app

Tammy Cipriani

4 Cyberthreats Small Businesses Need to Know

Data breaches have become more common in recent years, owing primarily to the rapid emergence of new threats. According to a new study, the average cost of a data breach increased 2.6% from 2021 to 2022.* Hackers can now access sensitive information a lot easier than ever before, thanks to the growth of the internet and the increasing interconnectedness of businesses. They can then sell that information on the dark web or use it to commit other crimes such as identity theft.

So, what can you do to safeguard your business against data breaches? The first step is being aware of the threats that exist. Second, you must take precautions to protect your data. Third, you need to know what to do if your data is compromised.

In this blog post, we’ll discuss a few of the threats you need to look out for to safeguard your business.

Don’t let these threats get to your business

Here are some lesser known cyberthreats that you need to be aware of:

Juice jacking

Juice jacking is a cyberattack where a malicious actor secretly installs malware on a public charging station. This malware can then infect the devices of anyone who plugs into the charging station. Once infected, the attacker can access the victim’s data. Crazy, right?

An attack of this nature needs to be proactively tackled because more people are using public charging stations to charge their devices. Remember, it’s not just phones that are at risk — any device connected to the infected public charging station is susceptible to juice jacking, including laptops and tablets.

If you must use a public charging station, take a few precautions. To start, only use trustworthy stations. Second, to keep your device from becoming infected, use a USB data blocker. Finally, ensure that your device is in “charging” mode rather than “data transfer” mode.

Malware-laden apps

The number of smartphone users has grown and along with it the number of mobile apps. While there are many legitimate and safe apps available in app stores, there are also many malicious apps cybercriminals release despite valiant efforts to keep app stores safe.

One of the biggest dangers of downloading bad apps is that they can infect your device with malware. This malicious software can wreak havoc on your device, including stealing your personal data, vandalizing your files and causing your device to crash. In some cases, malware even equips hackers to take control of your device remotely.

So, how can you protect yourself from downloading malware-laden apps? The best defense is to be vigilant and research before downloading any app, even if it’s from an official store like the App Store or Google Play Store. Check reviews and ratings, and only download apps from developers that you trust.

Malicious QR codes

It’s no secret that QR codes are becoming increasingly popular. Unfortunately, while they offer a convenient way to share information, they also present a potential security risk. That’s because scanning a malicious QR code can give attackers access to your device and data.

The best way to protect yourself against this type of attack is to be aware of the dangers and to take precautions when scanning QR codes. For example, you can use a reputable QR code scanner that checks malicious content before opening it. You can also avoid scanning QR codes that you don’t trust.

Using public Wi-Fi without a VPN (Virtual Private Network)

Public Wi-Fi is everywhere, and it’s often very convenient to use when you’re out and about. However, what many people don’t realize is that using public Wi-Fi without a VPN can be a security disaster.

When you connect to a public Wi-Fi network, you unwittingly invite potential hackers and cybercriminals to access your data. Without a VPN, anyone on the same network as you can easily see what you’re doing online. They can intercept your data and even steal sensitive information.

That’s why we recommend using a VPN. A VPN encrypts your data and provides a secure connection, even on public Wi-Fi.

Collaborate to tackle cyberthreats

 If you can’t devote sufficient time and effort to combating cyberthreats, partnering with an IT service provider is your best option. An IT service provider, like us, can help you with cybersecurity, backup, compliance and much more.

We can also improve your employees’ readiness to deal with cyberthreats by helping you provide regular security awareness training. Employees can benefit from this training by learning how to identify and avoid phishing scams, protect their passwords and detect other types of cyberattacks.

To learn more about security awareness training, download our eBook “Security Awareness Training: Your Small Business’s Best Investment” by clicking here.

4 Cyberthreats Small Businesses Need to Know

A Beginner’s Guide to Ransomware

What SMB’s Need to Know

Overview

IMAGINE BEING PART OF AN IT SEGMENT WITH SKY-ROCKETING GROWTH, MASSIVELY SUCCESSFUL WORLDWIDE DEPLOYMENT, ANNUAL REVENUE IN

THE BILLIONS AND DOUBLE-DIGIT GROWTH PROJECTIONS. IT’S A HIGHLY LUCRATIVE INDUSTRY THAT IS CONSTANTLY EVOLVING, WITH NEW VERSIONS OF SOFTWARE BEING RELEASED AND DEPLOYED EVERY DAY.

Sounds like an industry you’d want to be a part of, right? Unfortunately, we’re talking about ransomware.

Ransomware is a form of malware that encrypts a victim’s data, rendering files, applications or entire machines unusable. The malware programming community continues to look for new targets. It’s often a matter of opportunity. Organizations that have recently digitized operations, such as government agencies or medical facilities, or those with small security teams or little downtime tolerance, make for prime targets that threat actors aim to cash in on. After launching an attack and encrypting an organization’s data, the perpetrator demands payment, usually by untraceable means such as cryptocurrency, in exchange for a key to unlock the encrypted files.

To put it simply:

  • Threat actors launch targeted attacks via phishing, account takeover or other means.
  • Ransomware locks victims’ files with strong encryption, typically using RSA or customized symmetric-key algorithms.
  • Payment is demanded for a private key to unlock encrypted data.

Barriers to entry in the ransomware industry are low. Open-source versions of ransomware are available to anyone looking to tap into this profitable market. The emergence of these open-source ransomware programs hosted on GitHub and hacking forums are expected to further spur the growth of these attacks in 2022 and beyond.

Even if the would-be perpetrators don’t have the skills to create their own malware from free source code, they can still outsource development. Ransomware-as-a service

[RaaS] is a model that provides automatically generated ransomware executables for anyone who wants to attempt launching their own ransomware campaign.

RaaS is a variant of ransomware that is user-friendly and easily deployable. Cybercriminals can download a software kit either for free or a percentage-based fee. The goal of developers is to provide new variants to their subscribers, who then execute campaigns with the goal of infecting their targets’ computers. Some subscribers may look to generate larger revenues by executing more widespread attacks against a larger organization’s network. Once the payload detonates, victims are sent a ransom demand and payment deadline. If a victim pays the ransom, the original developer takes a commission — typically 5% to 30% of the ransom — and the rest goes to the individual or organization who launched the attack.

TO SUM UP:

  • 56% of organizations faced a ransomware attack
  • 50% of it professionals believe their organizations are not ready to defend against a ransomware attack

These programs are freely available for anyone who has the basic knowledge needed to compile existing code.

