning.

Globally, IT security budgets are demonstrating positive dynamics with a number of analyst reports showing that budgets continue to grow year over year. 


Kaspersky’s own survey of almost five thousand organizations across the world confirms this trend with 70 percent of respondents showing they expect their IT security budget to increase in the next three years. However, statistics from usage of the Kaspersky IT Security Calculator in October 2018- 2019 revealed that some businesses are not keeping up with this trend, as their IT security spending is lower than average.

Overall, budgets for SMBs were reviewed more actively (46 percent) than for enterprises (38 percent) and very small companies (16 percent). For small and medium businesses, the budget issue proves to be complicated as it’s not only about finances but also the alignment of the budget planning process. Another challenge to consider is the demands on human resources to hire experts in relevant cybersecurity risks and the protection methods needed for different business services.


“Budget planning is a very important process for companies to carefully consider as the proper investments ensure a company is ready to meet current cybersecurity challenges and threats,” said Sergey Martsynkyan, head of B2B product marketing at Kaspersky. “Though it may be a complex task which demands a deep understanding of business needs towards cybersecurity, it is important to understand how to address them and how much it can cost. At Kaspersky, we do our best to give organizations insights to help them with this process. Along with the report on IT security economics we prepare annually, the IT Security Calculator gives a glance on average cybersecurity spending as well as specific threats and advice on protection measures.”

The Kaspersky IT Security Calculator website with threat statistics and recommended protection is available, and free to use.

Thursday, December 12, 2019

SolarWinds Orion Suite v4.0 experiences Common Criteria Evaluation that includes Server Configuration Monitor, Log Analyzer

SolarWinds announced that the SolarWinds Orion Suite for Federal Government v4.0 is undergoing evaluation for Common Criteria to Evaluation Assurance Level (EAL) 2+ under the Netherlands Scheme for Certification in the Area of IT Security (NSCIB). 


The Common Criteria is an international set of guidelines and specifications designed to ensure information security products meet agreed-upon security standards for government deployments in 30 nations. Conformance is verified through laboratory evaluation and scheme certification.


SolarWinds SCM is designed to detect, track, and compare system and application changes. SolarWinds Log Analyzer allows IT professionals to collect, consolidate and manage logs. Both products are built on the SolarWinds Orion Platform, which provides a unified view and full visibility into the performance and availability of an IT environment.


“SolarWinds continues to invest in both the security of its IT products and new product development to better meet the needs of IT professionals in the public sector,” said Sandy Orlando, senior vice president of product, SolarWinds. “This year, two new products that are part of the Orion Suite, Server Configuration Monitor (SCM) and Log Analyzer, are undergoing Common Criteria evaluation for the first time.”

Wednesday, December 11, 2019

Red Hat extends security profile of its Enterprise Linux platform, renews FIPS 140-2 validation for Red Hat Enterprise Linux 7.6

Red Hat announced Tuesday the renewal of the Federal Information Processing Standard 140-2 (FIPS 140-2) security validations for Red Hat Enterprise Linux 7.6. Driven by the National Institute of Standards and Technology (NIST), FIPS 140-2 is a computer security standard that specifies the requirements for cryptographic modules -- including both hardware and software components -- used within a security system to protect sensitive information.


This renewed validation maintains and extends Red Hat’s leadership in providing mission-critical-ready open source technologies to government agencies and regulated industries, such as healthcare and telecommunications. 

With Red Hat’s FIPS 140-2 validated solutions, these industries can better meet necessary information security guidelines without compromising on the need for flexible software solutions. Red Hat maintains a strong commitment to providing open, more secure IT innovation to the public sector, with the company’s technologies now holding more than 20 active FIPS validations that meet the criteria for use by U.S. government agencies.


FIPS 140-2 validation is needed when agencies determine that specific information systems should use cryptography to protect data; if cryptography is required, then it must be validated. In order to achieve FIPS 140-2 validation, cryptographic modules are subject to testing by NIST-accredited independent Cryptographic and Security Testing Laboratories. 

The validation for Red Hat Enterprise Linux 7.6 was performed by Atsec information security corporation’s Cryptographic and Security Testing Laboratory in Austin, Texas. Atsec is an independent organization with long-standing experience in IT security standards.


In addition to the renewed certification of Red Hat Enterprise Linux 7.6, Red Hat Enterprise Linux 7.7 and Red Hat Enterprise Linux 8.1 are currently on the NIST "Implementation Under Test" list with the intent to extend FIPS 140-2 validation to the latest releases of the Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8 platforms.

Sunday, November 17, 2019

Kaspersky research finds top executives make cybersecurity decisions in two thirds of SMBs and enterprises

A recent Kaspersky study revealed that in about 65 percent of SMBs and 68 percent of enterprises, top tier management actively contributes to decisions regarding how their business protects against cyber threats. These statistics support the larger upwards trend of IT security managers being a part of IT decision making discussions. 


Additionally, C-suite involvement directly correlates to the size of IT security budgets, as companies who invest more heavily in IT security are more likely to have their executives involved in decision making processes.

The survey also reveals that there is a distinct correlation between cybersecurity budgets and top management involvement across organizations of all sizes. 

For companies with a budget of more than US$5 million, the majority (72 percent) have executives take part in the financial aspect of IT security. For companies with smaller budgets, up to $25,000 for enterprises and up to $2,500 for SMBs, the percentage of those with C-level executives involved in budget decisions is around 50 percent.


In regards to specific budget size, companies in which C-level executives are involved in cybersecurity decision making are better suited to the global cybersecurity budget pace. 

In these companies, cybersecurity spending reaches $264,000 for SMBs and $18 million for enterprises. These figures are almost equal to the average spending across all surveyed companies. For SMBs, budgets reached $267,000 in the present year compared to $256,000 in 2018, and for enterprises figures reached $18.9 million in 2019, up from $8.9 million last year.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...