Monday, June 16, 2014

BYOD Best Practices

Your employees are almost certainly bringing their own smartphones, tablets, and even laptops into your workplace. The Bring-Your-Own-Device (BYOD) trend delivers plenty of benefits, of course, including reduced capital costs and increased productivity. In fact, IT research giant Gartner predicts that by 2017, half of employers will not just allow, but require employees to supply their own devices. On the other hand, as we discussed a few months ago, the key to implementing a successful BYOD program is striking a balance between productivity and security.

Whether you're requiring BYOD or just allowing it, you need a strategy to manage it — in other words, tools and policies that lock down your employees' mobile devices enough to protect your data, but not so much that they can't do their jobs. 

Xantrion can help you tailor a BYOD strategy to meet your specific needs, but the first step is to understand what your needs are. Our new BYOD Best Practices guide will educate you about the most important issues in easy-to-understand terms so you can begin to make choices about your options.

Click here to read the guide, then give us a call to discuss how we can help you strike the right balance with your BYOD program.

Cybersecurity Recommendations from our Risk Mitigation Event


As underscored in our panel discussion on May 21 at the City Club of San Francisco, cybercriminals are getting much more sophisticated. The number of attacks keeps escalating, and that means as a business owner or manager you must be extra vigilant. The following is a summary of our panel’s recommendations for mitigating risk:
  • Take a multi-disciplinary approach- financial, IT, audit, insurance, legal
  • Follow your banker’s advice to prevent fund transfer fraud
  • Technical controls only go so far; adversaries are using sophisticated social attacks so procedural defenses are just as important as technical defenses
  • Review vendor agreements, in particular for insurance requirements and indemnity
  • Get an audit so you can sleep at night and provide assurances to insurance carriers and business partners of good practice
  • Consider a specific cyber insurance policy
  • Discuss your Breach Response Plan with your lawyer before you have a data breach incident

We’ll continue to keep your informed about cybersecurity and the latest recommendations for protecting your organization from threats. If you haven’t done so already, consider subscribing to our newsletter- we cover information about cybersecurity regularly. 

Wednesday, January 29, 2014

SMBs Need to Protect Themselves More Than Ever

We mentioned in October that 2013 marked an all-time high in attempted cyberattacks on our clients. It turns out we aren't the only ones noticing the trend — around the world, hackers have stepped up their attacks on companies of all types and sizes. Target's disastrous recent data breach has grabbed headlines, but we want to emphasize to small and midsize businesses (SMBs) that their smaller size doesn't make them immune. In fact, SMBs need to be more on guard than ever.

According to Verizon's 2013 Data Breach Investigations Report, companies with fewer than 1,000 employees accounted for 40% of last year's data security breaches worldwide. In fact, 31% affected companies with fewer than 100 employees. And when you rule out accidental breaches, the numbers get even more eye-opening: Symantec's 2013 Internet Security Threat Report says 50% of all deliberately targeted attacks were aimed at companies with fewer than 2,500 employees.

Putting it bluntly, hackers see SMBs as low-hanging fruit:

1. An SMB's assets are just as valuable as a larger company's, but its defense strategies are likely to be weaker.
2. Hackers have lots of smaller companies to choose from.
3. Hackers who compromise a smaller company's infrastructure can then use it to springboard into the systems of its larger partners, vendors, and customers.

Don't make the mistake of assuming your company is too small to be a victim of cybercrime. Let Xantrion help you assess your risks and draw up a remediation plan that will both prepare you to respond to a data breach and prevent one from happening in the first place.

Thursday, November 21, 2013

Minding Your PDQs with BYOD

One of the hottest topics in IT management right now is Bring-Your-Own-Device (BYOD) -- employees using their own personally-owned smartphones and tablets for work purposes. There's no point questioning whether or not to allow it: according to Forrester Research, more than half of employees are already using their own devices for work, and the IT research giant predicts that BYOD will be standard policy within 3 years.