NEW VARIATIONS

1 SODINOKIBI

It is a Ransomware-as-a-Service variant that accounts for a third of all ransomware incidents as per IBM’s Security X-Force. Sodinokibi spreads in several ways, including through unpatched VPNs, exploit kits, remote desktop protocols (RDPs) and spam mail. This variant may also be referred to as Sodin or REvil.

2 SNAKE

Gaining notoriety by wreaking havoc in the industrial sector, SNAKE ransomware is expected to create severe trouble in the coming years.

Targeting industry control systems, SNAKE disables ICS processes, freezes VMs and steals admin credentials to further spread and encrypt files across the network.

3 RYUK

It is a popular variant used in targeted attacks against healthcare organizations (such as the attack against United Health Services). Ryuk is commonly spread by other malware (e.g., Trickbot) or through email phishing attacks and exploit kits.

4 PHOBOS

Another RaaS variant, Phobos has been observed in attacks against SMBs, where cybercriminals gain unauthorized access to a network via unprotected RDP ports. Phobos shows similarities to CrySiS and Dharma ransomware.

NEW ATTACKS AND ADVANCES IN RANSOMWARE A GLIMPSE INTO THE LATEST CYBERCRIMINAL TRENDS

Updates & Promotions – Teaser Key Codes, Localized Versioning and More

Ransomware merchants are constantly trying to up their game to overcome security and backup defenses.

Let’s take a look at some of the latest advances in ransomware:

Experts have long touted backup (collectively, “backup” may refer to dedicated backups, replicas or snapshots) as the best defense against ransomware. Unfortunately, cybercriminals know this too, and have focused resources and development on new variants designed to overcome backup defenses. The latest ransomware innovations have built phased attacks to defeat backups in a number of ways, typically by building in periods for gestation and / or dormancy.

1 GESTATION

Modern ransomware does not detonate and encrypt immediately. The gestation period is designed to give the malware time to spread as widely as possible from machine to machine, typically by using the permissions of the systems it has infected.

2 DELETION

Once the ransomware has spread as far as it can, the next phase involves deleting network-accessible backups. Backup files have known signatures that make them easy to target and encrypt. In addition to targeting file signatures, ransomware uses APIs published by backup vendors to delete backups autonomously.

3 DORMANCY

Once spread, ransomware typically does not encrypt or delete backups immediately. With access to data, threat actors may begin extracting data to later use for extortion. The malware may lie dormant for a month, three months, six months or even longer before detonation.

Dormancy poses a challenge because malware is backed up along with legitimate data, creating an attack loop. When infected backups are used in recovery, the malware remains present and will detonate again.

Data exfiltration and the theft of usernames, passwords, personally identifiable information (PII), financial records and more is becoming increasingly popular among ransomware attackers. As per a recent report, roughly 50% of all ransomware cases involved data exfiltration, with the goal of increasing leverage against victims to pay ransom demands. Should the affected organization attempt to recover and leave the ransom unpaid, attackers threaten to release data publicly or post data for sale on the dark web.

Of all ransomware attacks, 65% are delivered via phishing. As threat actors engage social engineering to gain access to corporate systems, techniques such as business email compromise (BEC) and account takeover (ATO) attacks carry a significant risk of delivering a ransomware payload. Cybercriminals are tapping into social media sites and staging password or security alerts to prompt users to click. Some of the most common “in-the-wild” phishing subject lines are:

  • Microsoft: Abnormal login activity on Microsoft account
  • Chase: Stimulus Funds
  • Zoom: Restriction Notice Alert
  • HR: Vacation Policy Update
  • ATTENTION: Security Violation
  • Earn money working from home

A variety of subjects based on social media trends and current events along with the impersonation of familiar entities, such as your company or bank, are being used to take advantage of heightened stress, distraction, urgency and fear in users. These attacks are increasingly effective because they have users reacting before thinking logically about the legitimacy of the email.

TOOLS OF THE RANSOMWARE TRADE AN INSIGHT INTO HOW EASY IT IS TO BE A CYBERCRIMINAL

Tips & Tricks To Get Started – Ransomware Resources

BITCOIN ALLOWS HACKERS TO REMAIN ANONYMOUS

46%

Nearly half (46%) of all businesses globally have faced a cybersecurity threat in the last 12 months.

Resources for launching do-it-yourself ransomware campaigns are plentiful. The financial success of these attacks can, in part, be credited to the pseudonymous nature of processing ransom payments via cryptocurrency such as Bitcoin. Bitcoin is a highly liquid, decentralized, peer-to-peer digital currency, which makes it attractive for cybercriminals since payments are processed electronically without the need for a third-party intermediary. A charge processor, vendor or bank is not needed for verification of payment since every transaction is documented in a blockchain.

The blockchain’s ledger is distributed across potentially thousands of machines. In the world of ransomware, Bitcoin has become a widely accepted currency. More than 30 merchant services help manage Bitcoin transactions including:

A Beginner's Guide to Ransomware

PAST AND PRESENT:

Some of the Major Software That Has Contributed to Ransomware Include:

  • Cryptolocker
  • TorrentLocker
  • CryptoWall
  • Angler (Exploit Kit)
  • CBT-Locker
  • TeslaCrypt
  • Locky Unbreakable EncryptioAES
  • RSA
  • Tor
  • Curve ECC Network to C&C Server

Common Vulnerabilities and Exposures (CVEs):

Researchers at RiskSense identified 223 vulnerabilities associated with 123 ransomware families in 2021. This is an alarming increase from the 2019 findings of 57 CVEs tied to 19 ransomware families and indicates a shift towards attackers targeting data-rich applications such as SaaS. These included:

  • WordPress
  • Apache Struts
  • Java
  • PHP
  • Drupal
  • ASP.net
  • Jenkins
  • MySQL
  • OpenStack
  • TomCat
  • ElasticSearch
  • OpenShift
  • JBoss
  • Nomad

RANSOM MESSAGE USED BY THE RYUK FAMILY OF RANSOMWARE.

A Beginner's Guide to Ransomware

BIG MONEY HACKS VICTIM STORIES FROM COMPANIES THAT PAID UP

Ransomware turns to big targets, aiming to hit where it hurts – and cybercriminals are cashing in.

