by Felicien | May 20, 2019 | Education
Cyber attackers are highly motivated to obtain or corrupt your company’s data. But whether their motivation is to steal your funds outright, hold your data for ransom, practice espionage, or simply disrupt your business, most hackers cannot access your network without an “in.”
In other words, they require a login, personal access codes, or network access through malware to initialize their breach. Unfortunately, a recent report released by Verizon has concluded that 93% of the time, a cyber attacker’s “in” comes to them in the form of a social engineering attack on your employees.
The only way to prevent such breaches in your security is with proper cybersecurity training.
What is a social engineering attack?
Social engineering attacks are frankly less high-tech than traditional cyber attacks by highly knowledgeable tech criminals. In other words, they don’t require the extensive knowledge and tools needed to directly hack a highly protected computer system out of nowhere.
Social engineering attacks are more like street scams — only they’re usually done online or sometimes, over the phone. These scams use human psychology to fool individuals into willingly giving up sensitive information. In the case of your business, the targets are your employees.
There are several types of these attacks, including “phishing” and “pretexting,” which are quite similar and often go hand-in-hand. Phishing emails, however, remain the most common type of social engineering scam.
What are phishing emails?
In short, a phishing scam might be an email sent to the employees of your company that looks legitimate. It might (appear to) be from the employee’s bank, for example. It might request that your employee “click here” and login to (what looks like) the bank website so that the bank can “update your information” or “confirm your identity.”
A phishing email might also promise something to the recipient: “Here’s your free 50% off coupon! Click here!” or use a so-called emergency to illicit fear: “Someone has hacked your account. Click here to get it back.”
If your employee does indeed click on the malicious link of a phishing email, they will likely be taken to a blank or uninteresting page. In the meantime, however, the link click will have initiated the installation of malware onto the employee’s computer. This malware then enables the hacker to obtain sensitive information or disrupt or damage your company’s data.
How can company’s prevent phishing scams?
The reputational implications of any type of security breach — even one that doesn’t actually corrupt or steal your data or funds — can be enormous. Of course, it goes without saying that if you are caught in the crosshairs of a data ransom or cyber theft, the financial implications will be equally devastating.
As we’ve learned from the Verizon report, most security breaches are linked with phishing. Therefore, cybersecurity training for your employees is the best preventive solution you have for stopping security breaches before they start.
Employee training is not expensive, yet it is highly effective. Your employees should learn the following throughout their ongoing training:
How to identify a range of phishing and pretexting scams
How to proceed should they find an email, phone call, or social request suspicious
Your company’s strict policies and procedures for communication (for example, “We would never send emails requesting personal information from our employees as this would only be done in person.”)
Notice of increased risks for phishing scams around the holidays
Notice of the most recent and common scams currently trending
Cybersecurity training should be frequent and come at regular intervals throughout the year as attack strategies often come randomly in spurts and habitually change tactics.
While cybersecurity training is your best line of defense when it comes to phishing and security breaches, it’s also important to hire a reputable IT managed service provider (MSP) to handle your network and security. Your MSP should have experience and broad skill in protecting their clients from network breaches. Contact qualified MSPs in your area today to learn more about protecting your business from cyber attacks.
by Felicien | May 20, 2019 | Education
Moving from hardware solutions to software solutions isn’t a new concept for technology professionals, but network infrastructure has traditionally been a hardware-focused world even as applications move to the cloud. With the introduction of SD-WAN, or Software-Defined Wide Area Networks, IT professionals find themselves needing to retool their understanding of flexible networks and security. The MPLS (Multiprotocol Label Switching) has been in use for decades and is an extremely reliable — yet pricey — option for connectivity. Today’s SD-WAN provides the modern organization with the flexibility, scalability, security and efficiency needed to stay competitive in a fast-changing world.
