Tuesday, March 16, 2021

4 things to do to ensure your business continuity planning is a success

4 things to do to ensure your business continuity planning is a success

Working on creating a contingency plan for your business? That’s great! Here are 4 things you need to consider when preparing your new business continuity plan.

Audit of your business continuity plan
Having a business continuity plan alone is not enough. You need to audit it at regular intervals to ensure it is up-to-date and relevant. Often, business continuity plans aren’t used for years, and may be obsolete or irrelevant by the time an actual emergency occurs.

Creating a team for business continuity
Constitute a team for your business continuity project. Decide who will take ownership of implementing the business continuity in the event of an emergency. Break down the business continuity plan into smaller elements and decide who is responsible for each of them. Also, remember to designate a back up for each person in the team.

Mock Drills and Dry Runs
After your business continuity plan is ready you need to check if it really works. A dry run will tell you if it is really effective and also point out to loose ends, if any, that you can fix before the actual emergency.

Don’t forget a debrief
In case you do end up using your business continuity plan, make sure you do a debrief. It will help you determine the effectiveness of your business continuity plan. The brief should focus on identifying the losses you incurred from the disaster, the time taken for implementation of the business continuity plan, the key positives of implementation of your business continuity plan and also offer suggestions, if any for improvement. Irrespective of the size of your business, business continuity planning is indispensable. Bigger companies often have their own staff (IT as well as non-IT) for business continuity planning, but for SMBs to have their own business continuity planning team can be a bit of a strain on their resources. Consider teaming up with a MSP who is experienced in disaster recovery planning, so you don’t cut corners now to regret later.

Tuesday, March 9, 2021

What are the essentials of a business continuity plan?

What are the essentials of a business continuity plan?

An unexpected emergency can wipe out your business! A business continuity plan can help it survive. But, what should a good business continuity plan cover? Read this blog to find out.

A list of your key contacts
One of the most important elements in your business continuity plan is a list of all your important contacts who should be informed of the disaster. This can include all your C-level execs, HR managers, IT Manager, client facing managers, etc.,

A comprehensive list of your IT inventory
Your business continuity plan should contain a list of all the softwares, apps and hardware that you use in the daily operations of your business. This list should identify each of those as critical or non-critical and mention details pertaining to each of them such as
  • The name of the app/software
  • Version/model number (for software/hardware)
  • Vendor name and contact information for each of them
  • Warranty/support availability details
  • Contact information for customer support for these hardware/apps
  • Frequency of usage

Backup information
Data backups are critical to your disaster recovery and so your business continuity plan should include information about data backups. It should mention how often data is backed up, in what formats and where. It should also mention what data backups are available--ideally, you should be backing up ALL data already!

What’s your Plan B?
Make sure your business continuity plan lists a backup operations plan that will come into play in the event of a disaster. Examples include alternative workflows such as options to work remotely or to allow employees to bring their own devices to work (BYOD) until the time regular business premises or systems are ready.

Floor plans and location
Your business continuity plan should also include floor plans of your offices with the exit and entry points clearly marked up, so they can be used in the event of any emergency. It should also mention the location of data centers, phones, key IT systems and related hardware.

Process definition
Make sure your business continuity plan defines the SOPs to be followed in the event of an emergency.

Think business continuity planning is too complicated? Don’t give up! A lot of SMBs, don’t create a business continuity plan thinking it is too much of a hassle. But this can prove fatal to your business later. A qualified MSP can help you understand business continuity planning and even help you create a business continuity plan that’s best suited for you..

Tuesday, March 2, 2021

3 Reasons to prepare a business continuity plan

3 Reasons to prepare a business continuity plan if you haven’t done so already

A business continuity plan is the blueprint you need during an emergency to keep your business running smoothly. If you don’t already have one, here are 3 key reasons why you should focus on creating one ASAP.

It helps retain clients
As a business, if you have problems functioning, it will definitely affect your clients. For example, if your servers are down or your supply-chain mechanism is affected or your delivery process breaks, you won’t be able to fulfill your promise to your clients. Even worse, in some situations you may not even be in a position to communicate about the crisis to your clients adding to their frustration. A business continuity plan addresses these issues beforehand and can help reduce client dissatisfaction.

Salvaging brand image and reputation
There are certain events that end up affecting only your business. For example, ransomware attacks, virus attacks, data leaks, etc., Having a business continuity plan that caters for such events can be a blessing in times of such crisis.

Minimizing revenue loss
A business continuity plan can minimize the revenue losses that occur as a result of a crisis that interrupts your business operations.

In short, a business continuity plan helps minimize the impact of the crisis on your client relations, your brand image and your revenue by equipping you with a plan to handle the situation better.

