by Felicien | Jan 3, 2019 | Education
The securities industry has been as vulnerable to cyber attacks in 2018 as any other industry. According to the SEC’s Enforcement Division newly created Cyber Unit (formed in 2017 to enhance the ability of the Commission to identify and investigate all cyber-related threats to firms), 20 actionable cases were brought forward in fiscal year (FY) 2018. 225 open investigations are also being conducted by members of the Cyber Unit at the close of FY 2018.
Firms have an affirmative duty to establish policies and procedures designed to detect and deter cyber-threats. These include both the Safeguards Rule and the Identity Theft Red Flags Rule. Failure to put in place necessary protections designed to safeguard customer information and prevent fraud may result in enforcement action by the SEC.
SEC Cyber Security Enforcement Actions
This was the case with an enforcement action taken against a Des Moines, IA-based firm fined $1 million for its failure to put in place proper cybersecurity policies and procedures. The action came as a result of a cyber intrusion that fraudulently reset customer passwords. This allowed the cyber thieves access to more than 5,600 of the firm’s accounts, which allowed new profiles to be created and specific access to private documents of three customer accounts. The failure to have in place proper procedures in keeping with regulatory requirements made what was preventable inevitable.
As the old year ends and a new one begins, what are some of the cyber threats facing investment professionals? In keeping with mandated requirements from the SEC, FINRA, and state securities commissions, what should be done to keep ahead of the growing potential of a cyber attack or unwanted intrusion that threatens customer safety, privacy, and the integrity of U.S. financial markets?
The State of Cyber Security in 2018
A recently discovered data breach of Marriott International’s Starwood Hotel guest reservation database comprised the information of nearly 500 million customers. A Federal Trade Commission (FTC) consumer advisory released on December 4, 2018, announced that the breach, which began in 2014, impacts all hotel registrations made up to September 10, 2018.
Information that hackers were able to access includes customer names, addresses, phone numbers, email addresses, passport numbers, dates of birth, and the gender of the reservationist. Additionally, any Starwood loyalty program account information and reservation information entered was taken and for some customers, payment information (and possible expiration dates).
The compromise of Starwood customer information by hackers is just the tip of a very tall iceberg of incidents that took place in the U.S. and across the globe. Cybersecurity issues touched nearly every industry sector and business size, from Texas-based Jason’s Deli to social media giant Facebook. State-sponsored attacks have also been exposed in 2018, validating concerns about the integrity of the U.S. election process and the continuing influence of bad-faith actors such as Iran, Russian, and North Korea.
Those issues affecting business worldwide are those that affect financial professionals and the securities industry. Efforts must be taken to tighten up required controls that detect and deter cyber attacks. Paying lip service to these issues will result in the loss of customer confidence as further attacks expose vulnerabilities.
Cyber Security Issues for 2019 Affecting Financial Professionals
There are at least four specific cybersecurity issues that financial professionals should be aware of heading into 2019:
Testing a firm’s cybersecurity policies and procedures to ensure
Leveraging technology to police technology
The impact of artificial intelligence by hackers to access client accounts and information
The growing influence of the “Dark Web” and the exposure of personal and private information
These issues may be of particular concern for financial professionals looking to maintain strong customer relationships. Awareness of the potential for attack must be met with definitive action to strengthen systems and hold back minor and major intrusions that could have a long-term effect on business and the confidence the investing public has in the U.S. financial system.
Establishing and Testing an Investment Firm’s Cyber Security Policies and Procedures
The SEC noted in its enforcement actions taken against firms in 2018 that failed to protect client data that the failure stemmed from the lack of sufficient cybersecurity policies and procedures. Such policies and procedures are only one part of the solution to building robust IT systems capable of withstanding dedicated cyber attacks.
In addition to well-documented policies and procedures specifically tailored to the financial systems, firms and financial professionals must also work with their IT teams to test their ability to detect, address, and defeat cyber attacks. The loss of customer information to a data breach through a system vulnerability that could have been prevented hurts not only the entity breached but the industry as a whole.
