Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Wednesday, July 27, 2016

The DNC Makes Sure The Queen Gets Her Crown...


Here I was, all set to publish a post about the unfairness of taxing the income of only 55% of the population in this country to pay for the infrastructure and services that a full 100% of us enjoy, even while those who use the most services actually pay the least, if not nothing at all, but then all of the sudden, here comes these secret DNC emails from yet another hacked Democrat-controlled server, apparently a gift from evil Russians propped up by Uncle Vladi who, according to the left-side pundits, would prefer an “evil” Trump presidency to a “gonna perfect in everyway” Hillary presidency.

Whew! That was a mouthful! So, I have just one question to ask in light of the revelation provided by those 20,000 plus emails, which is the complete accuracy of our belief the DNC was never ever going to allow any serious competition to Queen Hillari-ous’s coronation: How do you feel about those emails, Berners?

We are seeing what was obviously a concentrated effort by the Democratic National Committee leadership, and I am sure a few key operatives within the Hillari-ous campaign, to do all they could to ensure that the Bernie Sanders campaign ended up exactly where it was supposed to – in second place, culminating in an endorsement of Hillar-ious by the Bern – and that all of the Berners ended up right where they were supposed to – in the ballot box in November, voting for Hillary Clinton for president.

See, once Bernie said he would support Hillar-ious if he lost, then all the DNC felt it needed to do to get all the Berners to vote “Clin-ton” (Simpsons reference!) in November was to make sure Bernie came in second place. And whether we believe a second place finish by Bernie was inevitable or not, it is very apparent that the top brass in the DNC was going to do all they could to make sure it happened. So while everyone at those Sanders rallies was all “hope and change”, sadly, you never stood a chance, no matter what, Berners. Thanks for playing, but the game was rigged against you from the start.

So, how does that make you feel? Personally, I’d be pretty damned pissed off. Not surprised at all, because hey, we’re talking about Hillar-ious here – that’s a person who is all about the backroom deal, the quiet settlement, the stacked deck, half-truths and bold-faced lies – but definitely pretty damned pissed off.

I know some of you were already pissed off that Bern kept his word and fell in line behind the Democratic establishment machine, so I am assuming the pissed off are even more pissed off and the not so pissed off and more understanding of Bern’s supporters are possibly now a little pissed off…maybe?

So, what are you going to do about it, Berners? Are you going to keep blindly following the Democratic party as they conspire against you and your beloved candidate and then take you for granted like they do the rest of their constituents, or are you going to do something?

Nothing’s happened at the convention that is going to make a difference – it’s not like there was ever a chance Queen Hillar-ious wasn’t going to get her crown, but are you going to now support the throne? I have a feeling that for all of your well-meaning principles and all your steadfast ideals, you are going to simply fall in line and vote Hillar-ious come November anyway. God save the queen! Enjoy being one of her loyal subjects, Berners…

Photo via Pexels

Wednesday, March 9, 2016

Enterprises Need To Protect Customer Data


While I have been working in the cybersecurity industry for slightly over six months now, I recently read a CMSWire article from David Roe that still managed to surprise me a little. The article stated new research from the AIIM (Association of Information and Image Management) indicated that 26 percent of organizations have lost customer data in the past year – and those are the ones that know about it.

Think about that for a second. Of all the companies out there that you do business with – the ones that have your name, your address, your phone number, maybe even a credit card number, or worse yet, your social security number – one in four of them knows for certain customer data in their possession has been compromised. Factor in those companies that don’t know but have already been compromised as well, and it paints an even scarier picture for us as consumers.

And if this statistic hasn’t floored you yet, let me share another sentence from Roe’s article: More than 36 percent of small organizations, 43 percent of mid-sized and 52 percent of large organizations have reported data breaches in the past 12 months.

See how this situation just got even worse? Which is more likely to have your credit card number or your social security number, the small organization or the large organization?

And to top it off, according to additional research from AIIM, not only are data breaches increasing with each passing year, they actually still remain nothing more than an abstract discussion point in most enterprises, according to Roe’s article. It seems that while organizations may care about security, their lack of understanding about what to do about it has them focusing on other things like theft by internal staff and proper disposal of obsolete electronics.

So, if I don’t have you scared enough about your personal information as it sits in the hands of the companies you do business with, let me share two more statistics from Roe’s article – only 13% of the organizations surveyed suffered data breaches because of straightforward external hacks, while 28% of data loss was due to staff negligence.

