by Felicien | Nov 12, 2018 | Education
In late 2000, Kirk Lippold was the captain of the U.S.S. Cole, an Aegis-class guided-missile destroyer. The Cole was severely damaged by terrorists who pulled alongside in a ship disguised as a garbage barge and set off a massive explosion. The Cole had a 40’ by 60’ hole ripped in its side; 17 sailors died, and another 39 were injured. The crew, working together under the Captain’s direction, saved the ship and was able to stabilize it and get it towed to a repair facility. It is still in service.
What Are The Lessons?
In a presentation to the Healthcare Information and Management Systems Society (HIMSS), Captain Lippold presented some lessons from the Cole crisis. They are:
It’s not a question of if, but when. You, as an executive, will face a crisis at some point.
You have to lay the foundations in staff attitude and skills for dealing with a crisis.
The first step is always to calm yourself. Everyone in the organization will be looking to you for direction and inspiration.
Remember that there are multiple perspectives. Be open to what your staff is telling you.
Not making a decision is not an option. Not to decide is to decide.
Act in the now, but always ask, “What do I do next?”
When the crisis is over, ask whether the situation just requires a reset or a whole new way of thinking.
When doing any of these things, brutal intellectual honesty is critical. Without it, you are not facing reality; you are merely crafting a fiction which will provide you with no resources when the next crisis hits.
Why Intellectual Honesty Is Critical
Part of intellectual honesty is not “buying” the organization’s vision of itself. This does not mean that real skills and dedication should not be recognized. It knows that every organization has blind spots. Facebook is a good example. So is Uber. Whatever their merits or demerits, their corporate culture led both management and employees to regard themselves as invincible.
From the other side of the coin, look at all the IT companies that had really superior products that vanished over the course of time. Consider DEC. Consider the AT&T personal computer line. If a company has excellent products but cannot market them effectively, those products will vanish from the marketplace.
It has been jokingly remarked that if AT&T’s marketing team were put in charge at KFC, the signs above the restaurants would read “Hot Dead Chicken!”
If a company has superior products but does not recognize what sets them apart from others in the market, their ads will not reflect that. At most, they will be mediocre.
Another part of intellectual honesty is recognizing just how severe a potential crisis can be. “It won’t be as bad as we think” is a first cousin to “it can’t happen here.” The intellectually honest answer is that “Yes, it can be that bad, and yes, it is going to happen here.” No organization is immune.
Captain Lippold emphasized that a leader in a crisis must be simultaneously in and out of the picture. He must be listening to subordinates, trusting them to convey what is really happening, yet at the same time recognizing that the staff is relying on him or her for leadership. He must also be thinking ahead to what is the next step. If all of that is not done, the executive in charge is deprived of accurate information and may well, by failing to think ahead, turn one big crisis into a cascade of smaller ones.
Communication Is Key
It does go without saying that for a spirit of teamwork, respect for executive authority, and professional commitment to existing, dialogue must have been frank and honest from the start. This is essential for building trust, and if trust is not present, all the authority in the world will not produce a good outcome in a crisis.
Does IT Have A Communications Problem?
One of the things to note about recent IT-related crises at Experian, Uber, Facebook, and now Google, is the tendency to not reveal problems, the issue information that minimizes them, then walk that back, and finally reveal the scope and the relevant details only after public pressure is applied.
One thing IT can learn from politics is that it’s not the crime, it’s the cover-up. In every case, the PR outcome for these companies would have been much better if everything had been revealed at once. As far as intellectual honesty is concerned, IT shops that have any interaction with the public need to view their responses from the general public’s angle and honestly ask them what their various possible responses would make them look like. This exercise could be quite revealing.
The Need To Anticipate The Worst
One reason the Cole is still in service is that the officers and crew had been relentlessly drilled in damage control. They had practice exercises in dealing with massive damage to the ship. They knew how to keep it in fighting condition even after an attack. When they had an actual crisis that could have sunk the ship, their training and the foresight showed. IT executives would be well advised to take the lesson to heart.
by Felicien | Nov 11, 2018 | Education
If you are experiencing problems with your Windows 10 Pro operating system, you are not alone. Thousands of users from the US, Japan, and South Korea flooded tech message boards late this week with complaints that their legitimately purchased software was deactivating itself.
