<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>McAfee Security Insights Blog &#187; CTO</title>
	<atom:link href="http://siblog.mcafee.com/?cat=168&#038;feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://siblog.mcafee.com</link>
	<description></description>
	<lastBuildDate>Sat, 21 Nov 2009 00:50:48 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>How to Deal with Terrible Tuesday</title>
		<link>http://siblog.mcafee.com/?p=1346</link>
		<comments>http://siblog.mcafee.com/?p=1346#comments</comments>
		<pubDate>Fri, 16 Oct 2009 23:49:32 +0000</pubDate>
		<dc:creator>George Kurtz</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Patch Tuesday]]></category>
		<category><![CDATA[Risk Compliance]]></category>

		<guid isPermaLink="false">http://siblog.mcafee.com/?p=1346</guid>
		<description><![CDATA[I&#8217;ve seen a lot of Patch Tuesdays.  If you look back at history, the concept of updating (“patching”) the Windows operating system began with the release of Windows 98.  The term “Patch Tuesday” didn’t actually start until 2004 when the ritual became more scheduled in an attempt to reduce patch cycles.  Each month Microsoft would [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve seen a lot of Patch Tuesdays.  If you look back at history, the concept of updating (“patching”) the Windows operating system began with the release of Windows 98.  The term “Patch Tuesday” didn’t actually start until 2004 when the ritual became more scheduled in an attempt to reduce patch cycles.  Each month Microsoft would reduce a small number of “patches” to address vulnerabilities, but this week was different.  Microsoft released 13 security bulletins that cover a total of 34 vulnerabilities, the most that Microsoft has <a href="http://siblog.mcafee.com/?p=1322" target="_self">ever addressed</a> on a single Patch Tuesday. </p>
<p>According to PC World:  &#8220;Microsoft says it will deliver its largest-ever number of security updates on Tuesday to fix flaws in every version of Windows, as well as Internet Explorer (IE), Office, SQL Server, important developer tools and the enterprise-grade Forefront Security client software.”</p>
<p>Of the 13 bulletins, eight are rated “critical” by Microsoft, the company’s highest risk rating. Five are deemed “important,” one notch lower on Microsoft’s severity scale. Nine of the vulnerabilities had been previously disclosed, allowing cyberattackers a way to break into Windows systems before the fix was available.</p>
<p>This kind of craziness leads companies around the world to engage in what I call “patch panic” – security administrators and IT management scrambling to try to understand each patch, what systems might be vulnerable, what threats could exploit those vulnerabilities, potential implications to their business (and how many nights and weekends they are going to have to work).  Some companies will spend weeks trying to collect this information to make decisions on which systems to patch and many will patch systems that don’t require it.  Hours, days and weeks of productivity will be lost.  What a waste of time.</p>
<p>The good news is, it doesn&#8217;t have to be this way.  McAfee recently <a href="http://newsroom.mcafee.com/article_display.cfm?article_id=3577" target="_blank">announced</a> one of the most creative products I&#8217;ve ever been associated with – <a href="http://www.mcafee.com/risk_advisor" target="_blank">McAfee Risk Advisor</a> – the first and only risk analytics solution to eliminate the manual, time-consuming and error-prone approach associated with patching efforts.  We do this by correlating threat, vulnerability and countermeasure information to pinpoint which assets are truly at risk for a specific threat.  It works in conjunction with McAfee Labs Global Threat Intelligence and Vulnerability Manager (formerly Foundstone), as well as countermeasures such as McAfee’s Network Security Platform (formerly IntruShield), Host Intrusion Prevention and VirusScan Enterprise to provide a <a href="http://www.mcafee.com/us/enterprise/optimize/risk_advisor_demo.html" target="_blank">complete picture of risk posture</a>. </p>
<p>McAfee customers with our Host Intrusion Prevention and antivirus products had protection in place before these vulnerabilities were announced, due to our partnership with Microsoft.  Buffer overflow protection capabilities within these products mean that customers receive out-of-the box protection and are not dependent on signature updates, unlike other vendors’ offerings.  Customers using our Application Control (formerly Solidcore) have absolutely no need to patch those systems, because they are completely blocked from these vulnerabilities.  This week&#8217;s news also highlighted the most popular threat trend around malicious sites and web attacks, like last week’s Adobe PDF vulnerability.  McAfee’s Web Gateway protected our customers from these vulnerabilities even before the announcements.</p>
<p>The bottom line is that life in IT security <a href="http://www.mcafee.com/us/enterprise/optimize/" target="_blank">doesn&#8217;t have to be a huge process</a> any more – we can eliminate “patch panic” and the countless lost hours, money and downtime that most people now take for granted.  We can also reduce the number of patches that need to be applied and let you apply them when it is least disruptive &#8211; drastically reducing patching costs and risks, while improving overall system availability and security. </p>
<p>We help customers patch on their schedule, not someone else’s.</p>
<p class="addtoany_share_save_container">
    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=McAfee%20Security%20Insights%20Blog&amp;siteurl=http%3A%2F%2Fsiblog.mcafee.com%2F&amp;linkname=How%20to%20Deal%20with%20Terrible%20Tuesday&amp;linkurl=http%3A%2F%2Fsiblog.mcafee.com%2F%3Fp%3D1346" target="_blank"><img src="http://siblog.mcafee.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Save/Bookmark"/></a>

