Showing posts with label internet security. Show all posts
Showing posts with label internet security. Show all posts

Tuesday, June 15, 2021

Why the world needs Zero Trust Security for email

Hackers are always working on new ways to infiltrate a network. As they continue to get more and more sophisticated, even the White House can’t always detect them. IT security teams need to consider new frameworks to protect their networks.


The healthcare industry is a notorious target for cyberattacks, and traditional cybersecurity measures simply aren’t effective anymore. Zero Trust Security for email may well be the answer.


What is Zero Trust


Zero Trust is a security framework that assumes that every person or device requesting access to a network is a potential threat. It is an emergent security strategy requiring a user validate their identity multiple times before gaining access, and even then, the user doesn’t get full access to the network.

According to TechBeacon, COVID-19 is accelerating the adoption of the model since users are more likely to access sensitive information remotely.

No single technology is associated with Zero Trust. Instead, it’s a comprehensive framework that incorporates several different principles and technologies.

Here are the guiding principles behind Zero Trust Security:
  • Nothing and no one is automatically trusted. Attackers could come from either inside or outside of a network.
  • Least privilege access. Users only get as much access as they need, thereby limiting exposure to sensitive data.
  • Microsegmentation. Security perimeters are broken up into small zones to maintain separate access for separate parts of the network.
  • Multi-factor authentication (MFA). A core value of Zero Trust Security, MFA means more than one piece of evidence is required to authenticate a user.
  • Strict controls on device access. Zero Trust Security systems monitor how many different devices are trying to access a network and ensure every device is authorized.
  • Real-time activity monitoring. It is critical to spot abnormalities in behavior in real time in order to shut down a possible hacking attempt immediately.



Why we need Zero Trust for email


According to Coveware’s most recent Q4 2020 report, email phishing overtook remote desk protocol (RDP) compromises as the dominant attack vector last year. Deloitte’s research also finds that 91% of all cyberattacks begin with a phishing email. Even the recent massive Colonial Pipeline ransomware attack was most likely caused by an employee falling for a phishing email.

These days, bad actors are using American tech companies to send malicious emails, such as Amazon SES, Sendinblue, and Mailgun. This puts malware out of reach of the early warning system run by the National Security Agency (NSA) because it is prohibited by law from conducting surveillance inside the United States.

In other words, we can no longer trust email sent from American hosting and infrastructure companies.

Nation state threat actors are sending sophisticated email phishing campaigns that pass the following security checks:
  • DNS Real-time Blackhole List (DNSRBL). This frontline defense system checks whether a sending IP address is on a blacklist of IP addresses reputed to send malicious email.
  • Sender Policy Framework (SPF). An email authentication method that indicates that a mail server is authorized to send email for your domain.
  • DomainKeys Identified Mail (DKIM). Another email authentication system that uses digital signatures to allow the receiver to check that an email was indeed authorized by the owner of that domain.
  • Domain-based Message Authentication, Reporting and Conformance (DMARC). Yet another authentication protocol that leverages SPF and DKIM to determine the authenticity of an email message.
  • DomainAge. Newly registered domain names sending email are a red flag and quarantined.

Malicious emails pass these checks because the bad actors registered new email domains, sat on them for years so they did not raise any red flags, took the time to configure and maintain their accounts correctly, and then hid behind American companies inaccessible to the NSA.

Therefore, in order to keep up in the cybersecurity arms race, what’s needed is a Zero Trust Security framework for email.



How Zero Trust for email can work


As part of a Zero Trust framework for email, MFA can be reimagined as an authentication method not for a user, but for a machine.

Let’s say a mail server is attempting to send you an email. During the SMTP conversation between mail servers, the sender claims it is a part of Amazon’s SES platform, and your MX record host verifies that this is true because it passes the security checks outlined above.

However, with a Zero Trust for email paradigm, those checks aren’t good enough. One more piece of evidence is required to authenticate that the email is truly legitimate and not a phishing attack cloaked under the guise of Amazon’s email platform.

I believe this new piece of evidence should be unique to each customer and be updated based on usage over time. In other words, it must be very difficult for bad actors to impersonate.

This new approach will yield a unique form of MFA, an additional piece of evidence required to authenticate an email. It would be especially useful for healthcare providers that not only need extra security to send HIPAA compliant email, but also must block incoming cyberattacks.


