by Felicien | Feb 1, 2018 | Education
In the fight to avoid security breaches, one area has proven over and over to be the weakest link. It’s the human factor. A survey done by CompTIA shows that human errors are responsible for 52 percent of all security breaches. Each day employees open emails; it’s part of their job. Often there are links in these emails, and most of them are legitimate. But then there’s that one link that downloads a virus into the computer system, and suddenly thieves have access to all company files.
A growing number of cybersecurity breaches come as a result of malicious email links. Educating employees about the various types of viruses has become a full-time job for many companies. In spite of regular meetings, webinars, and conferences, careless employees still open suspicious emails and click on links that open the door for cyberthieves. A recent report from Experian says that most employee training seminars are insufficient to alter employee behavior.
One study from MeriTalk reports that employees sometimes bypass security measures on purpose, then download a malicious virus without realizing it. That same report reveals that many employees view security measures as restrictive. They say it takes longer to get their work done each day. Employees can sometimes view security measures as cumbersome and annoying.
In spite of continuing education about data breaches, employees simply forget. They get busy working on something, then absent-mindedly open an email and click on a link that downloads spyware, ransomware and other malicious programs. Employee training about security threats has ramped up considerably over the past decade. And yet one study shows that 57 percent of company employees aren’t even aware of the current security protocols where they work.
Lack of communication
Another issue that was recently exposed is the lack of communication between the IT department and CEO. Some CEOs simply don’t want to spend the money to update their cybersecurity. They fail to equate a cyber breach with a monetary loss. Human beings seem to function under the fallacy that bad things only happen to other people. Cross-departmental communication is critical for everyone to understand what’s at risk.
With so many companies now employing remote workers, this lack of communication can quickly escalate. Remote workers should not be given access to any areas of the company’s network that aren’t necessary. A remote worker could accidentally leave their laptop in a restaurant or hotel. The IT department must be more vigilant about these matters. With greater control over who has access to what data, a company can better manage their risks.
Lessons learned
In just the last few years, massive data breaches at well-known stores like Target have everyone rethinking their data security. The federal government isn’t immune either. In 2015, the Office of Personnel Management (OPM) publicly disclosed that a data breach had occurred exposing the personnel records of over four million federal employees. Before this investigation was completed, the public learned that there were two separate breaches and that over 21 million records had been stolen. Most of these records included names, dates, social security numbers and even fingerprints.
This breach should have been a wake-up call for everyone. If the government can’t protect its data, then what chance do small business owners have? As unsettling as these types of breaches are, they have not resulted in dramatic changes to data security. Though businesses are taking the threat more seriously, most are not willing to spend the time and money to protect their data from intrusion.
Malicious employees
Another factor that isn’t spoken of much is the growing number of angry employees who expose a company’s network on purpose. These may be people currently working for the company or those who have recently been fired. When an employee is about to be fired, the IT department should make sure all their credentials are canceled before the employee leaves the building. Management can step in and try to mitigate the situation if they feel an employee may try to retaliate against the company. For everyone’s sake, it’s best to try to mend fences before allowing an angry employee to leave for the last time.
The ongoing cost of data breaches
For those who have already experienced a data breach, the lessons learned came at a high cost. Many of them are still dealing with the repercussions. A certain number of shoppers may never visit a Target store again. It sometimes takes years before consumers forget. The average cost of a data breach in monetary terms is $154 per record. If a company loses six million records, this is a significant amount of money. The cost is rising rapidly.
Also, a company’s reputation can suffer serious damage. Retail stores may not see customers returning to shop with them for months or even years after a cyber intrusion. Data breaches cause embarrassment for the business as well. Customers may not feel like they can trust a business anymore with their personal information. Customer trust is difficult to rebuild.
Conclusion
It’s time for companies of every size to take data breaches more seriously. Every company’s sensitive data deserves the best protection available. Employees should participate in regular monthly security awareness training. The IT department must have a solid system of checks and balances. The CEO should make it a priority to regularly communicate with the IT department.
Every business should strive to install the very best security programs they can afford. They must examine their weaknesses at every level and ensure IT professionals conduct annual vulnerability assessments. System-wide encryption, password management, and multi-factor authentication are strong measures that can help. When each enterprise, corporation, and company does its best to stop data breaches, we may see a decline in security gaps. Until then, a greater degree of diligence on everyone’s part can stem the tide of the growing number of data security leaks.
by Felicien | Feb 1, 2018 | Education
Ransomware has quickly become one of the biggest cyber threats to businesses today, especially given the recent Wanna Cry epidemic that infected hundreds of thousands of IT systems in more 150 countries. This kind of malware presents serious data integrity and financial concerns for affected businesses. It works by tricking a user into opening an executable file (either as an email attachment or downloaded from a webpage linked in an email) which then encrypts the victim’s files and holds them for ransom.