Tuesday, February 23, 2021

Business continuity planning: A must-have, not a luxury

Business continuity planning: A must-have, not a luxury

Business continuity planning is not an alien concept anymore. In recent times we have witnessed a lot of events that only serve to further intensify the need for business continuity planning. Examples include natural calamities like hurricanes, floods, wildfires, events like terror attacks or even pandemics like the recent Covid-19 outbreak.

While a business continuity plan cannot completely safeguard your business from all these events, it can certainly minimize the damage inflicted on your business. Top business consultants urge their clients to develop a business continuity plan as they consider it a part of the best practices for running a business. A business continuity plan can make the difference between survival and shutdown of a business during a crisis situation.

What is business continuity planning?
Business continuity planning is the process of creating a blueprint that helps your business respond and recover effectively from an unforeseen mishap. As discussed before, the unforeseen event could range from natural disasters to pandemics, or even accidents that affect just your place of business like a fire or even a cybercrime attack directed at your business in particular--basically, any event that can paralyze your business. A business continuity plan serves as a step-by-step guide that you can follow during an emergency to keep your business running smoothly.

True, a business continuity plan is not a sure shot method to survive a crisis, it won’t instantly eliminate the impact of the disaster, but it gives you the best chances of survival. If you are not sure of what a good business continuity plan entails , you can reach out to a reputable MSP to help you with the preparation and implementation of one.

Friday, December 4, 2020

The Enemy at the Gate

 


The Enemy at the Gate

As an MSP (Managed Service Provider)  who has been supporting small to mid-sized businesses for over 30 years, one thing I can tell you is that the mindset of "we are too small to be the target of a cyber-attack" is far more widespread than one might think.

Some might accuse me of exaggerating, or spreading FUD (Fear, Uncertainty & Doubt) like so much manure on the garden of business.. But in all fairness, I would say that I am understating the gravity of this phenomena.  The data doesn't lie. A recent Accenture/Ponemon study (PDF) shows that 68% of business leaders feel their cybersecurity risks are increasing, and Verizon found that 43% of breach victims were classified as small businesses.

Now, back to my initial postulation that SMB's seem to have a tendency to underestimate their risk.  How I know this to be true is that I find in many cases when doing cybersecurity assessments of prospective new clients, the most often overlooked facet of their cybersecurity maturity score is the firewall.  If there is one element of a businesses defense system that should not be ignored, it's network infrastructure, especially the firewall.

The simple fact is - an outdated firewall not only is likely to be laced with unpatched vulnerabilities, it also is not equipped to handle the threats todays cybercriminals bring to the party. Proper lifecycle management of perimeter security devices is about 5 years.  By that point, the technology has changed to meet the current level of threat to a point where simple subscription based services can no longer keep up.

Case in point - over 70% of all Internet traffic is secured by SSL encryption. The familiar HTTPS preceding the web URL tells you that the connection between you and that web server is secure.  But is it really? Many firewalls can not inspect SSL traffic, and so it passes directly to your browser, with all the potential vulnerabilities intact.  In fact, many of the bad actors who are perpetrating cyberattacks on all levels of business are working in that same "secure" space because they KNOW, most firewalls are either incapable of ferreting them out, or are not properly configured to do so because of the performance hit that results from deep packet inspection of SSL traffic.  It takes serious horsepower to un-encrypt, scan, and re-assemble SSL traffic.

More concerning to me on these visits is when I see big-box store level wireless routers often found on sale for under $100 and touted as a "firewall" being used in a business setting. Or even worse, just using the modem provided by the broadband provider du jour. Let me help you with this - for free - it's not good! No bueno, sehr schlect, call it what you will, but don't call it a business class firewall.  These devices do not have the intrusion prevention mechanisms, country of origin, BotNet, or malicious content filtering capabilities needed in today's cyberthreat landscape.

Yes, I see you out there with the sheepish grin.. While I might call you out for neglecting your businesses security, I don't blame you. Running a business is expensive, and you were probably given advice by someone, or read a review online, or have fallen victim to an IT support provider that really does not understand cybersecurity..  and so, I won't judge.  I would rather educate business owners on the harsh reality of why they need to work with a professional security focused MSP to ensure that the most critical component in their cyberdefense arsenal is right-sized for their current and mid-term needs.

The average payout for a ransomware intrusion on a typical business network is up to $111,605 (bankinfosecurity.com April 2020 study) and as a small business owner myself, the last thing I want to be doing is footing that kind of bill.  While you may recover from the problem, what is often missed in this calculation is the lost customer confidence that can further erode your bottom line over time.  Having the right firewall is the best first step a small business can take to defend against this type of intrusion, and a small price to pay in comparison to the risk.

