Tuesday, May 12, 2020

Go to Your Room!


Go to Your Room!

We are living in unprecedented times.

The new *Normal* has definitely shaken things up in the business world.  Take all the political posturing out, remove all the hype and fear-mongering, ditch the conspiracy theories..  The fact remains, the business world is changing.  If you are reading this as a business owner, accept the fact.. No..  Embrace the fact..  things are changing.  Change with them, or be doomed to midden heap of mediocrity...  or worse.. failed business.

Sounds harsh, right?  Now, in your best Darth Vader voice, say "Search your feelings, you know it to be true".

So what is this blog all about - as you might see, it is being delivered in a somewhat light tone, filled with candor.. I think..  The point is - with the new movement to a more work-from-home environment becoming more common, how do you maximize that for your business.

Here are a handful of truths:

  • Many administrative tasks can be accomplished from a home office
  • One of the largest burdens on business is the cost of commercial space
  • Engaging the younger workforce means accepting a different perspective on hours of operation
  • Productivity from a work-from home (WFH) begins with equipping them for success 
Let's touch on these, shall we?

Business Administration from Afar:

Many office tasks are not necessarily tied to a physical location.  If you are paper-heavy - meaning rooms full of file cabinets containing documents from decades ago, ask yourself the hard question - is it necessary?  If it is - come up with a way to digitize the information you absolutely need to keep, invest in a document management system for quick recovery based on keyword searches, and shred the paper.  You will end up with more productivity as a result.

If you have frequent meetings that require face-to-face contact - consider any one of the popular web conferencing platforms - accept that you will have to pay for the convenience on a monthly or annual basis, and embrace the technology that makes it possible.  Most importantly, equip the WFH employee with the proper tools to make it work well.

Cost of Commercial Space:

Like most business owners, I cringe each time I sign the check for my monthly lease payment for our offices.  It is a necessary evil.  I ran NetWerks from my home for 12 years before moving into commercial space.  We had outgrown what we had to work with, so the move was necessary (or add on to the house - I opted to get the employees outta Dodge).  But - I miss the fact that my overhead was not as overwhelming a burden as it is with commercial space, utilities, etc.

What you are likely to see as more businesses embrace a WFH posture is that they will be able to downsize their commercial space needs to some extent.  You may even see a resurgence of "Executive Suites" that share phone services, receptionists, conference rooms, copy & print services and desk space for those times when you have to meet with people face to face or just need to get away from the home office for a while.

The Current Generation:

Having been in business for over 30 years, and being the parent of three 20-somethings, I can say pretty comfortably that the current generations have not bought into the concept of long term employment and loyalty to the employer..  And there is a simple reason for that.. those in the 35 and under range have seen their parents get kicked to the curb by employers despite a lifetime of loyalty.  They've seen promises broken and the devastation that it triggers within the family unit. You might say that they have hereditary trust issues.

On top of that, many in the younger generation find themselves currently on the lookout for something more challenging, or something that has purpose or a bigger meaning.  They want to make a difference - have an impact - and when that opportunity dries up with one employer, they move on to the next shiny thing.  The average time of employment for under 35's has been well studied, and is under 5 years.  In a 2016 Rasmussen College study, the average tenure of employment for 24 - 34 year old's was a paltry 2.8 years.

Among their complaints and reasons for job-hopping - professional development opportunities, having their input valued, and flexible work arrangements.

Equipping for Success:

This is the foundation of a successful transition to Work From Home.  If you are not wiling to invest in setting your remote work force up for success, just don't do it.  You will be shooting yourself in the foot.  But - it is not all on the shoulders of the employer.. The employee bears a responsibility to ensure that the WFH environment is conducive to conducting daily business.