What Exactly Happened?
Starting on November 8, comments began to appear online from several users expressing frustration over the pop-up messages they received from Microsoft after booting up their computers. These messages included the error codes: 0xC004C003 or 0xC004C003, and incorrectly implied that the users were trying to run illegal copies of the Windows 10 Pro edition on their computers. Those affected by the glitch were then prompted to install the Windows 10 Home edition or to purchase a genuine copy of the Pro edition from the Microsoft store. Anyone who received a deactivation warning was still able to operate the computer using the Windows 10 Pro edition, although distracting watermarks were plastered across the screen.
Microsoft acknowledged that the company was fully aware of the DMR issue within hours of the first messages showing up online. A statement released from the company said it was still trying to determine the reason behind the deactivations to provide a fix, but at the time the exact cause was unknown. Engineers from Microsoft suspected that “some unspecified issue with the Windows Authentication servers” was the cause behind the deactivations.
On Friday, a day after Microsoft first address the deactivations, the company released an update about the bug:
“A limited number of customers experienced an activation issue that our engineers have now addressed. Affected customers will see the resolution over the next 24 hours as the solution is applied automatically. In the meantime, they can continue to use Windows 10 Pro as usual.”
As of Saturday, some users online were still reporting problems with their operating system.
Will This Affect Me?
The good news is that the deactivation problem seems to be affecting only a small portion of the total number of Windows 10 Pro edition users. Of the licenses which were affected, the vast majority of them were digitally updated from an early version of Windows. If you have not already received the warning after restarting your system, there is a good chance that your copy of the operating system is not affected by this bug. But for those who hit with the glitch, you have several options.
What Can I Do About It?
First, don’t panic and assume that you need to repurchase a new license for the Windows 10 Pro edition if you are still receiving a warning as of today. As long as you are using a genuine version of the operating system, there is no need to buy another copy, as the fix will automatically take effect. The best thing to do is just to wait. But if you are unwilling to wait, you can attempt to correct the issue on your own by running the Troubleshoot app. You can access the Troubleshoot app by going to Settings then clicking on Update & Security followed by Activation, and finally to Troubleshoot. This should correct the issue immediately.
by Felicien | Nov 10, 2018 | Education
Every year, the United States Marine Corps Birthday is celebrated with a cake-cutting ceremony and a traditional ball on November 10th. This event celebrates the establishment of the Continental Marines on November 10th, 1775.
Many Marines have become to view November 10th, the birthday of the United States Marine Corps, as their second birthday. This tradition runs very deep. Marines often wish each other “Happy Birthday” on November 10th and attend Marine Corps Birthday Balls, which are held in many cities across the globe. On this day, the Commandant of the Corps reads a “Birthday Message” to the Marines. The purpose of the birthday message is to contemplate the legacy of the Corps and the responsibilities that all Marines must honor.
History
For about three thousand years, fighting men have served as infantry to secure harbors and land bases and as boarding parties to launch attacks on other ships. The Royal Marines was formed in 1664 as the Maritime Regiment of Foot.
About 100 years later, a Continental Congress committee in the American Colonies met in Philadelphia, Pennsylvania to create a resolution calling for two Marine battalions to fight on shore and at sea for independence. The U.S. Congress passed “An Act for Establishing and Organizing a Marine Corps” on July 11, 1778. The Congress approved the resolution on November 10, 1775.
Is Marine Corps Birthday a Public Holiday?
The Marine Corps Birthday is not considered a public holiday. This year, it falls on a Saturday and the vast majority of businesses in the United States will follow regular opening hours.
Internal Celebration
Personnel, veterans, and other people associated with the Marine Corps celebrate this day. Usually, this day is celebrated with a birthday cake, a formal dinner, and entertainment at a Marine Corps Birthday Ball. The very first Marine Corps Birthday Ball was held in 1925.
Revolutionary Result
On this day in 1775, the US Marine Corps began under the name of the Continental Marines when the Second Continental Congress ordered two Marine battalions to serve with the Continental Navy during the American Revolutionary War. Both the Continental Navy and the Marines were dismantled after the war. However, eventually, the Marine Corps was re-established formally due to increasing conflict with France.
