Friday, May 17, 2013

Hacks & Attacks: Smaller Isn't Safer


Your business may be small, but you still need to think about protecting your important data and assets. According to Symantec's latest Internet Security Threat Report, 31% of all deliberately targeted hacker attacks are now aimed at SMBs, a 13% increase in just one year.  Why? Simple: SMBs typically have less network security than larger companies, and that makes them low-hanging fruit. Tech startups, accounting firms, legal practices, and other thriving SMBs can be temptingly juicy, both for their own resources and as a convenient springboard for a larger attack.  In fact, we have seen a couple of small businesses be targets of payroll and banking attacks locally over the past 3 months.

Typically, hackers leapfrog over standard network security with social engineering. They gather data from social networking sites about a specific victim within a company. Using that data, they craft email that looks like it originates from a known and trusted source ("spear phishing") or they spoof or infect a website the victim visits frequently ("waterholing"). When the victim opens the email or visits the site, it launches sophisticated malware that gives the hackers more access to the network so they can steal its data or use it to attack other targets.

In an era of socially engineered attacks, the best defense is to assume you're a target. You don't have to give up social networking sites. You do, however, need to start thinking about your employees themselves as your first line of defense. Start by raising company-wide awareness about spear phishing, waterholing, and other targeted attacks. After that:

-Develop comprehensive security policies and procedures.
-Review those policies and procedures with employees.
-Enforce them without exception. No one, even your top officers, should be exempt.
-Re-evaluate them regularly to ensure they're up to date.

Xantrion stays on top of security trends and follows industry best practices for blocking known attacks and mitigating the damage from any that get through. Let us help you evaluate your risks and develop policies and practices to manage them — call us to get started right away! 

Thursday, April 11, 2013

The Invisible Hole in Your Data Security

Data security is about a lot more than just passwords and firewalls. You may be overlooking serious risks to your business simply because you don't realize they're risky.

One current IT trend is a perfect example: allowing your employees to use their own smartphones and tablets on your corporate network. Letting employees access business information on personal devices wouldn't be so popular if it didn't have obvious benefits. On the other hand, it also has some potential drawbacks you may not have considered.

Imagine one of your employees losing a smartphone to a street thief. It shouldn't take a huge stretch of imagination -- smartphone-related street crime is growing nationwide and now accounts for more than half of all robberies in San Francisco. (In fact, one of our own team members was recently waiting at a bus stop when someone ran up and snatched an iPhone from the hands of the person standing next to her.)

Now, imagine your employee emailed himself an unencrypted document containing sensitive data like banking information, health records, or Social Security numbers. He intended to retrieve and work on it later on a secured laptop, but all his email gets pushed to his now-stolen smartphone, too. That document is now out of your company's control.

Granted, most thieves simply wipe stolen devices and resell them, but money and business secrets aren't the only things you could lose. With privacy laws requiring you to disclose the loss of confidential information, you now face potential fines for noncompliance -- not to mention the hit to your company's reputation.

Theft shouldn't be your only worry, either. What if you're accused at a trade show of trying to steal a competitor's business secrets by taking photos with the personal phone you also use for business? If your accusers seize your phone to copy its contents, they now have access to all your personal and corporate data. If you refuse to turn over your phone, your competitor may sue and subpoena its contents, which puts your company at risk of both a data breach and a hefty legal bill.

Security breaches often happen for one of these reasons:
1. You didn't follow your own data security policies.
2. Your data security policies aren't reasonable or realistic.
3. You don't have data security policies to begin with.

Let Xantrion help. We'll work with you to find the holes in your data security, patch them, and create security policies that make sense for the needs of your business. Contact us today to schedule an assessment.




Monday, February 25, 2013

Windows 8: Yes or No?

Windows 8 is visually different from earlier versions of the Windows OS we've all grown used to. After spending several weeks testing it to decide whether or not to recommend it to our clients, our engineers have reached a consensus: Don't upgrade unless you need to.

To be fair, many of the changes "under the hood" boost speed and performance, especially on laptops and aging desktops. On the other hand, the new Metro user interface is confusing and counterintuitive to anyone who isn't already familiar with it from using a Windows tablet. We're expecting lots of support requests from users who get lost trying to perform basic tasks like exit, shutdown, and restart.

If you do need to upgrade, we can disable Metro and configure Windows 8 so it works more like Windows 7. However, we can only think of a handful of reasons to upgrade:
  • You're currently running Windows XP and want to be able to use Office 2013.
  • You plan to deploy Windows tablets, and you want to use the same OS on your laptops and desktops.
  • You plan to add a large number of computers with Windows 8 preinstalled, and you want to upgrade your existing computers for consistency. 
If you're still not sure whether Windows 8 is right for your business, give us a call. We'll help you sort it out.

