(866) 251-4459 support@compnetsys.com
Upcoming NY state regulatory requirements for cybersecurity

Upcoming NY state regulatory requirements for cybersecurity

Traversing the Deep and Dark Web Isn’t Just for Hackers Anymore.
Understanding the nuances of cybersecurity and the Deep and Dark Web (DDW) is the best way to keep your data and organization safe.

In years past, talking about the “dark web” or the “deep web” was something that wasn’t done in polite company. However, today’s information security professionals are now bringing these terms to the forefront of business conversations.
While traversing the DDW may sound a bit perilous, not everything on it is illegal or bad. It’s time to clear up some confusions that surround these hidden parts of the Internet. If so, you can leverage your knowledge to proactively confront hackers and potential cyberattacks.
What is the DDW?
The Deep and Dark Webs are actually two different entities. The Deep Web refers to information on the Internet that’s not accessible by standard search engines such as Bing and Google. It doesn’t usually contain criminal information, but, instead, transactional details such as Instagram account information, banking transactions and confidential emails—Simply, data that’s stored behind a password-protected paywall and hidden from general assess.
The Dark Web is slightly more nefarious, and is technically a portion of the deep web that sells illegal products such as drugs and weapons. The dark web also provides cover for journalists and areas where the Internet is heavily censored.
The Dangers of the Dark Web
One of the key tools used to access the Dark Web is anonymization software such as the Tor browser.  With it, people can surf and connect anonymously to these dark webpages. It’s unclear how much of the DDW is being used by cybercriminals, and how much is simply being used by people who choose to remain undetected and unidentified.
It’s no secret that the Dark Web is a clearinghouse for the purchase of DIY tools for hacking—essentially tool kits that help less-sophisticated hackers launch attacks through malware, ransomware and phishing emails. While the average person purchasing these kits isn’t suddenly going to be a hacking genius, streetwise actors make these contacts to further their risky agendas.
Security Changes Are on the Horizon.
A key element of concern is the upcoming upgrade to .onion services managed by the Tor Project. These are designed to upgrade the privacy and security of individuals who want to remain anonymous. The majority of people using these services are completely above the law, and use them to circumvent censorship.
However, the concern lingers that those hosting servers on the Dark Web are now safe is they want a darker path for their surfing. In the past, Dark Web sites were discoverable if you knew their specific location. However, the updates slated for late 2017 are expected to provide a basis for next-generation encryption of applications. This would be a marked departure from the widely-publicized. onion URLs found on social media sites and traditional websites.
Security Threats from the DDW
Because most cybercriminals originate their attacks from within the Dark Web, understand the DDW is the first step towards preventing hacking threats of your business data,
Upcoming NY state regulatory requirements require that organizations take responsibility for formal assessment of cybersecurity risks, and implement an active cybersecurity program designed to address those risks. This requires a thorough understanding of the Deep and Dark Web.
This information can benefit a broader audience than just information security professionals, as DDW data may hint at security or fraud schemes against your organization—or even physical attacks against your company executives. It would be difficult to overstate the benefit that can be gained from taking steps to ensure you’re as well-prepared and knowledgeable as possible about these threats.
If you find it difficult to get your business leaders to invest in cybersecurity education at the level required to gain a true understanding of the DDW, let them know that the payoff can be significant in the form of details about competitors, mergers & acquisitions, and risks to your business.
Ready to learn more the Deep and Dark Web, and how to keep your business in {city} safe from hostile actors? Contact {company} at {phone} or {email}. Our cybersecurity professionals stay up-to-date on the latest happenings in the world of information security. Let us show you how an investment in cybersecurity will benefit your entire organization.

How a Mobile Device Management Platform Can Help Boost Your Security

How a Mobile Device Management Platform Can Help Boost Your Security

Here is a description of how Mobile Device Management Platform is being used to boost security in small and big firms all around the world.

