Patching is one of the easiest and most effective ways of protecting security systems.
If you are patching you are removing some of the capabilities of the bad guys to gain access to your system
CareMIT Managed IT Support Canberra
Delivering superior Managed IT Support and the Home of the Cybersecurity A.C.T.I.O.N. Plan ™
Sure it is!
A touch of sarcasm there I am afraid.
My first idea for a podcast was to interview people who had been targeted, exploited and/or who had experienced a cyber event.
It would be full of information about, no wait…..
No one is going to talk about being breached!
That conversation, if they had lost thousands of dollars or worse closed their doors, would be way tooooo painful.
Although it would be of huge benefit to others and my target audience it would definitely be detrimental to the interviewee’s health
If they survived, talking about it would have a negative impact on their revenue, reputation and brand.
Not the best idea I have had.
Scratch that!
Let’s interview people in the industry.
A bit of research on the interwebs and it confirmed a long-standing realization that not-for-profit organisations, charities and small and medium businesses are treated shoddily by the cybersecurity industry.
After a couple of conversations, I soon realized that the best in cyber had very little understanding of the space that is occupied by organisations with less than 50 staff.
There are a number of people that are in the cyber industry who are wholly based in normal business and who understand cyber and smaller organisations.
I actually hope that I can interview them, but
Most do not understand the challenges and problems associated with a struggling small and medium business environment.
Where making a simple decision could mean that you have a cash flow issue, a marketing issue, a cyber problem or a going out of the business problem
There are two areas where everyone has problems in cyberspace.
The first are NFPs, Charities and SMEs.
Second, are the elderly and mature.
Coming soon as a podcast and video:
Cybersecurity for normal small businesses.
Some straight answers to cyber questions that the others are reluctant to answer.
A podcast about how to build resilience and security into your business from the basics up.
Get answers to the questions that you need to ask about business security
And to make myself even busier I thought,
The most under-protected user of the digital world are the elderly, retired and mature
This area of the population are uneducated and ill-informed but most important they are innocent to the true capability of the cyber-criminal.
This makes them the number one target for the cyber creep.
They are under constant attack through scams, extortion and fear-mongering.
Hopefully going to be launching them both this month, see lockdown has some advantages.
The first episodes of both of them went live this week all I have to do is find the URL for them
#nonprofits #smallbusiness #ExecutivesAndManagement #AccountingAndAccountants #ProfessionalWomen #ceo #CareMIT #cybersecurity #infosec
When I was in the Navy, I was based at Garden Island in Western Australia on and off for 5 years.
In that time I was relatively fit and I represented the Navy in a number of sports.
I would pedal to work (20Km each way) at least 4 days a week.
On a good day 40 minutes from the front door to the office.
90 minutes on the way home because you had to stop at the pub to get the goss
If you know the island you know that there is one problem.
No matter what direction you were going morning, afternoon or even if you had the luxury of knocking off early, you ran into the wind
On the causeway, the easterly and the sea breeze were always in your face.
Both of them could get up to 40Km per hour.
The only consolation was the flatness around the area.
One day my bike was stolen.
Taken out of the backyard.
It wasn’t until it was gone did I realize what it was doing in my life, apart from keeping me fit.
I didn’t have to drive so the wife could have the car to ferry the kids and do all of the other stuff she needed to do.
I didn’t have to drive so there was always extra money in the budget for everything we needed.
I could no longer come and go as I pleased, I now had to fit in with everyone else.
I could no longer go to the pub on the way home.
In fact, apart from the initial cost, the bike had cost me nothing.
This is what is happening in the digital world.
We do not know or understand the heavy lifting that our digital devices and services are doing for us.
That is until they are gone.
When they are gone, we realize that the business, organisation, association or ourselves have taken them for granted.
They were doing everything.
So an accidental loss, a cyber event or an insider will cause havoc unless you have stood back and thought:
What If?
What if we turn it all off?
Now what!
That “what if” makes you proactive.
It builds in resilience.
It is the first step to increased revenue, improved capability and scalability.
Have you looked at the business and thought WHAT IF????
Cybersecurity for the C suite executive (CEO, CFO, COO).
Lets look at the facts!
No matter the size, shape or industry of an organisation.
No one is fully prepared for a full-on, bare knuckles, cyber ninja assault.
We are not talking about a random attack.
An attack that is being perpetrated against your organisation with Metasploit and a new copy of Kali.
This attack is from Mr. Creepy!
He knows what he is doing.
He knows what he is after.
But, more importantly, he also knows how to get it.
He has studied your organisation for months to find your weaknesses.
He has the skills and resources (very important) to break in and steal your crown jewels.
These are the people who give my industry grey hairs and stress lines.
Thinking that there is no way that you would be targeted by a professional is a grave mistake.
Because It no longer needs to be a professional!
They are quite happy to train others in the required skills.
They are quite happy to sell others their expertise.
