Showing posts with label Unified Threat Management. Show all posts
Showing posts with label Unified Threat Management. Show all posts

Thursday

Disposing of your PC

How to get rid of your computer


#1 Save essential files

Back up your data or transfer files to a new computer. The easiest way to do this is to invest in an external hard drive. If you're looking for secure ongoing backup and file syncing solution, use a cloud service such as Box, Apple iCloud, Google Drive or Microsoft’s OneDrive of for more assistance call 10D Tech 541.243.4103

Backing up data to the cloud will quickly transfer it back to a new machine or enable access to it via an Internet connection, even from your Android or iPhone. Storing data in the cloud is also very convenient if your computer dies and you need to restore your files. You can also get to the data if you travel and need access to data or information on a different device.
  1. Delete and overwrite sensitive files: Tax documents & other confidential data should be deleted with software specially designed to meet the government standards for secure data deletion. For hard drives in Windows PCs, try File Shredder (its free). For the older Macs with hard drives (pre-OS X El Capitan or OS 10.11) select the “Secure Empty Trash” option after deleting your files. You’ll see it under Finder > Secure Empty Trash. Macs with OS 10.11 and higher and Windows PCs with SSD drives, encrypt your drive. Encryption should be a standard practice at all times with all computers if it is available. Wiping your drive after these steps will securely erase your files.
  2. Turn on drive encryption. For Windows PCs with SSD drives, go to Settings > About. Toward the bottom, you'll see either an option for Drive Encryption or Bitlocker Settings. Follow the prompts to encrypt your drive. For Macs, go to System Preferences > Security & Privacy > FileVault and select Turn On FileVault. You'll then select a password and select Restart.
  3. Deauthorize your computer. Some programs, such as iTunes and Microsoft Office 365, only allow you to install software on a limited number of computers or allow a limited number of computers to access your files. So be sure to deauthorize your old equipment from your accounts - before uninstalling any programs.
  4. Delete your browsing history. Your internet browsers save info about your internet browsing history. How you have your settings configured, you may even store your usernames and site passwords at various websites. Obviously, you don’t want a stranger or, worse, a stranger with bad intentions having access to this information. For Microsoft Internet Explorer, you click on the cogwheel in the upper right corner, and it will open the browser menu, then click on the Safety option, and then Delete Browsing History. Make sure all of the checkboxes are chosen, so it all gets removed. Repeat this step for any other browsers on your computer (Firefox, Safari, Chrome). Firefox and Chrome, you will need to first sign out of your browser.
  5. Uninstall all of your programs. Many programs, such as Microsoft Office, will contain personal information like your name, address, and other details. We recommend uninstalling all programs before disposing of your computer. To uninstall programs on a PC: Start>Control Panel>Programs>click on program>click uninstall.
  6. Consult your employer or IT Dept about data disposal policies. If your computer is used for business, check with your company or IT Support company about how to manage the organization related information that is on your computer. Local, State and Federal laws require businesses to follow data security and disposal processes for deleting personal information about clients and customers.
  7. Wipe your hard drive. Once you've gone through and removed the information and data you know is there, perform a factory reset so you are confident that you have removed ALL of your personal files & software programs. Now restart your computer. Once the machine is back up, download & install the application “Eraser,” choose the most current version.
  8. OR physically damage your hard drive. If you are only looking to recycle your computer and are very anxious about somebody recovering your files, take out the hard drive and drill a couple of holes in it OR utilize the anger management training and beat the heck out of it with a hammer. This works for CDs, Jumpdrives cameras, etc, once the files you want are off them, a drill or hammer is a great way to say goodbye to your old media.


Friday

What do cybercriminals do with stolen data?


What do cybercriminals do with stolen data?
You’ve likely heard the stories of major data breaches that expose the personal information of millions of people. Perhaps you’ve even been a victim of this. But what actually happens to exposed data? How do cybercriminals actually use the data?

They sell it on the dark web. Credit card numbers, national ID numbers, email addresses, and passwords all fetch certain prices on the underground economy.
They launch spear phishing campaigns. With enough information, cybercriminals increase their chances of successful phishing attacks because they’re able to target specific individuals or organizations while sounding legitimate.
They pretend to be you. Identity theft is a top concern. If attackers gain access to your personal info, they can open accounts in your name, attempt to claim tax refunds, and file insurance claims, etc.
They attack even more accounts. In the case of stolen usernames and passwords, criminals use “credential stuffing,” which is an automated attack using those same usernames and passwords to gain access to other accounts.

Wednesday

#1 of 7 CyberSecurity Tips


We all now rely on technology. Our businesses rely on technology, big or small. Our clients find us online and use the 10D Tech website. We store confidential information and communicate via email. We download documents and research and file forms online. We manage other businesses networks.

10D Tech IS a target for bad guys. WE know IT and how to protect ourselves so that we can help our clients protect themselves. 

Numerous reports reveal that more than half of all small businesses are hit with a security breach. The financial consequences can be significant and for many, devastating. Right out of the gate, you’ll have to pay to have the systems recovered, get the data back, loss of reputation and potentially loss of your clients. 