With the average time to detect an intrusion ranging from 90 - 180 days, sometimes more, having a strong barrier to intrusion is the best first step you can take other than educating your workforce on how to recognize common threats. (Cybersecurity awareness training should be both mandatory and ongoing, and directed from the top down). The amount of downtime that occurs when a malicious intrusion happens can be staggering. To a a small business, this can often result in becoming the straw that breaks the camels back.  

Investing in the right firewall can mean the difference between long term success and failure. If you have not had a cybersecurity assessment performed in a couple years, partner with a reputable MSP or MSSP (Managed Security Service Provider).  They should be able to sit down with you, determine your organizational cybersecurity maturity level and make the right recommendations to help you safeguard your business.  If you are in the Western Massachusetts, Northern Connecticut area, contact us by web, or call us at (413) 786-9675.

Stay tuned for our next look at securing your business with our upcoming blog on endpoint protection.






Tuesday, May 12, 2020

Go to Your Room!


Go to Your Room!

We are living in unprecedented times.

The new *Normal* has definitely shaken things up in the business world.  Take all the political posturing out, remove all the hype and fear-mongering, ditch the conspiracy theories..  The fact remains, the business world is changing.  If you are reading this as a business owner, accept the fact.. No..  Embrace the fact..  things are changing.  Change with them, or be doomed to midden heap of mediocrity...  or worse.. failed business.

Sounds harsh, right?  Now, in your best Darth Vader voice, say "Search your feelings, you know it to be true".

So what is this blog all about - as you might see, it is being delivered in a somewhat light tone, filled with candor.. I think..  The point is - with the new movement to a more work-from-home environment becoming more common, how do you maximize that for your business.

Here are a handful of truths:

  • Many administrative tasks can be accomplished from a home office
  • One of the largest burdens on business is the cost of commercial space
  • Engaging the younger workforce means accepting a different perspective on hours of operation
  • Productivity from a work-from home (WFH) begins with equipping them for success 
Let's touch on these, shall we?

Business Administration from Afar:

Many office tasks are not necessarily tied to a physical location.  If you are paper-heavy - meaning rooms full of file cabinets containing documents from decades ago, ask yourself the hard question - is it necessary?  If it is - come up with a way to digitize the information you absolutely need to keep, invest in a document management system for quick recovery based on keyword searches, and shred the paper.  You will end up with more productivity as a result.

If you have frequent meetings that require face-to-face contact - consider any one of the popular web conferencing platforms - accept that you will have to pay for the convenience on a monthly or annual basis, and embrace the technology that makes it possible.  Most importantly, equip the WFH employee with the proper tools to make it work well.

Cost of Commercial Space:

Like most business owners, I cringe each time I sign the check for my monthly lease payment for our offices.  It is a necessary evil.  I ran NetWerks from my home for 12 years before moving into commercial space.  We had outgrown what we had to work with, so the move was necessary (or add on to the house - I opted to get the employees outta Dodge).  But - I miss the fact that my overhead was not as overwhelming a burden as it is with commercial space, utilities, etc.

What you are likely to see as more businesses embrace a WFH posture is that they will be able to downsize their commercial space needs to some extent.  You may even see a resurgence of "Executive Suites" that share phone services, receptionists, conference rooms, copy & print services and desk space for those times when you have to meet with people face to face or just need to get away from the home office for a while.

The Current Generation:

Having been in business for over 30 years, and being the parent of three 20-somethings, I can say pretty comfortably that the current generations have not bought into the concept of long term employment and loyalty to the employer..  And there is a simple reason for that.. those in the 35 and under range have seen their parents get kicked to the curb by employers despite a lifetime of loyalty.  They've seen promises broken and the devastation that it triggers within the family unit. You might say that they have hereditary trust issues.

On top of that, many in the younger generation find themselves currently on the lookout for something more challenging, or something that has purpose or a bigger meaning.  They want to make a difference - have an impact - and when that opportunity dries up with one employer, they move on to the next shiny thing.  The average time of employment for under 35's has been well studied, and is under 5 years.  In a 2016 Rasmussen College study, the average tenure of employment for 24 - 34 year old's was a paltry 2.8 years.

Among their complaints and reasons for job-hopping - professional development opportunities, having their input valued, and flexible work arrangements.

Equipping for Success:

This is the foundation of a successful transition to Work From Home.  If you are not wiling to invest in setting your remote work force up for success, just don't do it.  You will be shooting yourself in the foot.  But - it is not all on the shoulders of the employer.. The employee bears a responsibility to ensure that the WFH environment is conducive to conducting daily business.

