Infinet

How serious is Your Company about Securing its Data?

This article will discuss data security at most companies. It will look at some of the biggest mistakes company makes when securing data and some possible solutions.  

Today we use technology in almost every aspect of our lives. While that can be a good thing, there is a negative side to it. Anyone with the right technical know how can gain access to your company’s data, which they can use to destroy your business empire.

No matter the size of your company, you will need to create a plan that ensures all the data generated is secure. This plan is known as a security program. The program provides the framework that helps to keep the whole organization safe.

Some of the Biggest Mistakes that You Can Make in Securing Data:

  • Lack of a System on Where to Store Important Data.

When a system is not in place on where sensitive data should be stored, it increases the chances of it ending up in an unsecured location. One way to solve this is if a company creates a policy that categorizes what type of data is considered sensitive.

  • Cloud Misuse.

When a company stores data on the cloud, they are essentially storing their data on a hired computer. That means they have no control over it. If the data is of a sensitive nature, then it needs to be encrypted before being placed on the cloud. It is also important to understand the policy of the cloud services provider. It is especially so if you are required to share encryption keys with them.

  • Failure to Protect from Internal Threats.

One of the best examples of this kind of leak was the “Snowden” leak. The issue of the leak was because of weak governance issues. For instance, in this leak, the person managed to copy many gigabytes of data without any hindrance. Organizations need to be careful about giving employees access to data when they do not need it.

To fight off any chances of internal leaks, an organization needs to address the insider threats with appropriate controls. The controls need to be able to identify the damage and tell how much data has been stolen.

  • Trusting Technology.

One of the biggest mistakes a company can make is to have faith in its technology. It is important to note that as you work to improve security, hackers are also working. They are designing new and creative ways on how to get past your security. It is thus important that you have experts who conduct regular tests on your system. That way, they can help identify any potential leaks before they occur.

  • Failing to Invest Enough in Data Security.

When a business faces a data security challenge, it will most times look for a one size fits all solution. In such a case, the company may end spending too little to protect the data effectively. However, a business has to be willing to go further than this. It has to look for the most secure means of keeping its data secure.

  • Failure to Protect Physical Devices.

One of the easiest ways to hack a network is by using a device that is already accepted into the system. However, some organizations do not have measures in place to deal with the loss of physical devices. A good organization should have a mechanism that ensures stolen devices can no longer be allowed to access the system.

  • Failing to Take Care of the Human Factor.

An organization will spend a lot of money implementing the most complex security measures. However, most organizations drop the ball when handling the human factor. The staff is not well-trained on how to stay secure. There needs to be a training program for both new and existing employees. As changes are made to the security program, employees need to receive additional training.

Some of the most important Tips to Stay Secure.

If these measures are not being implemented at your organization, you need to start implementing them if you want to stay safe.

1. Make Use of Strong Passwords.

One of the easiest ways of keeping your organization secure is by implementing a strong password. Ensure that everyone who has access to your network makes use of a strong password. Use a combination of all character types on your keyboard for the best password. You should also ensure that your password is at least 8 characters long.

Never use any personal data as your password. Additionally, avoid using variations of personal data to create your password. Besides that, ensure that you change your password after every 90 days. It is also important everyone to have his or her own password and username. Having a generic password for everyone is dangerous.

2. Make Regular Software Updates.

Another simple but effective measure to keep your data safe is to keep all programs updated often. There is little use in installing the latest software if you will not make regular updates to it. Data is only as safe as the most recent updates to the system.

3. Encrypt Portable Devices.

Portable devices such as laptops are quite easy to steal. It is thus important that you take the extra step to ensure they are safe, even when stolen. One of the easiest measures to keep them safe is to encrypt them. The encryption software will make data on your hard drive unreachable unless they have a password.

4. Make Regular Backups.

Ensure that all company data is backed up to a secure offsite storage facility. Thus, even when your systems are compromised, your data will still be secure. The general rule of thumb is that backups should happen once a week. Getting data corrupted is painful but failing to have a backup can be even more painful.

Conclusion.