Every organization needs to take responsibility and enable security measures to protect their business as part of the monthly reoccurring costs, like phone bills and rent. You can’t just set it up and forget it because the attack protocols change daily.  The Hollywood version of fending off a hacker attack, with streams of data scrolling across the screen is unrealistic. The image of a computer genius pounding away on a keyboard like they are replying to a political Facebook post is just comical. Most hackers are in a business network for 68 days before being discovered. They sneak in through emails, phishing links and EBKAC (Error Between Keyboard And Chair)  The bad guys are good, really good, BUT beatable with the right tools, properly configured firewalls and staff training.

Here is the first of 7 important cyber security tips.

#1. Create a clear set of security protocols.
How will you protect your business? Take some time and write it out with your IT team (10D Tech). You know your business, the IT team knows theirs. They’ll help you with the details for protecting your network, hardware and client information.   Don’t skimp here because the cost of a security failure can close your doors.

Evaluation items you should regularly ask your IT Team:
  • How often do you run system updates, patches and network scans?
  • Do we need to protect and back up all of our data?
  • Does the staff have access to all of our sensitive data?
  • What software and applications are critical, and which are optional?
  • Where does the buck stop? The one throat to choke or the one back to pat?

Review the security plan every 6 months, and remember to include employee training in the security equation.  Your cybersecurity plan only protects the business if everyone knows it and follows it.

Next Tip: #2 Business Email Compromise (BEC) protection

Sextortion Scams


SEXTORTION SCAM
Have you ever received one of those emails that didn't really make sense but still made the hair stand up on the back of your neck? One of those could start with a message like:  “Send bitcoin right away or else I am sending compromising photos or information to your friends and family.
This is a new variation of an old scam. A little fear-inciting jolt that has you unsure of the nature of what the scammer is talking about… your mind races … How would they have anything I would not want to be exposed? What item or video could they have that I would want to hide? Then you think about the privacy in your own home? What device did they hack? Even if you know the claim is impossible and untrue, it is still very unsettling and a bit frightening. This new version of an old scam is called Sextortion and it preys on your fear of the unknown.
How does this scam work?
The bad guy tells you they have hacked your device/computer and they will release embarrassing information. They don’t tell you what they have, only that they have something from your personal device. It could be photos, emails or text messages. Most of the time the bad guy vaguely threatens to release the information they have stolen to your employer, your friends and your family. Sometimes the bad guys describe details of what they allegedly have on you.
What is it that they want? They’ll tell you that to avoid having your personal items exposed to everybody you have to pay them immediately using bitcoin.
Here’s the catch:
What would make you believe their claims are right when you know it can’t be right. The scammer provides just enough information from one of your hacked accounts. Equifax, Target, Facebook, Marriott, MANY more! Mine was my old MySpace account. There are too many breached companies to list them all, but in all likelihood, some of your information has been stolen. They give you just enough information, that adds credibility to their claim, to make you believe they may have something of yours that you want back. They’ll show an exposed password and/or your user name which they purchased on the dark web. By matching your email address with passwords, they have enough information to make you a little frightened. The scammers assume a small percentage of their chosen victims will react and pay the extortion fee. It’s in the numbers, 1 million emails sent, 50,000 people get nervous, 5,000 pay the $1,000 ransom and they have a $5,000,000 payday. 
That's only .5%  response on the 1,000,000 emails sent for a HUGE payday.
The 50,000 nervous people have a jump in their fear level start a Google search for how to purchase Bitcoin or think about what could they have.  OK DEEP BREATH, if you are like 99.5% of us you know you're being scammed but let us give you some advice in case you're still nervous. Don’t fall for it and don’t pay the ransom.
As proof, they may provide you with a legitimate username and password, most likely from an old account because those are the cheapest to obtain. Regardless if it is old or new, stop using the password they provided, change it immediately, especially if it is one of the 3 passwords you use. Using the same password will eventually lead the bad guys to an account that does have items you want to keep safe and private. If you use your password manager, it will assist you in changing that password as well as do a security search of your accounts for the same password. Change those as well. Rest assured, if the password they show you has been used to secure some of your other accounts, all of those accounts are also compromised. That is where the hair on the back of your neck should raise up.
If you really want to be secure and keep information private, use the two-factor authentication on your password manager. Consider the advice below by covering your camera lens with a piece of tape, post-it note or slide cover.

What should you do if you get a Sextortion email?

Even though there is no real bit behind this scam doesn’t mean you should not take some sort of action. Use the extortion scam as a cue to protect yourself online. The Federal Bureau of Investigation aka FBI advises:
  • Do not pay
  • Do not respond to the email
  • When opening unexpected attachments from people you know, use caution because their email addresses may have been spoofed
  • Change your passwords often
  • See if your other email addresses and passwords have been pawned or stolen
  • Stop using the password immediately (and while you’re at it, update any old passwords — using a password manager, like LastPass, is fastest)
  • Never ever send compromising photos of yourself to anyone unless you want everybody to see them.
  • Don’t open attachments from strangers
  • Turn off your computer’s camera or put a piece of tape over it when you’re not using it
I'll reiterate, DON’T reply to the email. The more you reply, the more likely you are to expose other items or information that they will use to manipulate against you.

8 questions about Windows 7 End of Life - #3 of 10 Cybersecurity for 2020

Frequently Asked Questions: Windows 7 End of Life (EOL) We know it is not easy to make changes, especially to the computer that you are f...