by Felicien | Oct 26, 2018 | Education
7 Cyberattack Facts
This Halloween we’re celebrating by sharing some scary cyberattack facts. Why? Because, unfortunately, cyber attacks are increasing. The cyber threat landscape is rapidly becoming more of a concern. Not only are businesses seeing an increase in the number of attacks, but these cyber attacks are continuing to evolve.
Here are the scary facts:
Cyberattacks are the third largest global threat this year behind only extreme weather events and natural disasters!
Around the globe, a hacker attacks someone every 39 seconds.
There are nearly 6,000 new viruses released every month.
There are more than 4,000 ransomware attacks a day.
Nearly 1 out of every 100 emails is a phishing attempt.
43 percent of cyber attacks are aimed at small businesses.
The cost of all this cybercrime last year? 600 billion dollars!
Read the details below:
Fact 1. Cyber attacks are the third largest global threat this year behind only extreme weather events and natural disasters.
According to the WEF’s Global Risks Report 2018, in terms of events that are likely to cause disruption in the next five years – cyberattacks rank behind only extreme weather events and natural disasters.
The Report reveals that:
The top five risks to global stability over the next five years are natural disasters, extreme weather, cyber attacks, data fraud, and failure to address climate change.
Cyber attacks are growing in risk as the potential fallout from an attack on connected industrial systems, or critical infrastructure becomes a serious threat.
Cybersecurity risks have grown both in their prevalence and in their disruptive potential.
The good news is that many of these cyber attacks aren’t succeeding. However, increases in their growth and sophistication are troubling. Plus, because nation states are performing cyber attacks, cyberwarfare becomes a real threat.
Fact 2. Around the globe, a hacker attacks someone every 39 seconds.
A study by Clark School study at the University of Maryland quantified the near-constant rate of hacking of computers with internet access to every 39 seconds on average. And for those who use non-secure usernames and passwords, there’s a greater chance that the hackers will succeed.
Michel Cukier of Clark School’s Center for Risk and Reliability and Institute for Systems Research identified these as brute force attacks where hackers use simple software-aided techniques to randomly attack a large number of computers.
The study revealed that once hackers gain access to a computer, they:
quickly determine if it will be of use to them,
check the software configuration,
change the password,
check the hardware and/or software configuration again,
download a file,
install the downloaded program and run it.
Fact 3. There are nearly 6,000 new viruses released every month.
A computer virus is a program or software(malware) that once in your computer multiplies in number and affects areas of the computer according to the codes it’s based on. Computer viruses are growing. With the rise in technology, we’re at increased risk of hackers using viruses to infect our networks. They continue to be a growing threat to organizations of all sizes, across all industries. And today’s free antivirus solutions (and some paid ones) are no match against sophisticated malware. Hackers are now using machine learning technology to circumvent security and infect computers with viruses. They also use AI (artificial intelligence) to launch attacks and infect computers to steal data.
Fact 4. There are more than 4,000 ransomware attacks a day.
The FBI has reported that since January 1, 2016, more than 4,000 ransomware attacks have occurred on a daily basis (on average). This is a 300% increase from 2015 when 1,000 attacks occurred daily. Ransomware is the fastest growing malware threat, and it can result in the temporary or permanent loss of your sensitive or proprietary data. It not only disrupts your operations, but you’ll also likely incur a financial loss to recover your data. Ransomware has the potential to ruin your business’s reputation.
Fact 5. Nearly 1 out of every 100 emails is a phishing attempt.
Researchers (from FireEye) reviewed over half-a-billion emails sent between January and June 2018. They found that one in 101 emails are malicious and sent with the goal of compromising a user or network.
When spam is discounted, only one-third of emails are considered “clean.” Highlights of the report showed that:
There was an increase in phishing attempts during tax season (January – April).
Impersonation attacks are commonly used for CEO fraud.
Hackers rely more on friendly name impersonation today.
The WEF’s Global Risks Report 2018 also revealed that 64 percent of all phishing emails sent during 2017 contained file-encrypting malware.