As firms increasingly rely on technology to conduct business, greater reliance must be placed on constant vigilance. The mentality cannot be that since an attack has not occurred, there is no problem; it must be that an attack may happen at any time.
Using Technology to Defeat Technology
Cybersecurity issues cannot be regulated away. The establishment of policies and procedures, as discussed, is one of the ways to identify the severity of these attacks and their potential impact on business. Working on using technology to prevent technology from causing cyber attacks and other unwanted intrusions is the next level for financial professions.
It stands to reason that these attacks are the result of machines finding ways to invade other devices. This may be to spread viruses that cripple or disable a recipient system for a period of time, or to disrupt business operations by denying access to customers, or to set in motion ransomware or other types of malware for the purpose of extortion. Policies and procedures establish recognition of the potential for harm but technology sets in place the necessary firewalls and disaster recovery processes for business to continue operating (with little to no disruption).
Artificial Intelligence
Machines, currently through the aid of those with ill-intent, lead the attack on financial systems, threatening the privacy of customer data. Artificial intelligence (AI) or the ability of machines to develop routines and learning processes that make devices less dependent on human input is also growing as a potential threat.
Facebook confronted this issue in the summer of 2018 when its Facebook AI Research Lab (FAIR) was forced to shut down a project involving the use of AI known as chatbots. Chatbots are a type of AI where programs that are automated to complete a specific task can communicate with each other to make the routine more efficient. The FAIR project attempted to add a negotiation element between the chatbots, which to the horror of researchers, resulted in the AI developing its own language at a rate that was faster than what humans could anticipate and control.
The growing presence of AI in technology and the use of robots, specifically chatbots, to complete basic tasks may very well be the way of the future. Its existence, however, should raise legitimate concerns and warrant additional protections and regulatory action to ensure that the results of an accidental experience (like the outcome of the FAIR project) does not set in motion a sponsored attack that could have the potential of taking down the U.S. financial system in 2019 (and beyond).
Dark Web
The dark web, which refers to encrypted information that is unavailable through traditional internet search engines. A part of the deep web, it is a facility for transactions in private data (most of which is financial in nature) that has been stolen and may be purchased with cryptocurrency such as bitcoins. eCommerce on the dark web has grown exponentially – the Economist reported that between 2012 and 2016 the sale of illegal drugs through the darknet increased from $12 – $17 million to $120 – $180 million in four short years.
Data breaches that have occurred with all too regular frequency in 2018 have produced information that has found its way to the dark web. The marketplace for compromised identity information (i.e., social security number, date of birth, payment information, etc.) is growing at a rate comparable to what the Economist reported for illicit drug sales. Financial professionals, particularly in the age of anti-money laundering (AML) programs required to prevent terrorist financing and other illegal financial activities, will be challenged to verify the legitimacy of customer information and protect against the introduction of dark web data used to illegally open accounts or engage in financial transactions.
These are only a few of the cybersecurity issues facing financial professionals entering 2019. Greater awareness and vigilance is required of everyone within the industry to get in front of the growing influence of technology on our lives. Protecting the integrity of financial systems is more than good business. It may very well be what prevents a global financial disaster from happening, the scale for which would be unprecedented.
by Felicien | Jan 3, 2019 | Education
Amazon is a gigantic player in online sales. It’s estimated that the Seattle-based online e-commerce site will be responsible for roughly 50% of all digital sales during the 2018 holiday season, one of the busiest shopping times of the year in the United States. In other words, one out of every two people shopping during the holiday season will buy something from Amazon.
But Amazon’s very ubiquity has made it a tempting target for cybercriminals and thieves. It’s also widely trusted by consumers, who benefit from the online retailer’s wide choice and speedy deliveries. As a result of the many sales made through Amazon and the trust it has engendered among its customers, scam artists are targeting Amazon shoppers.
A Scam That Sends Fake E-Mail
The most recent scam sends an e-mail to an Amazon shopper telling them that their password needs a reset. One of the most notable elements of the scam is that the e-mail looks very official, using Amazon’s logo. It tells the targeted Amazon shopper to enter their Amazon user ID and new password directly from the e-mail.