Recent Hacks:

1 GRUBMAN SHIRE MEISELAS & SACKS

The New York-based entertainment and media law firm suffered an attack by REvil (Sodinokibi) ransomware. Perpetrators stole 756GB of data deemed “valuable” before encrypting the rest. Initial ransom demands were $21 million, and when it was turned down, the attackers published data relating to Lady Gaga online. The law firm refused an increased demand of $42M and the remainder of the stolen data was put up for auction on the dark web.

2 WESTECH INTERNATIONAL

In early June, U.S. defense subcontractor Westech suffered a ransomware attack by “Russian-speaking” threat actors using the Maze ransomware variant. Sensitive data, including employee emails and payroll information was published, as data was again stolen before the encryption detonated. Based on the information published, it is possible military-related classified data may have also been compromised.

3 DUESSELDORF UNIVERSITY HOSPITAL

In September, a woman died en route to the emergency room after her ambulance was forced to reroute when the closest hospital to the accident, The University Hospital of Dusseldorf, was shut down by a ransomware attack. More than 30 internal servers were disabled by the ransomware, forcing the hospital to halt all services, including the Emergency Room. This marked the first-ever reported human death due to ransomware and was investigated as a murder case by German authorities.

4 CITY OF FLORENCE, ALABAMA

Ransomware attackers DoppelPaymer gained unauthorized access to the city’s IT network with the help of compromised credentials belonging to the city manager. They shut down the city’s email system and simultaneously compromised data stored in the municipality’s database. The city had to cough up $291,000 in Bitcoin to retrieve access to the email system and recover lost data.

Startups and small companies are most vulnerable to cybersecuritythreats in the supply chain. Adversaries aren’t going after a Lockheed Martin at the top, prime level. They’re going after the small businesses [that a larger organization relies on] that are the most vulnerable.

Katie Arrington, CISO

Office of the Undersecretary of Defense for Acquisition and Sustainment.

ADVANCES AGAINST RANSOMWARE

5 Ways a Good Backup and BCDR Solution Helps Defeat Ransomware

1 PROTECT

An effective BCDR solution provides both local and cloud data protection options, providing users with, at minimum, 3-2-1 data protection; 3 copies of data, 2 different media formats and 1 copy off-site. Replication to removable media, such as disk, helps create an air gap from the production network.

3 TEST

Look for features such as Recovery Assurance. Recovery Assurance automates the testing of backups – both locally and in the cloud. Customizable boot orders, machine reconfiguration and application-level scripts provide testing for both simple and complex environments and validate applications and services can be successfully recovered. Compliance tracking ensures defined RTOs and RPOs are being met.

2 SECURE

Impede hacker efforts by transitioning from a malware-susceptible Windows backup software to a purpose-built, hardened Linux backup appliance.

Hardening of the Linux kernel provides more resilience against malware and ransomware attacks.

4 DETECT

Using adaptive and predictive analytics against backup data, a good solution is constantly on the search for ransomware threat conditions.

Algorithms use machine learning to forecast threat conditions and proactive alerts are sent when ransomware conditions are detected.

5 RECOVER

Features such as Instant Recovery enable users to spin up tested, certified backup data on-premises in minutes, minimizing the impact of an attack.

This provides a virtual forcefield around the platform that ensures the digital assets of customers are protected.

COLLABORATE TO FIGHT AGAINST RANSOMWARE

Equipped with game-changing defensive mechanisms for its users, a good backup and BCDR solution can help transform a business by preventing successful ransomware attacks. However, taking this path alone might be quite overwhelming since it will require a lot of additional time and effort. That’s why, it is preferable to work with a specialist like us who can take the heavy load off your shoulders.

Feel free to contact us for a consultation.

Sources

1. Helpnetsecurity/2020/11/20/faced-ransomware-attack

2. Helpnetsecurity/2021/04/16/human-attack-surface/

3. Securityboulevard/ransomware-trends-you-need-to-know-in-2021

4. IDA/Ransomware statistics that you need to see in 2020

5. Techrepublic/watch-out-for-these-subject-lines-in-email-phishing-attacks

6. Prnewswire/top-cyber-security-experts-report

7. Wall-street.com/an-untraceable-currency-bitcoin-privacy-concerns-2

8. Darkreading/ransomware-attackers-set-their-sights-on-saas

9. Research.checkpoint/ryuk-ransomware-targeted-campaign-break

10. Securityweekly/revil-prominent-law-firm

11. Securityboulevard/westech-international-hacked-by-maze-ransomware/

12. SecurityWeekly/first-fatality-caused-ransomware-attack/

13. Crn/the-11-biggest-ransomware-attacks-of-2020-so-far-/3

14. Fcw/dod-cyber-cmmc-rules-williams

Security Awareness Training

Your Small Business’ Best Investment

Empowering Employees to be Security Savvy Stops Cyberattacks and Saves Money

Employees are at the heart of your company’s security. They are the last line of defense against cyberattacks and the first ones to notice when something unusual is happening at work. This makes them your most valuable security asset.

However, they can also be a vulnerability. When an employee makes a mistake, like mishandling data, clicking on a malicious link or giving a cybercriminal their password, they are opening the doors to expensive compliance failures and security nightmares for your organization.

The everyday choices employees make have a tremendous impact on your company’s security and success. That’s why it’s critical to educate them on the risks they might face and how to practice good cyber hygiene to keep your business compliant and safe from cyberattacks.

How can you empower your team to fight cybercrime? Create a comprehensive security awareness training program that arms them with the knowledge they need to avoid pitfalls — your company is only secure when everyone knows they are part of the security team.

When you have a well-trained team, they can promptly flag a possible threat. The faster you identify a threat, the better your chances of minimizing the impact it has on your business. After all, security is about more than just technology; it’s about people and processes, too.

How do Employee Choices Impact Security?

Every time someone logs on to your company’s network, answers an email or takes work home, they’re taking an action that could have security repercussions whether they mean to or not. The actions that employees take can result in insider risk for your organization.

As companies become increasingly dependent on technology to get the job done, employees have more opportunities to take actions that could be harmful. Insider threats have nearly doubled in the past two years both in frequency and cost. While insider risk is not something that can be eliminated completely, it can be mitigated, and security awareness training is an affordable and effective way to do it.

Human error is responsible for an estimated 82% of security breaches.

Everyone Needs to be on Board to Build a Strong Security Culture

Companies with a strong security culture have a high level of security awareness — and that’s a powerful asset. However, many businesses face challenges in getting the entire leadership in their company on the same page about the vital role their security culture plays in both defense and compliance.