Tuesday, December 18, 2012

Double Your Data, Double Your Confidence

We've recently added a second data center in Salt Lake City to supplement the one we already operate in Denver. In addition to doubling our capacity for remote hosting and offsite data storage, this new colocation facility lets us offer an extra layer of disaster preparedness to our clients for whom a single backup just isn't enough. In fact, Xantrion senior consultant Brian Taylor has already set that up for one of our clients, a financial services firm that wanted to be absolutely certain it could continue to operate.

Taylor spent a week in our Oakland offices setting up and testing all the hardware and software destined for the new data center and working with vendors to create a secure Internet connection between Salt Lake City and Denver. Then he and operations manager Nick Hensley installed the new equipment in Salt Lake City, with help from operations manager Christian Kelly.

"After that, replicating the client's data from Denver to Salt Lake City only took a week or so," Taylor says. "All I had to do was set up the software that compresses and copies the data, then make sure it continued to update incrementally after the initial full replication.

The financial services firm now has identical copies of its mail, file, and terminal servers, as well as all of its critical data, in two locations. Each is set to fail over to the other in the unlikely event of a significant outage at either data center. And Taylor, who's now helped to plan and set up both remote data centers, is ready to duplicate the process for any other Xantrion client that needs to keep functioning in even the worst-case scenario.

Wednesday, October 31, 2012

Replacing Exchange 2003: Making Smart Choices


If you're currently using Exchange 2003 to handle your email, it's definitely time to upgrade — but to what? Here's what Xantrion recommends for organizations with 150+ users:

·         If cost is your primary concern, upgrade your in-house Exchange server.


·         If data security and disaster recovery are business-critical, move your email to a hosted private Exchange server — that is, a server hosted in a secure remote data center, but dedicated to your organization alone.
You'll notice that we do not recommend Office 365 or Gmail for our larger clients. The chart below will explain why.


Option
2-Year Total Cost of Ownership
Comments
In-House Exchange
$54,859*

Lowest-cost method of providing full Exchange-based functionality.  

Vulnerable to natural disasters.  
Requires internal staff skilled in mail server management.
Hosted Private Exchange
$66,362

Full Exchange-based functionality.

Hosted in a disaster-resistant data center in Colorado.  
Does not require internal staff skilled in mail server management.
Office 365 Exchange
$51,790

Vulnerable to a San Francisco earthquake.  

Does not require internal staff skilled in mail server management.
Gmail
$64,728

Has fewer features than Exchange.

Security, privacy, and compliance concerns.
Vulnerable to a San Francisco earthquake.
Does not require internal staff skilled in mail server management.


*TCO includes the estimated cost of in-house engineers needed to maintain the server infrastructure (if any) and administer the mail system, as well as the cost of off-site data backup. HIPAA-compliant mail archiving would add $12/user per month, plus a one-time fee of $990.

Tuesday, September 18, 2012

Is Carbonite online backup service appropriate for my business?


As online backup services proliferate and the cost to back up a gigabyte of data steadily drops, we are regularly asked about really inexpensive solutions, particularly Carbonite.

We do not recommend Carbonite for our clients. Here's why:

1. Carbonite only maintains one copy of your data. If anything happens to that single copy, your backup is simply gone.

2. We've found numerous online complaints about Carbonite's support and system performance, including these recent examples:

-A customer who was unable to restore 75% of his data after a crash.
-A customer who lost access to a 300Gb+ backup for seven weeks.
-A customer who struggled to get a response from Carbonite support after his backup stopped working entirely. 

3.  Carbonite is unable to back up a live Exchange or SQL database. This alone should be a deal breaker for business users! Carbonite itself acknowledges this is an issue and suggests that you back up your database using another tool, then use Carbonite to back up the back up. We’ve found that this doesn’t work very well. For one thing, it doesn’t allow you to verify that the third party backup took place. For another, a full Exchange backup is so large and takes so long that you'll probably only manage one offsite backup per month — one per week, if you're lucky.  

Considering other offsite backup options? Give us a call. We’re happy to help.

Monday, August 13, 2012

Well planned and executed projects: that’s the Xantrion way!


Earlier this year, Xantrion engineer Stephen Ferrero took on a complicated project that involved upgrading a critical line-of-business application for a client that could only interrupt its 24/7 operations with a single day of downtime.

Working with the software vendor's technical staff and a third-party VAR as well as our client's internal production and testing teams, Stephen converted and backed up a large SQL database, configured servers, virtualized the application, and upgraded the necessary desktop clients. He also performed ample up-front planning and testing to confirm the timing of each step of the upgrade — and drew up a contingency plan for reinstalling the previous version of the software if necessary.

The final stage of the upgrade required the client to shut down operations so the upgrade team could complete some critical tasks. One day later, the software upgrade was finished and production restarted with no delay. The project went so smoothly, the client emailed us a few days later to say the upgrade would not have been possible without Stephen's diligent support.

Well planned and executed projects: that's the Xantrion way!