(866) 251-4459 support@compnetsys.com
Are You Tired Of Waiting For IT Support?

Are You Tired Of Waiting For IT Support?

The cost of downtime goes up exponentially when you’re waiting for an unresponsive IT company. So why bother? Try our responsive Help Desk instead. 

So much of the IT industry is dependent on time. How quickly an IT firm can respond to a problem, how much downtime their client deals with, how much they’re charged for on-site repair hours, etc.  The speed of resolution is a primary factor in how valuable an IT firm’s services really are.
We all know that downtime is bad. It’s bad for business, bad for employees, bad for clients – bad for you. When your systems fail, your employees sit around twiddling their thumbs, waiting for it to come back online. Your customers get more and more frustrated, waiting to get what they were expecting when they came to your office or called you that day.
But the truth is, it’s even worse than that.
Beyond the surface level issues caused by unexpected downtime, there’s the reality that downtime both wastes your money and costs you in revenue. When you really dig into the details, downtime can cost you a lot of money in a relatively small time frame.
That’s why it makes zero sense to put up with unresponsive IT support. Every minute of delay costs you more money in wasted staff hours, lost data, and lowered productivity, all on top of what you’re already paying the IT firm in the first place!
The reality of modern technology is that cybercrime, serious weather, or even human error can quickly take your systems offline. IT is now such a central part of a business that server failure and software crashes will affect every aspect of it.
The computer isn’t just one part of your business anymore. It’s how you process sales, place orders, track inventory, and more. That means that one full day of computer downtime equals one full day of not being in business.
Given that your IT is such a foundational part of your business, you need to invest in support that will make sure it keeps working for you, day after day, regardless of increases in cybercrime, or bad weather, or a careless employee.
{company} is proud to offer high-quality Help Desk support services for your business. Unlike other Lakeland network support companies, we won’t put you on hold when you need our help.
We know when you have problems with your technology, your employees are unable to stay focused and productive, which means time and money are wasted and work doesn’t get done. Our Help Desk professionals are here to give you the quick and reliable support you deserve with:

E-mail applications and Web browsers
Hardware and network troubleshooting
Printer installation and support
User administration
Desktop performance problems
Virus and malware infections

We specialize in proactive management and maintenance of your IT environment. With this type of support, most of the pending issues and possible threats in your system are neutralized before they affect your business. In-house IT staffs often operate on a break/fix model, which only address issues after a problem has occurred. Proactive maintenance keeps your systems running and your employees productive, which ensures a maximum return on your investment in technology and employee wages.
However, when something does go wrong, and you need our help, we won’t keep you waiting!
Technology issues need to be sorted out as quickly as possible, and that’s exactly what we’ll do. Our Help Desk services give you:

Access to knowledgeable technicians that are able to resolve issues remotely or come onsite when needed.
Around the clock availability via our online ticketing system, phone or email, which means you are never left without the help you need.
A thorough explanation of the situation in plain, easy-to-understand terms to help you understand what is happening with your technology.
Comprehensive support solutions for anything you need to stay productive, including remote access, printing, email, phones, connectivity, and more.

Your business can’t afford downtime, slowdowns, and breakdowns. Our proactive approach to IT management and Help Desk Services gives you the answers you need and speedy resolutions to any IT issues that may come up from day to day.
Our responsive Help Desk staff is internal and based right here in our offices.
Your assigned Help Desk technician will even come to meet you at your office – so you know exactly who you are talking to every time you pick up the phone and call.
We won’t make you wait on hold – you can speak with us directly by telephone. If it’s more convenient, you can access our Help Desk through the agent we set up on your computers, online portal, or email.

Law Firms Hot New Target for Hackers

Law Firms Hot New Target for Hackers

The legal industry is facing its most challenging obstacle to date and it’s not from judges, court cases, the mafia, felons or any of those things you might guess. Instead, these attacks against law firms are coming from hackers. Once viewed as impenetrable to hackers, today’s law firm is just about as likely to be hacked as any other business.

