CVE-2024-3400: PAN-OS Command Injection Vulnerability in GlobalProtect Gateway. Learn More

CVE-2024-3400: PAN-OS Command Injection Vulnerability in GlobalProtect Gateway. Learn More

Services
Capture
Managed Detection & Response

Eliminate active threats with 24/7 threat detection, investigation, and response.

twi-managed-portal-color
Co-Managed SOC (SIEM)

Maximize your SIEM investment, stop alert fatigue, and enhance your team with hybrid security operations support.

twi-briefcase-color-svg
Advisory & Diagnostics

Advance your cybersecurity program and get expert guidance where you need it most.

tw-laptop-data
Penetration Testing

Test your physical locations and IT infrastructure to shore up weaknesses before exploitation.

twi-database-color-svg
Database Security

Prevent unauthorized access and exceed compliance requirements.

twi-email-color-svg
Email Security

Stop email threats others miss and secure your organization against the #1 ransomware attack vector.

tw-officer
Digital Forensics & Incident Response

Prepare for the inevitable with 24/7 global breach response in-region and available on-site.

tw-network
Firewall & Technology Management

Mitigate risk of a cyberattack with 24/7 incident and health monitoring and the latest threat intelligence.

Solutions
BY TOPIC
Offensive Security
Solutions to maximize your security ROI
Microsoft Exchange Server Attacks
Stay protected against emerging threats
Rapidly Secure New Environments
Security for rapid response situations
Securing the Cloud
Safely navigate and stay protected
Securing the IoT Landscape
Test, monitor and secure network objects
Why Trustwave
About Us
Awards and Accolades
Trustwave SpiderLabs Team
Trustwave Fusion Security Operations Platform
Trustwave Security Colony
Partners
Technology Alliance Partners
Key alliances who align and support our ecosystem of security offerings
Trustwave PartnerOne Program
Join forces with Trustwave to protect against the most advance cybersecurity threats

7 Unromantic Security Comments That Could Ruin Valentine's Day

If you're out with that special someone this Valentine's Day weekend, and he or she happens to be an IT or security practitioner, they likely need a break from any job talk. Pressures have been running high lately - with a cavalcade of data breaches surely placing them on edge - so a plate of linguini with vodka sauce, a tall glass of Merlot, and some alone time with their companion might be just what the doctor ordered.

But, if discussion must turn to shop talk, try steering clear of these seven date-ruining conversational faux pas - or risk an early exit from the dinner table and, possibly, a broken heart.

1. "Relax, nobody wants to breach your company."

Why it's a bad idea to say: Attackers show no discrimination toward business size. As long as there is personal information to steal, no business - whether they're a dry cleaners or a Fortune 500 - is off-limits. And actually, the smaller the business, the potentially more at risk they are.

2. "It's not like you're the CEO. There's no pressure on you."

Why it's a bad idea to say: More and more bosses and executives are recognizing security as a business priority - not just a technical discipline. If a company is breached, the business suffers, and all eyes will turn to the captain of the IT ship.

3. "All I know is make sure your anti-virus and firewalls are in check."

Why it's a bad idea to say: Most businesses are dealing with a barrage of cyber threats on a daily basis. Sure, not all get in, but the ones that do likely evaded traditional security measures like anti-virus. More advanced technologies are necessary.

4. "Go out and get the hottest new product on the market!"

Why it's a bad idea to say: If only it were that easy. Bells and whistles aren't what organizations need, especially if they don't have staff skilled enough to even get the product off the shelf. Companies instead require a combination of proven solutions, threat intelligence and managerial expertise.

5. "Just hire more people."

Why it's a bad idea to say: This isn't terrible advice. But aside from having to plead with a security-challenged board for additional budget and head counts, IT professionals also must deal with a candidate pool that is markedly short of the skills necessary to assess and deter modern-day attacks.

6. "I just don't get it. How hard could it be to lock down a network?"

Why it's a bad idea to say: There's an old adage that security professionals need to be right 100 percent of the time, and the bad guys only once. Think of networks like Swiss cheese - with holes everywhere - and an eroding perimeter and third-party relationships only create more potential chaos.

7. "I'm sure there are rules around security. Just don't break those, and you'll be fine."

Why it's a bad idea to say: You're right. There are plenty of compliance rules and regulations around maintaining a secure environment. But those are merely the ground floor. Companies that only go as far as checking the compliance boxes are just asking for trouble.

**

Fair warning: There is a chance your date nods in agreement to some of this. Don't let them. You are now equipped to enlighten them. Yes, you.

And if you make it through dessert without them faking food poisoning, consider it a successful V-Day. Xo.

Dan Kaplan is manager of online content at Trustwave and a former IT security reporter and editor.

Latest Trustwave Blogs

Trustwave SpiderLabs Reveals the Ransomware Threats Targeting Latin American Financial and Government Sectors

Ransomware-as-a-service (RaaS) threat groups are placing severe and continuous pressure on the financial and government services sectors in Latin America, according to data compiled by the elite...

Read More

Trustwave Named a Trail Blazer in Radicati Secure Email Market Quadrant 2024 Report

Trustwave MailMarshal solidified its leadership position in the email security space, being named a Trail Blazer by the analyst firm Radicati Group in its Secure Email Market Quadrant 2024 report.

Read More

Trustwave, Telarus Announce Strategic Global Partnership

Trustwave is partnering with Telarus, a leading technology services distributor (TSD), which will allow it to leverage Trustwave’s comprehensive offensive and defensive cybersecurity portfolio and...

Read More