Equipping for success starts and ends with..  Policy.  Develop a firm WFH policy that lays out articles of engagement that, if unwilling to comply, results in that employee being relegated to a daily commute to the office.  This policy should contain at the very least:


  • A dedicated workspace separated from the general populace of the household - spare room, basement, converted attic..  it should not be located in a common area
  • The space *should* have a door, preferably with a lock, especially if the individual handles confidential information, or at least a locking cabinet for secure storage of information and the understanding that no confidential material will be left unattended or unsecured
  • High speed internet connectivity - if possible, isolated from the rest of the household network
  • Adequate lighting and a reliable source of power
  • Work related assets not to be used for personal purposes
From the employer's perspective, these should be non-negotiable.  Some have added items such as work attire being expected, set hours of availability, etc.  Tailor the policy to meet your corporate culture.


From a technology perspective, the employer should strongly consider providing the following:

  • Similar technology to that used in-office.  If laptop is used - provide a docking station with dual displays, full sized keyboard and mouse, high quality web-cam and noise cancelling headset/mic.  If your office is equipped with Voice over IP (VoIP) Telephony -include a VoIP desk-set that connects directly in to your office system as an extension.
  • If you do a lot of video conferencing, provide a portable green-screen and consider an acceptable list of backgrounds to use with the video conferencing platform on which you have decided to standardize
  • Standardize on a videoconferencing platform
  • Consider implementing a platform for secure file sharing
  • Consider implementing a centrally managed system for password management
  • Consider updating older applications that leverage cloud based tools to provide a consistent environment regardless of location such as Office 365
Other areas that would be a strong recommendation to ensure a secure WFH environment:

  • High performance firewall or SD-WAN platform to ensure that business traffic does not mingle with personal traffic
  • Create a standardized WFH Package of technology and offer a modest stipend to offset business use of home for added electrical/internet use
  • Consider partnering with an MSP (Managed Service Provider) to do the initial set up and on-boarding of your WFH users, including a network security assessment, managed antivirus/threat detection and remote support options so that your employees are able to work with minimal interruptions
Conclusions:

The "New Norm" is upon us..  what we make of it will determine how we fare in the coming months and years.  Learn the lesson that states simply: If you don't lead change, you will be lead by it.  Get ahead of the shift in how business is done, remain agile, and the results will more likely be in your favor.  By embracing a positive work from home posture - one that has been planned in detail - you are likely to see better productivity as a result - possibly better than if you had an office filled with workers.  Most importantly - consider this an investment into the future growth potential of your company.  Spending some capital today may mean the difference in continued growth and a downward spiral.


Wednesday, May 6, 2020

Ransomware emails: How to identify

Ransomware emails: How to identify and steer clear of them

Ransomware attacks have suddenly become more prevalent. Each year sees more of them. Hospitals, NPOs, shipping giants, etc., have all been victims of ransomware attacks. Your business could be too! Did you know that emails are one of the most common gateways for ransomware to get into your systems? In this blog, we tell you how you can stay safe by following a few tips.

If you think something is amiss, it probably is

Does that email seem unfamiliar? As though you weren’t meant to get it, or it doesn’t quite sound like your colleague wrote it? Perhaps it’s not. Malicious email senders often try to mask actual email IDs with something similar. For example: An email you believe to have come from billing@yourvendor.com might actually be from billing@yourvemdor.com. So take a good look at the email ID if you spot something ‘phishy’.

Attachments and form fills

Does the email contain an attachment that you are being asked to save to your computer? Or an executable file that you are asked to run? Perhaps you are asked to submit your personal details at an authentic looking website. Before you do any of these, check the authenticity of the email and the message. Were you supposed to receive it? Were you expecting an attachment? You might even want to call the sender and confirm if you are unsure.

The message seems to instill fear or a sense of urgency

Often, malicious email messages urge you to take immediate action. You may be asked to log onto your ‘banking website’ ASAP to prevent your bank account from being frozen, or enter your ITR details onto a webpage to avoid being fined by the IRS. Real messages from your bank or the IRS will never force or hurry you to do something.