But it isn’t Amazon that receives the new password. It’s the cyberthieves who set up and sent the e-mail. Once the target enters the information in response to the scam e-mail, the cyberthieves have the information to their Amazon account.
The thieves often set up Amazon gift cards for themselves, so that they have cash to be spent on Amazon. The gift cards are sent to their e-mail accounts, so they can use it before any theft is noticed. If the target customer has a credit card or debit card associated with their Amazon account, as most people do, the scam artists may shop until the cards are maxed out.
There are several variants to the scam. Sometimes, the cyberthieves set up the e-mail to say that new shipping information is needed or that there is a problem with an existing order.
But in all cases, a crucial element is the same. The e-mail looks official, and asks that the customer’s ID and password be entered directly from the e-mail. Entering it from the e-mail is what allows the cybercriminals to capture the user’s information and use it for themselves.
What Amazon Customers Should Do
Amazon customers need to be aware of the scam. They should never enter any of their account information in response to an e-mail about a problem with an Amazon order. For that matter, they should never enter any account information, of any type, in response to any e-mail, including debit card or credit card information.
If you get an e-mail like this, log out of your e-mail and log in to your Amazon account directly from the company’s web page, www.amazon.com. That page always has up-to-date information on your account and your orders. Customers will be able to see if there is any concern with their orders or shipping address.
If customers do need to change their log-in information, they should always do it directly on the Amazon site, not in response to an e-mail.
Finally, the Amazon site has a “take action” section on their website giving direct information on how to handle suspicious e-mails and scams by cyberthieves purporting to be Amazon. To access the section, click here.
The latest scam is easy to protect against. Customers should never respond to e-mails that look as if they’re from Amazon but always go directly to the Amazon website.
by Felicien | Jan 2, 2019 | Education
As small business owners rely on IT more than ever before, a growing number are turning to managed service providers to obtain the high-tech IT infrastructure, software and assistance they need to be successful. At the same time, there are many entrepreneurs and small business owners who don’t fully understand how managed IT services work and how they can propel a business forward. Following are five extremely important facts about managed IT services that will enable one to make wise decisions regarding when and how to use them.
Managed IT Services Save Time
Most small businesses can’t afford to hire a full-time IT technician. This means that, more often than not, regular employees must deal with IT problems. Because the average employee is most likely not an expert IT technician, it could take hours or even days to resolve serious IT issues. What is more, it is all too easy for an employee to make a mistake that results in downtime, a security breach or some other serious issue.
Working with a managed service provider saves time because MSP companies can prevent many IT issues in the first place. Companies offering managed IT services use only the best equipment and this equipment is monitored by experts to ensure that everything is working as it should at all times. In fact, most managed service providers offer a 99.9% uptime guarantee. If something does go wrong, a small business owner can count on immediate, expert assistance to get things running again. This frees staff members to handle other essential jobs such as sales, advertising and customer service, enabling your business to grow as it should.
Managed IT Services Save Money
Can working with a third-party IT service provider actually save money? A lot depends on which IT service provider is used and what services are purchased; however, for the most part, companies that use an MSP save a considerable amount of money. In fact, recent statistics indicate that small business owners can reduce IT costs by up to 40% by working with a managed service provider.
There are several reasons why managed IT service providers are so cost-efficient:
Small businesses that use an MSP don’t need to invest in their own equipment and then update the equipment periodically as the IT service provider handles this expense.
Small business owners who work with an MSP don’t have to take on one or more extra employees; this saves money that would have otherwise been spent on salaries and benefits.
IT service providers offer scaled services, making it possible for business owners to adjust IT spending by the company’s needs and budget.
Managed IT Services Boost a Business’ Security
Many small business owners have discovered that, contrary to popular misconception, they are prime targets for cybercriminals. Because small businesses are less likely to have strong security, hackers go after them regularly to obtain valuable customer and business data or to hold files hostage in exchange for a ransom.
Thankfully, small businesses can now obtain top of the line security at a very reasonable price by working with a third-party IT service provider. IT service providers use up to date security programs and procedures to protect company files from unauthorized intrusion. Furthermore, many offer employee training that can prevent common cyber crimes such as phishing and malware attacks.