A majority of cybersecurity services offered today include the best in vital technologies, from firewalls to anti-malware to data encryption and more. However, as important as this technology is, on its own, it simply isn’t enough to protect against threats like ransomware. The key to truly comprehensive cybersecurity is simple, yet often overlooked: the user.
Cybersecurity company Malwarebytes has found that as many as one-third of businesses like yours were hit by ransomware within the last year – the key to all these incidents? The “human factor”. Included in Malwarebytes’ Second Annual State of Ransomware Report, data showed that, of the 32% of organizations that were hit by malware, 20% had to immediately halt their operations.
It gets worse – further statistics showed that:
25% of businesses were hit with more than 20 ransomware attacks in 2016
31% of affected businesses in Australia did not know they were hit by ransomware, as compared to 9% in the US
46% of Australian victimized businesses paid the ransom, and after paying, 40% still lost their files.
Cybersecurity gimmicks — such as “set it and forget it” firewalls and antivirus software — fail to account for how important the user is. Even the most effective digital security measures can be negated by simple human error, which is why conventional solutions are simply not enough to ensure your business’ safety. Much of cybersecurity is dependent on the user, and as such it’s vital that you properly educate your employees in safe conduct. The more your workforce knows about the security measures you have in place, the more confidently they can use the technology in a secure manner.
“People [behind the ransomware attacks] are going to more of the human factor now,” said Malwarebytes Senior Systems Engineer Brett Callaughan to CNET. “A lot more attackers are becoming aware of the fact that they can make small amounts of money on a grand scale very quickly if they completely automate this. The attackers we’re seeing are extremely sophisticated — they’re not fussed about creating a file and making something look real. They’ll just go after the user and they’ll spray and pray. If you hit 100,000 email accounts and 10,000 hit the button and you’re charging $200 a piece? That’s a significant amount of income right there from doing very little.”
So what can you do? First of all, ensure your employees are comprehensively trained in cybercrime awareness and prevention so that they can help keep your business safe. Training should include:
How to identify and address suspicious emails, phishing attempts, social engineering tactics, and more.
How to use business technology without exposing data and other assets to external threats by accident.
How to respond when you suspect that an attack is occurring or has occurred.
Further vital information that your staff needs to maintain a secure business.
That said, employee awareness will only do so much. Remember that ransomware is likely today’s biggest threat to cybersecurity, which means anything less than a comprehensive defense won’t be enough. You hear about it everywhere, along with a range of possible solutions, most of which are defensive – ways to keep the intruders out before they encrypt your files and send you the ransom note.
Both industry leaders and cybercrime law enforcement members agree that the best defense against ransomware, other types of malware and similar cybersecurity threats is a robust data backup contingency. Have you invested in one for your business?
When developing your ransomware defense, keep these recommendations in mind:
Make a considerable investment in a comprehensive backup data recovery solution so that you can restore your data at a moment’s notice when necessary.
Test your backup and cybersecurity measures thoroughly and regularly; create dummy files and then delete them to see how fast they can be restored, or schedule a day to literally unplug your critical systems to find out how long it takes to get online again.
Be sure to make the most of the available resources (both provided online and through expert IT consultants) to ensure that you’re not overlooking vulnerabilities in your IT security methodology.
The good news is that you don’t have to do all this on your own. Partner with an experienced, expert provider of security support and solutions like {company} today to ensure you’re comprehensively protected from ransomware on all fronts.
For more information about how to train your employees to protect your business against ransomware, get in touch with {company} right away at {phone} or {email}.
by Felicien | Jan 31, 2018 | Education
It’s been coming since 2010—That’s when Steve Jobs announced that Apple was going to kill XServe, its enterprise-level server hardware solution.
Ever since that time, Apple has been slowly backing away from the server market.
This slow death of Apple server ambitions has now come full circle for individuals and small businesses with the release of an Apple support memo that states, “A number of services will be deprecated, and will be hidden on new installations of an update to macOS Server coming in spring 2018.”
What does this mean?
