Wednesday, November 25, 2015

Don't Let Your Security Blow Away in the Cloud

Whether you use only one application in the cloud or you've shifted your entire infrastructure there, your security needs to cover your entire infrastructure — public, private, cloud-based, and traditional. But as companies mix on-site data centers with vendor-provided cloud services, they often fail to adjust their data security accordingly. So says a new study from the SANS Institute, which found that fewer than a third of organizations have a strategy that describes how their traditional and cloud computing models work together, which data and applications to send to the cloud and which to keep in-house, and how to establish appropriate safeguards for each external cloud provider.

Respondents said they had a hard time creating a data security strategy, in part because they lacked visibility into cloud provider practices, and also because cloud providers didn't cooperate enough in supporting the customers’ security technology.

Xantrion can help you establish appropriate security policies both on premise and in the cloud. We can also help you choose vendors that are happy to be transparent about their own security practices, because that's who we choose to do business with.

Thursday, November 19, 2015

Mac Users' Security Honeymoon Coming to an End?

Apple laptop and desktop users don't have to worry about the constant threat of malware and exploits the way Windows users do — right?  Wrong.

That used to be more or less true, but with Apple's share of the desktop computer market now at about 17 percent, hackers are targeting OS X like never before. In fact, according to recent research, five times more OS X malware has appeared in 2015 than during the previous five years combined.

Granted, the researchers only found 948 unique samples of OS X malware this year, compared to the 400,000 new varieties of Windows-based malware that emerge every day. But the uptick strongly suggests that hackers are actively looking for ways to inject malicious code into OS X and circumvent its security mechanisms —possibly using iOS, which currently holds almost 40 percent of the global mobile OS market.

In short, if you use Apple products, your security safeguards need to include them. If you're not sure how, Xantrion is happy to help. We're experienced in protecting infrastructures that include Macs and iPhones — including our own! 

Thursday, November 12, 2015

US-China No-Hack Pact: Good, or Better Than Nothing?

September saw a historic agreement between the US and China prohibiting cyber espionage for economic gain — stealing trade secrets and intellectual property. But how will it work out in practice?

In the worst-case scenario, China will pay lip service to the agreement while turning a blind eye to, or continuing to sponsor, attempts to steal US IP, says Kevin Mandia, president of leading network security firm FireEye. However, he believes it's more likely that China will scale back its participation in cyber spying attacks on US companies, and may even put a stop to it entirely — especially since the US is likely to start fining Chinese companies for it.

In the end, Mandia predicts, the US and China will team up to battle cyber crime for the sake of a stronger global economy. And that makes the agreement better than no agreement.

Thursday, November 5, 2015

A Look at the Latest Lightweight Laptops

Laptops get thinner and lighter by the day. If it's time to upgrade your Windows laptop and you're hunting for something smaller than what you're currently lugging around, check out CRN's comparison between the two current leading lightweights: the 2.7-pound Dell XPS Touch and the 3.34-pound Microsoft Surface Book.

CRN gets into the details of processing power, graphics, battery life, and other specs, so we won't. The short version is that they're both sleek Windows machines that retail for about $1,700, and they both have features worth recommending. If you're trying to reduce weight, go for the Dell. If you want a laptop that converts to a tablet, choose the Microsoft. And if you want help making sure they work well on your network, choose Xantrion.

Thursday, October 29, 2015

The Internet of Things: Boon, Bane, or Both?

You've probably heard a lot of talk lately about the Internet of Things (IoT) — the idea of connecting objects ranging from medical devices to kitchen appliances to the Internet so they can collect, use, and share data for better performance and greater efficiency. The IoT could change our lives dramatically, but experts have some serious questions about how to handle the amount of data the IoT will generate, who will own that data, and how to keep it both secure and private.

The evolution of the IoT is going to create new security vulnerabilities at home and at work that we've never had to consider before. Where will our data end up, and how will it be used? It's something we're thinking about a lot at Xantrion, and we think you should be, too.

Thursday, October 22, 2015

The Health Care Industry Needs a Security Booster Shot

In early September, a Blue Cross Blue Shield affiliate in upstate New York revealed that hackers had compromised 10.5 million patient and business partner records in a data breach that had continued, undetected, for almost two years. It wasn't the first health care industry breach of 2015, and it probably won't be the last. It wasn't even the largest: back in January, hackers hit Anthem, the nation's second largest health insurer, and stole as many as 80 million people's records.

