One of the most common complaints I hear from information security
executives in large organizations is that they are constantly playing
defense, not offense. Their network security apparatus is designed to
wait for an attack, see if it’s successful and, if it is, to plug the
hole, then repeat.


By Nick Selby (Managing Director,
Trident Risk Management)

Vulnerability assessment vendor Rapid7
has announced the first of a series of steps to integrate its
penetration testing and vulnerability assessment scanning products. The
first step is a module that allows users of the Metasploit Framework,
which Rapid7 acquired in October to natively import NeXpose scanner results and then take automated action against vulnerabilities MSF is capable of attacking.


As an analyst, and now as a consultant, I raise issues of digital
and physical security: let’s talk about them, in plain terms, and
collectively move to do something. As a member of the security
digerati, I think we should be helping people, and we have to either
step up with a better way forward, or get the hell out of the way.