Showing posts with label Virus. Show all posts
Showing posts with label Virus. Show all posts

Monday

Avoid these 10 CyberSecurity mistakes in 2020: Network Breach

You are NOT Exempt from Online Attacks - 2 of 10

We frequently meet with small to medium size clients that have this false opinion that their business is too small or trivial to be targeted by Bad Guys, hackers, scammers, trouble makers or just general criminals. The fact is that every business, large or small, are possible targets for these criminals. The threat has become such a concern the Federal Bureau of Investigation (FBI) issued a High Impact Cyber-Attack Warning. On October 2, 2019, Alert Number I-100219-PSA describing and warning against ransomware attacks. Read the full alert release here https://www.ic3.gov/media/2019/191002.aspx


Last year a report written by the Ponemon Institute produced a survey of 1000 IT Support providers about the state of cybersecurity in small and medium-sized businesses. It revealed that 67% of their SMBs have encountered a cyberattack while another 58% have had a data breach in the previous 12 months. Another report writes that 60% of all SMB’s that have had a breach fail within 180 days. The breach will cost SMB’s: time, money, loss of reputation, possible fines, network downtime, loss of revenue coming into the business, loss of data and maximum effort to fix what was broken or stolen.

Find out if a business that you work with has been breached …“Oregon law requires businesses and state agencies to notify any Oregon consumer whose personal information was subject to a breach of security. In the event that a breach affected more than 250 Oregon consumers, the law also requires that a sample copy of a breach notice sent to more than 250 Oregon consumers must also be provided to the Oregon Attorney General.”  https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/data-breaches/

Most of these breaches were preventable. Furthermore, companies that do not manage credit card data or any customer/client information believe that cybercriminals will not target their company network. In truth, the Bad Guys are targeting multiple computer networks to find vulnerabilities, obtain sensitive information, take control of your network, lock your data up and demand financial payment to have it restored or just to cause damage.
The simple fact is if your business/organization has an online presence, you are at risk and must adopt cybersecurity as a business strategy to guard both your stored data and network resources.

Call us, 10D Tech, if you would like to create a technology security plan that prevents the crime and recovers the network/data quickly in case of a breach.

Thursday

Disposing of your PC

How to get rid of your computer


#1 Save essential files

Back up your data or transfer files to a new computer. The easiest way to do this is to invest in an external hard drive. If you're looking for secure ongoing backup and file syncing solution, use a cloud service such as Box, Apple iCloud, Google Drive or Microsoft’s OneDrive of for more assistance call 10D Tech 541.243.4103