Medical records are a juicy prize on the black market, selling for as much as $70 each, as Jim Trainor of the FBI Cybersecurity Division told CBS News in February. NPR's "All Things Considered" even reported recently that it found a "value pack" of ten Medicare numbers selling for about $4,700. So if your company is in the business of health care, you are almost certainly in a hacker's sights, and your data security is due for an immediate check-up.

Thursday, October 15, 2015

Your Bank Account's Safety is Your Responsibility

When fraud siphons cash out of your individual bank account, the law requires your bank to cover your losses in most cases. That's not the case for business accounts, even for one-person businesses. For the small business owner who gets stung by a cybercriminal, that can make a bad situation far worse.

We've discussed basic steps for avoiding cyber fraud before, but these recommendations bear repeating:
  • teach your employees the early warning signs of fraud
  • change passwords frequently
  •  require two people to approve any funds transfers or changes to your list of authorized payees
  •  perform all your financial transactions on a computer that's both password-protected and not connected to the rest of your network
If you have questions, or if you think you're being targeted, our security experts are here to help you protect your network — and your bank account.

Monday, October 5, 2015

Shortcut Keys for Windows 10

For those of you early adopters wanting to dive into Windows 10, click here for a two page guide from Microsoft that lists shortcut keys that you can use from the desktop in Windows 10.

Monday, September 28, 2015

Is Your Health Care Data Exposed to Cybercrime?

Health care's resistance to data breaches is at an all-time low, and the epidemic is getting worse. So says a recent study from Ponemon Institute, the leading data privacy and security research center. The numbers are intimidating: 90 percent of the country's health care organizations have had a data breach, such a huge percentage that it's affected more than 120 million people — one-third of the US population. Most breaches are due not to negligence, but to criminal attacks. And the pace of these attacks is accelerating: while 37 million health care records were compromised between 2010 and 2014, 99 million were compromised in the first quarter of 2015 alone.

However, the Ponemon study also offers some hope. More than two-thirds of health care data breaches are discovered during audits or assessments, and it turns out they're primarily caused by weak, stolen, or lost credentials and lost or stolen mobile devices — vulnerabilities that are relatively easy to address.

 If you're a health care company, it's time to apply some preventive care. Our security guide,"The 5 Critical Elements of Risk Assessment," will help you develop a treatment plan. After reading it, contact us for next steps.

Monday, September 21, 2015

Office 365 Bests Google Apps as Cloud Productivity Champion

Google Apps were a game-changer when they first came out, and they've owned the market for productivity software as a service ever since — largely because Microsoft's cloud-based versions of familiar Office applications lagged so far behind their on-premise peers in terms of features and functionality. Now that Office 365 has stepped up its game, Google Apps' market dominance is slipping, at least according to a new study.

The survey by cloud access security broker Bitglass shows that Office 365 tripled its adoption rate from 7.7 percent in 2014 to 25.2 percent in 2015. By comparison, Google Apps' adoption rate only climbed from 16.3 percent to 22.8 percent. Regardless of platform, though, the survey shows that worldwide, businesses of all sizes are giving up on-premise productivity suites in favor of cloud-based alternatives. Adoption rates have doubled in the last year and more than half of global businesses have now made the switch.

If you're considering moving your office productivity tools to the cloud, Xantrion can help you decide which tools to use and how to make sure they deliver the functionality and security your users expect and need.

Monday, September 14, 2015

Hack Me Once, Shame On You. Hack Me Twice…

In 2008 and 2009, Wyndham Worldwide Corp. was hacked three separate times, exposing more than 619,000 customer credit cards to more than $10.6 million in fraudulent charges. As a result, the US Federal Trade Commission sued the hotel chain for failing to take reasonable steps to protect consumer information.

Wyndham claimed it hired five different security consulting groups to audit its systems, but that none were able to find and fix the security hole that let the hackers into the company's systems. Wyndham's lawyers argued that these were reasonable steps, even though they were ultimately unsuccessful, but an appeals court ruled in August that the FTC could proceed in bringing enforcement action against the chain.

