Tom Olzak

About Tom's Blog:

On surviving the unthinkable and other challenges.

See Tom's Posts
Tom Olzak

Bio

Tom Olzak is a security researcher for the InfoSec Institute and an IT professional with over 27 years of experience in programming, network engineering and security. He has an MBA as well as CISSP certification. He is currently an online instructor for the University of Phoenix. He has held positions as an IS director, director of infrastructure engineering, director of information security, and programming manager at a variety of manufacturing, health care, and distribution companies. Before joining the private sector, he served 10 years in the United States Army Military Police with four years as a military police investigator. He has written two books, "Just Enough Security" and "Microsoft Virtualization." He is a frequent contributor of security management papers for CBS Interactive and the Infosec institute.

Contact

tom [dot] olzak [at] gmail [dot] com

Latest Posts by Tom

Workarounds without data?

|   A big part of business continuity planning is making sure we have manual processes or other workarounds in place.  They act as interim bandages to keep business processes moving forward.  Many organizations, especially those required to do so by regulation, have documented processes...

Business Continuity != Best Buy * Geek Squad

|   Never trust the salesperson to provide accurate information about maintenance agreements. Always check with the actual techs to make sure you are covered against four to six week business interruptions.

Does bug-fix speed reflect browser value?

|   Is it time to move from browsers with bloated code and slow bug-fix reaction times?

White House Blowing Smoke?

|   The White House Cybersecurity Coordinator wants us to believe that breaches into national infrastructure is simple hactivism.

Data Leakage: Catching Water in a Sieve

|   Data leaking from secure to user work locations creates a big data loss vulnerability.

Stop Repeating the Same Mistakes

|   Even if a solution seemed like a good idea a few years ago, that is no reason to perpetuate something which is now known to be a security vulnerability.

Playing Catch-up, Again

|   Controlling endpoint applications (installation, patching, hardening, etc.) is a difficult but necessary component of safeguarding your data and your network.

Learning from the Attack on the Apache Software Foundation

|   Even if we don't use Linux, there are lessons to learn from what happened to Apache.

Data validation: Ignore it and you lose

|   Failing to validate data causes several serious Web application vulnerabilities.

The Cyber-Czar Challenge: Nobody Really Wants Security

|   Obama's new cyber-car position is still empty, waiting for someone willing to work with no authority and to be a target for all the blame.

Browse CSO Blogs

See all CSO Blogs »

Recent Comments

RESOURCE CENTER