Apple is getting rid of many of the functions that individuals, small businesses, educational institutions, and software developers currently rely on to get things done.
But they aren’t just hitting the “delete” button.
If you already have these functions set up, you’ll still be able to use them with the spring 2018 release. Apple’s just going to make it difficult for you by hiding the “deprecated services.”
Basically, Apple wants us to forget that this functionality was once available, and wean the public off the macOS Server. Eventually, as fewer and fewer users are tied to the functions of the macOS Server, they will be discontinued entirely.
What is the rationale for getting rid of macOS Server functionality?
In its support memo, Apple tells us that they are going to “focus more on the management of computers, devices, and storage on your network.”
Apple ran the numbers and realizes that the money lies in selling and serving the iPhone, iPad, and Apple computers – not in server functionality.
The functionalities that are going by the wayside with the new macOS update are as follows:
Calendar
Contacts
DHCP – Dynamic Host Configuration Protocol
DNS
Instant Messaging
NetInstall
VPN
Website Hosting
Wiki
Apple provided a list of “potential replacements” in their support memo.
But the BIG question is: How can we get secure file access without the macOS Server VPN?
These macOS Server changes impact system admins who will lose some or all of the macOS Server tools they depend on, and the businesses they serve could be negatively affected.
At one time, Apple claimed that the macOS Server was, “so easy to use, you don’t need your own IT department.”
Now you’re going to need an outsourced IT professional, like those at {company}, to help you figure out your next steps and how to allow secure file access.
To help us out, Apple has provided three options for VPN alternatives to the macOS Server VPN function:
OpenVPN
This network tunneling VPN software option is compatible with iOS, Windows, Mac, Android, and Linux. Regarding security, it allows for granular remote access and connects to either your cloud assets or your company’s internal network. One of the prominent features of this VPN option is the onboard, fine-grained access control.
SoftEther VPN
This open source VPN option works across platforms (FreeBSD, Solaris Windows, Linux, and Mac) to deliver multi-protocol VPN functionality. SoftEther gives you mobile device compatibility through L2TP/IPsec server function. Part of the attraction of this VPN option is the low latency, fast throughput, and Nat-traversal firewall resistance.
Tcpcrypt
This software is used to encrypt traffic to and from high volume servers. It protects the user against passive attacks where criminals are eavesdropping on communications. Part of the attraction of Tcpcrypt is that they claim it, “requires no configuration…has no NAT issues…has very high performance (up to 25x faster than SSL).”
So, how do you run a secure file storage server without macOS Server VPN?
Apple certainly hasn’t given us much to go on in its recent support memo. The third-party VPN and encrypted traffic software options provided by Apple are certainly useful to the IT professional and systems administrator, but not to the home-based business owner or individual user who was enjoying the macOS Server VPN capabilities.
With Apple’s announcement to phase out macOS Server functionality, it leaves us with the question of file collaboration for small to mid-size businesses.
There are several ways that an IT professional – such as the IT support team at {company} – can enable the Mac users in your business to access and edit documents, spreadsheets, presentations, and databases in-house or on the move. Here are just a few of those alternatives:
Cloud-Based File Sharing Applications – These applications have become increasingly popular. You likely already use a home version of at least one of them – like DropBox, Google Drive, or com.
Office 365 – Office 365 is compatible across platforms and was built with secure file collaboration in mind. No need to go to the office to get your data – it’s all there at the touch of a button. Businesses worldwide have moved away from VPN and now rely solely on Office 365.
Remote Access Models – These popular cloud-based applications allow access to your home or office computer through a web interface. Options include companies like GoToMyPC, RemotePC, and LogMeIn.
As Apple takes its final walk away from server offerings, we realize that it is no longer a competitor in enterprise-level computing. Sure, Apple devices will always be used, but for now, they are peripheral to the server and cloud assets that are at the core of enterprise computing. However, Apple still holds the market share – and the hearts – of creative individuals and industries that have relied on Macs for years.
The experts at {company} will show you how to store data securely, access it freely, and collaborate instantly with colleagues. Enjoy the freedom of mobility while having everything you need at your fingertips – wherever you go. Contact us at {phone} or send an email to {email} to get started.
by Felicien | Jan 31, 2018 | Education
If communication is the key to personal and career success, then we should be doing everything in our power to ensure our communication lines are well established, extremely efficient, and thoroughly secure. Migrating to Office 365 might be what your business needs to get the most out of your email server.
Why migrate to Office 365?