John Sweeney of LogicForce explains: “Law firms are the subject of targeted attacks for one simple reason,” he recently said. “Their servers hold incredibly valuable information. That includes businesses’ IP, medical records, bank information, even government secrets. For hackers looking for information they can monetize, there is no better place to start.”
His comment highlights a growing problem for the legal industry. Each day, they are faced with new and practically unstoppable cyber-crimes. One of the most startling aspects of this troubling trend is that many times, the law firm doesn’t even know it’s been hacked. A 2016 study done on this topic showed that 40 percent of the law firms that were breached had no idea that a crime had been committed. This is disturbing on several levels.
If you’ve recently done business with a law firm, there is a possibility that your business, personal and/or financial information could already be in the hands of hackers on the other side of the world.
A global problem for law firms
The fourth largest law firm in the world, Mossack Fonseca lost 11.5 million files from its database. The information was eventually shared with journalists, the BBC and newspapers. This offshore law firm specializes in helping wealthy clients hide their money. The documents that were leaked contained highly sensitive information about wealthy clients and their offshore tax schemes.
Mossack Fonseca’s client base also included national leaders and well-known politicians. The documents that were leaked held clear evidence of how and where large amounts of money were hidden by illustrious leaders like Vladimir Putin. Embarrassing revelations were made public such as how British prime minister, David Cameron’s father, had been avoiding paying taxes in Britain for many years. Any law firm would find it difficult to recover from such a devastating breach of security.
Solving the problem
For most companies who are breached by cyber thieves, the recovery process begins with contacting those who were affected while stopping any other data leaks. With law firms, this process usually begins with helping the firm to find out whether they’ve already been a victim of a cyber-crime. This requires experts in cybersecurity who will run a series of tests looking for specific anomalies. Once they find out whether data has been lost, the experts will recommend a course of action. This typically includes securing the data so that no other intrusions will occur, while notifying those who were affected.
Law firm hacking on the rise
In spite of all the hype about hacking and cyber-security, a new report says that 14 million businesses were, in some way, affected by cyber-crimes last year. The experts believe that the reason the number is so high is that most small business owners do not believe they are at risk. This is also true of most law firms. They simply think they are exempt from data breaches. This leaves them even more at risk because they are unprepared.
Senior attorneys don’t fully understand how hacking is done and what types of weaknesses a hacker looks for. The principles at a law firm are often not up to date on the latest techniques that hackers are using. This leaves them defenseless. If you want to defeat an enemy, you must first learn everything you can about that enemy. Very few people including attorneys, understand the science behind hacking.
In addition, lawyers use a wide range of devices from smartphones to laptops and desktop computers. Each device is a potential gateway for cyber-thieves to enter and steal information. With the Internet of Things (IoT) now growing, even appliances in the break room can be hacked.
The recent rise in law firm breaches proves that professionals are still not fully aware of the dangers lurking around us on the internet. Attorneys may be reluctant to spend the money and time on a security team that will come in and create the proper security protocols. But waiting to see will place all customer data at risk. People often tell their attorney sensitive information that could harm their clients in many ways. A data breach is embarrassing and hard to explain to those clients who have entrusted you with personal information.
Preparing for data breaches
A good place to start for a law firm that does not have proper security in place is the American Bar Association’s guide. This comprehensive document includes a great deal of information about preventing cyber-attacks. It also addresses ways to respond once an attack has occurred. Employees should be trained about phishing attacks and this training must be ongoing because the method that hackers use evolves with each new attack.
The managers at a law firm can begin by engaging an outside IT security expert that specializes in legal data. The team of security experts will assess your current level of protection against intruders, then recommend new initiatives. They should institute a regular training program that teaches employees how to spot phishing attacks in emails. Even trained employees may get careless, but continual training helps everyone to remember how important it is not to click on suspicious links or give away passwords.
What a law firm can do today
Many law firms are also writing their own policies about password protection, log-in credentials, and web-surfing. Once you have policies in place that your employees are aware of, you can begin to enforce them and this will help to eliminate threats. Your onsite IT people should be checking weekly for patches and updates to software. New updates should be downloaded as soon as possible.
Regardless of the time and expense of these security initiatives, the alternative could be devastating. One of the most important assets a law firm has is its reputation. Once a data leak has occurred, it’s too late. Legal professionals must do everything possible to prepare and prevent these leaks.
There’s every reason to believe that this digital age will continue to expand across the world. Businesses and the legal industry are facing unprecedented challenges for the future, but there are solid remedies that work. It all begins with realizing how vulnerable you are and how important it is to protect your client’s information. Regardless of the cost, the alternative is just too costly.