Other things you can do

Regular data backups

Conduct regular data backups so that in the eventuality of a ransomware attack, you don’t lose your data. Cybercriminals having access to your data is bad enough--it damages your brand and business reputation and can even attract lawsuits from parties whose personal information has been compromised, but, not being able to retrieve all that data in the aftermath of an attack is even worse. Regular backups help you in that regard, plus when you have a pretty recent data backup you are not reduced to the state of helplessness where you HAVE to pay the ransom to retrieve your data.

Install an anti-malware tool

Last, but not least, invest in anti-malware tools that can detect malware attacks and alert you before you fall prey to them. Such tools scan emails, links and attachments and alert you if they are found suspicious.

No matter how big or small a business you are, ransomware attack is a reality and applies to you. It is better to be prepared than having to cough up huge sums of money to free up your data later and even then there’s no guarantee your data will be restored by the cybercriminal.

Thursday, April 30, 2020

The Hard Truth

photo credits: Dreamstime

The Hard Truth..

Whenever there is a crisis, the vultures and jackals will circle (and I mean no disservice to those vultures and jackals of reputable nature)..  In the days and weeks of the COVID-19 pandemic, the ner’-do-wells have stepped up their game, and cyber-attacks on businesses and individuals has escalated.  While this speaks to the baser side of human nature, that side that would maliciously take from others for personal gain, this post is not directly about that..

What this IS about is what we can do about it.

Sadly, many of us have the tendency to bury our heads in the sand and tell ourselves that “it will NEVER happen to me”.

Well, friends..  yes, in fact, it IS going to happen to you.  Maybe not today, perhaps not tomorrow.. but at some point, you will find yourselves in the cross-hairs of the enemy, and he ain’t flinching when he pulls that trigger.  Whether or not you are the recipient of a cyber head-shot or not is entirely up to you.

In the day and age of a heightened state of cyber-threats, the smart money is on ensuring that you have covered every base when it comes to securing your digital house from the jackals at the door.  As a US military veteran from the Cold War era, I could extol you with stories of the days of foreign agents in trench coats trying to turn people to the dark side.. and while some of the foundations are the same, the tools are far more sophisticated than getting a sailor drunk and offering fat wads of cash for information.

The concepts are not new, but the tools have evolved. Understanding the mechanics of the threat is vital to protecting our assets.  Too many examples exist of a “lock up after the bad guy has been and gone” mentality. One stunning example is the Equifax breach, but that is just one of many examples where the bad actor has been well entrenched. It’s time to have the hard conversation with ourselves about how much risk is too much?

Rather than spout a collection of buzz-words and fall victim to trendy posturing, we need to roll up our sleeves and get down to business. A deep assessment of where we are, and how do we prepare ourselves for those who would do us harm. For starters, we need to ask ourselves several direct questions:
  • Are we ready to take security seriously?
  • Do we have the right policies in place to educate, guide and hold our workforce accountable?
  • What are our strengths, weaknesses, opportunities, and threats?
  • Do we have the right people in place, both internally and externally, to make a move to a more secure footing?
  • Do we understand the potential cost of doing nothing?
  • Are the experts we are paying for doing the job? 

For many, especially in the SMB space, the answers to these questions can be an eye opening experience. No one is too small to be noticed.  No industry escapes the scrutiny of those of malicious intent. The key to a successful security policy is to understand that it is going to change. It has to be able to evolve along with the threats that are present - this means it has to be regularly re-evaluated.  There is no such thing as a once-size-fits-all policy.  Even the NIST Security Framework has components that may or may not apply to your organization.

Like in any 12 step program, the first step is accepting that you have a problem.  We ALL have a problem. Do we have the willingness to address it?  The important thing to understand is that you don't have to go it alone.

If you are ready to have that conversation, we are ready to help. With over 30 years in the information security arena, NetWerks is ready to guide you to a much more secure place.  Reach out to us through our web site to set up a no-cost, no-obligation meeting to get an idea where you are at.

Wednesday, April 29, 2020

How good is your password

How good is your password?

Did you know that having a weak password is one of the biggest security risks you face? This blog focuses on the best practices related to passwords that you can follow to ensure passwords are not your weakest link.