Taking a zero-trust approach to cybersecurity can safeguard your business by removing implicit trust and consistently authenticating each level of a digital interaction. Many companies have been implementing a zero-trust strategy to lower the risk of remote work and insider threats, limit third-party risk, manage cloud risk and improve their security culture.

60% of organizations will embrace zero trust as a starting point for fostering a strong security culture by 2025.

A major barrier to your organizational risk management might be a lack of strategic alignment. Often, a company’s leadership overlooks strategic risk management because they don’t realize the potential damage cyberattacks can cause.

Security Awareness Training has Concrete Benefits

Looking at some of the concrete benefits of security awareness training shows exactly how valuable the training is and why smart companies are making this small investment that gives them a big security advantage. Expecting your staff to study your policy and adopt security procedures on their own is unrealistic. The training you give your employees leads to adoption. They are informed and better understand risks post-training.

Immediately Expand Your Security Team Without Adding Headcount

Worryingly, 45% of respondents in a recent survey said that they are not responsible for maintaining security because they don’t work in the IT department. That’s a disaster waiting to happen. Security awareness training changes this mindset. When employees gain security savvy, they realize that maintaining security to fight back against cybercrime is everyone’s job.

By partnering with us, you can easily access the security expertise you need to mitigate today’s sophisticated attacks without having to hire in-house.

Maintain Compliance with National, Local, Regional and Industry-Specific Regulations

Data privacy and cybersecurity regulations are tightening in many industries, and the price of a compliance failure is high. Security awareness training is required under many data privacy and data handling statutes. Implementing this training equips your employees to identify potential risks and defend your organization from cyberattacks. By fostering a strong cybersecurity culture across your organization, you can not only minimize insider attacks but also ensure security compliance.

Lower Security Expenses, Like the Cost of Phishing

Phishing is expensive whether the attack is successful or not. If it hits, you’ve got a potentially devastating incident on your hands. If it doesn’t, the matter still requires investigation. The cost of just dealing with the headache of phishing altogether can be devastating for your business. According to the DBIR 2022 report, 82% of breaches involved phishing or social attacks.

Leading Companies Rely on Security Awareness Training to Prevent Cyberattack Disasters

Security awareness training gives companies an edge against cyberattacks by boosting cyber resilience, making them less likely to be crippled by a cyberattack. About 84% of leading organizations cite security awareness training as a key building block of cyber resilience.

Train Employees to Resist Your Top Data Security Threat: Phishing

The biggest security risk that any organization faces today is phishing. It is the number one cause of a data breach. Phishing is also the risk that employees encounter the most — and fail to detect the most as well — often opening their organization up to dangerous cyberattacks like ransomware.

Employees and Phishing are a Disastrous Combination

58% – 58% of employees have clicked on at least one malicious URL on their mobile devices.6

16% – 16% of employees have downloaded malware or riskware apps on their mobile devices.

75% – More than 75% of supply chain attacks include three steps — phishing is one among them.

Cybercriminals are adept at using hard-to-detect ways, like impersonating a well-known brand, to fool their targets into falling for a phishing message. They are so good with these that your employees cannot usually spot a sophisticated phishing email without training.

Help Employees Avoid Malicious Attachments

Inexperienced employees often fall for phishing lures that entice them to click on malicious links, download suspicious files and email attachments, enter their credentials on a fake site and even correspond with cybercriminals. That’s a huge problem for businesses like yours.

If a malicious file is attached as a Microsoft Office document, it can be even harder for your employees to understand whether the email is legit or not. Security awareness training teaches employees how to identify suspicious attachments carrying malware that masquerade as routine files.

Empowered Employees Protect Companies From Today’s Most Dangerous Threats

A new cyberattack is launched every 39 seconds.9 That’s bad news for

organizations that aren’t prepared since only 16% of employees are able to

recognize sophisticated threats without security awareness training.10

Ransomware and Malware

Ransomware attacks have surged by 13% to 25% in one year, which is more than the past five years combined.11 However, ransomware isn’t the only malicious software on the block. Payment skimmers, cryptominers, Trojans and other nasty malware types can also cause damage to your business. According to a recent study, 70% of malware-related breaches involved ransomware, one of the most common tactics used by capable threat actors in system intrusions and supply chain attacks, irrespective of the size of your business.

How security awareness training helps prevent this

Employees encounter these threats every day but are unlikely to detect them without training — if your employees are adequately trained, aware of threat patterns and know which actions lead to a threat, they will behave responsibly.

Account Takeover

A bad actor taking over a user account is a nightmare for every small business, especially if the bad guys hijack an account that contains sensitive customer data. Account takeover (ATO) fraud takes a number of forms, including phishing attacks, phone scams or credential compromises.

Business Email Compromise

In a common business email compromise (BEC) scenario, bad actors target a victim and pose as a company the victim’s organization would do business with to fraudulently obtain money or sensitive data. BEC also endangers a company’s reputation and relationships, with employees encountering this hazard daily. How security awareness training helps prevent this Effective training keeps your users aware of the signs of an ATO as well as the dangers of ATO risks, like phishing and credential compromise, and prevents these attacks from landing.

How security awareness training helps prevent this

Employees who have strong cybersecurity awareness are more likely to be suspicious when they experience unusual behavior when communicating with third-party service providers or suppliers.

Brand Impersonation and Spoofing

Bad actors will often use cloned or “spoofed” legitimate email messages from a well-known company like Microsoft to send phishing messages that trick unwary readers into taking an action to do things like correct a problem, collect a prize or snag a deal.

Data Breach

Employees are bombarded with malicious messages daily. However, getting tricked by a phishing email isn’t the only way employees can cause a data breach. Errors like sending someone the wrong file and other data handling mistakes are just as dangerous.

How security awareness training helps prevent this

When employees know what to look for, they can easily identify phishing emails and flag them. When your staff is unaware of spoofing emails, they may click on bad links, which could result in a data breach and downtime for your entire company.

How security awareness training helps prevent this

Security awareness training arms employees with knowledge that helps them resist threats like phishing while making them more thoughtful in general about how their actions and behaviors impact security.

Remote and Hybrid Workers

We are living in an era where 60% of knowledge workers are working remotely and 18% of them have no plans to go back to the office. The modern way of working remotely, coupled with greater use of public clouds, highly connected supply chains and cyber-physical systems, exposes your business to new and challenging attack surfaces.