Getting Help from the Experts
IT technology is continually improving. Hardware and software that was up to snuff a few years ago are now outdated. Naturally, most small business owners don’t have the time to keep up with technology changes that affect their industry. However, IT service providers do have the time and ability to not only stay abreast of recent developments but also invest in the newest equipment to provide the best possible service to their clients.
Additionally, IT service providers know how to handle any IT-related challenge you may face. If you experience downtime, are having trouble accessing your files or need help creating a secure internal communications plan, your IT service provider is available to provide immediate assistance. Many MSPs even offer 24/7 assistance to ensure that you get the help you need, when you need it.
Taking Advantage of Customized Service
There are many IT service providers for small business owners to pick from, making it possible for just about anyone to find the company that best suits his or her business’ needs and budget. In fact, there are even managed service providers that specialize in offering IT services to niche industries such as healthcare.
Managed service providers also offer flexible service options. A business owner can:
Use a managed service provider on a one-time basis
Hire a managed service provider to handle periodic tasks such as providing online customer service during holiday seasons and/or training employees in IT security and management
Delegate certain IT jobs to an IT service provider while managing others in-house
Have an IT service provider handle all IT-related work for the company
Managed service providers are well worth the cost. They have much to offer any company and small business owners who work with MSPs often find that they can save money, increase efficiency levels and serve customers better than ever before. Any small business owner who wants to boost his or her business may want to seriously consider the benefits of teaming up with an IT service provider and then do some research to see which exact managed service provider is the best fit for the business.
by Felicien | Jan 2, 2019 | Education
Technology is changing the face of almost every industry, and anyone who can’t keep up will be left behind. The United States has far more STEM jobs than qualified applicants to fill them, with the need growing steadily. Just in 2016, there were about 3 million jobs which couldn’t be filled because there weren’t enough people with the right education and skills. Businesses and schools are working hard to find ways to meet the technology gap, with programs encouraging students from a young age and scholarships for STEM majors.
When workers can’t adapt to the new environment, they won’t just be denied new and better opportunities. They will be stuck in whatever menial, low paying jobs are left, and there may not be enough of those if those when so many are automated.
The New Jersey Institute of Technology
NJIT has been working to provide the educational credentials with the necessary experience so graduates will be prepared to step into high paying tech positions. Students are well versed in aspects of various industries while learning necessary technology skills, such as maintenance, processing control and manufacturing. NJIT students get offers before graduation and earn 20% more than many of their peers.
The Growth of Automation
The increasing use of technology in every aspect of business is paralleled by the astronomical growth in automation. NJSpotlight.com predicts that as many as half of all jobs will be automated as soon as two short decades from now. Governor Murphy has made a promise to help support workers during this time of upheaval, and has set up a task force to evaluate possible upcoming changes.
By making a proactive plan, Governor Murphy hopes to protect the interests and livelihoods of the New Jersey workforce. He also wants to help prepare for the upcoming changes in the various industries which will be impacted.
Changes to the Economy
The automation task force is part of Governor Murphy’s economic plan. As the leader of the state, he wants to avoid unemployment and underemployment for New Jersey residents. Instead, he wants to find creative ways to help residents succeed in the new economy. One idea is lifelong learning accounts, which would allow residents to achieve new credentials and skills so they could become qualified for every changing STEM jobs.
One way Governor Murphy is trying to help New Jersey residents is by raising the minimum wage significantly. One of his top campaign promises was to raise the minimum wage to $15 per hour by 2021, and the change is being enacted incrementally. Although those changes aren’t happening as fast as he wanted, a higher minimum wage will help ensure that residents will continue to be able to earn their living even with a lower technology job.
Changes in Job Types
Studies predict that there will be more computer jobs, automation, robots and other technologies which will replace or enhance many current jobs. It is simply more cost effective to have a machine perform many tasks, and the newer technologies have other advantages like accuracy and safety. A job which might be dangerous for a human may be safely done by a robot.