15% Off Medical Practice Supplies


VIEW ALL



Manual Prescription Pad (Large - Yellow)


Manual Prescription Pad (Large - Pink)

Manual Prescription Pads (Bright Orange)

Manual Prescription Pads (Light Pink)

Manual Prescription Pads (Light Yellow)

Manual Prescription Pad (Large - Blue)

Manual Prescription Pad (Large - White)


VIEW ALL

Wednesday, March 7, 2018

To VPN or Not to VPN: Are Online Businesses Safe Enough?

You’ve been planning on this product launch for quite a long time. It’s expected to catapult your online business to well-deserved stardom, giving you significant hegemony in that particular niche. A titillating anticipation is in the air!


Have you strategized enough? Indeed.


Have you calculated the probable consumer reaction curves? Of course.


Most of all, are you confident about the unique value and originality of your product? Definitely.


Nothing can hold you back now.


And look where you started from. Such humble beginnings! It is remarkable how you, with the help of others, have taken this product from infancy to such admirable heights. When you first dipped your feet into the vast ocean of e-commerce, there was a massive possibility of you being obliterated by the huge waves of other wildly popular, longstanding products. But you stood your ground, and kept moving. Slowly and steadily, you gathered enough momentum to become a huge online business wave yourself.


Just one step is left between you and the gold-colored, success horizon: your product launch.


However, there’s an immediate cause for alarm, threatening to topple you over.


What you had been preparing to launch tomorrow is replicated and produced by your greatest rival, just the night before. You’re stunned to see YOUR creation selling like wildfire with the tag of your rival brand.


Now, it’s out there – your wonderful idea, swept away from your grasp because you had not considered or undertaken ONE highly important measure: setting up a virtual private network (VPN).


Could it have saved your future prospects? Or, to flip the coin, could your online business have survived without it?


Should one go for a VPN or not? Let’s find out.

Security:



Suppose you go to a region where the cold temperature drops many degrees below zero. Do you dare step out naked in the bone-chilling winds? No. You’d think of it as mere foolishness, wouldn’t you? The same goes for the unfathomable and unpredictable plane of the internet. You shouldn’t venture out exposed in any way. Malevolent entities are out there, eagerly searching for any unprotected slot. If they happen to find one, they will undeniably pounce and take advantage of you, without you even knowing it. This is how your rival company got hold of your idea, by surreptitiously eyeing your e-activity.


A virtual private network provides just enough amount of protective covering, encrypting all of your online business transactions and vital communications from prying eyes. With a VPN, no one will be able to hack into or release any dirty malware to your e-accounts. It’s a sure security measure which you should not miss out on.

Anonymity:



Imagine the internet as a dangerous ocean, with an unmeasurable depth. You need to get across it. How do you do it? With a boat, of course. This boat, which takes you over the waves, is your IP address. If someone else takes control of this boat, then you’re absolutely done for. So it is crucial that you protect your little boat at any cost, so that you’re able to safely cross the ocean.


Putting the analogy aside, whenever you access the internet over public networks (think coffee shops, hotels, airports), you’re putting your whole e-business at risk, because your ISP and other interested entities can see and sinisterly maneuver your IP address. However, a virtual private network can definitely lend you that desired veil of anonymity. By turning it on, you can freely roam the internet with a masked IP, and no one will be able to tell what you’re doing or see your private data.

Accessibility:



Sometimes, you get stuck at one point, and need different research to inspire you. But that valuable piece of information has been blocked by third parties, and you’re unable to access it online. How do you bypass the ban?


In another instance, you’re compelled to travel to a distant country in order to plant the seed of your e-business there. Expansion is what you’re hoping to get, yet foreign networks don’t respond to you the way you would like. They restrict your access, and even decide to keep an eye on you. How do you get around this unwanted attention, and connect to your native network?


One more: your e-business is slightly tricky to manage, and requires your employees to be spread out geographically. How do they safely stay in touch with one another, communicating on a private, central platform?


With a VPN, of course, which sets you up over a tunneled server, giving you secure credentials to surf about wherever you want, however you want.

Affordability:



I know what you’re thinking: this breathtakingly amazing service must come at a breathtaking costly price. But to answer your quite relevant apprehension, no, it doesn’t. A virtual private network is surprisingly easy to install, and quite affordable too. Just subscribe to a reputable VPN provider, configure the service on your device, turn it on over a high-speed connection like Spectrum Internet, and you’re protected! It’s that convenient, and at a measly price of around ten dollars per month.