Backing up data to the cloud will quickly transfer it back to a new machine or enable access to it via an Internet connection, even from your Android or iPhone. Storing data in the cloud is also very convenient if your computer dies and you need to restore your files. You can also get to the data if you travel and need access to data or information on a different device.
  1. Delete and overwrite sensitive files: Tax documents & other confidential data should be deleted with software specially designed to meet the government standards for secure data deletion. For hard drives in Windows PCs, try File Shredder (its free). For the older Macs with hard drives (pre-OS X El Capitan or OS 10.11) select the “Secure Empty Trash” option after deleting your files. You’ll see it under Finder > Secure Empty Trash. Macs with OS 10.11 and higher and Windows PCs with SSD drives, encrypt your drive. Encryption should be a standard practice at all times with all computers if it is available. Wiping your drive after these steps will securely erase your files.
  2. Turn on drive encryption. For Windows PCs with SSD drives, go to Settings > About. Toward the bottom, you'll see either an option for Drive Encryption or Bitlocker Settings. Follow the prompts to encrypt your drive. For Macs, go to System Preferences > Security & Privacy > FileVault and select Turn On FileVault. You'll then select a password and select Restart.
  3. Deauthorize your computer. Some programs, such as iTunes and Microsoft Office 365, only allow you to install software on a limited number of computers or allow a limited number of computers to access your files. So be sure to deauthorize your old equipment from your accounts - before uninstalling any programs.
  4. Delete your browsing history. Your internet browsers save info about your internet browsing history. How you have your settings configured, you may even store your usernames and site passwords at various websites. Obviously, you don’t want a stranger or, worse, a stranger with bad intentions having access to this information. For Microsoft Internet Explorer, you click on the cogwheel in the upper right corner, and it will open the browser menu, then click on the Safety option, and then Delete Browsing History. Make sure all of the checkboxes are chosen, so it all gets removed. Repeat this step for any other browsers on your computer (Firefox, Safari, Chrome). Firefox and Chrome, you will need to first sign out of your browser.
  5. Uninstall all of your programs. Many programs, such as Microsoft Office, will contain personal information like your name, address, and other details. We recommend uninstalling all programs before disposing of your computer. To uninstall programs on a PC: Start>Control Panel>Programs>click on program>click uninstall.
  6. Consult your employer or IT Dept about data disposal policies. If your computer is used for business, check with your company or IT Support company about how to manage the organization related information that is on your computer. Local, State and Federal laws require businesses to follow data security and disposal processes for deleting personal information about clients and customers.
  7. Wipe your hard drive. Once you've gone through and removed the information and data you know is there, perform a factory reset so you are confident that you have removed ALL of your personal files & software programs. Now restart your computer. Once the machine is back up, download & install the application “Eraser,” choose the most current version.
  8. OR physically damage your hard drive. If you are only looking to recycle your computer and are very anxious about somebody recovering your files, take out the hard drive and drill a couple of holes in it OR utilize the anger management training and beat the heck out of it with a hammer. This works for CDs, Jumpdrives cameras, etc, once the files you want are off them, a drill or hammer is a great way to say goodbye to your old media.


Friday

Living The Human Firewall Life

From the 10D Monthly Security Awareness Newsletter

The 5 Traits of a Human Firewall 
The security of our organization depends upon you, the human firewall. You help prevent security events and control the input and output of sensitive information by exhibiting these five traits. 

Trait 1: Thinking before clicking
Phishing attacks remain the top strategy in every cybercriminal’s playbook. They flood organizations with emails containing malicious links and documents, knowing that all it takes is one click. Generic attacks are easy to spot, thanks to their poor grammar, spelling, or awkward phrasing. Others take a much more sophisticated approach, as in the case of spear phishing, which targets specific people and organizations. A human firewall reads emails carefully, hovers over links to display the full URL, and treats all requests for sensitive data with skepticism.

Trait 2: Using situational awareness 
Situational awareness simply means minding your surroundings, staying alert, and never making assumptions. For example, if you see an unfamiliar person in an area normally reserved for authorized personnel, or notice a secured door left open, don’t ignore it! Maintain a clean desk so as not to lose sensitive materials, and shred those materials when no longer needed. When traveling or working remotely, keep an eye on your personal belongings, stay alert for shoulder surfers, and use discretion when accessing or discussing highly sensitive information in public. These are all basic, non-technical behaviors of a strong human firewall.

Trait 3: Respecting privileged access
Access includes everything from login credentials to badges or keycards that allow you to enter secured areas. Respecting access means ensuring that whatever clearance you’ve been granted never gets misused for any reason. It means closing and locking doors, preventing tailgating (when someone slips in behind you without you knowing), never allowing someone to borrow your credentials, locking workstations when not in use, and maintaining strong, unique passwords for every account and every device.

Trait 4: Reporting incidents immediately 
Incidents happen. Reporting them immediately is the only way we can mitigate damages and reduce future risk. It doesn’t matter how big or small the incident seems. A secure door left open, an unknown individual hanging around the office, a phishing email, a smart device or computer malfunctioning—we rely on strong human firewalls like you, to inform us of these types of incidents as soon as possible. If you see something or hear something, say something!

Trait 5: Always following policy 
Human firewalls always follow our organization’s policies and never circumvent them for any reason. Why is this so important? Because policies define our security culture. They set the standards for how data is collected, stored, transferred, and destroyed when no longer needed. They exist to ensure that the privacy of our employees, clients, consumers, and partners remains intact. Failure to follow policy could lead to data breaches, ransomware attacks, or other damaging security incidents. And while we require that you know and follow our policies at all times, we also encourage you to ask questions when you’re unsure of something.