Often, employees think they can get away with risky behavior like writing down passwords or opening suspicious emails when working remotely. Plus, cybercriminals know that remote workers are more likely to fall for phishing tricks and less likely to report a problem or ask for help if they don’t even know whom to ask.

Insider Risk

Every employee is an insider, and every employee brings a certain degree of risk to the table whether they intend to or not. A recent study reveals that negligent employees were responsible for 56% of insider threats, while malicious insiders caused 26% of attacks.

How security awareness training helps prevent this

A strong security culture is a major determinant in reducing your company’s overall risk, and security awareness is the foundation on which it is built. If security is top of mind for everyone, employees make fewer mistakes and notice suspicious behavior faster.

Start a Security Awareness Training Program and Reap Immediate Benefits

Don’t wait! Security awareness training is just what the doctor ordered to reduce risk and keep your business safe in today’s volatile threat landscape.

Contact us today to schedule a no-obligation consultation.

904-559-1600 ex 915

References:

1,14 The Cost of Insider Threats, 2022 | 2,6,7,8,11,12 DBIR, 2022

3,4 Gartner, 8 Cybersecurity Predictions for 2022-23 | 5 IBM Cyber resilient Organization Study, 2021

9 University of Maryland | 10 HIPAA Journal, 2021 | 13 Gartner, 7 Top Trends in Cybersecurity for 2022

6 Factors to Consider When Refreshing Your Technology Infrastructure

Introduction

Every business wants to achieve their goals and be successful. However, if you approach your technology infrastructure as an afterthought, you could be seriously restricting your organization’s potential.

Continuing to use outdated systems in today’s fast-paced digital age could quickly become a liability because:

  • It can harm your team’s productivity and interrupt their workflow
  • Technology that doesn’t integrate hinders overall business productivity and success
  • It can create vulnerabilities and lead to severe cyberattacks

A technology refresh allows a company to assess its IT infrastructure’s present condition and evaluate the benefits of trying something more effective. For a company’s long-term success, it’s ideal to examine its current IT infrastructure —hardware, software and other technology solutions — and see what other options are available that would better suit its needs.

Remember that your IT infrastructure is a critical component of your business. An up-to-date and high-quality IT infrastructure is a significant asset that allows you to do business and achieve your goals successfully.

You must continually fine-tune and enhance your IT infrastructure to keep up with changing consumer demands , fluctuating data volumes, increased network traffic, compliance requirements and other evolving facets of your organization. However, some barriers prevent many organizations from investing in their technology infrastructure, such as time, a lack of expertise, apprehension about change and financial constraints. When you work with an MSP, they will assist you in planning and implementing a technology refresh that suits your business.

Before you refresh your technology infrastructure, there are six factors you need to consider that will be discussed in the upcoming sections.

Factor #1: Strategy

Your IT infrastructure refresh strategy should be based on your long-term vision. If you try to rip up and replace platforms every year without a plan, it can eat up your time, drain your wallet and cause employee dissatisfaction.

You must have a clear understanding of where your company is now and where you want it to go in the future, and if any technology component is preventing you from growing, it’s time to replace or update it. Ensure that your key stakeholders are informed about the change ahead of time to avoid friction later on.

Your strategy must consider a few key indicators that show you whether your technology infrastructure is assisting you in realizing your vision. These indicators are:

Performance

Performance issues with the technologies you use regularly are a sign that your IT infrastructure is struggling to meet the demands placed on it. Only the best performing solutions should be included in your infrastructure.

Obsolescence

Your infrastructure may have outdated solutions that are no longer supported by updates, making it vulnerable to hackers or non-compliant with industry standards. The only way to keep your infrastructure from becoming obsolete is to upgrade.

Innovation

When a path-breaking technology emerges, incorporating it into your infrastructure can provide a significant competitive advantage. Any innovation that saves money in the long run, improves efficiency or increases productivity, should be enthusiastically embraced.

Security

The protection of your company against cyberthreats and disasters is far too important to overlook. Always make sure that your current technology infrastructure can also integrate your disaster recovery plan.

Factor #2: Goals

Setting goals requires you to make challenging decisions and confront the reality of your business and technology. Once you have a good idea of how you want your business to look in the future, you can create a roadmap and lay down weekly, monthly, quarterly, half-yearly or yearly goals. These goals serve as guideposts for you and your employees as you build your company.

Ask yourself the following questions before setting goals:

? What are you hoping to accomplish?

? Is your technology helping or hurting your goals?

? If your current technology is hindering your progress, what technologies can assist you in achieving your goals?

Goals are important because they translate your vision into measurable targets. It also helps employees understand exactly what they are expected to do and when they are expected to do it.

The Significance of Goals

Establishes a direction

Goals point the entire workforce and processes in the direction of the company’s vision.

Motivates employees

When employees know what is expected of them, they become more passionate and engaged in their work.

Set performance standards

Goals serve as yardsticks for determining an organization’s and its employees’ successes and failures.

Creates a foundation for budgeting

Allocating funds becomes easier once the path for the company’s development has been clearly defined.

Factor #3: Budget

Before you begin a technology refresh, you must first establish a budget. Asking the questions below is a good place to start:

? How much can you afford to spend on a technology refresh?

? Are you willing to go beyond your budget if necessary?

? How much can you go over budget?

Budgets are one of the many tools used by businesses to achieve their goals. Consider your technology refresh budgets as a way to align your IT infrastructure with your vision, rather than as a burden or unnecessary spending.

To create an optimal technology refresh budget for your company, follow these steps:

Evaluate the previous year’s refresh budget

Review your technology refresh budget from last year (if you have one) to see where you want to make changes. You probably don’t need to invest in certain technology components again if you spent money on them last year.

Understand your recurring expenses

Certain costs, such as cloud storage space and domain name renewal, will remain relatively constant from year to year. Examine if any recurring expenses haven’t been factored into previous budgeting decisions.

Make a list of your IT infrastructure’s components

Make a list of the IT components you have and the dates they were purchased or last updated. After you’ve finished your list, you can decide whether or not you need to refresh any components.

Communicate with employees

Employees with hands-on experience with IT components should be included in the budgetary decision-making process. They can notify you of areas that require investment and improvements.

Factor #4: Priorities

If you want to stay within your budget when planning a technology refresh, you must prioritize which technologies need updating.