So what do you think?


After going through all of the benefits of a VPN, do you think it is a worthwhile measure to protect your online business with? Or do you wish to pass it over and stay exposed?


15% Off All Business Cards

VIEW ALL

How Facebook Marketers Can Manage Privacy to Protect Business Security

If it happened to Mark Zuckerberg, it can happen to anyone.


In June of 2016, hackers briefly took control of Zuckerberg’s personal Twitter and Pinterest accounts. Using a password they’d obtained from a LinkedIn security breach – which Zuckerberg had re-used on the other networks – they gained access, and then posted messages boasting of their success.


Facebook itself has also fallen victim to cybercrime. From 2013 to 2015 the social media giant transferred tens of millions of dollars into bank accounts belonging to a Lithuanian swindler who had forged email addresses and invoices in order to trick Facebook employees into sending him payments that they believed were going to a major Asian manufacturer of computer parts.


Both incidents were enabled by online impersonation – also called e-personation – which happens when someone takes advantage of the relative anonymity offered by digital communications to masquerade as another with the intent of causing harm or perpetrating fraud. In Zuckerberg’s case, the hackers pretended to be Zuckerberg himself in order to show off their hacking prowess – and mock his incompetence. In the Facebook scam, the criminal forged email addresses, invoices and corporate logos to divert payments from the supplier into their own accounts.


For Zuckerberg personally, and for Facebook as a company, the consequences of e-personation weren’t severe. Zuckerberg’s hacked Twitter and Pinterest accounts were mostly unused, his access was quickly restored, and his primary Facebook account was unaffected. So he lost face briefly, but little else. Facebook maintains that they were able to recover “the bulk of the funds” stolen from their company after the hacker’s arrest and the start of extradition proceedings.


The outcome can be very different for small to medium-sized businesses victimized by digital fraud, however. Not only do these companies generally have fewer resources available to prevent or combat security breaches, but they’re often less able to survive the business disruptions or financial losses that accompany them.


And the consequences of victimhood might be even more serious for you – both as an individual and as a marketer.

With Opportunity Comes Risk



E-personation scams grow and thrive on a diet of publicly available information. The more facts scammers are able to gather about potential victims, the more likely targeted phishing or fraudulent email campaigns are to succeed.


As the largest social media network in existence today, and the most widely used by advertisers, Facebook has become a virtual paradise for identity thieves, who see it as a perfect “hunting ground” for stalking potential victims and gathering intimate details about their lives and finances. As Facebook’s total user base has increased in size, the number of users with illegitimate or malicious intentions has grown as well. One report states that as many as 600,000 individual accounts may be compromised daily. Another survey found that among social media networks, Facebook is trusted least by its users.


This is especially important to you if you’re among the more than 250,000 social media marketers who use Facebook on a daily basis for professional purposes. Because all Facebook Pages (business accounts) must be maintained and administered by users with personal Profiles (individual accounts), you’re essentially mandated to use an individual asset (your private Facebook account) at work.


You probably think quite often about how to protect yourself online, but you may not have considered how your job might be putting others – your family, friends, and acquaintances – at risk. But by publicizing their relationship with you (and your employer) you might well be making them into targets.


So what can marketers do to protect themselves, their networks, and their employers on Facebook? 

Here are some simple tips:


Apply current best practices to keep your personal Profile safe


Any business Page on Facebook is only as secure as the Profiles that administer it. To protect your employer – as well as yourself – configure yours correctly. Facebook recommends that you use two-factor authentication to protect your login details, and it’s a good idea to set up email alerts to keep you informed whenever your account is accessed from a new device. Choose a strong password, change it regularly, and refrain from sharing it with others. Facebook itself offers additional guidelines on its Security Page.


The benefits of following these guidelines are more than worth the time you’ll spend reviewing them. Make sure your company’s Page has the right administrators, and that these admins have the right privileges. Because Page security depends upon the security of the Profiles that administer it, and because all admins are humans who make occasional mistakes, it’s wise to have as few administrators as possible. Do designate at least two, so that someone’s available to step in should the primary administrator’s account ever be compromised. But you don’t keep a large number of people in this role.