Office 365 provides you with some new, much-needed features like:
Microsoft Lync Online with real-time collaboration and communication.
SharePoint Online that offers world-class collaboration and an easy-to-use information sharing platform.
Microsoft Office Professional Plus with the most popular client tools on the planet such as Microsoft Word, Excel, PowerPoint, Outlook and OneNote. This ensures that you always have the latest versions of these apps at your fingertips, whether it be while working on your desktop, or on a tablet at home.
Microsoft Exchange Online and an improved experience with mainstream e-mail and messaging.
What are my migration options?
Microsoft offers three main bulk migration options for Office 365: Cutover, Staged, and Hybrid:
Cutover Migration works best for businesses with 2,000 mailboxes and under. With this option, you can’t keep mailboxes on-premises, only in the cloud.
Staged Migration works best for Exchange 2007 and 2003 but requires a directory. Staged Migration can keep mailboxes on-premises as well as in the cloud, and there’s no limit to the number of mailboxes that you can move.
Hybrid Migration works best with Exchange 2010, 2013, and 2016, and like Staged Migration, it also requires a directory. Not only can Hybrid keep mailboxes on-premises as well as in the cloud, it also provides seamless functionality across environments.
What if these options don’t quite fit my needs?
If these options don’t fit your needs, there are also three less common options. The IMAP option works best with Exchange 2000, but it won’t move calendar items or tasks. If you prefer a more hands-off approach, or if your business is simply too large for the other options, you can have Microsoft Office import items for you. This is an excellent option if you have more than 10TB of data. Or, if you prefer, you can use third-party applications like Lotus Notes, or Novell GroupWise to migrate your mail and data, but this option doesn’t allow mailboxes to be stored on-premises, only in the cloud.
How to Prepare for Migration
After you’ve selected the option that meets your migration needs, you should begin preparing for your migration to Office 365. Microsoft recommends that you use the email migration service Outlook Anywhere (also known as RPC over HTTP), to connect to your on-premises Exchange Server. This allows you and your staff to use Outlook as you normally do without the need for special connections such as hardware, smart cards, or security tokens. Once you enable Outlook Anywhere, verify that you can connect to it outside your corporate network. Then configure Outlook Anywhere on your on-premise Exchange Server. This allows you and your staff to use Outlook as you normally would, without the need for special connections such as hardware, smart cards, or security tokens. Once you have it configured or enabled, you will want to verify that you can connect to it outside your corporate network.
Next, you should set permissions on your account so that after migration you can connect it to your new Office 365 email system. Remember that the admin must be assigned “Full Access permission” or “Receive As” permission to modify the Target Address. Also, be sure to turn off the unified messaging until after the migration is complete.
To begin the migration, you will want to verify your domain address in Office 365. Use directory synchronization to create users in your new Office 365. Next, create a list of mailboxes that you want to migrate and create a migration endpoint that’s connected to the on-premises server. These Migration Endpoints capture the remote server’s information and provide the credentials for migrating your data.
Now You’re Ready to Migrate Your Mailboxes.
If you are performing a stage migration, select the users to include in the first batch of the migration. Now you can begin the migration. Once you receive notification that the sync is complete, verify that the migration worked to ensure there are no errors and that you have included the appropriate users in the Office 365 Admin Center.
After Migration
After your migration to Office 365, you should complete a few post-migration steps to ensure the new system is running smoothly and effectively:
Route emails directly to your new Office 365. It can take up to 72 hours for some email systems to recognize the change from on-premises to cloud email.
Activate your Office 365 user accounts by assigning the appropriate licenses.
Create an auto-discover record so users can quickly access their new mailboxes.
Lastly, you should retire your on-premises email servers and celebrate as the migration is now officially complete!
At this point, you should feel a sense of accomplishment (and well-deserved at that). But your work isn’t done yet. Through Office 365 Support you can easily try out all the new features and maybe even gain a level up on the old features. Office 365 walks you through signing in, creating and saving projects, sharing and collaborating with staff, and setting up your mobile apps. Then, it introduces you to a few new things that will increase your productivity at work, such as Flash Fill in Excel or morphing your slides in PowerPoint.
Finally, schedule regular training for your staff to make the most out of your new Office 365. Then you can “pat yourself on the back!”