And what does the cybersecurity industry consider staff negligence? Well, while this can include things like leaving your laptop at a Starbucks while your operating system is unlocked or losing an external hard drive with customer information on it, most negligence constitutes employees clicking on something they shouldn’t have in an email they have received. Each of us can relate, as I am sure we have all ended up with a virus that forced us to either rollback our operating system to its last update or bogged our computer down so badly that we had to re-image our hard drive. But imagine that you made this little mistake at work and instead of it planting a virus, you were instead taken to what you thought was a company login page and typed in your corporate ID and password. Seem like something you’d never accidentally do? Well, good for you, but apparently 28% of people out there are still doing it.

While Roe wraps up his article by calling upon enterprises to better train their staff on how to better spot these types of false login page phishing attacks and working to make their employees more aware of potential threats like these, I am going to wrap up my article in a slightly different manner. Why? Because I believe that no matter how well you train your staff, and no matter how careful they are, there is still a chance they will accidentally end up on a fake login page and provide credentials to the bad guys. You can’t tell me that you don’t find yourself making little mistakes here and there when you’re tired at the end of a long day, or rushing to get something done. It happens to the best of us, and all the security training in the world isn’t going to fix that.

What will fix it, however, are cybersecurity solutions that take the human factor out of the equation. Still train your staff on security best practices and how to spot phising campaigns that are seeking to steal their login information, but back that up with an anti-malware solution that pre-scans every file on every endpoint before it executes and quarantines the files and user actions that seem suspicious.

It is time for enterprises to secure all of their systems and every endpoint from the little human mistakes everyone on their team is going to make from time to time by seeking out an anti-malware solution that actually stops these attacks before they can occur.

Photo by Michal Jarmoluk via Pixabay 

Wednesday, December 9, 2015

Credit Unions and Cybersecurity


I recently conducted some research on the cybersecurity challenges credit unions are facing and here is what I learned:

Data security breaches are a significant problem for credit unions because once members begin to question the safety of their personal information, these financial institutions can incur massive losses before member trust can be restored. Many consumers have been known to reduce the number of financial services they’ll put through their credit union following a breach, and some have been known to leave the credit union entirely.

The National Association of Federal Credit Unions found that, on average, a data breach costs a credit union just over $225,000. While credit unions have implemented security measures and devoted resources to protecting customer data, much like all industries, their measures are failing to keep up with the ever-increasing sophistication of attempts from hackers to gain access to credit union members’ personally identifiable information.

Even though federal regulations have been imposed on credit unions to ensure a basic level of security for member data, these regulations, even when met, are still falling short of stopping data breaches caused by malware. Thus, credit unions may be meeting regulations, but are still not meeting members' security expectations.

With endpoints that can vary from ATM machines to company laptops to customer and vendor portals, credit unions inadvertently provide many avenues for a cyberattacker to gain the foothold they need to launch malware and access databases housing sensitive customer information like social security numbers, passwords and credit card numbers.

And unfortunately, their own infrastructure is not all these credit unions have to worry about. As reported in a recent Business Insurance article, when asked what keeps her up at night, Debbie Matz, the head regulator for 6,350 U.S. credit unions, answered: a cyberhacker sneaking in through a credit union vendor, cracking through to the larger U.S. financial system and wreaking havoc along the way.

The credit union vendor portals Matz refers to can include a vendor’s own separate payment processing systems, like point of sale systems, which also leave credit unions vulnerable no matter how well they secure their own infrastructure. If a point of sale system endpoint is left unsecured, credit union members' personal information becomes vulnerable to theft and the endpoint can be used as an access point to larger systems.

One of the scariest parts of this story is that credit unions across the country are relying on traditional antivirus solutions to protect their infrastructure. These solutions are less than 50% effective at stopping threats, at best, and usually, threats are only identified after they cause damage. The data breaches these solutions don't stop are expensive to repair and also harm brand identity, which can lead to a reduction in revenue and even litigation.

There really is only one solution that can secure a credit union’s infrastructure as well as protect it from attacks originated at vendor portals. Credit unions should seek out a solution that uses artificial intelligence and machine learning to protect every endpoint in their infrastructure from not only malware that has been identified by antivirus software, but also malware that has never been seen before. Once their own infrastructure is secured with this technology, credit unions should insist their vendors do the same, thus securing their organization completely from over 99% of malware.

