A visual look at Malware Networks
[Jul 28, 2011]
Thought I would share this interesting visual showing of the growth of malware delivery networks. Malware software has been around for years, but malware networks are increasing becoming a much more concentrated, dynamic and significant threat.

Infographic produced by Blue Coat Systems
What clients share about Redpoint Risk
[May 17, 2011]
I often ask my clients for a brief client testimonial to share with prospective clients. Recently I received one from a client whom I have had the great opportunity to work with for the past several years.
I have worked with Nifco America, a Japanese manufacturing company since 2007 (Initially while still at Deloitte and continuing as Redpoint Risk). Our relationship represents a fundamental goal I set as an independent consultant; to be a responsible, respected, and dependable partner.
The testimonial itself is a letter, which can be viewed here.
A selected quote from the testimonial:
“Chad is extremely knowledgeable of controls within computer system and understanding the security risks from outside and well as from within the company. I would highly recommend his services to any company looking into becoming compliant with J-SOX or just looking to improve upon the security of their systems.”
I would like to personally thank Nifco for the opportunity to work with them in the past and ongoing into the future.
‘Primitive’ Postures
[May 10, 2011]
I don't like arbitrarily assigned “risk scores” to communicate risk and security postures…
There should be no 1-5 nor Low, Medium High….. unless those qualitative or “touchy-feely” ratings as I like to call them are clearly associated and defined with concrete quantitative values.
Generic non-business example:
“I have a medium-low to medium priced car. “
That isn't very clearly defined now is it? It depends entirely on your perspective and most likely financial stance. Pretty sure Mr. Trump would find my car to be low to very-low priced. A freshly graduated college student may find my car to be medium-high to high priced.
What's the point? - The car has an MSRP of $23,195. There is a clear (quantitative) answer that anyone can understand.
Question: How confident should an organization's risk management stance be if they rank risks on a scale of 1-5?