  1. Avoid sequences and repetitions: How many times have you used passwords like dollar12345 or $$$BobMckinley. Passwords containing sequences and repetitions are just easier to hack.
  2. Avoid using your personal data: Do not make your birth date, bank account number or address a part of your password. It puts your data at stake if your personal information is stolen.
  3. Don’t repeat passwords: Make sure you pick unique passwords every time. Unique, not only verbatim, but also in combination. For example, if password one is a combination of number, symbols and letters in that sequence, password two should be letters, numbers and symbols.
  4. Manual password management is not a good idea: Invest in a good password management tool. You can even find some free ones online. But, manually managing passwords, by writing them down on a spreadsheet is a big NO.
  5. Password sharing: Discourage password sharing across the organization. Every employee should have unique access to data depending on their role and authority. Password sharing gets things done faster, but can do irreversible damage.
  6. Password policy: Have a password policy in place and enforce it. Conduct timely audits to ensure the passwords match the specified safety standards. Also, take corrective actions against employees who don’t follow your password policies related to password sharing, setting, etc.
  7. Don’t use dictionary words: Hacking software programs can guess dictionary words faster. The key is to mix things up a little bit--some numbers, some symbols, some punctuation and some alphabets.
Don’t choose passwords that are way too simple just because they are easier to remember, because, more often than not, it can get you into a lot of trouble.

Wednesday, April 15, 2020

Keeping your data safe: Access Control

Keeping your data safe: Access Control

Cyberattacks are a commonplace today. Malwares such as viruses, worms and more recently ransomwares not only corrupt your data or hold it hostage, but also inflict irreversible damage on your brand and business. As a norm, most businesses these days do invest in anti-virus/cybersecurity systems. But, is that really enough? The answer is--NO. Because, they often overlook one important aspect--access. Ask yourself, how easy is your data to access? How can you strengthen the walls that keep your data safe? Read this blog to find out.

Role-based access

Always follow a role-based access permission model--meaning people in your organization have access to ONLY the data they REALLY need. Generally, the higher the designation, the deeper the data access permission and stronger the rights. For example, someone at the executive level may not be able to edit your MIS spreadsheet, but a manager should be able to.

Formal password controls

No matter how good your cybersecurity, you need to ensure the protocols are followed at the ground level. Enforce policies regarding passwords strictly and hold violators accountable. Examples include-
  • Password combinations - Ensure your staff follows the recommended best practices when selecting passwords so there are no ‘easy-to-crack’ passwords
  • Password sharing - Thoroughly discourage password sharing across your organization. No matter who asks for it, passwords shouldn’t be disclosed unless authorized as per the protocols.

Don’t ignore physical security

Virtual security is a must, but so is physical security. Though there is only so much physical access controls can do in keeping your data safe in the BYOD era of today, don’t overlook this aspect. Installation of CCTV cameras on-floor, biometrics/card based access to your workspace/server rooms, etc. also have a role to play in data safety from the access perspective. 

Training & reinforcement

Finally, train...train...train. You need to train your employees on the protocols for data security and access so they don’t mess up accidentally. Conduct mock drills, refresher trainings, follow up with quarterly audits, and use positive and negative reinforcements to ensure everyone takes it seriously. Because, at the end of the day, no cybersecurity software is good enough, if the best practices related to data access are ignored.

Tuesday, March 10, 2020

Smaller firms less likely to keep up to date on the basics that protect them

Smaller firms less likely to keep up to date on the basics that protect them.

On the never ending problem of cyber security, small firms often do not have any/much in-house IT support. As a consequence, they may be less likely to be able to make sure their software is consistently updated to reflect any patches released by the product’s maker. This simple oversight, deliberate or not, is a major source of data breaches and ransomware attacks.
Think back many years to when Microsoft pulled the plug on maintaining Windows XP. Many users refused to upgrade because there were afraid of losing compatibility with other software programs, the unintended consequences of moving to a new OS, or just not being sure how to install an upgrade. Whatever the issue, it meant those users had an operating system that was no longer updated to reflect the latest security fixes. Their operating system became an unlocked gate.