US Marine Corps Today
The United States Marine Corps is the combined-arms task force on the air, on land, and at sea for the US Armed Forces. The US Marines Corps has more than 180,000 active duty personnel and 40,000 personnel in the Reserve for the Marine Corps. The Marine Corps Reserve is the biggest command in the U.S. Marine Corps.
Undoubtedly, the Marine Corps Birthday is a special day for hundreds of thousands of Marines across the globe. For more information about the United States Marine Corps Birthday and how this day is celebrated, don’t hesitate to contact us.
by Felicien | Nov 9, 2018 | Education
There are many pieces to the massive Federal exchange that enrolls people for insurance under the Affordable Care Act (ACA, “Obamacare.”) One of them allows insurance brokers and agents to enroll potential beneficiaries directly. (This is different from the consumer-facing part of the exchange, where consumers can enroll themselves.) On October 13, 2018, the Centers for Medicare and Medicaid Services (CMS) detected “anomalous activity” and by October 16, confirmed that a breach had cooccurred. About 75,000 individuals’ records were stolen. CMS shut down the system on October 20 to install new security measures and planned to have it back online by October 27.
CMS was unusually close-mouthed about the breach, noting only that it was contacting those affected and would offer them identity theft protection. This being the case, we can only speculate about what exactly happened. It could have been as something as simple as an agent leaving their password on a Post-It Note under their keyboard, or as sophisticated as exploiting an unknown fundamental vulnerability in the myriad of software packages that make up the entire exchange system. It must also be remembered that the Exchange software talks to several other systems, including the IRS, and the breach may have come from anywhere in the chain. A 2015 report by the HHS Inspector General found the that the whole healthcare.gov system suffered from some vulnerabilities which had not been rectified as of the date of the report. It is now, of course, three years later.
What Lessons Can We Learn From This?
Because CMS has explained virtually nothing about how the breach happened, it is hard to tell what lessons we can draw from it – other than to note that so far, any system that humans can attempt to secure, humans can find a way to penetrate. No system is entirely safe.
Because CMS did not respond to questions, we do not know, for example, whether end-to-end encryption was used for data transmission, and we do not know if the particular data files accessed were encrypted. Encrypting data in both storage and transmission provides an additional layer of protection – in the ideal case, even if the hackers get the data, they can’t use it.
Was It An Inside Job?
Security officials in both the public and the private sectors are well aware that even with all recommended safeguards in place, they are still vulnerable to hacks by employees or other trusted agents. After all, someone has to be able to access that data to use it. Even if the USB ports on the laptops and desktops are filled with glue, even if biometric identifiers are used, an insider can dump data, zip it into a file, and send it to cloud storage, where it can be accessed by anyone with access to that portion of the cloud. And that will include a population beyond one’s own employees. A really sophisticated hacker can keep events from being logged or modify the logs so that there is no trace that the transmission ever happened. Based on the information CMS was willing to release, we cannot conclude that this was not an inside job. The only fact that militates against it is that the amount of data stolen was so small. If someone were really trying to make a killing on the dark web, they would steal far more. Perhaps this breach was just a “proof of concept.” Or it may merely be a case of unauthorized access. We just don’t know.
Trust? Verify? But?
The experiences of the military and the National Security Agency (NSA) with insider theft of data in recent years suggests that even the steps the military and the intelligence services have taken cannot completely protect them from inside jobs. Edward Snowden, Chelsea Manning, and Reality Winner all were thoroughly vetted and had authentic credentials. Still, the data got out. (Perhaps it is true, as was said in the early data of the web, that “…data wants to be free.”)
No One Is Safe
Security experts repeatedly tell us that our existing systems cannot be made impenetrably secure. It is the very nature of the technology we use now – for health insurance, for banking, for voting – to send large amounts of critical data across unsecured networks for at least part of their journey. All we can do is encrypt, vet out employees, and – hope.
by Felicien | Nov 9, 2018 | Education
Cybersecurity is one of the main concerns for most businesses, and for a good reason. Companies of all sizes, from small mom-and-pop businesses to large corporations like eBay, are facing cyber attacks. Each year, cybercriminals become more and more innovative when it comes to the types of cyber attacks they launch against organizations. Here are three types of cyber security solutions your business must have to protect against cyber attacks.
