by Felicien | Jun 4, 2019 | Education
Are You One Of Many Affected By The Quest Diagnostics Breach?
Financial & Medical Information of 12 Million Exposed
Quest Diagnostics reports that almost 12 million people could have been affected by a data breach.
On Monday, June 3, 2019, Quest Diagnostics said that American Medical Collection Agency (AMCA), a billing collections provider they work with, informed them that an unauthorized user had managed to obtain access to AMCA systems.
Quest Diagnostics is one of the largest blood-testing providers in the U.S.
Anyone who has ever been a patient at a Quest Diagnostics medical lab could be affected by the breach.
AMCA provides billing collection services to Optum360, which is a Quest contractor. AMCA first notified Quest about the breach on May 14th. Quest reports said that they are no longer using AMCA and that they are notifying affected patients about the data exposure.
The information included in the breached system includes:
Bank account information
Medical information
Credit card information
Social Security Numbers
Other personal information
In its filing, Quest reported:
“Quest Diagnostics takes this matter very seriously and is committed to the privacy and security of patients’ personal, medical and financial information.”
What Should You Do?
Anyone who was affected by the data leak should freeze their credit report to prevent criminals from opening credit card accounts in their name. They should also be concerned that their Social Security numbers were exposed.
If you believe that your information has been leaked, you can contact Quest Diagnostics’ customer service at 1 (866) 697-8378 or on their contact page.
by Felicien | Jun 4, 2019 | Education
In today’s digital economy, cybersecurity is just as important as traditional, physical security. Many small businesses that wouldn’t dream of leaving their stores or offices unlocked and unguarded give little time or effort to a cybersecurity strategy. That’s in spite of 2018 research from Hiscox revealing that nearly half of small businesses suffered a cyber attack in the year prior to the study. Clearly, the notion that hackers won’t bother with the “little guy” is mistaken.
Other reasons that small businesses ignore cybersecurity include lack of resources and understanding. Physical security can be felt and seen. Locked doors, security cameras, and security guards are visible deterrent features.
Cybersecurity is different. It’s mostly invisible, and your average user won’t notice it. That said, cybersecurity isn’t as difficult to implement as some imagine. Here is how to cyber secure your company in 60 minutes or less.
1. Audit Your Existing Cybersecurity Measures
If your company has any cybersecurity measures in place, the first step is to review these. Look for holes or vulnerabilities in your plan. Review your internal IT policies, looking for weaknesses that a disgruntled employee or even a bad actor could exploit.
If no one in your company is in a position to perform this audit, or if you aren’t sure whether you have any cybersecurity measures in place, you need to bring in a consultant to perform this task. If you’re working with a managed service provider (MSP) already, check to see whether cybersecurity is a service they offer.
2. Train Staff on Phishing Techniques and Other Email Scams
Remember that notion that master hackers probably aren’t interested in coming after your small business because you’re the little guy? There’s actually an element of truth there. The likelihood of some shadowy group of elite European hackers employing TV-show-level hacking skills to break into your computer systems is pretty low.
That doesn’t mean you’re safe from all cybersecurity threats, though. Most of the time, hackers will get into your system by phishing.
Phishing Explained
Phishing schemes can take on a number of forms. Generally, they involve a realistic-looking email that’s made to look like it comes from a trusted organization (say, Microsoft) or from a trusted and important individual (say, your CEO or another executive).
Organization-based (or credential-based) phishing campaigns may include a link to a convincing but fake login page. Users enter their credentials, which go straight to the hackers who set up the scheme. Those hackers now have credentials necessary to log onto your company’s systems.
Personality-based phishing campaigns usually involve some social engineering. The “CEO” tries to convince a low-level user to do something that’s a breach in policy, and the user complies, hoping to impress the CEO. Instead, he or she gives away the store.
Training Is Key
Phishing schemes are not that complicated, and most users can identify them easily with even 60 minutes or less of training. Invest in this training to keep your business safer.
3. Set up Two-Factor Authentication
Two-factor authentication (2FA) is an added layer of security that can be enabled on many types of accounts. With 2FA, users enter their username and password as normal, but there’s an additional step. Users will also need to enter a randomly generated code (usually sent via text message). 2FA should be enabled wherever possible in your organization. Taking this step alone will cripple most credential-based phishing attacks.