As you can see, migrating to Office 365 isn’t easy. That’s why businesses count on the experts at CompNetSys to handle the migration for them. For more information contact us at: 1.866.205.8123 or support@compnetsys.com
by Felicien | Jan 31, 2018 | Education
Data is the foundation of any business. Building a business without protecting your data is like building a home on wet sand, leaving the tide to sweep it away. With all the ways data is being stolen today, there are a few steps you should take to build a secure foundation for it.
Use strong passwords.
If you or your employees use simple, and easy-to-guess passwords, you could be leaving your business more vulnerable than you know. Develop strong passwords that use capital and lowercase letters, as well as numbers and symbols. And, change your passwords every two months.
In December 2017, SplashData created the list using over 5 million hijacked passwords in just one year’s time. Passwords such as “123123,” “Password,” “admin,” “monkey,” and “whatever” were the most popular among the infiltrated accounts. Ensure that you and your employees don’t use common passwords. Additionally, it’s important not to write down passwords but rather encourage your staff to memorize them. Lastly, don’t use the same password across multiple programs. If someone can figure out your e-mail password, they may try to get access to other programs with it.
Put up a strong firewall.
Firewalls control the internet traffic going to and from the computers on your network. They provide an important barrier between your business and the outside world. This is especially important if you have multiple computers connected to the same network. This same firewall protects the spread of a virus from one computer to another. In the off chance that a computer wasn’t protected and got infected, this would keep it from spreading the virus throughout your network.
Install antivirus protection.
While firewalls are an excellent source of protection from viruses, they can’t do everything. This is where antivirus protection comes in. An antivirus program constantly scans your computer to prevent viruses by detecting suspicious files. If it finds a suspicious file, the antivirus will work to isolate it and keep it from spreading until deleting the file and neutralizing the threat.
Update your programs regularly.
Updates always seem to come when we are at our busiest. You no sooner begin your workday, when a notification pops up reporting that there’s a new update ready to install. While it may be tempting to put off the update until your task is done, this isn’t recommended. Whenever there’s an opportunity to update, it’s important to do so. Updating is like having a secret security group constantly working to keep your business safe. Updates provide protective patches that safeguard your data from the latest cyber attacks, such as Meltdown or Spectre. Plus, they keep your computers and systems running at optimal performance.
Secure your laptops.
Laptops offer the portability to take work home with you. This comes with an entirely new risk to your company. Laptops can easily be lost or stolen, so you must secure them. A recent study, by Dell Company, shows that a laptop is stolen every 53 seconds.
Securing a laptop can be done in a few ways.
If you must leave your laptop in your car, lock it in your trunk to better protect it from thieves.
Set your laptop to require a strong password at startup.
Use encryption software to secure your laptop. Encryption software makes the data on your computer unreadable until the right password is entered.
Secure your mobile phones.
Phones can be used to complete many of the same tasks that employees perform on their computers but without the same level of protection. It’s important to treat these like you do your laptops. Ensure all employees’ phones use encryption software, password protection, and remote wiping capabilities. For example, you can easily trace where your iPhone is by using the “Find My iPhone” app on a different device. If you can’t find your phone, you can protect your data by remotely locking and/or erasing the information on your phone.
Backup regularly.
With all the ways that your data can be compromised, it’s incredibly important to backup data regularly. This protects data that could be wiped out due to a virus or a lost or stolen laptop. Without regular backups, you run the risk of not only losing your data but having to spend valuable time and money to replace it.
Educate your employees about e-mail, IM and surfing the Web.
The 2017 Internet Security Threat Report (ISTR) reports that: “Business Email Compromise (BEC) scams, relying on spear-phishing emails, targeted over 400 businesses every day, draining $3 billion over the last three years.” This report shows the importance of training employees on e-mail and internet safety to secure your business’s data. The #1 reported security risk in 2017 was misaddressed e-mails. This can occur when an employee mistypes another employee’s name in the “To” line of an email. Criminals purposely create websites and e-mails that are similar to those for your business. They look legitimate and can easily trick an untrained employee. For example, your employee can get an e-mail that looks like it came from a person in HR asking for a copy of their contract. If the employee didn’t recognize the e-mail address as being incorrect, they could inadvertently release confidential information. Employees should be trained to remain vigilant and constantly look for e-mails that are phishing attempts or have red flags such as simple grammatical mistakes or excessive punctuation. Implement a policy to flag suspicious e-mails. And, train all your employees on the importance of not opening or clicking on any suspicious e-mails or links.
No one understands the importance of your business’s data more than you. These eight simple steps can ensure that the foundation of your business’s data is strong and secure, allowing you to focus on your success rather than threats.