What do cybercriminals do with stolen data?


What do cybercriminals do with stolen data?
You’ve likely heard the stories of major data breaches that expose the personal information of millions of people. Perhaps you’ve even been a victim of this. But what actually happens to exposed data? How do cybercriminals actually use the data?

They sell it on the dark web. Credit card numbers, national ID numbers, email addresses, and passwords all fetch certain prices on the underground economy.
They launch spear phishing campaigns. With enough information, cybercriminals increase their chances of successful phishing attacks because they’re able to target specific individuals or organizations while sounding legitimate.
They pretend to be you. Identity theft is a top concern. If attackers gain access to your personal info, they can open accounts in your name, attempt to claim tax refunds, and file insurance claims, etc.
They attack even more accounts. In the case of stolen usernames and passwords, criminals use “credential stuffing,” which is an automated attack using those same usernames and passwords to gain access to other accounts.

Accidental data breach by clicking ‘Send'


Merely having a HIPAA-compliant email service isn’t enough to keep a clinic or agency within the regulations. The organization still needs to train its employees to use the Health Insurance Portability and Accountability Act compliant service properly, as well as implement the necessary policy and administration measures to guard its Electronic Protected Health Information (ePHI) records. If these aspects aren’t addressed, an organization could easily find itself suffering from a significant breach, the resulting fines, penalties and possibly failure.

Data breaches have become one of a medical clinic or insurance agency’s greatest fears. If you study the reparations, penalties, recovery costs and the ensuing investment in new security measures, data breaches are unbelievably expensive. That is aside from accounting for the interruption to regular business or the long-term damage to their brand reputation. 60% of all organizations that experience a data breach fail within the next 120 days … 120 days!

A clinic in Michigan closed its doors on April 1st, 2019 just months after a ransomware attack deleted EVERYTHING. http://www.startribune.com/all-of-records-erased-doctor-s-office-closes-after-ransomware-attack/508180992/
Only 3 weeks ago, Eye Care Associates in Ohio had a trojan virus attack that severely affected their ability to do business and as of today (8/16/19) they are still struggling to recover and keep doors open https://businessjournaldaily.com/eye-care-associates-hit-by-ransomware-attack/

In both of these examples the clinics did not lose any patient data but Where the attack succeeded was interrupting business operations, Loss of reputation, loss of company data, costing it patient bookings and eventually, for Dr. Scalf and Dr. Bizon, the closure of their clinic.

Analyzing all breaches over the past 5 years will tell you that encryption is the most suitable way to make data confidential both in transit and at rest.

When organizations evaluate their need for email security, they all come to the conclusion that they need better access control, encryption, measures to ensure data integrity, documentation that the email is secure and much more. Some will find that they need more advanced mechanisms than others, such as opt-out email encryption to reduce the chances of employees accidentally causing data breaches. Ultimately, some businesses may decide that they have the capabilities to make their emails HIPAA-compliant in-house.

Others will choose to go with a HIPAA-compliant provider, like 10D Tech, that understands how to mitigate the problem in this complex regulatory world. This approach is generally easier and helps to spread the risks onto the provider, as long as a Business Associates Agreement (BAA) is signed. When audited, a clinic or organization simply refers to their provider for the documentation and reports of compliance. The end result of either method will be more than just HIPAA compliance. If your company has been judiciously following HIPAA’s recommended path of performing security reviews and implementing mitigation strategies, then it will end up with a secure email system as well. With the right systems in place, an organization will reduce its chances of suffering a data breach.

Accidentally causing a data breach is as easy as clicking ‘Send.’ Are you prepared?

8 questions about Windows 7 End of Life - #3 of 10 Cybersecurity for 2020

Frequently Asked Questions: Windows 7 End of Life (EOL) We know it is not easy to make changes, especially to the computer that you are f...