The Basics of SD-WAN
At its most basic, you can think of SD-WAN as a way to tie together a variety of disparate networks as it is equally efficient with internal as well as external internet and even cloud-based applications. Instead of a more rigid WAN network, SD-WAN allows you to configure your network quickly from a centralized location, reducing the potential of human error that can bring your network to its knees and productivity to a screeching halt. Since all variables are driven by software that you configure, this structure can be quickly scaled and new remote locations added without requiring an intense investment in time and physical hardware or redesign.
How Do You Manage a Software-Defined Network?
A key value that you gain when you shift to an SD-WAN is the ability to make shifts locally as well as globally from a centralized dashboard. This makes changes swifter, but also helps protect your network by ensuring that universal security standards are applied at all locations equally. Using an SD-WAN configuration gives you the added benefit of consolidated troubleshooting and error reporting so you can quickly identify any trouble spots or network hotspots and shift resources as needed to add speed and efficiency to your network — something that users are sure to appreciate, even if they never realize it is happening.
What Are the Business Benefits of SD-WAN?
Upgrading your network from a more restrictive model to SD-WAN has a variety of benefits for your organization. While some of these gains are realized upfront, others will continue to add value to your organization over time.
The cost of connectivity using an SD-WAN is less expensive than traditional MPLS, an especially important point when you consider the bandwidth-heavy applications that business users require.
While there is a high level of expertise required for upfront configuration of a software-defined network, ongoing changes are less intensive and can potentially save you consulting fees in the future.
Your business users will appreciate that network availability is high because there is no need to take the network down to make configuration changes or upgrades.
Your technology team is able to define networking rules in the language of business — SLAs, security restraints, apps and users — making the network easier to understand and maintain in the future.
With Gartner noting that nearly 25% of businesses will utilize SD-WAN in 2019, there is a growing body of knowledge within the IT community that makes it easier to find resources to support your network infrastructure. The SD-WAN market is expected to grow to $1.3 billion by 2020.
Cloud-based applications continue to emerge in all sectors of business, and it can be challenging to protect these applications without a consolidated hub of security rules. SD-WAN allows everything from SaaS to traditional connections to be covered under the same business rules.
Branches and remote workers will appreciate having access to the same high quality of connection that they enjoy at the office, instead of having to deal with restrictive security procedures and application latency.
Instead of relying on the hardware to make decisions about connections speed and connections as with MPLS, SD-WAN makes agile decisions about the best way to connect users and the data or applications that they need to access.
What Type of Business Benefits from SD-WAN?
While there are many benefits of SD-WAN, there is one downside that can be a deal-breaker for certain organizations. Software-Defined WAN does provide extremely reliable uptime, but there can be more packet loss than you would see with a hardware-based network. In this case, you may want to consider a hybrid infrastructure that lets you gain the benefits of SD-WAN for the majority of your applications yet maintains any heavy applications that simply cannot abide packet loss on a more traditional MPLS. The majority of organizations are looking for ways to reduce their cost of connectivity and have very heavy use of their internet or intranet connections — making SD-WAN ideal. Businesses that are growing quickly or expanding into new regions are also likely to see gains from making the switch.
Many organizations are seeing that shifting to an SD-WAN model may help them future-proof their business by creating a flexible, scalable and secure model that can grow with their business. From the reduced cost of connections to the high availability environment, it’s clear that the conversation around SD-WAN will not be going away in technology groups around the world.
by Felicien | May 20, 2019 | Education
Small businesses technology and business leaders may feel as though their data is safe, but nothing could be further from the truth. According to SmallBizTrends.com, nearly 43% of phishing campaigns are targeted specifically at small businesses, a dramatic increase from 18% in 2011. Unfortunately, a 2017 report from Keeper Security also shows that the greatest cybersecurity threat to small businesses is their employees, with more than 54% of data breaches caused by employee or contractor negligence. Protecting the data within your organization is crucial, and the costs that are associated with a data breach continue to rise. Small businesses are increasingly focused on ways to mitigate the risk associated with data storage and use and that often starts with having a comprehensive backup and data recovery process in place. Here are some suggestions from industry leaders on how to protect your critical small business data from a cyber attack or other loss of access.