Equipping for success starts and ends with..  Policy.  Develop a firm WFH policy that lays out articles of engagement that, if unwilling to comply, results in that employee being relegated to a daily commute to the office.  This policy should contain at the very least:


  • A dedicated workspace separated from the general populace of the household - spare room, basement, converted attic..  it should not be located in a common area
  • The space *should* have a door, preferably with a lock, especially if the individual handles confidential information, or at least a locking cabinet for secure storage of information and the understanding that no confidential material will be left unattended or unsecured
  • High speed internet connectivity - if possible, isolated from the rest of the household network
  • Adequate lighting and a reliable source of power
  • Work related assets not to be used for personal purposes
From the employer's perspective, these should be non-negotiable.  Some have added items such as work attire being expected, set hours of availability, etc.  Tailor the policy to meet your corporate culture.


From a technology perspective, the employer should strongly consider providing the following:

  • Similar technology to that used in-office.  If laptop is used - provide a docking station with dual displays, full sized keyboard and mouse, high quality web-cam and noise cancelling headset/mic.  If your office is equipped with Voice over IP (VoIP) Telephony -include a VoIP desk-set that connects directly in to your office system as an extension.
  • If you do a lot of video conferencing, provide a portable green-screen and consider an acceptable list of backgrounds to use with the video conferencing platform on which you have decided to standardize
  • Standardize on a videoconferencing platform
  • Consider implementing a platform for secure file sharing
  • Consider implementing a centrally managed system for password management
  • Consider updating older applications that leverage cloud based tools to provide a consistent environment regardless of location such as Office 365
Other areas that would be a strong recommendation to ensure a secure WFH environment:

  • High performance firewall or SD-WAN platform to ensure that business traffic does not mingle with personal traffic
  • Create a standardized WFH Package of technology and offer a modest stipend to offset business use of home for added electrical/internet use
  • Consider partnering with an MSP (Managed Service Provider) to do the initial set up and on-boarding of your WFH users, including a network security assessment, managed antivirus/threat detection and remote support options so that your employees are able to work with minimal interruptions
Conclusions:

The "New Norm" is upon us..  what we make of it will determine how we fare in the coming months and years.  Learn the lesson that states simply: If you don't lead change, you will be lead by it.  Get ahead of the shift in how business is done, remain agile, and the results will more likely be in your favor.  By embracing a positive work from home posture - one that has been planned in detail - you are likely to see better productivity as a result - possibly better than if you had an office filled with workers.  Most importantly - consider this an investment into the future growth potential of your company.  Spending some capital today may mean the difference in continued growth and a downward spiral.


Wednesday, May 6, 2020

Ransomware emails: How to identify

Ransomware emails: How to identify and steer clear of them

Ransomware attacks have suddenly become more prevalent. Each year sees more of them. Hospitals, NPOs, shipping giants, etc., have all been victims of ransomware attacks. Your business could be too! Did you know that emails are one of the most common gateways for ransomware to get into your systems? In this blog, we tell you how you can stay safe by following a few tips.

If you think something is amiss, it probably is

Does that email seem unfamiliar? As though you weren’t meant to get it, or it doesn’t quite sound like your colleague wrote it? Perhaps it’s not. Malicious email senders often try to mask actual email IDs with something similar. For example: An email you believe to have come from billing@yourvendor.com might actually be from billing@yourvemdor.com. So take a good look at the email ID if you spot something ‘phishy’.

Attachments and form fills

Does the email contain an attachment that you are being asked to save to your computer? Or an executable file that you are asked to run? Perhaps you are asked to submit your personal details at an authentic looking website. Before you do any of these, check the authenticity of the email and the message. Were you supposed to receive it? Were you expecting an attachment? You might even want to call the sender and confirm if you are unsure.

The message seems to instill fear or a sense of urgency

Often, malicious email messages urge you to take immediate action. You may be asked to log onto your ‘banking website’ ASAP to prevent your bank account from being frozen, or enter your ITR details onto a webpage to avoid being fined by the IRS. Real messages from your bank or the IRS will never force or hurry you to do something.

Other things you can do

Regular data backups

Conduct regular data backups so that in the eventuality of a ransomware attack, you don’t lose your data. Cybercriminals having access to your data is bad enough--it damages your brand and business reputation and can even attract lawsuits from parties whose personal information has been compromised, but, not being able to retrieve all that data in the aftermath of an attack is even worse. Regular backups help you in that regard, plus when you have a pretty recent data backup you are not reduced to the state of helplessness where you HAVE to pay the ransom to retrieve your data.

Install an anti-malware tool

Last, but not least, invest in anti-malware tools that can detect malware attacks and alert you before you fall prey to them. Such tools scan emails, links and attachments and alert you if they are found suspicious.

No matter how big or small a business you are, ransomware attack is a reality and applies to you. It is better to be prepared than having to cough up huge sums of money to free up your data later and even then there’s no guarantee your data will be restored by the cybercriminal.