This suggests that in the future, the bar for doing enough to keep your customers' data safe is going to rise. If you aren't sure whether you need to do more, download our guide to "The 5 Critical Elements of Risk Assessment" and call us for a security audit.

Friday, September 4, 2015

Installing Windows 10: Not For Amateurs

We recently surveyed Xantrion engineers to see whether the free upgrade to Windows 10 was something that people should undertake on their own.  The answer is that, while Windows 10 is a fine operating system, most users won’t be able to complete the upgrade without some amount of professional troubleshooting. 

Our engineers have upgraded a variety of systems at this point ranging from custom gaming rigs to stock computers from major manufacturers.  The computers also ran the gamut from brand new to 6 years old running Windows 7 or 8.1.   Our experience has been that only 10% of computers upgraded without issue. 80% of computers worked fine after some troubleshooting.  Another 10% of the upgrades failed entirely with the computers needing to be rebuilt from scratch.  The 80% of computers that required troubleshooting could most likely be handled by retail support services from stores such as Best Buy.  Unfortunately, the troubleshooting is likely beyond what a typical user might be expected to handle. 

The bottom line is that Windows 10 is a good operating system and you should feel comfortable buying a new computer running it.  However, you should be prepared for a trip to your local repair shop to solve problems you are likely to encounter if you upgrade an existing system.

Monday, August 24, 2015

Cyberthreats: A Bullet Aimed at the Bottom Line

CFOs no longer believe that cyberattacks are exclusively a problem for the IT department to handle. In fact, a recent Deloitte survey shows they consider cyberattacks one of the greatest threats to a company's financial health. Meanwhile, a new Grant Thornton report on CFO involvement in security indicates that CFOs have ultimate responsibility for security at 38 percent of organizations. The same report shows that nearly half of executives think the biggest barrier to developing an enterprise-wide cybersecurity strategy is an inadequate understanding of cyber risks and their impacts.

If you're a CFO who believes the security buck stops at your desk, our guide to the 5 Critical Elements of Risk Assessment will help you develop a plan for staying on top of new threats while implementing protections that balance affordability and effectiveness.

Monday, August 17, 2015

Cyber Cons Are Getting Increasingly Clever: You Should, Too

Determined criminals are constantly inventing new ways to access your company bank account. Sometimes they try to break in. Sometimes they try to steal your passwords and account information. But some of their techniques are designed to get you to simply hand over the money — and these cyber cons are becoming even more common.

One con we recently became aware of involved a corporate controller who received what looked like email from the company's CFO forwarding a request from the CEO to process a wire transfer. In another case, a cyber con artist registered a domain name similar to that of a large manufacturer, then bribed an employee in the manufacturer's accounts receivable department. Click here for more on how to avoid cons like these.

Monday, August 10, 2015

Cybersecurity is a Top Management Issue

If the devastating and embarrassing hacks successfully perpetrated on Target, JPMorgan Chase, Home Depot, and other established brands have proved one thing, it's that top management needs to take responsibility for cybersecurity. However, a recent Ponemon study shows that most boards of directors don't understand the risks as well as they should. 

Smart C-level executives and boards of directors are starting to recognize just how much responsibility they have for protecting the safety, security, and integrity of their networks and data. They're finally aware that cyber risk is one of the most pressing threats to the business, right up there with credit risk, liquidity risk, and operational risk. But awareness isn't enough. It takes action:
  1. Educating the board and C-suite about the company's cyber risk profile
  2. Finding sufficiently expert advisors to provide ongoing insight and assistance
  3. Conducting regular reviews of the company's cyber risk management plans and breach readiness status 
Xantrion can help you understand your organization's risk profile and improve your ability to manage the cyber risks you face. Contact us for help building an approach to cybersecurity that reaches all the way to the top.

Monday, August 3, 2015

Sorry, Windows Server 2003, We're Through


Microsoft officially stopped supporting Windows Server 2003 on July 14. That means no more patches or upgrades to fix glitches, bugs, and most importantly, security issues. That's not a great position to be in, considering that as recently as 2013, Microsoft issued 37 patches to Server 2003, an average of more than 3 patches a month.