When creating any security measures, the top leadership must lead by example. They must be willing to spend money on programs that help to educate employees. It is important to note that data security is an ongoing process that will require regular revisions.

How serious is Your Company about Securing its Data? Read More »

A New Strain of Ransomware Attacks a Michigan Hospital System.

On July 5th, 2017, disaster struck a series of hospital networks in Michigan. Caro Community Hospital, Caro Medical Clinic and Caro Quick Care all lost access to not only their desktop and laptop computers, but also phones, email services and even patient records. A message on a computer screen confirmed administrators’ worst fears—They were a victim of ransomware.

Ransomware Hits Michigan Hospital System

According to Caro CEO, Marc Augsburger, the ransom note provided a single email address to use to determine the payment required to recover the locked data. The hacker specified a payment of $120,000 should be made in Bitcoin!

Instead of paying the hacker, hospital administrators decided to quickly shut down all electronics following the attack. This caused a great deal of disruption, but the damage was mitigated due to IT policies and procedures that were already in place. Hospital staff were well trained on keeping paper-based records in the event that such an incident occurred. All computers and other devices were also backed up remotely on a regular basis, so it was only a matter of time before Caro could get its systems back up and running.

What made this ransomware attack so unique was the extent of the machines affected.

Traditional ransomware strategies seem to be one of quantity over quality. The files on a single infected machine are quickly encrypted, and the ransom is typically a few hundred dollars. This particular strain didn’t just affect servers, computers and other devices, everything connected to the Caro network was affected, including the VoIP phone systems that were operated by those computers.

Make no mistake—The disruption was absolutely a bad thing, but the situation could have been far worse were it not for these policies. They also helped guarantee that no personal information of employees or patients was compromised during the attack.

It took nearly two weeks to get all hospital operations back up and running. Caro administrators contacted both the FBI and the local police in the immediate aftermath, both of which are still searching for the person or people responsible. The FBI indicated that this was a brand-new strain of ransomware, and one that they would continue to watch out for in the future.

The State of Malware  

As the Caro hospital staff discovered, ransomware is the “latest trend” in terms of cyberattacks. To say that the digital world is getting more dangerous is something of an understatement:

  • There were 22 million new malware samples in the first quarter of 2017 alone.
  • A new malware specimen is emerging every 4.2 seconds, a pace that’s getting faster all the time. To put this into perspective, there were only about 6.8 new malware samples discovered in the entirety of 2016.
  • In 2015, attacks occurred at a rate of about 1,000 per day. Fast-forward just a year later, and that number climbed to about 4,000 per day – an increase of 300%!
  • The number of phishing emails is also on the rise. In the first quarter of 2016, 92% of phishing emails contained some form of ransomware. Just a few months later, that number grew to 97.25%.

Learning as much about ransomware and other forms of malware is the key to ensure your organization doesn’t suffer the same fate.   

If you had to make a list of the worst cybersecurity threats facing businesses today, it’s this particular strain of malware that can encrypt all of the files on a computer and network. This means that every kilobyte of data on a machine is lost forever, unless you’re willing to pay a hefty fee to the criminal holding your data hostage.

According to a study conducted by Friedrich-Alexander University, most of these attacks are successful because of overconfident users. 78% of people claim to be aware of the risks associated with clicking on unknown links in emails, and of phishing in general—Yet they go on to click on these links anyway.

Because ransomware infections are most often the result of accidentally downloading a malicious file, many assume it’s a situation where a little common sense goes a long way. Recent events have proven this isn’t enough.

As a business leader, it’s important for you to understand that ransomware is just one of the many types of digital threats that should concern you. Hackers are getting more sophisticated all the time, and the key to staying protected involves making an effort to stay one step ahead of them. Cybersecurity training for your employees is essential.

If you’re in {city} and would like to find out more about cybersecurity issues, OR if you’re interested in cybersecurity training for your staff, please don’t delay—Contact {company} at {email} or {phone}.

A New Strain of Ransomware Attacks a Michigan Hospital System. Read More »

Why You Must Replace Your “Subpar” IT Service Company.