How to Simplify Microsoft Outlook 2016

How to Simplify Microsoft Outlook 2016

Microsoft Office 365 now has over 60 million active users each month and has become a favorite of large and small business owners. Just about every task that business people complete each day can be accomplished using Office 365. From Excel spreadsheets to professional word processing, users say they get more done with Office 365.
Their flagship email program is Outlook and this program can handle much more than your average email tasks. It integrates perfectly with the other Office 365 programs and it features a similar look and feel. The “Ribbon” that everyone has become so accustomed to has many of the same commands as you might see in Word. That makes it much easier to learn how to become an expert user.
Outlook 2016 features so many good shortcuts and handy tricks to make every project go smoother. However, sometimes users simply want to sort through their emails, answer them and move on to something else. For those times, you can follow a few easy steps to create a much more streamlined Outlook experience.
Simplifying the Home Page
The home page of Outlook 2016 contains six major areas. The ribbon runs across the top, then across the middle are four sections. On the far left is the folder pane, next is the Inbox and then the wider section is your reading pane. On the far right is the calendar. Here’s where you can set appointments. Down below, across the bottom is a new area that Microsoft has recently incorporated in the design called the Navigation Pane. This area contains links for your Mail, Calendar, People, Tasks, and More.
This new area replicates some of the other areas on the page. Therefore, you can just close the whole right-hand section where the traditional calendar is located. To do this, simply click on the small “X” in the upper right-hand corner. This makes the Calendar area disappear. When you’re ready to restore that area, simply click that X again and the pane reappears.
In addition, you can minimize the whole Navigation Pane by clicking on More (represented by dots). Select “Navigation Options” from the drop-down list. A small dialog box appears where you can check the box that says, “Compact Navigation.” This reduces the Navigation Pane to small icons that are barely noticeable. They will still work the same as the original, only now they’re inconspicuous.
Following along that same concept, you can also remove the left-hand pane which contains your folders. Now, you’ve effectively reduced the Home Page from six sections to three. This is a good idea for anyone who just wants to comb through their emails, see what is important and respond. Your attention is no longer drawn away by a busy-looking page. Now things appear much simpler. If you need to look at any of the sections you’ve removed, it’s very easy to restore each section. For the folders, you can click on the word “folders” and they will appear until you click the word again. In many Microsoft programs, hovering over a word or section causes additional information to appear. This is a good way to learn more about a section or get a quick look at what is contained in an area. These pop-outs usually appear when you hover over them and then disappear once you move your cursor.
Working with the Ribbon
The Ribbon in Outlook 2016 contains four major tabs with various tools available. It’s easy to remove the Ribbon if it seems distracting. Simply click on the arrow on the far right side and this collapses the Ribbon. The keyboard shortcut for this action is Control+F1. If you need to quickly show the Ribbon, then click on the View tab and it will appear until you click away. It’s often just that easy to make a section appear or disappear. This makes it fast to remove areas you might not need and it’s a good method of personalizing your Outlook program.
If you’d like to just completely get rid of the Ribbon, there’s an icon in the upper right-hand area next to the question mark. Click on that and you’ll see that they are three options for the Ribbon. You can Auto-Hide, Show Tabs or Show Tabs and Commands. The last one is the most commonly used. The other two allow you to have as much of the Ribbon at the top as you need. If you click on Auto-Hide, the whole Ribbon disappears leaving you with a very clean looking page that deals only with your Inbox and Reading Pane. You can quickly move through emails or read over longer emails that require more attention. When you need to temporarily view the Ribbon, just place your cursor over the colored bar at the very top and the Ribbon will reappear.
Personalizing your Program
Once you get the hang of how easy it is to close and open areas, you can adjust your Outlook email program so that it displays only those things that you work with most often. Microsoft purposely builds software programs that can be easily modified by the user to give each person their own personalized experience.
One thing that many users probably know but may forget is that all Microsoft programs have one thing in common: you can right-click in whatever area you’re working and get a list of options. Often, on this list, you’ll see the action you want to take, thus preventing you from having to completely restore an area of the page. This is a quick, easy way to accomplish almost any task.
Reading Emails
The new Outlook also allows you to click on “Reply” and then start typing your email. There’s no longer a new window that appears. This has proven to be a huge time-saver. Let’s say you’ve clicked reply but you want to add some bolding to your typing or use a larger font. Highlight the text and the font section appears next to your typing. This works exactly the same as it does in Word. You can quickly change fonts, colors, add underlines or bolding, highlight text or even add indenting to your paragraph. If you right-click the Inbox, you’ll see a different set of commands that pertain only to the Inbox.
Attachments can be viewed just by clicking on them. If you’re reading an email that has a Word doc attached, just click it once and it opens in the Outlook program. If you double-click on the attachment, it will open up in Word. This is also true for PDF attachments. This can save lots of time if you only need to take a quick look at an attachment someone sent with their email.
Keyboard Shortcuts
One of the big time savers in all Office 365 programs involves learning the keyboard shortcuts. People who use these daily say that it improves their speed and prevents them from losing focus. If you print them out and keep them handy, you’ll quickly learn the most commonly used ones. Below are a few that everyone uses in Outlook, but there are many more that you could learn if you want to be an over-achiever:

Alt+S: send email
Ctrl+R: reply to email
Ctrl+M: or F9 to Send/Receive all
Alt+R: reply to all in email or switch to work week calendar view
Ctrl+G: open the “Go to date” dialog and jump to any date in the calendar
Alt+W: forward email or switch to weekly calendar view

More Shortcuts
Press Ctrl + [the place number of the item] to switch between email, contacts, calendar and other items in Outlook. This is a quick way to move from one task to the next. Create a reminder by pressing Ctrl + Shift + N. This creates a virtual sticky note that you can drag anywhere on the screen.
When setting appointments go to your calendar and just type a phrase like, “next Thursday” or “one week from now” and your calendar will automatically open there.
You can block annoying emails that you don’t want to receive by going to Home>Junk email options and selecting the sender you wish to block. View long emails as a conversation by clicking on the message and then selecting View>Show as Conversation. Flag a message for further inquiry by pressing the Insert key to toggle the flag off and on.
Learn to Make Outlook Work for You
Outlook 2016 includes so many great time-savers like these. If this is a program you use daily, it’s a good idea to become a pro at using them. You can cut precious minutes from your busy day simply by learning how to streamline and personalize Outlook. As Microsoft continues to update its Office 365 programs, they will build in many more shortcuts. They’re easy to learn and the company offers a number of great video tutorials and training videos to help even a novice learn all the helpful features.

Hacking Alert – An Employee Of Your Manufacturing Company May Be Sending Intellectual Property To a Criminal and Not Know It!

Hacking Alert – An Employee Of Your Manufacturing Company May Be Sending Intellectual Property To a Criminal and Not Know It!

Your manufacturing company is in the crosshairs of hackers. Cyber-spies are using backdoor viruses to steal intellectual property from businesses like yours.

According to Verizon’s 2017 Data Breach Investigations Report, these cyber-spies are supported by nation states.

620 of data breaches hit the manufacturing sector last year, and 94% were committed by state-affiliated actors.
91% of the intellectual property (IP) that was stolen was proprietary data owned by manufacturing businesses.

China in particular expanded their state-sanctioned hacking of US manufacturers in 2017. It’s expensive to do the R&D necessary to design and build a product. It’s a lot less costly just to steal it. Nation-state cyber-espionage is the predominant cause of breaches in the manufacturing industry.
In February 2018 the Worldwide Threat Assessment of the U.S. Intelligence Community confirmed that some nation-state actors are continuing to use cyber attacks to “acquire U.S. intellectual property and proprietary information to advance their own economic and national security objectives.” They say that advances in manufacturing, particularly the development of 3D printing, almost certainly will become even more accessible to a variety of state and nonstate actors and be used in ways contrary to our interests.
The problem is that while manufacturing increasingly involves high-tech processes, in many cases manufacturing businesses don’t have the right IT security in place.
40% of manufacturing security professionals say they don’t have a formal IT security strategy in place. And 37% say they don’t have an incident response plan. This makes manufacturing businesses a prime target for hackers who want to steal IP.
A Backdoor Could Be Secretly Leaking Your IP
The Verizon report reveals that most computer intrusions in the manufacturing industry began with a spear-phishing email that was sent to a company employee and which contained a malicious link or attachment. The malware comes in the form of a backdoor that gives the hacker secret remote access to the computer.
A backdoor is an undetectable technique where a technology system’s security is bypassed without anyone knowing so a thief can steal data. Hackers use backdoors to install malware to modify a code or detect files and gain system and data access. Any connected device in the manufacturing process is at risk.
Social engineering and malware-based cyberattacks combined for a whopping 73 percent of all data breaches in the manufacturing sector last year. Spies favor email phishing techniques with malware to compromise victims.
A recent article in the CIO Journal stated: “Almost any connected device, whether on the shop floor in an automated system or remotely located at a third-party contract manufacturer, should be considered a risk.”
Manufacturers aren’t asking their Technology Service Providers to perform cyber risk assessments on technology they use on the factory floor. If they did, these backdoors could be detected and “closed.”
This is a nightmare that will only get worse if manufacturing companies don’t perform their due diligence where IT security is concerned. If this doesn’t scare you, these statistics should. In 2017:

21 percent of manufacturers lost intellectual property to hackers.
Four of the top ten cyberthreats facing manufacturing organizations are caused by their employees.
28 percent of manufacturing organizations lost revenue due to cyber threats.
Over 35% of manufacturing executives believe IP theft was the primary motive for the cyber attacks in their businesses.