We know breaking up is hard to do, even when you've known for a while that it has to happen. Your legacy applications may not run on newer versions of Microsoft Server, and your existing hardware may not support them. Not upgrading is not an option, though. For one thing, running an unsupported OS puts you out of PCI and HIPAA compliance. More importantly, it's now open season for hackers on Server 2003 — and if you're still running it, you're on your own. 

It's time to say goodbye to Server 2003. If you're still relying on it, or if you're trying to prioritize the changes that upgrading is going to require, let us help you make a plan to move on.

Monday, July 27, 2015

Public or Private Cloud? Wrong Question

 If you're considering moving some (or all) of your applications to the cloud, your first question might be "public or private?" That's a false choice, though. According to Verizon's latest State of the Market Enterprise Cloud 2014 study, the breadth of cloud services available today can't be broken down that easily. It makes more sense to choose an appropriate cloud service for each individual workload based on these three criteria:
  1. the risk profile of the workload 
  2. how the workload and associated data are divided between your premises and the cloud service provider's
  3. the amount of cloud environment management you're willing to shoulder
We couldn't agree more with Verizon's conclusions for assessing which variation of cloud, if any, is appropriate for your various applications. Download Verizon's free study — you'll find the details on pp. 5-6.

You'll also notice that Verizon lists all the services a cloud project might require: consulting, application portfolio evaluation, deployment and architecture design, "business of IT" support, active management of both on-site and remote cloud hardware and software, user and helpdesk support, and services around other IT areas affected by the cloud. Xantrion offers all of these services, and we're ready to help you start designing a plan to use cloud services in the ways best suited to your business.

Monday, July 20, 2015

One Foolproof Trick for Better Passwords

So you're using a password management tool to keep track of all your passwords. What if that tool gets hacked? That's not a joke — it happened last month at LastPass, a web-based service that encrypts multiple passwords. Although LastPass users' actual passwords weren't compromised, their email addresses and password reminders were.

The LastPass incident is a valuable reminder that the most secure place to store your passwords is still inside your head. But can you remember the password for every website you use without making the security mistake of reusing passwords? We certainly can't. That's why at Xantrion, we recommend and use a simple trick that generates passwords that are hard to crack but easy to recall. It just takes three steps:
  1.  Start with a word you won't forget, and spell it with at least one special character. For example, "apple," spelled "4pp!e." You'll use this "seed" password in all your other passwords.
  2. Come up with a simple algorithm based on the site's domain name. For example, you could use the first and last letters of the name as the first and last letters of your password
  3. Combine the two. In our example, then, your password for WebEx would be w4pp!ex, and your password for Salesforce would be s4pp!ee.
You can make the details as complicated as you want, but as long as you remember the domain name and your personal algorithm, it's easy to generate unique, high-quality passwords you still won't have to write down or store anywhere.


Monday, July 13, 2015

Spending Smarter on Security

Are you putting your cybersecurity dollars where they'll do the most good? Probably not. A recent RAND study found that organizations aren't as strategic about security spending as they could be — and that as a result, their security costs will rise 38 percent over the next decade. On the other hand, RAND says that an effective security staff can cut the cost of cybersecurity by 19 percent in the first year and 28 percent by the tenth year.

Xantrion's experiences align with the study's results and its recommendations. We see technologies designed to detect and isolate intrusions offer less protection with every passing year as hackers come up with countermeasures to circumvent them. After a decade, these technologies have lost as much as 65 percent of their effectiveness. On the other hand, we've found that improving overall security hygiene and reducing risk exposure through measures like network access control, firewall policy enforcement, and patch management remain highly effective.

If you're looking for experienced security professionals who can deliver the most bang for your cybersecurity buck, contact Xantrion. We'll help you keep your protection levels high and your costs low.

Friday, July 10, 2015

How to Harness the Power of the Cloud for Security Conscious Organizations

According to a recent study by Verizon, while individual figures vary from survey to survey, the trend is clear - the cloud is now mainstream. Verizon research found that 65% of enterprises surveyed are using the cloud, and they are increasingly trusting more complex and mission-critical workloads to it.  They also found that 72% expect to put more than half their workloads in the cloud, including SaaS, by 2017.  That's up from 58% today.

Read the full article here