Mobile device management (MDM) is a term used to administer mobile devices such as tablets, smartphones, laptops, and desktop computers. MDM is usually implemented using third party software.
Why it is Necessary.
MDM is used to ensure that employees are productive and that they do not breach company policy. Most organizations use the MDM platform to control the activities of their employees that might have an effect on their operations. Such a platform is mainly concerned with segregating corporate data, securing documents, emails, and enforcing corporate policies. Most of the areas it deals with are to do with the security of an organization. The implementation can be on-premises or via the cloud.
Some of its functionality can include the configuration settings of applications on mobile devices. In recent years, providers of MDM platforms have added desktops and laptops to the list of devices they manage.
By protecting and controlling the data and the settings on applications for all devices connected to a network, MDM can cut down support costs and the risks a business is exposed to. The primary goal of an MDM platform is to optimize security in an organization while cutting down cost. With mobile devices flooding the market and a part of business operations, having a tool that lets you monitor the device is necessary.
Find the Balance with MDM.
Data security and preventing data leaks have been the main driving force for MDM platforms. In recent years, a lot has been achieved in this area. The various MDM platforms can manage the security of devices without reducing functionality. The MDM works for both corporate-owned devices and personal devices. With a robust control of your security, you can prevent the loss of sensitive data that could have an impact on your competitiveness.
Have some Clear Goals in Mind.
As you search for an MDM platform, you will discover that there are many of them out there and they all have unique approaches to managing the security of your data. All of the approaches will have their weaknesses and their strengths. However, you need to understand the goals you have before making your choice. One of your main goals should be to secure your data while providing a simple and efficient user experience for users of the network.
Improve the Security of Your Data.
When an organization decides to implement an MDM, security is usually their primary goal. Some of the measures that an organization can take to improve security are to enforce encryption and a passcode. Additionally, it should have a means to wipe the device if it is stolen or lost. These are the basic features offered on a standard MDM platform. However, some advanced MDM platforms such as Maas 360 also have some extra features. For instance, it can restrict copy pasting, taking screenshots, blacklist, and whitelist apps, and even limit the access time of some apps by the time of day.
With the rise of infections amongst mobile devices, it is important to get only the best. It is estimated that there are 16 million infected devices around the world at any given time.
Some of the Measures an Organization Can Take to Secure Mobile Devices.
While an MDM platform is great, users still need to take some steps to ensure that they are secure. Here are some of the things organizations can do to stay safe:

Hold seminars to educate employees about app security. Inform employees about the dangers of downloading third party app and the risks of having weak device permissions on a device.
Restrict employees to downloading applications from authorized sources only. This can be sources such as Google Play, the App Store, and the organization’s app store. The rule needs to be enforced at all times when possible.
Act quickly if something goes wrong. It is important to have automated policies for mobile devices when it is discovered that a device is compromised or has a malicious app installed.

Keep Work Data separate from Personal Data.
If an organization decides that it will make use of an MDM platform, employees may raise issues to do with the privacy of their data. For instance, they may wonder if the organization will now have access to their private emails, their photos, and texts. On some of the most sophisticated MDM platforms such as MaaS360, it is possible to create user environments that keep personal and work data separate.
This is known as containerization. In essence, the MD creates a sandbox where all company activities are supposed to take place. When the employee leaves the sandbox or has their device stolen, a selective wipe can be done to ensure that all corporate data is removed from the device. Personal data will not be affected by the wipe. It is important that all employees understand the importance of MDM platforms in securing organizational data.
The Benefits of Central Management.
Whether the IT department runs the MDM platform or the work is outsourced, the ability to manage everything from a central point is ideal for efficiency. It also eliminates the cost and headache of trying to manage each device individually.
Picking the MDM.
While many SMEs continue to embrace MDM, many of them know that a one size fits all solution is not possible. Besides that, with evolving security threats, it is important to choose a platform wisely.
Get the right experts to help you make your choice. They can help you make just the perfect choice for your security needs. Besides that, they can contribute to managing the MDM for you. Trying to choose from among the top vendors of MDM platforms by yourself can prove to be quite a nightmare.
Summary.
Employee’s devices are here to stay, and they will continue to play a crucial role in the workforce. It is thus up to businesses to come up with a way to manage them before they cause a major security breach. MDM platforms are the perfect tool to ensure that an organization can reduce the risk of leaked data.