They are quite happy to tell others where they are going wrong.
They have created capabilities and skills that they have incorporated into something to sell.
This increases the capability of the inexperienced cybercriminal immensely.
Want to avoid being on the radar as a prime target then YOU NEED TO DO SOMETHING.
Here is something to start with.
#nonprofits #ExecutivesAndManagement #AccountingAndAccountants #ProfessionalWomen #ceo #CareMIT #cybersecurity #infosec
If you are not worried about a cyberattack then you have probably not been given the right information!
#Cybersecurity or business security should be one of those areas of business that keeps you up at night.
To tell you the truth it should be one of those areas that terrify you!
When the script kiddy targets you with a random automated attack it is not personal, it is just business.
If you have done nothing or very little in the way of protection then you quickly become a victim.
With the average time inside a network of more than 250 days, most organisations have no systems or capabilities to detect them never mind identify or stop them.
From initial infection to the point where your world ends can be as little as 24 hours or they can sit inside your network and wait.
6 – 12 months is normal.
In that time they are documenting your network, your people, your intellectual property, your systems, your access to money and anything else that they can find.
While you are blissfully unaware of them being there they are getting ready to deliver the coupe de tar.
In addition, while they are rummaging through your proverbial underwear drawers your systems could be spamming your friends, running denial of services attacks on corporate networks, bitcoin mining, storing porn for pedophiles all while they destroy your backups and other systems.
And that is just a random capability from an inexperienced criminal, just imagine what Mr. Creepy can do you if he singles you out and makes you his sole purpose in life!
We have put together a simple 2 page ransomware advice brochure (The before, during and after plan) that could go a long way to reducing the impact of a ransomware attack.
#nonprofits #ExecutivesAndManagement #AccountingAndAccountants #ProfessionalWomen #ceo #CareMIT #infosec
There is a huge difference between a cyber attack generated by a script kiddy running an automated system and one where you are being targeted by a dedicated hacker.
For one, if you are targeted by a dedicated hacker then you already know that you have something worth protecting and you have, hopefully, done something about it.
The biggest problems with cyber attacks on the internet are that 95% of them are coming from an automated system controlled or managed by trainees (script kiddies).
Automated systems have three reasons they are used:
There are a number of ways for anyone to get hold of an automated system. They can download an operating system that has an automated system running on it. Kali, Parrot OS or Black-arch are all very good examples but there are others.
Designed as penetration testing tools, these systems have all of the requirements that they need to target organisations, multinationals, or anyone connected to the digital world.
Before you ask, yes it is all legal and above board as long as you are not targeting someone else.
To make these systems more effective they allow them to either download additional components from GitHub or design and program your own applications.
The old saying that whenever anything is free you are the product rings true with these systems as well. The creators of these systems keep track of people using them and incorporate any updates into their own releases.
To set up one of these systems all you need is a computer. Once you have administrator access to a computer you can download a virtual environment (VMware if you have some money or Virtual Box for free) and you can then install these operating systems as a virtual operating system.
You can even run the operating system on a microcomputer (Raspberry Pi) for under $100.
Once set up you now have access to the tools and capabilities that, if used correctly, can rival someone who has been in the industry for years. Almost like a novice woodworker creating a dovetail joint on their first try without knowledge of what to do.
No training, just using other people’s knowledge.
In addition, and a bigger issue, what they do not know can be learned or discovered by simply searching google.
The capability and effectiveness of these systems allow them to set up the automated attack and target a huge number of vulnerable systems based on blocks of internet-based addresses.
Simply they can find out if there is a targetable vulnerability just by using facets of the automated systems.
These free operating systems have the capability of making money.
To make serious money, though, you need to work with partners. Working with partners can be both beneficial as well as detrimental to their own security.
When it comes to making money it is either through selling information on the dark web, selling cryptovirus decryption keys to vulnerable people or selling access to compromised systems to leverage other attacks.
To avoid being a victim you need to implement some protective strategies.
You need to apply the CareMIT business security methodology to the organisation but to start at the basics this is what you need to do:
At the basic level, the users of these automated systems are just as vulnerable as the people that they are targeting. A severe case of “user beware”, because if you do not configure the system correctly you are just as vulnerable as your targets.
At the most fundamental level, we all know that most people between 13 and 30 have a limited ethical attitude and good and bad is debatable.
That’s why we have the proliferation of these systems.
Secure your business!
Get proactive!
Do the scorecard!
Read your report!
Linkto scorecard https://caremit.scoreapp.com
#ceo #ExecutivesAndManagement #ProfessionalWomen #CareMIT #cybersecurity #infosec
Since small and medium businesses, charities and not for profit organisations are now the bread and butter of cybercriminals targeting.
Isn’t it about time that we started to look at the reasons?
The digital world is complex.
Every area requires a different set of skills and knowledge. There are areas where some of the skills and requirements flow from one area to another, but these are definitely an uncommon occurrence.