Periodically review the list of privileges granted to writers, editors, advertisers, consultants and others within your company (Facebook calls these Roles). Delete any users who have become inactive and limit everyone’s access to the minimum level necessary.

Don’t publish Page content using administrators’ personal profile names.


By default, postings on a Page will appear under the company’s name, not the name of the individual who created it (though other administrators will see the Profile responsible for posting the content, this information will not be visible to others). Keep this setting intact, and ensure that all other administrators are posting under the company’s name as well. Not only does this unify your messaging and keep you on-brand, but it also prevents you from becoming a target of scammers seeking specifics about your company. Such information can be used to make phishing attempts look more believable and authentic.

Carefully weigh the pros and cons of identifying Team Members on your Page and their Profiles.


One of the ways that social media engagement can benefit your company is by making your brand more personal. Using your real name and photograph online can help building your customers’ trust. And identifying in-house subject matter experts (SMEs) as team members can help you showcase the intellectual capital that your company possesses.


However, Facebook is often used by criminals trying to map individuals onto the roles they fill within their organizations. These maps are then employed to create highly targeted and specific fraudulent email campaigns like the one that victimized Facebook itself. Before identifying anyone as a Team Member on your Page, ask yourself: what objective does this identification accomplish? What are the risks? People in some industries (such as cybersecurity) are more likely to be targeted, as are those in certain departments (accounting, payroll). Identify Team Members only in ways that are limited and strategic.

Regularly audit the information that’s available about you and your company online

You probably google yourself from time to time. It’s natural to be curious about what others might be saying about you online. But this natural curiosity can also help to keep you safe. One of the most common Facebook scams involves setting up a fake profile under a name that’s almost identical to yours, complete with a photograph copied via screen shot, and then using the fake account to request money from people in your network. It’s also common to see falsified Pages on Facebook, ones with no connection to the legitimate brand or real company they appear to be advertising. Sometimes scammers use these Pages to promote fake contests or sell counterfeit products. Other times they’re merely intended to defame the real brand. In any case, you should report any fake Profiles or Pages you come across to Facebook immediately.

Hold appropriate professional boundaries.


Don’t blog or post about your employer outside of the workplace without a clear goal and express permission. Maintain a clear separation of roles, and avoid promoting your employer to your personal network.

Cooperate and create strong relationships with members of your company’s IT department.


They can provide quick and reliable answers to your most pressing security questions. What policies and procedures does your organization have in place to deal with online fraud? Is there a process for remotely deleting data from personal devices that have been lost or stolen? What endpoint security software is currently being used in your company, and how often is it changed or updated?


These might seem like technical questions, but getting good answers involves building relationships. Years ago, IT departments and marketing departments were widely separated within organizational structures, but today’s marketers depend heavily on data analytics and computing-driven insights, and can only benefit by drawing closer to IT professionals. Not only can forging these alliances help you stay safe, but it can also enable you to take better advantage of the tools at your disposal.

Help create a culture of openness and transparency.


Companies have long lamented that social media causes their employees to waste huge amounts of time at work, but when it’s your job to be present on social media regularly and for extended periods, the game has changed. Nonetheless many marketing professionals may still feel embarrassed or ashamed to admit that they’ve clicked on an infected link or installed a questionable app. All human beings make mistakes, and even the most professionally accomplished social media manager has been distracted or careless at some point. A culture of honesty and open communications can help prevent the spread of malware by allowing security personnel to combat infections soon after they occur.


Good habits can go a long way when it comes to defending against online fraud, and organizations with carefully designed policies and procedures are less likely to be at risk. Start talking and thinking about privacy and security now, and you’ll be doing your part to keep cybercriminals from gaining a dangerous foothold in your company.


15% Off All Business Cards

VIEW ALL

Friday, January 5, 2018

How Data Science Aids Enterprise Risk Management

When it comes to enterprise risk management, there is no greater tool at our disposal than data science. Many companies are starting to come to the realization that data is perhaps their most valuable commodity because it can be used for more than just spotting key trends and identifying markets; it can also highlight ways to reduce risk and even increase gains, by helping predict future outcomes.


However, don’t be fooled into thinking data science is only the process of amassing data. More importantly, it involves purposely mining data to find key insights and specific examples that can help companies protect themselves in the decision-making process, ensuring high-quality decision-making. Knowledge, or in this case data, is power.