While credit unions definitely face some substantial challenges when it comes to cybersecurity, the technology already exists to secure their data – they just need to deploy it.

Photo via Pexels

Wednesday, November 18, 2015

Healthcare Industry Hardest Hit


According to a report from the Ponemon Institute, the cost of a lost or stolen record in the healthcare industry is over double that of other industries. Security Week reports that cost to be $363 as opposed to the average of $154, with the average breach having a total cost of $3.8 million. This has led the online magazine for Internet and enterprise security news to report the headline “Data Breach Costs Rise, Healthcare Industry Hardest Hit”.

But what is driving this massive increase in security breaches and their cost in this vital industry? As with many industries, it is the adoption of technology and human interaction with that technology that is creating new challenges.

Healthcare is Becoming Digital

The Health Information Technology for Economic and Clinic Health Act, passed by congress in 2009, encourages healthcare providers to digitize records. While good news for patients who will ideally be able to access their medical records from anywhere in the world, this process is not only increasing the volume of digital records, it is increasing the number of endpoints required to manage them. Advances in technology are putting a mobile device in every caregiver’s hands, but this is putting great strain on healthcare provider IT teams to keep up with a constant barrage of attacks on these endpoints by viruses and malware deployed by cybercriminals hoping to gain access to sensitive information.

Providers are Retaining Sensitive Patient Data

And speaking of sensitive information, gone are the days when your doctor knew your medical history from memory and kept a back-up copy in a file folder behind the reception area. Today, with electronic billing and digitized healthcare records, more and more sensitive patient data is being retained on networked computer systems. This has made healthcare provider infrastructure an attractive target for cybercriminals.

It’s Getting Cloudy (and Mobile-y)

InformationWeek predicts that by 2020, 80% of healthcare data will pass through the cloud at some point in its lifetime. Patients are becoming more technologically savvy and that means the use of mobile apps to access healthcare systems and records. Providers can only be so vigilant with the implementation of cloud security and BYOD policies because all it takes is one compromised device for a significant breach to occur.

We’re Only Human

While healthcare providers can secure systems and put all of the “detect and respond” technology they can buy in place, one of the biggest threats to their security is the very thing that makes them great – their employees. Providing healthcare to large numbers of patients can result in a very fast-paced and stressful environment. Workers can suffer from fatigue and distractions. This can lead to disaster since all it takes is one wrong click on one malicious link to compromise an entire infrastructure.

A Solution to All of These Challenges

I mention “detect and respond” solutions because while being mildly effective at alerting healthcare infrastructure administrators to attacks AFTER they happen, these traditional antivirus and malware detection solutions will never PREVENT the attacks that come as a result of these new healthcare industry technology challenges. Only a “preventive” solution that scans and detects the characteristics of files to locate potentially malicious files BEFORE they execute will guard against these new challenges.


For this reason, healthcare providers should seek a solution that uses an artificial intelligence and algorithmic science engine to scan every file on every endpoint in their healthcare infrastructure instead of one that simply alerts them once a breach has occurred. By deploying such a solution, healthcare providers can truly secure every endpoint in their infrastructure. This means regardless of whatever “detect and respond” solutions they have in place, no matter how many digital records their team processes, and no matter how many times employees click on something they shouldn’t, a “preventive” solution will have them covered because files are quarantined BEFORE they execute, stopping threats BEFORE they can do damage.

Photo by Darko Stojanovic via Pixabay

Wednesday, September 30, 2015

Mr. Parker, Eternal Vigilance and Our Hard-Earned Money



Remember when we were kids and there were only a few things we had to watch out for? Things like strangers in vans, strangers with candy and strangers that offered you candy to get in their van? Remember when as long as there was an adult you knew and trusted that could see you from wherever they were sitting, things were safe?

I mean, we had to watch out for Halloween candy that had razor blades in it, open bottles of Tylenol and Richard Ramirez that one summer, but all in all, when I look back to those golden years of yesterday, I always felt pretty safe.
Fast forward to today, and I feel like they are coming at us from every angle! You’re able-bodied, you have a job, a little bit of money put away, a decent car and a decent place to live and now, all of the sudden, you are prime target #1 for every sleazeball out there!