You may not be scared of technology, but as a small business owner, tracking the release of new updates or taking the time to install them as soon as they come out probably just isn't a priority. You have a business to run. Adding to this problem, you may also allow your employees to use their personal laptops, mobile devices, and tablets for work duties. If that is the case, then every program on each of those devices is subject to the owner’s willingness and ability to update everything in a timely fashion. If any single device accessing your corporate files and data misses a security patch and is breached, so is your business.

The lesson here is that you need to take action to implement a company-wide process for maintaining all of your software applications so they don’t become an unlocked door in the middle of the night. A managed service provider can develop a plan to address update and security fixes on all the devices that access your data. It can be more than a small business owner can handle, so instead of ignoring the problem, reach out to find real solutions that will protect your business.

Tuesday, March 3, 2020

Cyberattacks and the vulnerability of the small business

Cyberattacks and the vulnerability of the small business

You cannot go a day without reading about some big name company or even government agency being hacked and critical data being compromised. What you don’t see in the media is that most of the attacks happen to small firms, and that this is where a lot of the cybercrime is occurring. What any business, but especially a small business, needs to be afraid of are cyber attacks that disable your operations, disrupt customer interaction, or breach your customer’s personal data. Contrary to what one might expect, smaller firms are far more likely to be targets of hackers than large firms. They are also likely to have less sophisticated security measures in place. Any firm’s existence can be threatened by these events, but smaller firms are often unable to rebuild after a major breach. Studies show that customers are less forgiving of smaller firms than larger ones when their personal data has been compromised. The lesson here is that smaller firms are more vulnerable and need to be extremely vigilant. Talk to a managed service provider about some basic steps you can take to protect your business.

Tuesday, February 25, 2020

Denial is not a solution: Something you owe your customers and your employees

Denial is not a solution: Something you owe your customers and your employees

Why do so many people procrastinate about making a will? Why is it so hard to get young people to buy health insurance? Because it is one of those “probably won’t happen--at least in the foreseeable future, and I‘ve got more interesting things to worry about or spend my money on” issues.

Small business owners tend to take the same approach to making business continuity plans in case of a disaster. They are usually fully consumed just running the business and keeping revenues steady and growing. Diverting energies and resources to a “what if” scenario just isn't an imperative.

There are affordable, effective tools out there that will allow any smaller firm to develop effective business continuity plans, but they only work if you take action. Our best advice to overcome denial? Think of this scenario: If something happened right now and your entire operation came to a halt because of a cyber attack, a power failure, data loss, or a single point of failure hardware event, what would you do? Do you even know who you would call in for help?

It can be a scary thought, but one that merits your attention. Talk to a managed service provider about a proposal to develop a complete business continuity plan. You owe it to yourself and to all the employees who rely on your for their livelihood.

Tuesday, February 18, 2020

Limited investment capital and planning for trouble

Limited investment capital and planning for trouble

Small businesses often fail to take the time to make business continuity plans. One aspect of a business continuity plan involves developing plans to handle the loss of physical infrastructure and hardware. Unfortunately, smaller and younger firms often fail to address these issues because they lack the necessary capital to invest in additional or supplemental equipment. Redundant servers, battery back systems or uninterruptible power supplies, and data backup systems that allow for offsite backup storage are the most obvious examples.

These can represent considerable capex for a small firm. However, these costs need to be weighed against the costs that would be incurred if a severe business interruption occurred. Encouragingly, new technology is creating tools for redundancy and data protection that don't require additional hardware investments. The cloud is probably the single biggest savior for small businesses looking to defend against business interruption events. The cloud means you can offload many of your business processes and infrastructure to the cloud and sidestep creating expensive redundancies on your own. Offsite data storage, increased efficiencies as a result of shared data center costs, SaaS, and even data collaboration tools are added cost savings that can be provided by the cloud.