What is data science and how does it help enterprise risk management?


In the 1950s and 1960s, when enterprise risk management began to be practiced, decision makers didn’t always have data to back up their choices and, when confronted with a risk, they trusted their gut or relied on experience based on a set of principles and guidelines.


However, since then, two things have changed. Firstly, we now live in a world where finance has been significantly deregulated. Although this has led to increased possibilities for the creation of money on a large scale, it has also made the global economy less predictable. Secondly, we now have the technology at our disposal to not only estimate the outcome of a situation with a high degree of accuracy but also use that data to plan the next steps to take with a variety of options to use in addition to spotting possible future problems well before they become an issue.


Put simply, data science includes the following:
  • Validating and testing data to ensure information is correct. 
  • Testing implemented changes. 
  • Creating algorithms to collect data in specific areas. 
  • Data mining, which is the process of scouring databases to create new information. 
  • Explaining complicated findings to employers and stakeholders. 
  • Know when to say no and when to say yes


Using data science to aid enterprise risk management not only provides valuable data, it also helps you make crucial decisions. By performing the right checks, companies will be able to produce high-quality estimates on what could possibly happen, for example, if they dropped an important client or changed a supplier, allowing companies to feel more confident in their decisions.

Turn potential losses into a win



Inevitably, disaster will strike businesses, but with the help of data science consultants, these disasters can potentially be reduced, stopped or even guided to success.

Use your data to strategize



Data can be used to create a method/routine and, in turn, build company policy. There are five steps to enterprise risk management and all of them work with the aid of data science.
  • Risk identification – use the data to find the risk. 
  • Risk analysis – analyze the risk and how it is caused. 
  • Risk response – use the data to strategize how to eliminate the risk 
  • Risk control – implement the changes. 
  • Risk monitoring – monitor the effects of the new strategy. 


Put simply, once you have discovered the causes of risk and prevent them from getting worse, you can ensure it doesn’t happen again by developing a strategy to look out for the signs of this problem in the future.

Develop a clearer image of how well your business is doing



Through the collection of data, analysis and the creation of insights, companies are able to understand how well they are doing in a much clearer way which not only allows them to isolate risks but understand the value of their company in a better way.


One of the best ways to do this is to apply data science to analyze data to be prepared for auditors. This way companies can find issues before audits take place and fix them before they turn into a bigger problem.

Back up your arguments with high-quality data



There will be times when executives or employees are certain there is a risk right in front of them but just can’t prove it. Data science allows them to dive deep inside this data and find what they are looking for. If they are correct, they will then have the evidence they need to warn their colleagues and action change.


On top of this, you will be able to identify potential risks you weren’t even aware of and unmask business practices you didn’t realize were secretly destroying your business, for example, bad or even illegal sales practices.

The more data you have the more valuable it becomes



Every day, the amount of data a company possesses gets larger and larger, and within this data are many different possible scenarios allowing more complicated questions to be asked.


Dunkin’ Donuts is the perfect example of this. As the company’s profits were starting to slump year upon year, it decided to launch a loyalty card to collect data on what customers are spending their money on. This turned out to be a genius idea because it allowed Dunkin’ Donuts to use this data on specific customers to reach them with deals that appealed to them, saving Dunkin’ Donuts from disappearing.


Data science is the tool that allows enterprise risk management to function in the 21st century. As it becomes a more effective tool, we are likely to see it’s use more frequently in the office and play a more integral part in how we make decisions and analyze the risks associated with them. In fact, it may even replace the decision-makers themselves.


And the benefits don’t stop in just enterprise, they can also be found in a number of industries, from transport to healthcare, and anywhere else where data can be created or mined. Wherever risk can be minimized, there is always data science to help – not only to collect information, but also to direct decision-making.

15% Off All Business Cards


VIEW ALL CARDS



Tuesday, December 1, 2015

How to Stop Security Breaches Before They Cost You

 

Image courtesy of (Stuart Miles) / FreeDigitalPhotos.net
 

Too many employees have unnecessary access to high-level data; that is the conclusion drawn by Charles S. Clark in Two-Thirds of Federal IT Managers Fear a Security Breach from Colleagues. (It seems we should have learned this from the Edward Snowden leaks, but apparently not.)