To change this paradigm requires buy-in from leadership. However, although the manufacturing industry is focused on innovation, updating and enhancing technologies on the factory floor is a cumbersome, slow process. Hackers know this.
It’s time to protect your intellectual property. Develop a cyber-risk management program with the help of your Technology Solutions Provider. They can do a complete IT risk assessment and detect if there are any backdoors installed on your systems.
The right Technology Solutions Provider (TSP) will customize an IT strategy for you that includes protection for your intellectual property.
Data Security: With ever-increasing threats from cybercrime, your manufacturing business requires risk assessments, data protection, data recovery, staff awareness training, and maximum security of your critical data. You must be able to backup, protect and recover your proprietary and confidential information. To do this, you should outsource your disaster recovery and backup solutions to an expert TSP who will analyze your current state of preparedness and offer guidance on potential courses of action.
Disaster Recovery/Business Continuity: You must be able to recover data after a power outage, disaster, or when IT services are compromised. This requires backing up data to a secure, offsite location so it can be retrieved anywhere you have an internet connection. This way, your employees can continue working.
The right TSP will:

Develop and deploy a complete Business Continuity and Disaster Recovery Plan, a customized program to integrate the policies and procedures into your corporate culture, and conduct training sessions to ensure all employees are comfortable with procedures.
Maintain an on-going program designed to ensure the validity of the Business Continuity and Disaster Recovery Plan and keep the plan up to date and communicated to all key personnel.

Security Enhancement Via Continuous Monitoring and Maintenance: The right TSP provides continuous monitoring to remotely view your technology network, identify risks and halt IT attacks and breaches. They will address IT issues before they cause downtime or data loss.
Identity and Access Management: They will help you comply with security and regulatory requirements, allowing only authorized individuals to access confidential information.
Virtualization—Servers, Desktop, Storage, Applications, Data Center: Virtualization in information technology refers to the use of virtual servers, desktops, storage devices, applications, and computer network resources. It allows you to virtualize your entire IT infrastructure or specific aspects of it. Virtualization simplifies technology to promote security and efficiencies and reduce costs for your manufacturing business.
The right Technology Solution Provider will ensure the security of your intellectual property. They will also be available 24/7 to provide the specialized and customized IT Service and Support you need to succeed.

New Threat Alert From The FBI – Password Spraying

New Threat Alert From The FBI – Password Spraying

7 Steps To Protect Yourself
You probably use a number of personal identification numbers (PINs), passwords, and passphrases to get money from ATMs, to use your debit card when shopping, or to log in to your personal or business email. Hackers represent a real threat to both your personal and business password security and confidential information. Now, these criminals are using a technique called Password Spraying to steal your information.

According to information derived from FBI investigations, malicious cyber actors are increasingly using password spraying against organizations in the United States and abroad. In February 2018, the Department of Justice in the Southern District of New York indicted nine Iranian nationals, who were associated with the Mabna Institute, for computer intrusion offenses. However, password spraying isn’t limited to this group. Other hackers are using it to gain access to both personal and business confidential information.
Manhattan U.S. Attorney Geoffrey S. Berman said: “Today, in one of the largest state-sponsored hacking campaigns ever prosecuted by the Department of Justice, we have unmasked criminals who normally hide behind the ones and zeros of computer code. As alleged, this massive and brazen cyber-assault on the computer systems of hundreds of universities in 22 countries, including the United States, and dozens of private sector companies and governmental organizations was conducted on behalf of Iran’s Islamic Revolutionary Guard. The hackers targeted innovations and intellectual property from our country’s greatest minds. These defendants are now fugitives from American justice, no longer free to travel outside Iran without risk of arrest. The only way they will see the outside world is through their computer screens, but stripped of their greatest asset – anonymity.”
How Does Password Spraying Work?
Password spraying is a type of brute force attack where hackers use a username with multiple passwords to gain access to your IT system. With traditional brute force attacks, the criminal uses one username with multiple passwords. Employing a lockout functionality, which locks the criminal out after a set number of login attempts, is an effective means of dealing with traditional brute force attacks.
However, with a password-spray attack (also known as the “low-and-slow” method), the malicious cyber actors use a single password against many accounts before moving on to another password. They continue this process until they find one that works. This strategy works for them because they can avoid account lockouts. It circumvents lockout functionality by using the most common passwords against multiple user accounts until they find one that works.
Password spraying targets single sign-on (SSO) and cloud-based applications using federated authentication. A federated authentication identity provides single access to multiple systems across different enterprises. Criminals target federated authentication protocols because it disguises their activities and ensures their anonymity.
Attackers use password spraying in environments that don’t use multi-factor authentication (MFA), rely on easy-to-guess passwords, or use SSO with a federated authentication method.
 
