Showing posts with label ransomware. Show all posts
Showing posts with label ransomware. Show all posts

Monday

8 questions about Windows 7 End of Life - #3 of 10 Cybersecurity for 2020

Frequently Asked Questions: Windows 7 End of Life (EOL)
We know it is not easy to make changes, especially to the computer that you are familiar with working on, but now that it’s about to lose vital security update support...  It’s time to move on! Windows 10 offers a significant upgrade in user productivity and security support, which will make the upgrade worth the cost for many companies.
If you’re facing an upgrade from Windows 7, here are several answers to the most common questions we get asked about and what EOL means for you.

Is there a Difference Between End of Mainstream Support & End of Extended Support?
  • Mainstream support includes feature updates, security updates, technical support and the ability to make feature requests. It is typically active for the first 5 years of a product’s lifecycle. Mainstream Support ended for Windows 7 on January 13, 2015.
  • Extended support still keeps some feature updates patching, along with those critical security updates. You lose the ability to make feature requests and some support options, but not all. Once Extended Support ends, ALL support is gone, including security updates.
Can I Keep Using Windows 7 After January 14, 2020?
Yes, but you’d be leaving your business at serious risk for a data breach.
There’s a connection between outdated software and compromised devices and networks. The famous WannaCry ransomware attack that impacted hundreds of thousands of systems in 2017 was studied, and it was found that nearly 70% of infected systems were running outdated software, Windows 7 to be exact.
Here’s what you’re facing if you keep running Windows 7 after it loses all support:
  • More significant risk of data breaches & malware infections.
  • Any new software will be less likely to work properly.
  • New printers, hardware or other devices will have a difficult time functioning.
  • Technology is always advancing and you’ll be left behind.
  • Technical support will be hard to find. Tech's don't want to be the last one to touch an old machine that is at risk of being breached.
How Do I Know If A Computer Can Upgrade to Windows 10?
If you have had that computer around the office for a long time, you may have a few problems trying to update your computers to Windows 10.  The old machine will need to meet the minimum requirements to support the new Operating System (OS).
Windows 10 requirements include:
  • It should have the latest version of either Windows 7 SP1 or Windows 8.1 Update.
  • Processor: 1 GHz or faster or SoC
  • RAM: 1 GB for 32-bit or 2GB for 64-bit
  • Hard disk space: 16 GB for 32-bit or 20 GB for 64-bit
  • Graphics card: DirectX 9 or later with WDDM 1.0 driver
  • Display: 800 x 600
What About Windows 8? Will It Go EOL?
If you are running Windows 8, then you’ll have a few more years before Microsoft support stops. The Windows 8 EOL date is January 10, 2023.

Will Internet Explorer (IE) On Windows 7 Be Supported?
No, support for Internet Explorer on Windows 7 computers will also be discontinued on January 14, 2020.

How Do I Get A Free Upgrade To Windows 10?

If you are working with 10D Tech and our Managed IT Support: Full Subscription, we include upgrades to the Windows 10Pro Operating system on approved and verified computers.  

If I Can’t Upgrade in Time, Do I Have Any Other Support Options?
Wellllll … Yes, Microsoft has created a lifeline for users of Windows 7 Professional and Windows 7 Enterprise because you are not the only one who has put off making the change. However, it will cost you! You can purchase extended security updates through January 2023, but why?  For about the cost of paying for the extended support, you can refresh your work stations to brand new. We have some really great solutions that will bring your networks up to date, refresh your technology and keep you working without the worry of your computer left alone out in the world of Bad Guys like a single antelope on the Sahara surround by a pack of Jackals. Unfortunately for the Windows 7 Home version – NO!  

Which Windows Operating System Am I Running?

Windows 7
  1. Select the Start button, type Computer in the search box, right-click on Computer, and then select Properties.
  2. Under Windows edition, you'll see the version and edition of Windows that your device is running.
Windows 8
  1. To find out which version of Windows your device is running, press the Windows logo   key + R, type winver in the Open box, and then select OK.
  2. If you're using a touch device, swipe in from the right edge of the screen, tap Settings, and then tap Change PC settings. Continue to step 3.
  3. If you're using a mouse, point to the lower-right corner of the screen, move the mouse pointer up, click Settings, and then click Change PC settings.
  4. Select PC and devices & PC info.
  5. Under Windows, you'll see which edition and version of Windows your device is running.
  6. Under PC & System type you'll see if you're running a 32-bit or 64-bit version of Windows
Windows 10
  1. To find out which version of Windows your device is running, press the Windows logo  key + R, type winver in the Open box, and then select OK.
  2. Select the Start  button & Settings  & System  > About 
  3. Under Device specifications & System type, see if you're running a 32-bit or 64-bit version of Windows
  4. Under Windows specifications, check which edition and version of Windows your device is running

Friday

Living The Human Firewall Life

From the 10D Monthly Security Awareness Newsletter

The 5 Traits of a Human Firewall 
The security of our organization depends upon you, the human firewall. You help prevent security events and control the input and output of sensitive information by exhibiting these five traits. 