According to sources quoted by Clark: “As many as 63 percent of respondents said they view other employees as the greatest security risk, while fully 92 percent said general employees have access to more information than is necessary.”

Once an employee is granted security access at any level, it is uncommon to monitor what they do with it. Few realize the enormous vulnerability of big data and the more databases are integrated, the larger that risk grows. Nowhere is that more apparent than in health care.


Health-Care Sector at Greatest Risk
According to the Wombat Security Breach Report: Healthcare Edition (November 2015), the health-care sector reported the largest number of security breaches at 37 percent, triple the amount of the retail sector.

Health-care breaches are also more expensive, with an average per record cost of $363 versus an average per record cost across all other industries globally of $154 or less than half.
Points of vulnerability include local hospitals, doctor’s offices and medical centers, insurance companies, and health-care clearinghouses. Health-care breaches tend to be very large and can result in identity theft.

Of 105 incidents from June to October 2015, the causes in order of frequency are:
  • Unauthorized disclosure or access (42 breaches)
  • Theft (38 breaches)
  • Hacking and IT incidents (16 breaches)
  • Data loss (8)
  • Improper disposal (1)

Human error resulted in 1.5 million patient records — including police reports, Social Security numbers, medical service records, and drug test results — being publicly posted on Amazon Web Services.

It is not a matter of if — but when — any business has a data breach. It is imperative that companies have both a plan for prevention and policies in place for immediately responding to any data breach.


How to Prevent Data Breaches
The first step is better staff training: more than 90 percent of data breaches in the first half of 2014 were preventable. Security personnel should be limiting access to data to only those who need that access and immediately removing it when duties change.

All employees need better training on e-mail, social media, and mobile device usage when it comes to protection from phishing and other hacks. Every employee must know not to click on links in e-mails, or to download apps onto their company computer running on the internal LAN. Controlling what apps employees download onto their Smartphones that contain company data is another challenge.

Does your company have a process all employees and vendors have immediate access to in case of theft of their laptop or mobile device? All training required of employees should also be required of consultants and vendors.

If you walked down the halls and asked each employee to whom they would report security breaches and how would they reach them, would they know? Do you annually survey your employees to ensure they are familiar with security practices?

Do they know not to talk directly to the media and to whom they should refer any media inquiries? Read the link immediately above for 12 specific methods for making employee devices safer.


Use a CDN as a First Line of IT Defense
Regardless of the size of your company or IT staff, putting a Content Delivery Network (CDN) between your online servers and hackers can prevent many issues. Some CDNs have a strong focus on security, watching for and recognizing threats immediately.

Although CDNs have been around for years, most people still are unclear of their benefits or even what they are. Imperva Incapsula has produced a comprehensive CDN Guide to explain what a CDN is, the architecture, and how CDN caching works.

CDNs provide benefits beyond prevention of data loss. They can also ensure a DDoS attack does not make your site unavailable and decrease page load times which can lead to more search engine traffic. A CDN is one of those rare services that has a strong upside immediately rather than only being seen as a preventive expense in case of attack.

All types of sites WordPress blogs, partly because of plugins, are being continually hacked. All businesses should have a blog, and it should be protected by:
  • Keeping WordPress, the theme used, and all plugins continually updated
  • A hidden login page or additional pop-up to guard the login page
  • Only permitting strong passwords
  • WordFence plugin to block fake Google crawlers and comment spam bots

Few realize that so many hackers are running password crackers and crawling blog posts with bots that they can impact the entire server a blog is on. The traffic to most sites today – and especially WordPress blogs is 56 percent to 90-plus percent bots.


Act Immediately to Control a Breach
Response speed is critical because attackers are moving more quickly, exploiting zero day security vulnerabilities before most businesses are even aware they’ve been published.

Highly targeted spear-phishing attacks are on the increase as are Trojanized software updates, making it easier to target specific industries and companies. Read the link immediately above to learn more about sophisticated methods being used, Smartphones, wearable health apps, and how the Internet of Things (IOT) increases security complexity.

Custom Business Cards

20% Off!

Linen Business Card Template (Sky)Appointment Reminder Cards (100 pack-White) Business Card Templates
Linen Business Card TemplatePearl Finish  Business Card Template
Platinum Business Card TemplateGold Finish Business Card
Iridescent Pearl Finish Business Card (Style 4)