4. Review and Strengthen Your Password Policy
Lastly, set up a password policy that forces users to create complex passwords and change them regularly. You’ll reduce your exposure to threats of stolen credentials and thus tighten up your cybersecurity strategy.
Conclusion
These 4 steps can help you improve your organization’s cybersecurity, but they aren’t a comprehensive strategy. We can work with you to form a cybersecurity strategy that’s comprehensive and customized to your business. Are you ready? Contact us today.
by Felicien | Jun 3, 2019 | Education
Here’s an honest truth: managed IT services cost money. With any business expenditure, it’s a good idea to understand the value that the expenditure will bring to the organization. We believe businesses can improve on many fronts by implementing managed IT services. One of the biggest areas of benefit is financial. Here are 6 ways that implementing managed IT services helps your bottom line.
Increase Productivity
Equipment downtime can be a huge detriment in any business setting. In the “break it fix it” model, businesses operate normally until something breaks, then work stops. If it’s IT equipment, the in-house IT team descends and attempts to fix. If, after some amount of time has passed, IT decides the problem is beyond them, they call in outside help. Then they wait. And wait. And wait some more. Work isn’t getting done while that piece of equipment is down. Waiting for an outside specialist can cost your company in a big way.
With managed IT, your managed service provider (MSP) is the outside specialist. As soon as something goes down, the MSP is on it, bringing their skills and specialties to bear on the problem. Use managed IT to get your business back up and running faster than the traditional model can.
Stabilize Monthly Spending
With the “break it fix it” model, your IT spend can spike wildly from time to time. When a high-value piece of your IT infrastructure goes down or even just needs replacing due to age, your costs soar. Companies self-managing their IT services also face sudden spikes in software upgrade costs.
Managed IT can stabilize your monthly IT spend. In this model, you pay a stable monthly rate for service regardless of how much or how little help you need in a given month. Software upgrades (or, more likely, subscription and licenses) are rolled into this monthly fee as well, removing those software spikes from your budget. Your finance team will appreciate this predictable expense.
Lower Your Initial Investment
Along the same lines, you can lower your initial IT infrastructure investment through managed IT. Depending on the terms of your agreement, some amount of your equipment may be owned by the MSP. The less equipment you have to purchase yourself, the lower your initial IT infrastructure investment.
Every MSP agreement is different, customized to the needs of the client business. If up-front costs are an obstacle for your business, be sure to craft a service agreement that lowers these costs.
Lower Overall IT Infrastructure Costs
Even if your MSP isn’t providing all your hardware as part of your plan, you’ll still lower your overall IT infrastructure costs in many MSP arrangements. For example, if hosting, storage, and backup are part of your MSP agreement, you eliminate some of your need for on-site servers. You’ll save money on hardware, power, and even real estate — since you won’t need space to house those servers.
The same principle applies to a number of other functions, including network monitoring and security. You won’t need to devote systems and system resources to functions that you offload to a managed IT provider.
Free Your IT Staff
Partnering with a managed IT services firm frees your IT staff to do what matters most. Contrary to what many assume, the goal of implementing managed IT isn’t necessarily reducing staffing levels. Sure, some larger businesses may benefit from reducing a bloated, inefficient in-house team, but the real value in managed IT service is freeing up your in-house team.
Your existing IT staff adds value to your company by wholeheartedly pursuing whatever high-value IT interests your business has—or, at least, it should. Many times, though, IT employees are too busy troubleshooting PCs and malfunctioning equipment to focus on the IT elements that are truly core to your business. Enlist a good MSP to handle the day-to-day IT troubles (among other things), and you’ll enable your IT staff to focus in and add value in the areas that are truly critical to your business.
Scale Your Business
It’s great to be a part of a growing business, but the growing pains are real. Scaling your business can cause IT headaches: new equipment is needed for each new employee, not to mention all the behind-the-scenes tech infrastructure, like server space, bandwidth, and software licensing.
Managed IT is the solution here, too. Your MSP has far more capacity than you need, so they can handle scaling issues during periods of growth or reduction.