So before you throw up your hands and say you cannot afford to address business continuity, take another look. The cloud can redefine the paradigm of “business continuity.”

Tuesday, February 4, 2020

Are you subject to Data Protection laws?

Are you subject to Data Protection laws?

This blog introduces a new topic that many may be unaware of: Data Protection laws. These are laws that define fully, or in part, what type of data is covered by government regulations, proscribe general standards for the securing of covered data, and may also require notification of victims and governmental authorities in the event of a breach. Small businesses, no matter what product or service they provide, are likely subject to some manner of regulations regarding the storage and use of digital data. For instance, any medical office or organization that handles medical records is subject to HIPAA, the federal law regarding health data privacy. Meeting IT regulations can be expensive and time consuming and they also require timely upgrades. Failure to stay up to date can lead to fines, penalties, and a damaged reputation.

Chances are, you are subject to some data protection or data security laws. You are also very likely to be subject to breach notification laws. As a small business you should consider having an audit conducted to determine if you possess data that may be regulated by these laws. Failure to be aware that you are covered by them does not protect you in the event of a data breach.

In our next blog, we will discuss one category of information that is the focus of many data protection laws. This category is referred to as Personally Identifiable Information. When you discover what that includes, it will be pretty apparent why protecting this data is important for the integrity and success of your business.

Tuesday, January 28, 2020

Ransomware Part II

Ransomware Part II

In our last blog, we explained what ransomware is, and why it can be an especially troublesome virus. Today, let’s look at what you can do to avoid falling victim.Prevention is the best cure. Follow standard “data hygiene” principles that you probably hear about all of the time. Update your OS, software, and apps whenever a new release or patch is released. Do this ASAP. Some patches may be released solely as a result of the discovery of a vulnerability. Watch out for phishing scams. If anything looks “off” about an email, don’t open it. And never open links you aren't totally sure of. If unsure, email back to the sender to verify they actually sent you a link. Unfortunately, human error is one of the biggest problems for data security. Employees unwittingly open links received via email or download information from insecure websites.

Beyond prevention, the most important thing you can do to make sure your data cannot be held ransom is strictly adhering to a regimen of backups. Routinely backup your data. However, with ransomware, even backups may not be foolproof. If your data has been infected and you are unaware of it, or the backup is not segregated from your network, your backups may also be corrupted. Given the severe consequences of a ransomware attack, consider having a security evaluation done by a managed service provider who will have the security expertise to advise on the best backup protocols for your situation. Ransomware presents some unique challenges that require more sophisticated data protection protocols. Contact a managed service provider for a complete security evaluation.

Tuesday, January 21, 2020

Ransomware part I

Ransomware part I

The daily reports of cybercrime are important reminders about the need to protect your business from malicious behavior that could threaten the success of your business. There are so many different things that can attack your computer, steal your data, and wreck your day. One of the most troublesome has been the development of ransomware. (FYI. Ransomware isn’t actually all that new-- some version has been around for decades)  Ransomware is a type of computer virus that takes your data hostage and like any kidnapping scheme, demands money for the release of your data.

Why is ransomware so nasty? Because it steals the most important thing your business possesses. Data. Worse, once infected there isn’t generally a way out. No one can “disinfect” your machine. You aren't going to be able to call in IT support to solve the problem. Basically, you have three options.

  1. Pay the ransom. This payment is usually via credit card or bitcoin (a digital currency). Some ransomware viruses even provide help lines if you're having trouble. Of course there are no guarantees your will get access to your data–these are thieves you’re dealing with.
  2. Don’t pay and lose your data - This has its obvious downsides, unless…
  3. You have a safe, clean backup. In that case, you are stuck with the nuisance of restoring your data with the backup, but you aren’t out any money. However, this comes with a caveat: your backups have to be clean. The problem with ransomware viruses is that just making backups may not be sufficient to protect your data, as the backups can be infected also. In the next blog, we will address your need to add an additional layer of protection to handle ransomware attacks.