We have to watch out when we get money from an ATM because they’ll sneak up on us, or maybe they’ve already placed a card reader over the ATM card slot and are waiting for us to simply take out 20 bucks so they can gank us for all we’ve got! We have to watch out for that same card reader scam at the gas pump, too. I know 99.99% of the people who handle your credit card are trustworthy, but you still do hear about people getting card numbers lifted at retailers these days. It also seems like you stand a much better chance of not getting ripped off by the actual human holding your credit card than you do once the merchant lifts all your personal information off of that card and then stores it in their payment system. Target ring a bell for anyone out there? I didn’t get any fraudulent charges on the card I used that month at Target, but I did get a nice, brand new shiny credit card and new account number from Chase just in case.

And speaking of scams, just this past Saturday morning, I got a phone call I have to tell you about. There I was, minding my own business, about to take a live check to the bank when the phone rang. Yes, folks, an actual live check, if you can imagine! I was going to have to actually walk inside the bank! Can’t remember the last time I had to do that! Yes, those ATM machines sure are scary, but hey, much less scary than the line in the bank or one of those many colorful Orange County bank robbers that get the cool names like the Hawaiian Shirt Bandit, Cool Grandpa Bandit, and Lady In A Crazy Wig Bandit. Yeah, I made those ones up, but you know what I am talking about.

But, anyway, back to my story – back to the phone call. I am about to take this live check to the bank and my cell phone rings. It’s a 202 area code phone number with a caller ID listed in Washington, D.C. My first thought is, what the hell do they want? Haven’t I sent them enough money already this year? I don’t answer the call, but the caller leaves an automated message with the phone number, asking for a return call. Normally, I just ignore these calls, but this is the third call from that number in three days so I figure I better call them back and tell them I am not interested in their magazine subscription, low-low financing on a new automobile or whatever thing it is that they are peddling that I don’t want, that way, at the very least, they’ll stop calling me.

So, I call the number, and that is when it gets interesting. A man that sounds to be about my age or so with a very thick Indian accent answers my call and proceeds to tell me that I have reached the “IRS” and that they have been trying to reach me.
I laugh as I think to myself that the United States Internal Revenue Service sure as hell has never had a hard time reaching me before! They always seem to find my paycheck and me just fine every couple weeks. The man on the other end says that he wants to just confirm that he is speaking to the right person, so I figure, I am game...let’s see what they know about me.

Turns out to be pretty scary – He’s spot on with my first and last name, middle initial, full address, and obviously, my phone number. Granted, this information is available all over the Internet from just about any form I have filled out in the past 10 years, but nonetheless, a little annoying that they have all this info ready and at-hand when they are on the phone with me.

I proceed to tell the man on the phone that I am not sure why they are calling me because I am all paid up. He then apologizes, but doesn’t understand what I mean. I proceed to remind him that he works at the IRS and ask him if he understands what they do there. I explain that the take money from me every time I get paid and then another lump sum once a year, but right now, I am all paid up!
He them proceeds to tell me they have sent me multiple unanswered letters because, apparently, I owe so much in back taxes that I am now subject to a lawsuit being filed against me by the government. Now, keep in mind, this entire time, I am being very patient while this man struggles to get this entire story out in English, tripping up more than a few times.

I proceed to explain to him that since they have my correct address, the letters should have reached me no problem and that I am starting to wonder if he is really calling from the IRS. He then proceeds to tell me that he wants me to write down his name, his badge number, my case number and the toll free number to the IRS so that I always have it handy throughout what is most likely going to be a long and drug-out investigation by the IRS to determine exactly how much money I owe them.
I proceed to listen as “Mr. Parker” – and I confirmed that was the last name he was giving me because believe me, he had a really hard time saying it – gave me his badge number, my case number and the toll free number to the IRS. I looked up the number and it is, in fact, the main information line for our friends over at Internal Revenue.

I then proceeded to explain to Mr. Parker that I still didn’t believe he was who he said he was and that I really did not think he worked at the IRS. Once flustered, he became even harder to understand and I wasn’t really sure what it was he was saying by the time I wished him a good day and hung up the phone.

I reported the number – (202) 684-6436, so you all can keep an eye out for it – to the Do Not Call Registry, which naturally has my phone number as a happy registrant, but as you can imagine, I have very little confidence anything will be done by the folks who actually work in Washington, D.C. to stop these guys from making these calls.