	</p>]]></content:encoded>
			<wfw:commentRss>http://siblog.mcafee.com/?feed=rss2&amp;p=1346</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remember The Past, See The Future</title>
		<link>http://siblog.mcafee.com/?p=1286</link>
		<comments>http://siblog.mcafee.com/?p=1286#comments</comments>
		<pubDate>Thu, 01 Oct 2009 16:31:35 +0000</pubDate>
		<dc:creator>George Kurtz</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Risk Compliance]]></category>

		<guid isPermaLink="false">http://siblog.mcafee.com/?p=1286</guid>
		<description><![CDATA[It is hard to believe it has been five years to the day that McAfee acquired Foundstone, the company I helped start. At the time of the acquisition I knew McAfee as a solid AV vendor – nothing more. As I reflect back on the past five years, McAfee has had some ups and downs; however, there [...]]]></description>
			<content:encoded><![CDATA[<p>It is hard to believe it has been five years to the day that McAfee acquired <a href="http://www.foundstone.com/us/index.asp">Foundstone</a>, the company I helped start. At the time of the acquisition I knew McAfee as a solid AV vendor – nothing more. As I reflect back on the past five years, McAfee has had some ups and downs; however, there has been a transformation of the company that might not be evident to the casual viewer. Like watching your children grow, you don’t always see the day-to-day change, but when you look at the last five years, it is startling.</p>
<p>Over two billion dollars in investments later, we have added some amazing technologies through our own development as well as acquisitions that include SafeBoot, Solidcore, Secure Computing, MX Logic, and the list goes on. We have added new revenue streams and have significantly decreased our dependence on selling just AV. We also have a skipper at the helm in Dave DeWalt that is not shy in <a href="http://www.nytimes.com/2009/07/06/technology/business-computing/06virus.html">making bold moves</a> to aggressively attack our competition.</p>
<p>My walk down memory lane is an interesting exercise as I contemplate the next five years of McAfee. Today I am humbled at the opportunity to <a href="http://newsroom.mcafee.com/article_display.cfm?article_id=3570">become McAfee’s worldwide CTO</a>. As the dominant player in digital security, my first goal is to drive thought leadership with our customers and prospects and to demonstrate that we have what it takes to solve complex security challenges. My second goal is to drive innovation across all our product offerings as we continue to broaden and diversify our portfolio. To achieve these goals I will be assembling the “Office of the CTO” with heavy hitting CTOs across our business units as well as our geography’s.  </p>
<p>There is much work to be done, but I am confident we will continue to beat our competition and deliver world-class security technologies to consumer, mid-market, and enterprise customers. You will be hearing a lot more from the team in the coming months so stay tuned and keep reading our blogs.</p>
<p class="addtoany_share_save_container">
    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=McAfee%20Security%20Insights%20Blog&amp;siteurl=http%3A%2F%2Fsiblog.mcafee.com%2F&amp;linkname=Remember%20The%20Past%2C%20See%20The%20Future&amp;linkurl=http%3A%2F%2Fsiblog.mcafee.com%2F%3Fp%3D1286" target="_blank"><img src="http://siblog.mcafee.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Save/Bookmark"/></a>

	</p>]]></content:encoded>
			<wfw:commentRss>http://siblog.mcafee.com/?feed=rss2&amp;p=1286</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