Fact 6. 43 percent of cyber attacks are aimed at small businesses.
This was reported in Symantec Corporation’s Internet Security Threat Report. They also revealed that 1 in 40 small businesses are at risk of being the victim of a cybercrime. Hackers don’t discriminate when choosing businesses. They are targeting their money. Small businesses are big targets for phishing attacks. Phishers target employees who are responsible for the company’s finances. When the phishing emails are opened, it can result in sensitive financial information being exposed. This is how the cybercriminal gains access to a company’s money.
Fact 7. The cost of all this cybercrime last year? 600 billion dollars! That’s three times the amount spent on Halloween candy.
In the February 2018 report “Economic Impact of Cybercrime – No Slowing Down” it says that cybercrime may now cost the world almost $600 billion, or 0.8% of global GDP. The reasons for this growth are as follows:
Quick adoption of new technologies by cybercriminals
The increased number of new users online (these tend to be from low-income countries with weak cybersecurity)
The increased ease of committing cybercrime with the growth of Cybercrime-as-a-Service
An expanding number of cybercrime “centers” that now include Brazil, India, North Korea, and Vietnam
A growing financial sophistication among top-tier cybercriminals that, among other things, makes monetization easier
Do these facts scare you too? Are you worried about the cybersecurity of your business? If so, contact us, and we’ll help you determine if you are adequately protected.
by Felicien | Oct 26, 2018 | Education
What’s The Remote Access Protocol And Why Should I Worry About It?
The Remote Desktop Protocol (RDP) is a means that Microsoft provides for Windows (and Mac) users to access another computer remotely. Remote computer access is often used by IT people to diagnose and repair a problem with a computer. If you’ve ever worked with a company’s Help Desk, then the technician may have asked for remote access to check out your computer. The help desk tech has all the powers and abilities that the user has.
If that user is an administrator (if only one user is authorized on the computer, that user is set up as an administrator by default), they have total control over the remote computer. They may well have total control over the network as well, depending on how the network administrator’s permissions are set up.
So How Does RDP Work?
RDP works by connecting the computer remotely, then controlling it over a local network or the internet. The internet port used for this is 3389. If that port is open in the remote computer’s settings, anyone can potentially connect to it and control it.
The FBI recently warned that hackers are constantly scanning the internet for open RDP ports and selling the access information that they find on the Dark Web. Several types of ransomware and other exploit tools rely on finding open 3389 ports. One security company, Rapid7, found 11 million open 3389 ports on the internet in 2017. There are over 1,000 attempts to find open RDP ports per day.
Obviously, if you don’t know your ports are open, you are not going to be able to protect them. The first step is to make sure that only machines that need remote access are set up for it. Your system administrators can use several methods to make sure that only computers that need remote access have it.
But We’re Covered…Or Are We?
Ah, you say, but we are protected against this kind of attack because we have all our RDP-enabled computers protected by a password. Guess again. If you look, you may well find RDP servers (and servers in general) that are not password protected. Sloppy system administrators (sysadmins) all too often leave the machines they manage unprotected, so they don’t have to remember the passwords to them.
Even if both the servers and the remote machines are protected by usernames with strong passwords, there are two ways that hackers can still access them. One, called a brute-force attack, keeps trying usernames and passwords until it scores a hit. This is known as a dictionary attack.
The other way is to use lists of username/password combinations that are automatically created, bought on the Dark Web, stolen, or some combination of this. The only defenses against this are two-factor authentication or the use of security keys (dongles).
In two-factor authentication, users have to enter a second password, sent by SMS to a smartphone or by email, to log on. When dongles are used, a physical device, such as Google’s Titan security key is used.
Use of biometric identifiers (fingerprints, face scans, retinal scans) is another way of either single-or two-factor authentication (i.e., the user is required to use a password and scan a fingerprint.)
How Bad Is This Problem Really?
Remember, once a hacker gets into your system via RDP, you are probably vulnerable if you do not have two-factor authentication and/or biometric identifiers enabled on all your machines, both Mac and Windows. In any other condition, you are vulnerable. The lists of RDP endpoints being sold on the Dark Web include those stolen from airports, hospitals, nursing homes, and government agencies.