Naturally, a Google search of the phone number yields a number of scam registry sites and complaints and funny stories from people who messed with the person on the phone far worse than I did, but I always think back to all of those episodes of American Greed and all of our elderly Americans who continue to fall victim to scams just like these and it makes me sad that we live in a world today where things like this have really become so common place.

It’s bad enough that I have the real IRS trying so hard to milk me dry, but having to deal with Mr. Parker and his obviously organized scammer friends on one of the two days a week when I am actually trying to relax is really annoying. Makes you wonder how it is that we got here. How is it that I have to now watch out for people who will even go as far as to steal a house – go ahead, look it up – they file paperwork to steal the title to your house from the County Clerk’s office – when all I used to have to do was simply stay where an adult I knew could see me and all would be fine?
Don’t get me wrong, folks, we live in an amazing time, and I know that a lot of us live some really great lives – definitely not trying to be a Debbie Downer, but just remember, as the saying goes, the price of freedom is eternal vigilance, and eternal vigilance is the only thing that will keep me and you from losing our hard-earned money to all the Mr. Parker’s out there.

UPDATE: Looks like this scam is large enough,we're actually doing something about it. 

Wednesday, September 16, 2015

It's Time To Secure Cyberspace


Whether left or right, liberal or conservative, libertarian or mainstream party hardliner, taxpayer or tax money recipient, I think most of us as Americans can agree the one thing we expect from our government is to shield us from attack.

I am confident when alien invaders strike from above or a foreign army lands on the beach or zombies come streaming across the land, our military will be ready and willing to fight to defend us. But, there is a scary, new frontier that all the aircraft carriers, jet aircraft, smart weapons and the most highly-trained and prepared military force in the world are all powerless to stop without a serious shift in U.S. government policy: cyberspace.

I recently read an article from the U.S. Chamber of Commerce on a small business that was forced to close its doors by a hacker, or a group of hackers, or maybe even that group of folks in those guy-from-England masks themselves. Sorry for the vague and wordy description, but I’m afraid to type out their name in case they have their Google alerts on!

The business featured in the article developed a site designed to allow people to post their opinions on political issues of the day, essentially providing a forum for people to debate back and forth through pre-recorded video. This was truly a small start-up, founded by college students and funded with a mere $35,000. This site could have been the next great thing, but once users posted videos commenting on the Israeli-Palestinian conflict, hackers set out to destroy the site.

The attack began by redirecting the site’s main page to another page, which featured a graphic of that famous hacking mask and some green Matrix-style falling letters and numbers. Every time the site’s owners had the page redirect fixed, it was hacked and redirected again. Each time a hack was fixed, it was costing the site’s owners money because paid contractors maintained the site. Though they eventually found some angel coders to fix the hacks for free, the relentlessness of the attacks led the business owners to abandon their site and try to operate their vision through a mobile app. Unfortunately, though, the mobile app never caught on and hackers successfully silenced another site that had great capital potential.

According to a study by the National Cyber Security Alliance, these small business owners are not alone. One in five small businesses becomes the victim of hacking and of those that do, 60 percent go out of business within six months. But, according to a recent U.S. Chamber of Commerce article, as cybercrime increases, our country still lacks policies to defend America’s cyber networks and the companies that use them.

The biggest problem for businesses that get hacked is they simply do not have the resources to fight back. They are completely on their own, fighting the attack in a silo. There is no “911” to call, no federal agency to ask for help when an attack occurs. The business can only hunker down and rely on the limited personnel and funds they have to combat the relentless attacks of people with a very unlimited resource – their own free time.

The only way we can fix this problem is to demand that our government step in to defend these small businesses – to defend us as Americans – just as they would if the hackers landed on the beach with a gunboat and an army in tow.

According to the U.S. Chamber of Commerce:

One of the first steps our country's leaders should take to strengthen our defenses, experts say, is to pass federal cybersecurity information sharing legislation, which would protect firms that share information about data breaches and other cybersecurity-related experiences with public officials and other companies. Without it, business leaders will remain understandably hesitant to share information about attacks for fear of litigation or other consequences.

This sounds like a really great idea to me. Fortunately, legislation that would accomplish this has already passed the House and is being debated in the Senate. Let’s hope the people we put our faith in and send to Washington see fit to make every small business owner just as safe from cyberattacks as they are today from aliens, zombies and foreign armies.