The technological resources that your small business uses on a daily basis are more than just “tools” in the traditional sense. In many ways, they’re the very foundation from which your 21st-century operations are built.

  • IT is how you communicate with your clients, guaranteeing that you can perform the type of work that meets their needs and exceeds their expectations.
  • It’s how your employees communicate with one another, and come together to form something much more powerful than any one of them could have on their own.
  • It’s also how you address the challenges of today while getting ready for the demands of tomorrow—Carving out a competitive advantage for your business that will carry you through into the next decade and beyond.

However, none of this makes any difference if your subpar IT service company is killing your chances.

Bad IT Services

Many IT service companies get a low score from their clients. Lengthy response times, reactive approaches to technology, excessive turnover rates and high prices with poor value are all among the many factors that small businesses have just “learned to deal with.” But you shouldn’t!

Here are a number of reasons why you should replace your subpar IT service company with a competent one.  

They’re Not the Only Ones Who Know Your Network.

One of the major reasons small business owners are hesitant to look for alternative IT service companies is the fear that they won’t be able to find another that knows their network like their existing provider does. Regardless of the quality of your relationship, you can’t argue that it’s taken time to build. Third-party representatives have come in and examined your system, what you need, and what you’re trying to do. It will be difficult, if not next to impossible, to start all over again. Right?  Wrong.

In truth, your service provider should be documenting every aspect of your IT infrastructure in detail. Diagrams, passwords and asset documentation should all be readily available to you. All of this information can be turned over to your new provider, giving them an excellent starting place to make your IT foundation stronger than it was before.

Your IT Isn’t as Unique as You Think It Is.

We’re not saying that your business isn’t unique in the marketplace. Undoubtedly, there are things you do that nobody else can match — This is likely why you have such a strong relationship with your customers in the first place.

Luckily, this doesn’t extend to your IT infrastructure. Sure, things were built with your specific business in mind. However, a true IT expert will have seen it all before. Competent network engineers are ready for anything and everything they encounter.

The Transition Won’t Be as Tough as You’re Anticipating.

High-quality IT service providers are used to taking over for competitors who aren’t living up to their customers’ expectations. While it’s true that there is always the potential for some risk, it’s nothing that good short- and long-term planning can’t resolve. Remember that you’re bringing a new company into the fold—So leverage the power of their experience to your advantage.

The Benefits Outweigh Any Potential Disadvantages.

All of this gives way to the most important factor of all—the fact that the benefits will far, outweigh any perceived negatives you may be worried about. Sticking with your subpar service company isn’t just killing the return on investment for your IT assets, it’s literally stifling the growth of your business.

  • It’s making it harder, not easier, to do the essential work you’re responsible for.
  • It’s causing you to lose hours of productivity due to unintelligent infrastructure design and unnecessary catastrophes like server failure.
  • It’s causing you to play catch-up because you’re being reactive rather than proactive.

A truly great IT service company is more than just a solutions provider. They’re a partner in your business success.  They’re not just proactively maintaining your IT environment, repairing small problems today before they have a chance to become bigger and more expensive ones later—They’ll act as your virtual CIO, providing you with the expert insight and advice you need to align IT with your long-term strategy.

Absolutely none of this will be possible if you stick with your subpar service company. If so, you’re hurting your chances of successful growth for your business.

Even though the decision to switch is appropriate, replacing your subpar IT service company can be stressful. Luckily, the hardworking team at {company} is ready to stand by your side every step of the way. If you’re in {city} and would like to find out more about this or other IT related topics, please don’t delay — Contact us by phone at {phone} or by sending us an email to: {email}

Why You Must Replace Your “Subpar” IT Service Company. Read More »

Ransomware Infects a San Francisco TV & Radio Station with Devastating Consequences.

Radio and television station KQED has been taken “back to the stone ages” because of an advanced ransomware attack launched in June of 2017.  No one is sure how the ransomware got into KQED’s system.