Perimeter Security
The first type of cyber security solution your business should have is perimeter security. This type of solution serves as a barrier between the Internet and your network. Mobile devices, cloud technologies, and web services provide a significant number of new opportunities for organizations. However, these technologies also add to the number of solutions and services that need to be kept secure. If there is a vast web of connections, it can be easy for just one malware to invade and spread throughout the entire network. To deal with such threats, you need to establish a perimeter security framework that will guard access to vital data, applications, and services.
Some examples of perimeter security solutions include the following:
Firewalls
Intrusion preventions system
Spam protection
Firewalls refer to a set of protocols that dictate what can and cannot enter your network. A firewall works by monitoring outgoing and incoming traffic. Firewalls scan where payloads are coming from and determine whether these sources are trusted. Firewalls are typically used to prevent Trojans and other malware from entering a network. However, firewalls can also be used to prevent employees from sending sensitive data outside your network.
The main disadvantage of firewalls is that they can be circumvented if hackers send payloads that are trusted to avoid detection. Therefore, you should use an Intrusion Prevention System (IPS) along with your firewall. An IPS is a solution that is intended to identify malicious network activity. IPSs use “anomaly-based detection” to look for patterns in data, applications, IP addresses, and network packets that may suggest an intrusion. An IPS are able to identify intrusions even if they come from a trusted source. The IPS is a useful solution for identifying hackers who make changes to already existing malware to avoid detection. IPS kill, or quarantine identified malicious payloads to prevent the spread of malware through your system.
Some research studies indicate that as much as 91 percent of cyberattacks begin with a phishing attack, which is often sent through email. The hacker sends an offer or requests to encourage users to click on the links, which are full of malware. Spam solutions work by flagging emails and blocking ads to make sure employees don’t have to see threatening or annoying emails. Some spam solutions come with a “safe browsing” feature that checks the destination of an URL to ensure that it is safe.
Intranet Security
Another type of cyber security solution is an Intranet security solution. An important of cybersecurity is protecting individuals devices and computers from malware that has managed to infiltrate your local network. The most common strategies for Intranet security include the following:
Updating and patching software
Anti-malware software
Human Security
Many computer users mistakenly believe that the only treats they need to consider are innovative hackers and malware attacks. A side effect of this is that many companies pour all their resources into intranet security and perimeter security, only to ignore human security. IBM conducted a study in 2016 and found that 23 percent of all security breaches are caused by human mistakes, such as having weak passwords, connecting to networks that are unsecured, and answering spam emails. If trusted individuals in your organization perform these actions, spam blockers, firewalls, and anti-malware software become useless.
Here are a few tips that will help you ramp up human security within your organization.
Employee Training
You should offer comprehensive security awareness training to your employees so that they are equipped with the skills to protect themselves and your organization from a variety of threats. You can hold training seminars in-house, or you can get support from a third-party to train your employees.
Your employees should learn about the different types of malware, such as worms, ransomware, and Trojan horses. Teach your employees about the capabilities of each form of malware so that they know the warning signs if their device becomes infected.
Establish a strong password policy. Teach your employees about the importance of a strong password and inform them of proper techniques for setting good passwords. Not only is it right to use complicated passwords with symbols, numbers, and uppercase and lowercase letters, but it’s also important that the password is lengthy. You should also have your employees use different passwords for different applications. That way, if a hacker is able to get a hold of a password, they are still not able to access all of the applications within your network.
Security Testing
Not only do you want to train your employee, but you also want to conduct security testing to ensure your employees have learned all the information you want them to know. Security testing is excellent for reinforcing the security practices you want your employees to adopt. According to some studies, security testing has helped some companies reduce susceptibility to threats by up to 20 percent. There are many different software solutions out there that you can use to test your employees. For example, some solutions send fake spam emails to employees. If employees fall for the spam emails, the solution corrects the actions of the employee and tells them what they should do in the future.
For more information about the types of cybersecurity solutions that your business should have, don’t hesitate to contact us.