The skills to implement and manage a website are different from networking which in turn are different from the requirements for coding. Its not the fact they are different, the problem is the required level of skill to do it correctly.
Anyone with a little bit of help can write code, but to write it correctly, securely and properly requires years of skill and practice.
When it comes to the business world, we have a significant requirement for using the digital world. In most cases, we see the introduction of a digital component into an organisation as easy.
It is not. To implement and configure is easy. To implement and configure securely, correctly and in a way that will benefit the organisation takes more than a fundamental underlying knowledge.
Most SME’s are doing more with less just to keep themselves in profit. Throw in another complicated process or system and they now have more to do with the same amount of time.
Business security takes time. To secure an organisation takes time.
A solution is to employ someone on staff to manage the ICT and we will then give him the role of security professionals. Getting someone with the required skills will cost money.
The second alternative is to enter a service level agreement (SLA) with a Managed Service Provider (MSP) and contract the support of the OCT and security to someone else. Again this requires the correct skills as well as culture.
Both options will free up some time.
Security solutions for SME’s can be expensive. When it comes to technology and the integration of different technologies into the business environment we see some significant costs.
Comparing the costs of a breach to the costs of putting the right technology in place, it is a no brainer, but not until after the fact.
SME’s have the same compliance and governance of multinational corporations but do not have the resources to implement tier 1 or 2 technological solutions.
They make do with what is available and inexpensive not realizing the impact of these additional vulnerabilities can have on their business.
To reduce all three of these issues, as already mentioned is a contractual agreement with an MSP or a Managed Security Solution Provider (MSSP).
They bring the required expertise, they free up time and in most cases they are a viable and cost-effective.
A better solution is to look for an Organisation that has normal MSSP skills but has the capability to add additional security components around your Organisation.
SME’s are a prime target for cybercrime.
They have reduced expertise, minimal money, and an attitude, we are too small to be a target, that leaves them wide open to a cyber event.
Our industry, the people who know and think we understand the bad guys have been pushing for an attitude change for the last 10 years. In a large number of ways, we have failed, especially in the SME space.
In some, we have failed significantly.
By the time we get called in, after a cyber event, it is way too late.
To late to recover, too late to respond and definitely too late, in a number of organisations, to get back to business as normal.
Most SMEs, after a cyber event and especially after a ransomware attack, have but 3 choices,
Here are 3 cybersecurity strategies that every SME should implement to be more secure and avoid that devastating cyber event.
Increased awareness of business security in a workplace is vital in today’s business world.
Not many businesses know where to go to get that training.
Training needs to be done as an ongoing process.
Once or twice a year is inadequate. But training and education has to be easy, bite-size pieces, easily digested, easily implemented and easily followed.
In addition to ongoing training, you also need to incorporate business security into your onboarding process to instill the required cultural elements into new people on staff.
Want some free cybersecurity training, here is something that will definitely help
https://wizer-training.com/partner/caremit
SME’s have a limited understanding of the new risks delivered to the business via our digital components.
The game has changed significantly in the last 10 years and we, as small and medium businesses, are constantly playing catch-up.
We are significantly hampered and handicapped by the impact and scale of our digital usage.
It is everywhere, used in every component and used all of the time.
To understand the risks without understanding the systems you need some help.
Here is some help for you.
Https://CareMIT.scoreapp.com
With the report, you can now implement a gap analysis and work out what you need to do to increase security around your organisation.
The report also ties in well with:
If you are looking for a better way to manage security within your Organisation, you need to look no further than a framework.
A framework is a documented system that allows an organisation to follow the bouncing ball and tighten up the security in a regimented way.
The more the components of the framework are implemented the more secure and mature the organisation.
Frameworks are easy to follow and implement and the one I recommend is the National Institute of Standards and Technology (NIST) cybersecurity framework.
https://www.nist.gov/cyberframework
Answer the 98 questions, honestly, and you now have a road map to implement cybersecurity in a significant way.
The NIST cybersecurity framework also gives you a number.
Between 0 – 4, it can be used as a comparison between businesses, supply chain components, and government departments so you can do business with like-minded organisations.
It is not too late to implement any of these strategies. The bad guys are getting more and more clever, so time is running out.
They are targeting everyone who is connected to the digital world, the internet, with more sophisticated systems, a number of them are now fully automated.
Some of those automated systems have minimal human involvement after the initial set up.
From initial social engineering attack, all the way through to payment of ransom everything is automated and driven by machine learning.
Every SME should be implementing a training and education process, doing a risk and gap analysis and implementing a cybersecurity and business security framework.
With that everything else will follow.
The business will be more stable, the culture of the organisation will change and getting back to business as normal after an attack can be significantly easier.
The impact of a cyber event for an organisation implementing these 3 components or not is significant.
If you haven’t implemented these 3 strategies in the last 12 months, 2 years or 5 years then 2020 is going to be a bad year.
But it’s not too late.