From a business point of view, BYOD is great news. Your employees can be productive anywhere using the tools they like best, and their devices don't come out of your budget. But from IT's perspective, BYOD is a potential security nightmare. If an employee's mobile device is lost or stolen, your company could lose control of sensitive information — bank accounts, donor lists, patient records, investment account — and incur significant business, legal, fiscal, and reputational damage. But since your employees are using multiple operating systems on a seemingly infinite variety of devices, each running an ever-changing array of apps, there's no one-size-fits-all way to protect that information.

As a BYOD company ourselves, Xantrion is extremely familiar with the privacy and security concerns BYOD raises, as well as the mitigating measures companies can take. We've evaluated the leading mobile device management solutions and identified which ones best suit specific situations. We also understand the operational best practices, like organization-wide BYOD policies and employee training, that optimize the effectiveness of technical controls.

Letting employees use their own mobile devices doesn't have to mean losing control of your business data. Call us today for help sorting through your many options and developing a custom-tailored BYOD strategy.

Smaller Businesses Have Become Bigger Targets for Digital Criminals

We've never seen anything like it. In 2013 alone, hackers and fraudsters have made more attempts to compromise our clients' data security than they did in the previous ten years combined. The primary targets seem to fall into two categories: businesses that handle large sums of money (investment advisors, accounting firms, payroll companies) and those with revenues between $10 million and $50 million. We suspect thieves choose these small and midsize businesses because they're big enough to be profitable targets, but small enough to lack enterprise-scale security.

Digital risk management needs to be a top priority for your business even if it isn't in one of these higher-risk categories. Banks are shifting part of the liability for fraud from themselves to their customers, and insurance companies are denying coverage to applicants who aren't proactive enough about protecting themselves, so start laying the groundwork today:
  • Supplement the technology you use to block technical attacks, like mobile device encryption, with procedural defenses to protect against sophisticated social attacks.
  • Ask your bank and/or auditor about best practices to protect your electronic financial transactions -- for example, requiring two confirmations for transfers over a certain dollar amount, or using a dedicated banking PC with Internet access restricted to your bank's website.
  • Consider having your business formally audited so you can use the audit to prove your adherence to best practices to insurance carriers, business partners, and regulatory agencies.
  • Work with an attorney to develop a response to fraud and data breaches before you need it.
Contact Xantrion today to find out more about how we can help you fend off security breaches and manage digital risks to your business. 

Friday, September 13, 2013

IMPORTANT NOTICE: Win XP end of life April 2014

It's always hard to say goodbye -- but if your company is still using Windows XP, the time has come to part. Microsoft has announced that April 2014 will mark XP's official End of Life (EOL). After that date, Microsoft will no longer provide paid support or security patches.

For security and performance reasons, we strongly advise our clients not to continue using XP past EOL — or to wait until the last minute to implement a newer operating system. 

Of the thousands of computers we support, nearly one in four is currently running Windows XP, so we expect high demand for our help making the migration to Windows 7 or 8. To ensure a smooth transition, we will contact you to begin the planning process. 

Thursday, August 15, 2013

Customer Kudos for Xantrion Consultant

Nothing makes us happier than positive feedback from a client, and Xantrion consultant John Warno gets lots of positive feedback from the clients he serves. But don't take our word for it — here's the most recent email we received from one of his satisfied clients.

Good morning Anne and Tom,

I have been meaning to give some feedback on John for a while.  He has always done a great job for us, very client-oriented, technically proficient and very easy to work with.  His personal style has made it  easy for our staff to work with him, which has helped us address our IT issues when they come up.  We were grateful to have him.  As a someone who runs a firm that sells professional services, I understand how important and rare it is to establish that kind of relationship with a client.

So this week I’m working in our office in LA.  John was here when I came in yesterday.  Listening to him talk to our staff here, from our regional VP to our administrative assistant, I was struck by his genuine desire to be helpful and his professional yet open, warm manner.  You guys should be proud of him because he represents Xantrion so well.  We feel very fortunate to have him working with us.

I hope you are both well and thriving.  Things are going well for us as we move through an exceptionally busy year.  Xantrion and John are part of what has made us successful.

Many thanks,

Paul

Paul Harder | President
Harder+Company Community Research