Importance of Immediate Data Access
Your business data is arguably your most important digital asset and one that is accessed hundreds or even thousands of times each day. Your employees utilize business data from a variety of systems to look up customer orders, create POs and track shipments while consumers are online placing orders and tracking status. Until you truly experience a major loss of data access, you may not realize the crippling effect that it would have on your organization’s operations.
Dangers of Data Loss
The first hit that you would feel with the loss of access to your data is in the productivity of your teams. Workflows grind to a halt as employees scramble to figure out how to perform their daily activities without access to the information that they take for granted. In many businesses, the data stored within your CRM or other data repository is driving your website, meaning ordering comes to a crashing halt should the secure connection to your data falter. Technology teams scramble to figure out where the problem lies, putting all other IT needs on the back burner for the foreseeable future. Plus, your team may need to call in consultants to help identify a breach and begin remediation as quickly as possible. If your team identifies that a breach has occurred, you may have to report to customers and stakeholders that sensitive data has been accessed by unauthorized parties. This can devolve into trust issues with your business, negative publicity and ongoing loss of revenue even while you’re attempting to return to operational readiness.
Data Consolidation Makes Protection Easier
Business data structures often grow organically, with additional databases and information structures added over time. While this may make sense as you’re bolting systems together, eventually it can become an unruly tangle of disparate systems that makes security and data integrity more challenging for your teams. A regular review of business systems with an eye towards data consolidation is a project well worth considering as your timeline permits. It’s often helpful to work with a trusted technology partner to ensure that you are considering all the options that are available for the security of your data both in transit and at rest.
Protecting Business-Critical Data
There are a variety of protections that you can put in place to maintain both access to your data as well as its integrity. Creating a robust backup and disaster recovery process allows your team to define the best case scenario for data backups — local only, short-term local with a regional cloud-based backup or cloud only. There are dozens of different ways you can configure your backup process, but what’s important is that it meets the needs of your business both now and in the future. When you have a documented backup and disaster recovery process in place and test it on a regular basis, you have added peace of mind that your small business data is protected and quickly accessible in the event of a cyberattack or natural disaster.
Assessing and Managing Cybersecurity Risks
As your business matures, it’s imperative that you create a review schedule to assess and manage your cybersecurity risks. This includes everything from monitoring employee activity logs to protecting passwords to educating staff members and contractors against tapping, clicking or interacting with suspicious website content or email attachments. Data encryption, email and web filters and the regular application of patches to your servers and applications can also help reduce the risk of a cyberattack on your small business. Sometimes, the challenge is as simple as assuring that you have redundancies on your power supply so you don’t run the risk of losing servers during a power surge. Other remediation issues can be much more intensive, but putting together a full list of options helps you understand and ultimately reduce the risk to your organization.
Your data is being bombarded with threats on all sides, and it’s up to your technology team to help protect your organization. Creating a robust backup and disaster recovery plan with a trusted technology partner can help you walk through an audit of all pertinent systems and quickly identify problems that can be resolved quickly and define a strategy for ongoing review and support. Without access to your data and business information systems, you can quickly find that your organization is grinding to a slow and painful halt.
by Felicien | May 17, 2019 | Education
Microsoft Teams is a relatively new addition to Microsoft’s Office suite. Teams is a powerful collaboration tool. It’s kind of like Microsoft’s high-powered answer to Slack. Create teams for whatever purposes make sense in your business. Communicate and collaborate within those teams to get stuff done. The killer feature in Microsoft Teams is the ability to collaboratively use nearly any other component of the Office suite directly inside the Teams application.
Team Meetings
Whether your team is a mix of on-site and virtual or completely virtual, you still likely need to hold meetings from time to time. Microsoft Teams includes a Meetings function, allowing those that aren’t present to join in on an in-person meeting. All you need is a device running Teams in the conference room. If you’re the host, all you need to do is create the meeting in your Outlook Calendar like you normally do.