Trait 1: Thinking before clicking
Phishing attacks remain the top strategy in every cybercriminal’s playbook. They flood organizations with emails containing malicious links and documents, knowing that all it takes is one click. Generic attacks are easy to spot, thanks to their poor grammar, spelling, or awkward phrasing. Others take a much more sophisticated approach, as in the case of spear phishing, which targets specific people and organizations. A human firewall reads emails carefully, hovers over links to display the full URL, and treats all requests for sensitive data with skepticism.

Trait 2: Using situational awareness 
Situational awareness simply means minding your surroundings, staying alert, and never making assumptions. For example, if you see an unfamiliar person in an area normally reserved for authorized personnel, or notice a secured door left open, don’t ignore it! Maintain a clean desk so as not to lose sensitive materials, and shred those materials when no longer needed. When traveling or working remotely, keep an eye on your personal belongings, stay alert for shoulder surfers, and use discretion when accessing or discussing highly sensitive information in public. These are all basic, non-technical behaviors of a strong human firewall.

Trait 3: Respecting privileged access
Access includes everything from login credentials to badges or keycards that allow you to enter secured areas. Respecting access means ensuring that whatever clearance you’ve been granted never gets misused for any reason. It means closing and locking doors, preventing tailgating (when someone slips in behind you without you knowing), never allowing someone to borrow your credentials, locking workstations when not in use, and maintaining strong, unique passwords for every account and every device.

Trait 4: Reporting incidents immediately 
Incidents happen. Reporting them immediately is the only way we can mitigate damages and reduce future risk. It doesn’t matter how big or small the incident seems. A secure door left open, an unknown individual hanging around the office, a phishing email, a smart device or computer malfunctioning—we rely on strong human firewalls like you, to inform us of these types of incidents as soon as possible. If you see something or hear something, say something!

Trait 5: Always following policy 
Human firewalls always follow our organization’s policies and never circumvent them for any reason. Why is this so important? Because policies define our security culture. They set the standards for how data is collected, stored, transferred, and destroyed when no longer needed. They exist to ensure that the privacy of our employees, clients, consumers, and partners remains intact. Failure to follow policy could lead to data breaches, ransomware attacks, or other damaging security incidents. And while we require that you know and follow our policies at all times, we also encourage you to ask questions when you’re unsure of something.

Accidental data breach by clicking ‘Send'


Merely having a HIPAA-compliant email service isn’t enough to keep a clinic or agency within the regulations. The organization still needs to train its employees to use the Health Insurance Portability and Accountability Act compliant service properly, as well as implement the necessary policy and administration measures to guard its Electronic Protected Health Information (ePHI) records. If these aspects aren’t addressed, an organization could easily find itself suffering from a significant breach, the resulting fines, penalties and possibly failure.

Data breaches have become one of a medical clinic or insurance agency’s greatest fears. If you study the reparations, penalties, recovery costs and the ensuing investment in new security measures, data breaches are unbelievably expensive. That is aside from accounting for the interruption to regular business or the long-term damage to their brand reputation. 60% of all organizations that experience a data breach fail within the next 120 days … 120 days!

A clinic in Michigan closed its doors on April 1st, 2019 just months after a ransomware attack deleted EVERYTHING. http://www.startribune.com/all-of-records-erased-doctor-s-office-closes-after-ransomware-attack/508180992/
Only 3 weeks ago, Eye Care Associates in Ohio had a trojan virus attack that severely affected their ability to do business and as of today (8/16/19) they are still struggling to recover and keep doors open https://businessjournaldaily.com/eye-care-associates-hit-by-ransomware-attack/

In both of these examples the clinics did not lose any patient data but Where the attack succeeded was interrupting business operations, Loss of reputation, loss of company data, costing it patient bookings and eventually, for Dr. Scalf and Dr. Bizon, the closure of their clinic.

Analyzing all breaches over the past 5 years will tell you that encryption is the most suitable way to make data confidential both in transit and at rest.

When organizations evaluate their need for email security, they all come to the conclusion that they need better access control, encryption, measures to ensure data integrity, documentation that the email is secure and much more. Some will find that they need more advanced mechanisms than others, such as opt-out email encryption to reduce the chances of employees accidentally causing data breaches. Ultimately, some businesses may decide that they have the capabilities to make their emails HIPAA-compliant in-house.

Others will choose to go with a HIPAA-compliant provider, like 10D Tech, that understands how to mitigate the problem in this complex regulatory world. This approach is generally easier and helps to spread the risks onto the provider, as long as a Business Associates Agreement (BAA) is signed. When audited, a clinic or organization simply refers to their provider for the documentation and reports of compliance. The end result of either method will be more than just HIPAA compliance. If your company has been judiciously following HIPAA’s recommended path of performing security reviews and implementing mitigation strategies, then it will end up with a secure email system as well. With the right systems in place, an organization will reduce its chances of suffering a data breach.

Accidentally causing a data breach is as easy as clicking ‘Send.’ Are you prepared?

8 questions about Windows 7 End of Life - #3 of 10 Cybersecurity for 2020

Frequently Asked Questions: Windows 7 End of Life (EOL) We know it is not easy to make changes, especially to the computer that you are f...