Conclusion
By now it’s clear: that managed IT can help your bottom line. If you’re ready to begin the conversation about how we can help you, contact us today.
by Felicien | Jun 3, 2019 | Education
One of the major advantages of newer technologies is their ability to connect employees working remotely. Connections to colleagues, data and files help make doing business more productive, effective and accurate, no matter where employees and their teams are.
That’s why more companies are establishing bring-your-own-device (BYOD) policies. Such guidelines allow companies to save on the costs of providing employees with their own mobile devices or paying for their maintenance and replacement.
Adopting such policies requires companies to set clear guidelines for the use of such devices and what obligations employers and employees have.
What Are the Advantages to BYOD Policies?
Along with the cost reduction, there are several other advantages for companies that choose to use BYOD rules:
Increased employee satisfaction. Employees who can bring their own devices are more satisfied in the workplace, don’t have to manage multiple devices and can use their own device for work-related tasks.
More productivity. Employees with access to workplace apps on their own devices can respond faster to inquiries, gain needed information and address issues quickly.
Flexibility. Make it easier for employees to work from home, remotely or while traveling with ready access to communication and apps that let them do their work effectively.
Reduces uncertainty. For companies that pay for voice and data services for employee devices, switching to a BYOD policy saves not only on contract costs but also on data and voice overage charges.
“Employees who are willing to spend their own money to procure their own devices can be a boom for their bottom line. In some ways, this is a perfect arrangement. Employees get to use their chosen device, which can improve productivity and morale while saving companies money,” notes a recent article.
What Are the Primary Disadvantages to BYOD Policies?
The primary concern for many companies considering adopting a BYOD policy is security. Consider that for every device you add to your network, that’s one more device that has access to sensitive, proprietary or protected information. A company-owned device provides far more control of what websites are accessible, when devices are updated and how usage is monitored. Companies can control what anti-virus, anti-malware and anti-phishing tools are installed and how frequently they’re updated. Control means a greater understanding of what’s protected and how.
Another concern to BYOD workplaces is compatibility and support. Your employees are likely using multiple devices with multiple operating systems and capabilities. Your IT team will likely be responsible for some aspects of device management, including installation and updating of apps, security processes such as VPN and other protections, and ensuring security patches are applied. Having more devices in play means more expertise is required of your IT employees.
When employees leave, there need to be clear procedures and auditing rules about ensuring that all access to company files, apps and data is removed immediately.
Scalability is another concern. As the number of employees grows, with some of them using multiple personal devices, the staff demand for management and updating grows accordingly. Company network infrastructure also needs to be expansive enough to accommodate all the new devices.
For employees, the main concern is privacy. Employees may wonder how much of their personal activity and device usage is accessible to their employers.
Are There Other Options Besides Company-Provided and BYOD?
Some companies choose one of two alternative policies that reduce the risk:
COPE. Corporate-Owned, Personally Enabled devices are those employees can use as their own but are purchased by and owned by the company. However, employee privacy concerns can make such an approach unpopular.
CYOD. A choose-your-own-device approach requires employees to select from a limited number of devices for use with employer applications and access. While this helps minimize the amount of support required, it may require employees to spend more on new equipment.
How Can Employers Maintain Security with BYOD?
Clear and consistent policies are key to effective BYOD workplaces. Here are a few of the considerations you should use when implementing BYOD policies:
Determine what operating systems and devices your company is willing to support
Create device enrollment practices, requiring devices to be registered and authenticated before they are connected to your company network
Require strong password or passphrase guidelines, including length, complexity, change frequency and failed-attempt blocking
Create automatic lockouts on devices after a period of inactivity
Require employees to immediately report lost or stolen equipment
Mandate that personal devices can be disabled or wiped in the event of a loss or theft
Install required anti-virus, anti-malware and anti-spam software on all BYOD smartphones, tablets and laptops
Automate regular backups of company applications and data from personal devices
Keep devices and applications up to date using automated patching and updating tools
Encrypt all BYODs, ideally with full device encryption. If that’s not possible, require all sensitive data to be stored in encrypted folders on the devices
Determine if BYOD users will be allowed to print, copy, save or email information pulled from your servers
Require employees to sign an agreement stating they understand all the policies, procedures, regulations and consequences for noncompliance
Detail the consequences of not adhering to company policies
When companies pay attention to the policies and guidelines necessary to ensure secure and proper use, BYOD policies can be an advantage to employers and employees alike.
by Felicien | Jun 3, 2019 | Education
IT consultants provide valuable insights to businesses looking for guidance on technologies that lead to better business outcomes.