Cybercriminals May Be Using Go Via To Target New Victims

Cybercriminals May Be Using Go Via To Target New Victims

It seems like every day there is a new phishing scam or ransomware virus making headlines and giving business owners and individuals alike something new to worry about. Cybercrime is on the rise, and the perpetrators are coming up with new tricks and tactics as fast as cyber security professionals can uncover them.

A new malware infection seems to be targeting Australians using the popular Go Via website. This much-used toll payment provider gives users a fast and convenient way to take care of toll fees racked up during their daily commute and other travels. Recently, an email claiming to be from Go Via is making the rounds, and it has IT professionals concerned.
The email contains a message similar to this:
Subject: your go via tax invoice statement now
Dear Client
Your go via tax invoice statement is now available for download
If you have a post-paid account, ensure your monthly invoice is paid by the due date to avoid unnecessary fees.
To view previous tax invoice statements, login to your account using your account number and PIN at govia.com.au
You can view up to 18 months of tax invoice statements online anytime, at no extra cost.
While the reply address appears to be legitimate, the link informing the recipient that their statement is “available for download” does not. If you were to hover your mouse over the hyperlink, it would reveal that it directs you not to the Go Via website, but rather to someone’s personal Office 365 account. Specifically, to an unknown individual’s SharePoint account. If you were to click on this link to download the promised statement, the only thing you would be receiving would be a malicious infection.
Incidents like this serve as a reminder to constantly stay on alert when checking your inbox. Even when an email looks to be legitimate, it’s always worth taking an extra minute or two to carefully read through the message and double-check that any attachments or embedded links are what they claim to be before you click.
Hovering your mouse over a hyperlink, even one that doesn’t appear to have been altered (meaning it appears as a web address) will reveal where the link actually leads. If the revealed link doesn’t match the hyperlink, leads to a different domain, or leads somewhere entirely different from where the hyperlink text implies, DO NOT CLICK. Often the only thing you need to do is open an infected link to activate whatever malicious payload its attached to, meaning that once you end up on a strange site and realize something is off, it’s already too late.
Taking the time to practice smart email behavior and training your employees to do the same can protect your business against scams and cyber attacks that have the potential to do serious damage.
Want to learn more about the steps you can take to protect your business against cyber attacks and phishing scams? Contact Xstra Group today at {email} or {phone}. We’re the IT professionals {city} businesses trust.

Equifax Data Breach Compromises Personal Information Of More Than 143 Million Consumers

Equifax Data Breach Compromises Personal Information Of More Than 143 Million Consumers

Consumer Credit Score Giant Equifax At The Center Of What May Be The Worst Data Breach In History.