KQED Cyber Security

Ransomware brought this public television and radio station to a grinding halt— All Internet-connected devices, tools and machinery were cut off in an attempt to isolate and contain the  attack that infected the station’s computers. More than a month later, many remain offline. Although the station has continued its broadcasts, it’s found that functioning in a non-Internet world is extremely frustrating and difficult.

This incident highlights the need for businesses like yours to protect themselves and their IT devices from debilitating cyberattacks.  We’re more vulnerable today than ever before.  It’s up to you to take proactive measures to protect your business.   

Ransomware: An Old Threat Reborn

Ransomware isn’t new. In fact, it’s one of the oldest types of malicious software programs, and is becoming increasingly prevalent as more people rely on IT and Internet connections for their day-to-day operations.

Ransomware essentially locks a user out of their system, or holds data hostage until a ransom is paid. Once the ransom is paid (generally through a wire transfer or cryptocurrency transaction), the data or service is unlocked, and (theoretically) the user can recover their data.

However, there are more issues of concern:

  • Ransomware is a type of virus, so it can self-replicate throughout computers, servers, and other devices operating on the same network.
  • Paying the ransom doesn’t necessarily mean your system will be unlocked. Some forms of ransomware are designed to just disrupt, while others may have been long abandoned by its creators.
  • Paying the ransom can be expensive. While some ransomware attacks only amount to a few hundred dollars, others can be in the range of thousands—especially those targeting large enterprises.
  • Paying the ransom doesn’t mean your data hasn’t been copied or otherwise breached. You still need to react as though your data has been shared, including confidential identity and financial information.

KQED’s Ransomware Attack

KQED’s ransomware spread quickly throughout their network, including their Internet of Things devices. The ransomware then encrypted data on their Microsoft computers, but was halted before it could encrypt a significant number of systems. The problem was that it had already infected the network; if the system was brought back up, it would only continue to propagate. Consequently, Internet access had to be removed for many of the systems until the issues could be properly isolated and dealt with, device by device.

To avoid further infection, all Windows computers had to be wiped and restored, and KQED had to upgrade its security measures. This attack came in the wake of—but was not related to—several global ransomware attacks, which took down computers throughout the world.

In order to decrypt the files, the ransomware requested approximately $3,637 for each file to be decrypted. The total ransom requested was in the millions, which was impossible for KQED to pay.

How Can You Defend Against Ransomware Attacks?

In the past, many security systems were limited to only identifying already known attacks. This meant new vulnerabilities and custom attacks were impossible to defend against. KQED was vulnerable to attack even though it had relatively up-to-date security—This may have been the case because its security system was running based on antiviral templates.

New security systems scan for the presence of ransomware attacks and can mitigate the majority of these threats, not only by identifying individual attacks, but also being able to identify suspicious behavior. Machine-learning algorithms and artificial intelligence have now made it possible to scan for the behavior of potentially malicious programs.

KQED was struck by a new piece of software that had not yet been identified. However, it’s unknown whether its suspicious behavior might have been flagged by a more advanced threat-detection system.

Note: In addition to having up-to-date security measures, your systems must be regularly backed up. You should be able to deploy a backed-up instance of an entire system to protect your organization from virtually any threat—including physical hazards such as fire or earthquake.

KQED had a single network composed of many different devices, which couldn’t be reset altogether. The ultimate consequences for KQED were that:

  • They couldn’t complete a significant amount of work for weeks.
  • Online broadcasts went down for more than twelve hours.
  • They lost a significant portion of their work and weren’t able to use their computers or the Internet for a substantial amount of time.
  • It took weeks to even begin to repair the damage—and these are weeks the station will need to pay for in terms of man hours and IT costs.

All of this could have been prevented through better security measures and security training for their employees.

Cybersecurity is our specialty and priority at {company}. Cyber threats are growing exponentially, and we’ll block them by eradicating all potential security weaknesses. Your systems will be protected by a next-generation firewall, antivirus, and spam-filtering system. Plus, we’ll conduct security awareness training for you and your staff on an ongoing basis, so they can recognize a threat in an email, or on a web page.

Ransomware Infects a San Francisco TV & Radio Station with Devastating Consequences. Read More »

Talk to our Team