First, determine which technologies are essential and which are optional. Technology refreshes/upgrades that your company can’t unleash its true potential without should be considered essential. Optional refreshes are “nice to have,” but they won’t make or break your ability to meet your goals.

Answering the following questions will help you identify essential technology:

Does the technology help you achieve your business goals and ultimately, your vision?

? How frequently do you use this technology?

? Is this technology critical to any cor e departments/business units?

? Is this technology reliant on any other technologies?

? Are there any other technologies that rely on this technology?

? What would the revenue loss be if this technology became obsolete?

? Will this technology’s disruption (downtime) result in any compliance violations?

? Will there be fines, lawsuits or other penalties imposed if this technology is not operational?

? Is this technology critical to your market share or reputation?

Technology refreshes are required for a company to progress and stay in business for a long time. Because technology is constantly changing, you will find that your company is falling behind and unable to keep up if you continue to use outdated technology components.

Factor #5: Integration

When upgrading or refreshing your technology infrastructure, keep in mind that technologies that integrate well can help you achieve your goals more effectively. No one wants to invest in various technologies to discover that none of it works together. Integration is critical for today’s technology infrastructures because the current technology landscape is growing at an unprecedented rate and businesses may have to depend on multiple vendors for different solutions.

Integration meets companies’ growing IT demands by making it easier to combine new solutions with the existing IT infrastructure. In fact, many manufacturers design their technology products with future integration in mind.

One of the primary reasons why businesses invest in integration is to optimize business processes. A centralized infrastructure improves the efficiency of information exchange and workflows, resulting in increased productivity. It also lowers operational costs, improves overall reaction time and ensures that information is readily available when required.

Eventually, it adds value for customers by improving the performance and quality of products and services. There are further benefits such as:

  • Enhancing the overall robustness of the infrastructure and making new technology implementation easier
  • Promoting data integration and security
  • Preventing operational and business process interruptions and failures
  • Better data governance and management

Factor #6: Review

After you’ve considered the five factors listed above and created the ideal architecture for your refresh, ask yourself whether it will genuinely accomplish what you need it to. This is where peer feedback from your community or a third-party audit from an MSP might help.

Include the following steps as part of your review:

Conduct a gap analysis

Examine how closely the outcomes adhere to the original goals. This gives you a good idea of where you should improve next time.

Determine stakeholder satisfaction

Decide how to proceed if core individuals are dissatisfied with the change.

Evaluate the schedule and budget

Will the refresh/upgrade be completed on time and under budge t? If not, figure out what needs to be reformed.

Determine possibilities for improvement

When you review with the mindset that nothing is perfect or complete, you will uncover areas that need improvement in the future.

Document the lessons learned

You must document every detail of a refresh/upgrade so that it can be reused when needed. It can help in report generation as well.

Partner for Success

Technology refresh is essential to keep up with rapid technological advancements and to gain a significant advantage over competitors. Get started on your path to refresh/upgrade success with an experienced partner like us. Knowing that the process is in expert hands gives you peace of mind and time to concentrate on growing your company.

Contact us to learn more about how we can assist you in implementing the optimal technology refresh strategy for you to increase your chances of success in today’s highly competitive business environment.

Call 904-559-1600 ex 915

What’s Lurking in Your Server Closet?

Cyber Monsters and Data Loss

Your minds start to wander as you glance over your backup logs, hoping that today isn’t the day the monsters come out to play.

Welcome to the life of small and medium-sized businesses (SMBs). On the surface calm, cool and collected – masters of their domain. Yet, deep down, they know something is lurking in their server closets and beyond — monsters that cause data loss, downtime and bleed businesses dry. Businesses everywhere are constantly looking over their shoulders thinking, “what if I’m next?”

Unfortunately, it isn’t a matter of if but when.

This eBook aims to shed light on the cyber monsters that cause data loss, wreak havoc in your production environment, delay strategic initiatives and trigger major business losses. This eBook also provides solutions on how to bring an end to their reign of terror, allowing businesses to concentrate on their growth without worry.

Limitations of Software-as-a-Service (SaaS)

Many are still clueless about the limitations of native data protection capabilities among SaaS providers.

The usage of SaaS applications like Microsoft 365 and Google Workspace has exploded in recent years thanks to rapid digital transformation. However, despite this rise in popularity, there are still misconceptions about who is responsible for data protection.

SaaS providers like Microsoft 365 follow the Shared Responsibility Model, where the customer is considered the “controller” of the data and the provider acts as the “processor” of that data.

As a processor, it is their responsibility to add, delete or modify data upon request. That means if any malicious activity or accidental deletion request is authenticated by valid credentials, the processor will consider the request legitimate. As a result, accidental, malicious or fraudulent deletions, in all cases, are the responsibility of the customer/controller.

Sadly, many IT pros and businesses are either unaware or ignore the obligations that come with the shared responsibility model, and operate under false assumptions. For instance, SaaS applications have native solutions to protect data. In reality, these built-in features are usually archival solutions. That means deleted data is stored for a limited period only and restoring it can be a slow, cumbersome nightmare.

The bottom line is operational and contractual responsibility for SaaS data lies firmly in the hands of the users and not the SaaS vendors. Ignoring this fact can severely damage your business.

Overlooked Compliance Matters

Fear of compliance matters and negligence prevents businesses from keeping a disaster recovery (DR) plan on par with required standards.

Granted, DR testing can be challenging — right from keeping up with environmental and personnel changes to having the required time and resources to properly test. However, not testing leaves businesses in the dark regarding the effectiveness of their DR plans. In effect, they are left with a “living dead” DR.

A well-crafted DR plan increases the possibility of a business recovering lost data and resuming normal operations with minimal disruptions. It’s a missed opportunity, not to mention a huge risk, to put in the hours and resources to create a disaster recovery plan only to then not test it. One of IT-based businesses’ greatest nightmares is realizing that their non-tested DR plan isn’t working as intended, and by the time this realization hits, they’re already in the middle of a disaster – which is exactly when the DR plan is supposed to work.

In sectors like healthcare, finance and government, strict compliance standards like HIPAA and FINRA demand a disaster recovery plan with a specified uptime. Accurate assessment of uptime and gauging whether defined recovery time objectives (RTOs) can be met is not possible without DR testing.

A lack of DR testing leads to long hours of unplanned downtime that can cost businesses huge amounts of money depending on the size of the business, not to mention penalties and legal fees that arise from non-compliance. With these kinds of losses, businesses might very well join the ranks of the walking dead.