How Bad Could This Get?
So far, the use of RDP as a means of network penetration has been limited to attempts to install ransomware or steal banking, credit card information, and online shopping information.
There is little evidence (remember, we don’t find it unless we look for it or the hackers make a mistake) of any state actors or terrorists using it. But RDP access is really low-hanging fruit for them.
Practically everything runs on computers today, and the vast majority of them communicate over the internet with unencrypted data. Imagine terrorist hackers shutting down first-responder communications systems. They also have the potential to shut down hospital EHR systems or disrupt air traffic control at the airport.
Once we begin to think of the vulnerabilities in our systems, this problem of open RDP ports gets worrisome very quickly. Small wonder that the FBI is warning everyone about it.
In 2017, just one Dark Web site had 85,000 RDP endpoints for sale. It has dozens or hundreds of imitators. We just do not know until the FBI or some other agency finds the Dark Web site and tries to take it down. If you work with a managed IT services company, then it can be worth your while to ask them to check your computers and networks to see whether you have RDP ports open and susceptible.
by Felicien | Oct 25, 2018 | Education
Depending on the age(s) of your child (ren), your response to this topic may be, “She’s too young – she doesn’t even have an identity yet.”
Alas, not so. In our electronic society, kids exist in databases even before they’re born. And they are an attractive target for several kinds of bad actors on the dark web – those who want to exploit their names and other data for identity theft, such as opening credit card accounts, child pornographers looking for images that can be photoshopped, school bullies, and so on. Although this post focuses on identity theft, taking the steps described herein will also protect your children from other bad actors.
What’s So Bad About Social Security Numbers?
As they were originally intended, nothing. The original intent was to use them to associate a specific individual with a specific record of earnings. But over the years, they morphed into the closest thing we have to a national identifier. Many organizations ask for it as a kind of reflex, with no intention of either using it or controlling its use. They have the notion that having an SSN makes your child a “real boy” (as opposed to a wooden one like Pinocchio?).
This leads to the first set of steps.
Get your child a Social Security Number. You will need it for some legitimate things about your child’s identity, including passports. (Try taking the child abroad without one.)
Once you have it, put it in a safe place, like a bank safety deposit box. The same goes for birth certificates and other papers that identify your child. And of course, their passports
Never give anyone an SSN, or a copy of identifying documents, without knowing why they want it, and what the intended use is. If it is just a bureaucratic reflex, ask what you can do instead of handing it over.
Make sure the organization has a policy of destroying documents that are no longer needed. (This will guarantee a lot of comical blank stares.) The only acceptable responses are “we return them” or “we destroy them with a cross-cut shredder.”
Monitoring Your Child’s Financial Existence On The Web
Your child, from the moment of birth, is a thing that businesses highly value – a customer, even if it’s you-by-proxy until your kid starts watching TV or using a computer or tablet. This means that your child will have an online existence from the moment of birth, and perhaps before. Those who exist can be exploited. So, you need to monitor your child’s financial identity. This means:
Check your child’s Social Security Earnings Record every year. You can get this by calling 800-772-1213 or submitting SSA-7050 Form. If you know the child has never worked and you see any earnings, that is a sign of possible identity theft. Contact Social Security immediately. A list of Social Security local offices can be found here.
The same goes for earnings in excess of what you know a child who is working earned. A non-certified copy of the earnings record is free; a certified report is $34.00. There is no reason to get a certified copy just to monitor your child.
Check all three of your child’s credit reports every year. Reports are free once per year. The three large credit bureaus that control most of the records are Equifax, Experian, and Transunion. Their online sites are Equifax, Experian, and Transunion.
Check any packages sent to your child. If you permit them to place orders online, make sure that what they got is what you or they ordered.
All these steps are relatively easy. The hardest part is teaching your child to be cautious (and safe) online. Social media are havens for identity thieves, and worse, predators. Teach your child to reveal private information only to trusted parties you have indicated that you approve of. For anything else, teach the child to respond with something like, “My parents don’t want me telling that.”