Having a strong relationship with your IT consultant leads to more productive collaboration and discussions that are more fruitful. It begins with making the right choice to be your IT partner and requires commitment, communication and trust to remain effective. The scope can be vast or project-specific.
As noted in a recent ITBusinessEdge article, “Consultancy firms can help with everything from one-off projects for companies that don’t have enough time to pull together a team, to long-term projects that require a team with deep experience in an emerging or cutting-edge technology.”
Here are a few tips for making and keeping a great relationship with your IT consultant.
What Should I Look for in an IT Consultant?
The relationship begins during the selection process for an IT consultant. It starts with being clear about what your company needs from the consulting engagement. Define your desired outcomes, whether for a specific project or a longer-term, ongoing relationship. These scope documents should include your expected timeframe, internal resources, reporting expectations and success factors.
You should be clear about your immediate and future needs, whether they’re an improvement in network performance, better IT security, compliance mandates or better efficiency.
There are several things to consider during the selection, including
Who will be working on your account (ask to meet them before signing)
How much experience the consultant has with your business
Performance, success stories and references
An understanding of your business, its needs and your industry
Think as granularly about the project as possible so you aren’t surprised by anything down the road. Do you need a very hands-on team? Can your working structure or schedule be flexible? What development methodologies are a must-have? While it may take a little more time and effort, making sure you’re selecting the right firm from the start will result in a smoother ramp-up and integration process.
What Communication Should I Have with an IT Consultant?
Regular status meetings are an important part of the consultant-client relationship. Updates should happen on a mutually agreed schedule that’s included in your contract. The meetings should have a clear purpose, agenda and outcome. In most cases, these meetings should review progress on projects and data on the performance of deployed technologies. There should be a discussion of business needs and potential solutions using emerging technologies, too.
Communication with your IT consultant needs to be a two-way street. You should provide regular feedback on the consultant’s work, including what’s working well and what needs to be improved.
How Do We Prepare for Working With an IT Consultant?
Your internal IT team may feel intimidated by having an outside IT consultant become more involved in the decision-making and strategy for your business. The reality is that most internal IT staffs are stretched thin and cannot manage the day-to-day tasks, the strategic IT discussions and project management you need.
It’s important to be clear about how the IT consultant and your internal IT staff will work together. It’s important to think of the consultants as part of your IT team, a valued extension. Internal and external teams need to work together to achieve your goals. That means broad information sharing, progress updates, shared work and a true partnership.
Your IT consultant needs a candid assessment of the IT team and other relevant staff members. They also need to understand your products or services, your market and your existing technology solution. Many IT consultant relationships begin with an assessment of your current IT systems, hardware, software and business processes.
There’s another component to prep work with an IT consultant. If they’re going to be deployed internally, be sure they have the resources necessary from the start. That means a clean workspace, equipment, passwords and system access, an email account and phone number. You should communicate to your teams who the consultant is, why they are being hired and the scope of their work.
Provide the consultant with the procedures, policies, company overview, safety protocols and a sense of the company culture before they walk in the door.
How Should We Monitor the IT Consultant’s Work?
It begins and ends with trust. You need to trust that your consultant is doing what you’ve contracted for. Consultants usually have ample experience, extensive technical knowledge and experience with assessments and project management. Communication should be regular and consistent, knowing that you shouldn’t micromanage and that urgent issues will be brought to your attention.
You also need to trust that your IT consultant will be fully informed of technical options for your company. As the client, you are the ultimate decision-maker, but you need to be comfortable with taking a leap of faith. Your consultant’s recommendations may be very different from what you expected, but if believe that their guidance will give your business a competitive edge, it’s important to take their recommendations seriously.
You should also appoint an internal contact who will be the consultant’s primary liaison within the organization, solving day-to-day problems and answering questions. This contact also needs access to the CEO or other senior leadership and have a seat at the table when making decisions about projects and the consultant’s work.
An IT consultant brings with them knowledge, experience and solutions focused on boosting your business. Having a clear sense of how to work with them effectively means a greater return on your investment and better outcomes.