Here are the Penalties and Legal Fines for Non-Compliance

What's Lurking in Your Server Closet?

Purge all Closet Monsters with Unified BCDR

Unified BCDR is your one-stop solution for slaying cyber closet monsters that take away the peace of mind of businesses. Protect data across physical data centers and virtual and SaaS applications with ransomware detection, self-healing backups, dark web monitoring and much more.

Easy SaaS Data Protection

A unified BCDR solution provides powerful, yet easy-to-use SaaS data protection for Microsoft 365, Google Workspace and Salesforce. It allows administrators and users to restore data and get back to work in just a few clicks, and it’s backed by enterprise security and compliance.

No DR Surprises

A unified BCDR solution with Recovery Assurance performs the highest level of application recovery testing with no IT time or effort. It fully restores applications, performs analytics, measures recovery time and recovery point, and identifies reasons why recoveries failed.

Detecting cyber monsters capable of causing data loss is far from simple and can drain a lot of your time and effort. As a result, it’s always best to work with an expert, such as ourselves, who can help you through the process. Please do not hesitate to contact us if you would like to schedule an appointment.

Your Biggest Cybersecurity Risk: Your Employees

Cybercriminals work round the clock to detect and exploit vulnerabilities in your business’ network for nefarious gains. The only way to counter these hackers is by deploying a robust cybersecurity posture that’s built using comprehensive security solutions. However, while you’re caught up doing this, there is a possibility you may overlook mitigating the weakest link in your fight against cybercriminals, your employees.

[Read more…] about Your Biggest Cybersecurity Risk: Your Employees

12 Password Best Practices

With the business world heavily reliant on digitalization in this day and age, the use of technology in your organization is unavoidable. Although technology can undeniably give your business an advantage in increasingly competitive markets, there are many troublesome areas to keep an eye on. This is why interest in cybersecurity has risen in recent years.

Password protection is the best place to start if you want to ramp up your cybersecurity. Setting a password to secure an entity’s data is called password protection. Only those with passwords can access information or accounts once data is password-protected. However, because of the frequent use of passwords, people tend to overlook their significance and make careless mistakes, which could lead to breaches in security. This makes it imperative for businesses to devise strategies to educate employees about best practices when using passwords.

6 Password “Don’ts”

Protect the confidentiality of your passwords by following these six password “don’ts”:

1. Don’t write passwords on sticky notes
Although you may feel that writing down passwords improves password protection and makes it more difficult for someone to steal your passwords online, it can make it easier for someone to steal your passwords locally.

2. Don’t save passwords to your browser
This is because web browsers are terrible at protecting passwords and other sensitive information like your name and credit card number. Web browsers can easily be compromised and a wide range of malware, browser extensions and software can extract sensitive data from them.

3. Don’t iterate your password (for example, PowerWalker1 to PowerWalker2)
Although this is a common practice among digital users, it is unlikely to protect against sophisticated cyberthreats. Hackers have become far too intelligent and can crack iterated passwords in the blink of an eye.

4. Don’t use the same password across multiple accounts
If you do so, you are handing cybercriminals a golden opportunity to exploit all your accounts.

5. Don’t capitalize the first letter of your password to meet the “one capitalized letter” requirement
Out of habit, most of us tend to capitalize the first letter of our passwords to conform with the “one capitalized letter” requirement. However, hackers are aware of this, making it easy for them to guess the capitalized letter’s position.

6. Don’t use “!” to conform with the symbol requirement
However, if you must use it, don’t place it at the end of your password. Placing it anywhere else in the sequence makes your password more secure.

6 Passwords “Do’s”

Protect the confidentiality of your passwords by following these six password “do’s”:

1. Create long, phrase-based passwords that exchange letters for numbers and symbols
For instance, if you choose “Honey, I shrunk the kids,” write it as “h0ney1$hrunkth3k!d$.” This makes your password harder for hackers to crack.

2. Change critical passwords every three months
Passwords protecting sensitive data must be handled with caution because there is a lot at stake if they are compromised. If you use a password for a long time, hackers may have enough time to crack it. Therefore, make sure you change your critical passwords every three months.

3. Change less critical passwords every six months
This necessitates determining which password is crucial and which is not. In any case, regardless of their criticality, changing your passwords every few months is a good practice.

4. Use multifactor authentication
It’s your responsibility to do everything in your power to keep nefarious cybercriminals at bay. One of the best approaches is to barricade them with multiple layers of authentication.

5. Always use passwords that are longer than eight characters and include numbers, letters and symbols
The more complicated things are for hackers, the better.

6. Use a password manager
A password manager can relieve the burden of remembering a long list of passwords, freeing up time for more productive tasks. Need a password manager? We can help. Call today for a complimentary consultation 904-559-1600 x 915

Adhering to password best practices requires constant vigilance and effort on your part. As a result, it is best to work with an expert managed service provider (MSP) like us who can help you boost your security and put your mind at ease. Contact us for a no-obligation consultation.

Balancing a Proactive and Reactive Approach to Cyber Incidents

A cyber incident is a type of security event that can harm a business like yours. Ranging from data breaches and system failures to malware attacks and phishing scams, these incidents can hinder productivity, revenue growth, and customer satisfaction.

In most cases, a cyber incident will result in data loss or downtime. This can include loss of confidential information, customer data or business records. In some cases, a cyber incident can also cause business interruption or financial loss. Download our Infographic on Cybersecurity and Business to learn more.

We can all agree that no one wants their business to be hacked. A single cyberattack can rob you of your time, money and peace of mind. In addition to getting systems operational and data restored, you have to let all affected parties know that their data may have been compromised. This can be a difficult situation to navigate for anyone, but it doesn’t have to be the end of the world.

In this blog, we’ll provide you with proactive and reactive approaches to tackle an attack, cope with the aftermath of a hack and prevent future incidents.

Balancing a Proactive and Reactive Approach to Cyber Incidents

Proactive Approach to Cyber Incidents

By taking these proactive steps, you can help protect your business from the devastating consequences of a cyberattack:

Routinely update your passwords

It’s critical to update your passwords regularly to help keep your accounts safe. By updating your passwords every six months, you can help protect your accounts from being hacked.