And, of course, it is obvious that you should keep your operating system, anti-virus, and anti-malware software updated. If you check every day, you will find that there is almost always an operating system patch, virus and malware definitions updates, or driver updates waiting to be installed.
Check to see if you can configure your OS and virus/malware software to update automatically. This exposes you to potential bugs, of course, but it will give you some peace of mind in the long run. Unless you are a true geek, consider it.
There are lots of other ways to keep your children safe online and this is an important topic you should discuss with them at the earliest time. You just can’t wait until your kids are teenagers anymore to talk about cybersecurity and online predators.
by Felicien | Oct 25, 2018 | Education
As data breaches echo around the world, Canada now has its own law, paralleling Europe’s General Data Protection Regulation (GDPR) and the USA’s Health Insurance Privacy and Portability Act (HIPAA). These regulations govern disclosure of data breaches to people whose data has been lost, stolen or somehow leaked to the public.
Responsible leaders in U.S. companies should note that there is no exemption here for foreign-owned or operated companies. If your data breach involved Canadians, even those residing outside Canada, you have to comply.
Types of Organizations Included
Note that the law applies to organizations, which of course includes businesses. But the range of the law covers other entities as well. If you can be considered an organization of any kind, you may need to comply with these regulations.
What happens if the breach occurs in Canada, but for some strange reason, no residents of Canada were involved? You’re still required to comply with the law. (As always, legal questions are best answered by lawyers.)
The law was passed in 2015 and becomes effective November 1, 2018. Penalties for any violation can be up to $100,000. (This is a pittance when compared to penalties under the GDPR and HIPAA.)
What Do I Have To Do If There’s A Breach?
You must disclose it to affected Canadians, including the following information:
The data and nature of the breach and what specific data are at risk
What your organization has done to reduce risk and harm
How the affected Canadians can reduce their risk after the breach
Information about the organization’s contact information
The procedure for filing complaints
Is There More To This Than Meets The Eye?
Yes. It’s important to be aware that the law governing data breaches is not a stand-alone act. It is an amendment to PIPEDA, the Canadian Personal Information and Electronic Documents Act. A summary of Canada’s privacy laws, and links to more specifics can be found here. A discussion of the specific laws related to digital information is here. You need to understand and comply with both.
The wording in PIPEDA leaves room for the judgment of executives. It covers situations where “…it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to the individual.”
Whether intentional or not, the wording is somewhat vague and ambiguous. Certain words should be interpreted in the light of precedents set in the Canadian courts. There is no way to determine the true meaning of many of these terms when applied to a specific data breach, including:
Reasonable
In the circumstances
Real risk
Significant harm
What Really Happens After November 1, 2018?
Although the law takes effect on November 1, 2018, it will not actually take effect until the Office of the Privacy Commissioner of Canada has written and published its implementing regulations after consultation with stakeholders.
If you are concerned about the impact on your Canadian operations, it is important to track what is going on in the process of writing and implementing these regulations.
There is, for example, no guarantee at this point that the regulations, when written, will not be retroactive. You should comply now.
Should All Data Breaches Be Reported?
The answer to this question can be found by looking at the experiences of other companies – Facebook, Uber, Google, and Experian – that suffered data breaches and did not report them.
Every single one received a great deal of bad publicity. Many of their executives were fired for the way they mishandled the breach.
The applicable rule here that all should remember is: “It’s not the crime; it’s the cover-up.”
A data breach is bad enough. It exposes the personal information of millions of people to hackers and thieves. Any organization that has a data breach also has a duty to report it promptly. The guidelines for reporting it and notifying affected parties are clearly spelled out in the law. Your best assumption is that either you will have to report the breach, or someone will report if for you.
Fines and penalties can be much more severe for those organizations that wait too long before reporting a breach or do not follow the guidelines.