Many jobs have already disappeared, or at least declined significantly. It is easy to see, even though the changes seem gradual. Cashier jobs and gas station attendant positions were replaced by automatic checkout and “pay at the pump,” leading to open worry and discussion by residents who were worried about losing their own jobs to technological changes.
Retail salespeople and cashiers are the most in danger of losing their livelihoods, and the United Way predicts that there is a 90% chance of those positions disappearing. Other jobs which could be on the chopping block include sales representatives, movers, janitors and health aides.
Preparing for the Future
Many people are anxious, even if they personally have the training necessary to get one of the best new tech jobs. When there is so much change, and it seems to be happening so fast, people can feel uncertain about how the changes will affect them and their own position.
Governor Murphy’s task force is predicting huge changes by the year 2025, and his focus is on innovation and change. When one door closes, another opens; the loss of some jobs means merely that other jobs will be created to help with the new way things are done. If everyone works together and focuses on the end goal, the end result will be a steady rise in employment and residents in good-paying technology jobs.
by Felicien | Jan 2, 2019 | Education
Companies today are increasingly relying on freelancers to support one-time or ongoing projects. The growing need for freelance support can create complex challenges for companies.
How, for example, can companies manage projects across time zones? How can freelance and in-house staff access the same information and collaborate in real time? How can companies provide access to necessary information quickly when needed but keep systems and access secure when projects are done?
Answering these questions led to the development of Microsoft 365 freelance toolkit. The service leverages tools already in use by many businesses via common Microsoft applications.
The toolkit provides functionality explicitly designed to address freelance management and simplify the complexities of working with teams comprising internal and external employees. It includes a curated set of templates, tools and best practices designed to help organizations launch, manage and execute projects that rely on freelance talent.
How Is the Microsoft 365 Freelance Toolkit Organized?
The toolkit uses four functional areas that Microsoft calls “workloads.” Each is designed to work with existing tools to address core needs:
Communication
Collaboration
Analytics
Workflow
How Does the Product Manage Communication?
SharePoint has long been a powerful tool allowing teams to access critical information and understand complex projects. Leveraging your existing SharePoint investment, toolkit users can learn about a project or program, access necessary training materials and see best practices. These spaces allow for key stakeholders and adopters to understand projects, including goals, metrics and desired outcomes.
Users can post use cases, guidelines for using freelancers for the project, FAQs or Microsoft-provided research reports on the gig economy, alternative work arrangements, and the future of work.
As with all the workloads included in the toolkit, the communications space is customizable.
How Do Freelancers and Staff Work Together?
The collaboration space uses Microsoft Teams and Microsoft Planner as a way to get cross-functional and distantly located teams moving in the right direction.
With these tools, your organization can provide a shared space for teams to hold discussions and to track project progress in one place. Team member assignments can be managed and updated online, and files can be shared using intelligent search tools.
Your organization can grant guest access at no additional cost to freelancers. When the project is concluded, you can easily remove team members who no longer need or should have access.
You can also learn from best practices detailed in the space, including whether to use email; how to use, review and comment on documents, slide presentations and spreadsheets at the same time; and capture shared notes.
How Can the Toolkit Measure Success?
With Power BI, you can create connectors and dashboards that measure key performance indicators about the use of freelancers. Analytics help to gauge which internal groups benefit most from using freelancers. By using the business and data analytics tools, your organization can connect multiple data sources, ease data prep and generate easy-to-read reports.
How Can I Manage Repetitive Tasks Associated with Projects?
There are multiple processes associated with using freelancers. Provisioning, budget, compensation, compliance, monitoring and assessment tools all play a role in managing freelance workers.
Using Microsoft Flow, toolkit users can reduce the reliance on manual, repeated tasks with workflow automation tools. Create seamlessly integrated processes among apps and services to send notices, synchronize files, collect data and report on progress and needs. Using Boolean logic strings, you can streamline and simplify many processes.
As your business evolves, it may require a rapid influx of resources that cannot be acquired using traditional hiring practices or budgets. The freelance market offers companies greater flexibility and reliability. Now, with the Microsoft 365 freelance toolkit, you’ll be able to manage freelancers and empower them to solve pressing business needs.