Your Email Is Also At Risk
Hackers also prey on email accounts that use inbox synchronization (which pulls emails from the Cloud to inboxes on remote devices). Malicious actors use inbox synchronization to obtain unauthorized access to your organization’s email directly from the Cloud. Then they download email to locally stored files, identify your company’s email address list, and secretly apply inbox rules to forward your sent and received messages to them.
The United States Computer Emergency Readiness Team (US-CERT) details how hackers use password spraying, what you should watch out for, who is at risk, and the impact this type of attack can have on your organization.
Your Technology Service Provider can explain this to you and your employees in plain language, and help you protect your organization against password spraying and other attacks.
 Traditional Tactics Techniques & Procedures

Using social engineering tactics to perform online research (i.e., Google search, LinkedIn, etc.) to identify target organizations and specific user accounts for initial password spray
Using easy-to-guess passwords (e.g., “Winter2018”, “Password123!”) and publicly available tools, execute a password spray attack against targeted accounts by utilizing the identified SSO or web-based application and federated authentication method
Leveraging the initial group of compromised accounts, downloading the Global Address List (GAL) from a target’s email client, and performing a larger password spray against legitimate accounts
Using the compromised access, attempting to expand laterally (e.g., via Remote Desktop Protocol) within the network, and performing mass data exfiltration using File Transfer Protocol tools such as FileZilla

Indicators That You’ve Been Attacked

A massive spike in attempted logins against the enterprise SSO portal or web-based application;
Using automated tools, malicious actors attempt thousands of logons, in rapid succession, against multiple user accounts at a victim enterprise, originating from a single IP address and computer (e.g., a common User Agent String).
Attacks have been seen to run for over two hours.
Employee logins from IP addresses resolving to locations inconsistent with their normal locations.

Typical Victim Environment
The vast majority of known password spray victims share some of the following characteristics:

Use SSO or web-based applications with the federated authentication method
Lack multifactor authentication (MFA)
Allow easy-to-guess passwords (e.g., “Winter2018”, “Password123!”)
Use inbox synchronization, allowing email to be pulled from cloud environments to remote devices
Allow email forwarding to be set up at the user level
Limited logging setup creating difficulty during post-event investigations

The Impact
A successful network intrusion can have severe impacts, particularly if the compromise becomes public and sensitive information is exposed. Possible impacts include:

Temporary or permanent loss of sensitive or proprietary information;
Disruption of regular operations;
Financial losses incurred to restore systems and files; and
Potential harm to an organization’s reputation.

7 Steps You Can Take To Mitigate Password Spraying Attacks

Enable MFA and review MFA settings to ensure coverage overall active, internet facing protocols.
Review password policies to ensure they align with the latest NIST guidelines and deter the use of easy-to-guess passwords.
Review IT helpdesk password management related to initial passwords, password resets for user lockouts, and shared accounts. IT helpdesk password procedures may not align with company policy, creating an exploitable security gap.
Many companies offer additional assistance and tools that can help detect and prevent password spray attacks, such as the
Make sure your employees change their corporate passwords every 60 days.
Establish a password policy that prohibits easy-to-guess passwords. Enable multi-factor authentication (MFA) for all web-based applications. If MFA practice is already in place, review current protocols thoroughly to ensure it is maintained well
Ask your Technology Solutions Provider to conduct Security Awareness Training for your employees at all levels.

The FBI Reporting Notice
The FBI would like you to report any suspicious or criminal activity to your FBI field office or the FBI’s 24/7 Cyber Watch (CyWatch). Field office contacts can be identified at www.fbi.gov/contact-us/field. CyWatch can be contacted by phone at (855) 292-3937 or by e-mail at CyWatch@ic.fbi.gov.
Your report should include:

The date,
Time,
Location,
Type of activity,
Number of people affected,
Type of equipment used for the activity,
The name of your company or organization, and
A designated point of contact.