Wrap Up
Despite all the efforts devoted to cybersecurity, the public is still extremely vulnerable. In years to come, security experts may find ways to stop the onslaught of data breaches around the world, but today, the best course of action is to follow the data breach laws.
by Felicien | Oct 24, 2018 | Education
Efficiency in the workplace is paramount to success. This concept is widely held across office environments everywhere. But while technology plays an increasingly valuable role in the way the world does business, that’s not to say it doesn’t come with its own unique set of drawbacks. Laptops and mobile devices are presenting problems within the workplace, particularly in regard to productivity.
In the workplace, screens often serve as barriers, and today’s businesses are tasked with coming up with new ways to minimize these technological distractions. One effective method? Banning laptops from meetings.
The research is clear: laptops and mobile devices are no good for productivity, especially when it comes to meetings. Banning laptops and mobile devices from meetings can boost both productivity and efficiency. From reducing the amount of time it takes to conduct a meeting, to encouraging employees to be more present and engaged, banning laptops may be the next big trend in business.
The Dangers Of Multi-Tasking
Technology that’s been designed to improve our productivity can actually serve as culprits. They can interfere with our point of focus, whether that be our boss or colleague during an important meeting or a lecturer in the midst of a seminar. Laptops distract from learning, both for users and for those around them.
Research shows that multi-tasking is a killer of productivity. This doesn’t apply to just individual productivity, either. It can also have negative effects on the organizational level, which is causing problems for businesses everywhere, regardless of industry. One report concluded that multitasking within organizations is even impacting the global economy, resulting in a loss of $450 billion.
The human brain simply does not retain information as well when there is a distraction like a laptop or mobile device competing for attention. There are numerous studies that back up these claims. In fact, when employees use their laptops or mobile phones during a meeting, they’re known to do a number of things that hinder productivity, including asking questions that have already been answered. It may seem like nothing but a minor inconvenience to some, but gather enough instances like this, and you’ll see how much time (and money) is at stake.
Not only is multi-tasking thought to hinder productivity, but it also makes employees more prone to distractions. Other negative effects include poor critical-decision-making and underperformance.
Benefits Of The Ban
There are several benefits to banning laptops from meetings. From boosting creativity to cutting down on meeting time and even encouraging engagement, banishing laptops from the meeting room may be doing your company more good than you initially realize. This is why a growing number of managers are making the call.
Here are some of the benefits associated with banishing laptops from meetings.
Time Management
Commanding complete attention during company meetings can lead to more valuable, engaging discussion. A meeting in which all participants can easily understand and contribute input concisely is an effective one.
More Engagement
One of the most important aspects of a meeting is being present in the moment. Staring at your screen makes this impossible. Employees fixated on their laptops won’t be able to make eye contact, and their body language may be off-putting during a meeting. Banning laptops during meetings is just one way to promote engagement and the sharing of ideas.
Better Comprehension
Writing notes by hand has been scientifically proven to help in information absorption. While taking notes during a meeting may at times be necessary, using a laptop to do it is not. Encourage teammates to use pen and paper to increase comprehension.
Tips To Take Control
Business owners and managers can do a number of things to further promote engagement during meetings. Once you’ve made the decision to ban laptops, you may want to put a solid system into place. Establishing a firm “no laptop” rule during meetings will help things remain consistent across the board. You may even consider a check-your-laptop-at-the-door rule that will help drive the point on home with your colleagues. If you are hosting a remote meeting where laptops are necessary, implement a rule that states all other apps and windows must be closed. This small step alone can help increase comprehension and cut down on distractions.
Banning laptops may seem futile if you are wasting time in other ways. A good rule of thumb is to let employees know how long the meeting will be, as well as whether or not there will be breaks. Not only is this common courtesy, but it can also help minimize the anxiety that may come with not having instant access to emails and texts.
If you know that your meeting will consist of need-to-know information, encourage fellow employees to use pen and paper. By providing these tools ahead of time, you’ll make it that much easier for your team to follow through.
These small steps can do wonders for promoting productivity and helping your employees make the most of their time in the office. While laptops are commonplace in today’s office setting, and often vital for productivity, leaving them off the table for a while (literally) can act as the first step toward more meaningful meetings.