Here are a few tips on how to create a strong password:

  • Use a mix of upper and lowercase letters, numbers and symbols
  • Avoid using easily guessable words like your name or birthdate
  • Use a different password for each account
  • Don’t reuse passwords

Use a virtual private network (VPN)

A virtual private network encrypts your company’s data and gives you complete control over who has access to it. This can aid in the prevention of data breaches and the protection of your company’s information. However, make sure to select a reputable provider offering robust security features.

Conduct regular security awareness training

As a responsible business executive, you must ensure that your company’s security awareness training program is comprehensive, engaging and adaptable to new threats. In today’s digital age, this is critical to protect your business.

Run regular phishing tests

Phishing is a type of cyberattack that employs deceitful techniques to try and obtain sensitive information from users or cause them to download malicious software. Phishing attacks can be highly sophisticated and challenging to detect, which is why it is essential to periodically test your employees to assess their vulnerability to this type of attack.

Reset access controls regularly

It is crucial to regularly reset access controls to prevent unauthorized access to protected resources. This helps to ensure that only authorized individuals have access to sensitive information. Resetting access controls can be done manually or with automated tools.

Use multifactor authentication (MFA)

Multifactor authentication is a security measure that requires your employees to provide more than one form of identification when accessing data, reducing the likelihood of unauthorized data access. This can include something they know (like a password), something they have (like a security token) or something they are (like a fingerprint).

Before we move on, take note of the cybersecurity training topics recommended by the Small Business Administration (SBA) for all small businesses:

  • Spotting a phishing email
  • Using good browsing practices
  • Avoiding suspicious downloads
  • Creating strong passwords
  • Protecting sensitive customer and vendor information
  • Maintaining good cyber hygiene

Reactive Approach to Cyber Incidents

The National Institute of Standards and Technology’s (NIST) reactive incident response framework covers the following five phases:

Identify

To develop an effective incident response plan, security risks must be identified. This includes, among other things, threats to your technology systems, data and operations. Understanding these risks allows you to respond to incidents more effectively and reduce the impact of security breaches.

Protect

To protect your company, you need to develop and implement appropriate safeguards. Security measures to guard against threats and steps to ensure the continuity of essential services in the event of an incident are examples of safeguards.

Detect

Detecting anomalies, such as unusual network activity or unauthorized access to sensitive data, are needed to limit the damage and get your systems back up and running faster following an incident.

Respond

A plan to respond to detected cyber incidents is critical. This strategy should include breach containment, investigation and resolution strategies.

Recover

To minimize disruption, you must have a plan to resume normal business operations as soon as possible after an incident.

Balancing a Proactive and Reactive Approach to Cyber Incidents

Implementing the above proactive and reactive steps requires time, effort and skillsets that are possibly beyond what you can commit to at the moment. However, you can still accomplish this by collaborating with TruTechnology as your IT service provider. Our experience and expertise may be just what you need. Feel free to reach out to schedule a no obligation complimentary technology consultation here.

Also, to walk you through incident prevention best practices, we have created a checklist titled “Cyber Incident Prevention Best Practices for Small Businesses,” which you can download by clicking here.

5 Hidden Costs of Not Having the Right IT Support

When you don’t have the right IT support, it can cost you — and not just in dollars.

1. UNEXPECTED AND UNPREDICTABLE BILLS
A lack of planning on your IT services company’s part could mean you end up footing big, unexpected bills for issues that should have been dealt with before they ever became major problems.

2. LOST MONEY AND REPUTATION
Hackers are getting smarter every day, and if your business IT services company isn’t keeping up, it leaves you vulnerable to data breaches, data loss, and ransomware, which could cost you much of your money, and even your reputation.

3. LOWER PRODUCTIVITY
Not having the right support could mean you constantly face issues throughout the day, like slowness, app crashes, and the need to regularly reboot computers, which is a major drag on productivity.

4. SQUANDERED PERSONAL TIME
An IT provider who is not planning ahead could leave you holding the bag, spending nights and weekends dealing with problems on your own as business time cuts into personal time.

5. LOST GROWTH OPPORTUNITIES
Ultimately, your technology should help your business grow, and without a team to align your technology with your business goals, you could be missing out on huge growth opportunities.

The IT services company you choose to work with your business is a defining factor in whether your business succeeds or fails. Don’t risk choosing a business IT services company that will set you up for a loss. At TruTechnology, we’re here for you 24/7/365 — and we’ll ensure your business’s success on a daily basis.

TruTechnology is proud of our 99.97% customer satisfaction rating

“Our trouble tickets have significantly decreased compared to the previous IT company we had for years. But the thing I’ve noticed that really separates TruTech [apart from the rest] is that they really care, plain and simple.”
— Gregg Cohen, CEO, JWB Real Estate Capita

What a Top Notch IT Provider Can offer your Business

There are several reasons why small and medium-sized businesses (SMBs) like yours can sometimes struggle to meet all your technology needs in one location. One reason is that small businesses often lack the resources of large corporations, so making the most of what you have is essential. Another reason is that small and medium-sized businesses suffer the most from sudden personnel losses and extended leaves of absence.

[Read more…] about What a Top Notch IT Provider Can offer your Business

How to Protect Your Business From a Ransomware Attack

Jimerson Birr, a business law firm with an overarching mission of adding value with every engagement, has assembled a dynamic panel to offer resources and tools to companies for preventing and responding to ransomware attacks.

A successful ransomware attack can cost a business hundreds of thousands of dollars or more in cash, plus weeks of lost productivity and temporary or permanent loss of records, information, and long-term customer trust.

The “Protecting Your Business from a Ransomware Attack” Seminar includes the perspectives of cybercrime forensics expert Toni Chrabot, retired FBI Special Agent in Charge and Risk Confidence Group’s CEO, Doug Lowenthal, CEO of TruTechnology, a NetGain Technologies Company, cyber insurance specialist Vicky Zelen, CEO of Zelen Risk Solutions, Trooper Adam Johnson of the Florida Bureau of Criminal Investigations and Intelligence and Florida Highway Patrol Special Services Command, and Lynne Rhode, Esq., Special Counsel for Jimerson Birr. The panel is moderated by the firm’s managing partner Charles B. Jimerson, Esq.

Tony Haskew

Project Engineer

Tony Haskew has 15+ years of experience in the IT field. He started working as a web developer in the 90’s and over the years migrated into the administration of systems and infrastructures of companies. 

Tony enjoys working on new technology and finding new ways to address old issues in the management of IT systems.

Outside of work, Tony is a 3D printing enthusiast, commission painter, and enjoys spending time with his family.