How to Join a Microsoft Teams Meeting on the Go
If you’re the one that needs to join the meeting from a distance, here’s what to do. Open your Teams app and click or tap on the Meetings tab. If your organization is using Outlook for its calendar functions, this tab will populate with the meetings you’ve been invited to. Look for the one you’re trying to join, and click the big “Join” button. This will launch a call, and you’ll see avatars or photos for the others who are joining the meeting.
Controlling Your Presence During the Meeting
Tap anywhere (or, on a computer, move your mouse) to bring up meeting controls. You can mute or unmute your device’s microphone, toggle video on or off, and adjust volume. In the upper right corner (on mobile) you may see a button for adding additional people to the meeting (if you have the rights). You’ll also see a button to view any chats associated with your Team or the meeting itself.
You or others can share files into the Teams meeting. Once displayed on your screen, you can pinch to zoom in. When you’re done viewing the file, close it out and return to your main meeting window (whether that’s a video or just an audio interface with avatars).
If You Don’t See the Join Button
If you don’t see a “Join” button, then you’re dealing with one of two problems. If you sometimes see them and sometimes don’t, then your meeting organizer likely isn’t creating the meeting properly. The organizer might need to experiment with creating the meeting within Teams rather than from Outlook.
If you never see the button, then your IT group likely has not implemented the Meetings function within Teams. Contact IT with a request to enable this feature.
Wrapping Up
You now know how to join a Teams meeting on the go, but there’s a lot more to Teams than that. For help navigating Teams or the rest of the Office suite, contact us today. We’re here to help!
by Felicien | May 17, 2019 | Education
Do Not Disturb on Android can do more than you might expect. Here’s how to enable and customize Do Not Disturb on your Android device.
Today’s quick tech blog explains how to enable Do Not Disturb on Android devices. We’ll also give a basic explanation of how to customize this feature, making it even more powerful. Note that terminology and locations vary on Android devices. If you don’t see exactly what I describe, look for something similar.
What Is Do Not Disturb on Android?
Do Not Disturb on Android does what you’d expect based on its name: when enabled in its default mode, it silences all notifications. It’s a good choice while you’re sleeping (or want to be), while you’re presenting at work or displaying content from your device, or while driving.
Default mode has its usefulness, of course, but sometimes it’s a little too…nuclear. You might want to cut down on the notification madness, but you still want to be alerted if your significant other (or boss, or VIP client) calls. This includes calls, texts, news alerts, and any other app notifications. Good news: Do Not Disturb can be customized, making it a powerful feature for tailoring which people and which apps are allowed to reach you. We’ll get to that, but first, here’s how to enable Do Not Disturb.
Enabling Do Not Disturb on Android
To enable Do Not Disturb, open your settings. Navigate to the Notifications menu. In most Android versions, you’ll see an option for “Do not disturb.” You can toggle this on right from this menu, or you can click on the widget for further options. “Turn on as scheduled” (or some variation of that) is a useful way to automatically toggle off notifications from, say, 11pm until 7am.
A few things to note about the default mode: first, toggling on Do Not Disturb essentially disables Android’s notifications system. You won’t receive any from anywhere. If it’s critical that someone be able to contact you anytime, day or night, you need to customize your Do Not Disturb (see below).
Second, you can always manually disable your scheduled Do Not Disturb. This is useful if you’re out late and still want to be notified about incoming calls or texts. Just come back to the main Notifications page and toggle it off. It will remain off until the next scheduled window.
Customizing Do Not Disturb on Android
Most people can’t get away with default Do Not Disturb. If you want to allow certain people or apps access to you even during Do Not Disturb sessions, go back to the notifications menu in settings and click the widget for Do Not Disturb. Click “Allow exceptions” and start customizing. There are tons of options here. You can enable notification from specific contacts or from repeat callers. You can choose to allow event/task alerts (think work calendar notifications), too.
From there, options vary depending on your phone’s manufacturer and the version of Android that you’re using. Use the principles described with whatever options your phone gives you.