Atlanta-based consumer credit score provider Equifax announced Thursday that the company had been the target of a major data breach. This breach is thought to have occurred between mid-May and July of this year, with the breach finally being discovered on July 29th. Equifax took immediate steps to determine exactly what had happened and how hackers were able to gain access to the affected files.
In a statement released by Equifax Chairman and CEO Rick Smith, the breach was confirmed, and an explanation was offered to the more than 143 million affected consumers. It’s been advised that Equifax has been in ongoing contact with law enforcement, and has been fully cooperative with their continued investigation into the incident in an effort to locate the offenders.
A comprehensive forensic review was completed by a top cyber security provider, which uncovered the source of the breach and the number of files involved in this incident. It appears that the hackers responsible exploited a US website application vulnerability to access information that includes names, Social Security Numbers, and drivers’ license numbers, as well as a few hundred thousand credit card numbers. While the bulk of the affected users are US residents, Equifax has stated that some Canadian and UK users were also impacted.
It was also discovered that while this is still one of the worst data breaches ever to have occurred, hackers were not able to gain access to any of Equifax’s core data bases.
In an attempt to protect their customers and put forth maximum effort where damage control is concerned, Equifax is offering a complete identity theft protection package to each affected US consumer completely free of charge. A dedicated call center and web page have been created for consumers to get updated information on the situation, and take advantage of the identity theft protection package. Consumers are advised to get in touch with Equifax as soon as possible to determine if they are among the 143 million users impacted by this data breach and start taking steps to protect themselves from any potential consequences.
Equifax has vowed to invest even more into their cyber security systems in order to stop an event like this from ever occurring again. They’ve stated that their focus is on looking after their customers and doing everything they can to keep any possible damage resulting from this incident to a minimum. While it may feel like too little, too late for some, Equifax has made a real effort to step up and take responsibility for what has happened.
That being said, for affected consumers, the nightmare is only beginning. Data that has been stolen more often than not finds its way onto the dark web, and even if the hackers responsible were so inclined, there is no getting that data back once it’s hit the criminal marketplace. As this breach gave hackers millions upon millions of Social Security numbers with vital information like full names, addresses, and dates or birth attached to them, they’ve been able to create neat little identity theft packages to be sold off to the highest bidder.
When a data breach involves passwords or login credentials, a victim can change that information with relative ease and put the breach behind them. When your entire identity has been compromised, that’s not so easy. And while Equifax is offering free protection to US data breach victims, that complementary protection – as mandated by regulators – only needs to be offered for a full year after the incident is made public. At the end of that year, victims are left hoping that nothing is done with their data from that point on. And that’s rarely the case.
Credit card numbers can be replaced, but your Social Security number and date of birth are tied to you permanently. You can’t change your identity. This means that consumers involved in this data breach will remain at risk of identity theft and all of the headaches that go along with it for years to come. Bank loans taken out under someone else’s name using your information, or credit cards activated under your own name to be used by a stranger are both very real possibilities for those who have had their information stolen during this massive Equifax data breach.
At its core, this incident serves as a stark reminder of the ongoing dangers we face in a digital world. Cyber security is constantly evolving, but so are the criminals who are in search of ways to circumvent that security. The smallest vulnerability can lead to a major catastrophe, and while a company like Equifax has the capital available to rebound from even this disaster, a smaller business would collapse under the financial and reputational damage.
Want to learn more about the steps your business needs to be taking to keep a data breach incident like this from happening to your customers? Contact the {company} team at {email} or {phone} today. We’re the cyber security experts businesses in {city} trust.

Tips for Evacuating Before a Storm

Tips for Evacuating Before a Storm

Unless you properly prepare for tropical storms and hurricanes in advance, not only your property and business, but your life could be at risk.  This may require evacuating.  Plan your evacuation in advance, especially if you live in a hurricane-prone area.

Have your Evacuation Grab Bags ready to go.  Make sure they’re waterproof and easy to carry.  Essentials include:

2 gallons of water per person, per day for at least 3 days (including animals).
Non-perishable foods, and a can opener for canned foods.
Pet food and bowls.
Clean clothes and toiletries.
Your medications (for at least 7 days).
A First-Aid Kit.
Important documents in a flame and water-proof container.
Cell phones, chargers and battery backup.
Cash in small bills ($100 or more).
A flashlight and extra batteries (LED flashlights last longer).
A Battery-Powered Radio.
Spare car and house keys.
Whistle to signal for help.
Dust masks to filter contaminated air, and plastic sheeting and duct tape to shelter-in-place.
Moist towelettes, garbage bags and plastic ties for personal sanitation
A map with your evacuation route marked
A wrench or pliers to turn off utilities before you leave.

When you’re ready to evacuate, keep these tips in mind:

Take roads less traveled.  There are often secondary highways and state/provincial roads that go to the same place as major highways or interstates.  Use Google Maps to plan your evacuation route.
Use the Gas Buddy App to know where you can find gas when travelling. Be sure to fuel up at every single opportunity.
Install the Zello app on your smart phone. Make sure your family members, coworkers and friends do this as well. It’s faster than making a phone call, and saves time texting and emailing.  Plus, you can tune into public channels that provide emergency information.
Don’t wait until the last minute.  Use Expedia or hotels.comto book hotels in advance. You can always cancel it if you don’t need it.    if needed.
Unless you have a safe deposit box at your local bank, store your valuables, paperwork and jewelry in your dishwasher. It’s waterproof and built into your cabinets so it won’t blow around.

Be safe everyone.
For more information, visit:

 The National Hurricane Center
Ready.gov
The Red Cross