Thursday, October 29, 2015

The Internet of Things: Boon, Bane, or Both?

You've probably heard a lot of talk lately about the Internet of Things (IoT) — the idea of connecting objects ranging from medical devices to kitchen appliances to the Internet so they can collect, use, and share data for better performance and greater efficiency. The IoT could change our lives dramatically, but experts have some serious questions about how to handle the amount of data the IoT will generate, who will own that data, and how to keep it both secure and private.

The evolution of the IoT is going to create new security vulnerabilities at home and at work that we've never had to consider before. Where will our data end up, and how will it be used? It's something we're thinking about a lot at Xantrion, and we think you should be, too.

Thursday, October 22, 2015

The Health Care Industry Needs a Security Booster Shot

In early September, a Blue Cross Blue Shield affiliate in upstate New York revealed that hackers had compromised 10.5 million patient and business partner records in a data breach that had continued, undetected, for almost two years. It wasn't the first health care industry breach of 2015, and it probably won't be the last. It wasn't even the largest: back in January, hackers hit Anthem, the nation's second largest health insurer, and stole as many as 80 million people's records.

Medical records are a juicy prize on the black market, selling for as much as $70 each, as Jim Trainor of the FBI Cybersecurity Division told CBS News in February. NPR's "All Things Considered" even reported recently that it found a "value pack" of ten Medicare numbers selling for about $4,700. So if your company is in the business of health care, you are almost certainly in a hacker's sights, and your data security is due for an immediate check-up.

Thursday, October 15, 2015

Your Bank Account's Safety is Your Responsibility

When fraud siphons cash out of your individual bank account, the law requires your bank to cover your losses in most cases. That's not the case for business accounts, even for one-person businesses. For the small business owner who gets stung by a cybercriminal, that can make a bad situation far worse.

We've discussed basic steps for avoiding cyber fraud before, but these recommendations bear repeating:
  • teach your employees the early warning signs of fraud
  • change passwords frequently
  •  require two people to approve any funds transfers or changes to your list of authorized payees
  •  perform all your financial transactions on a computer that's both password-protected and not connected to the rest of your network
If you have questions, or if you think you're being targeted, our security experts are here to help you protect your network — and your bank account.

Monday, October 5, 2015

Shortcut Keys for Windows 10

For those of you early adopters wanting to dive into Windows 10, click here for a two page guide from Microsoft that lists shortcut keys that you can use from the desktop in Windows 10.

Monday, September 28, 2015

Is Your Health Care Data Exposed to Cybercrime?

Health care's resistance to data breaches is at an all-time low, and the epidemic is getting worse. So says a recent study from Ponemon Institute, the leading data privacy and security research center. The numbers are intimidating: 90 percent of the country's health care organizations have had a data breach, such a huge percentage that it's affected more than 120 million people — one-third of the US population. Most breaches are due not to negligence, but to criminal attacks. And the pace of these attacks is accelerating: while 37 million health care records were compromised between 2010 and 2014, 99 million were compromised in the first quarter of 2015 alone.

However, the Ponemon study also offers some hope. More than two-thirds of health care data breaches are discovered during audits or assessments, and it turns out they're primarily caused by weak, stolen, or lost credentials and lost or stolen mobile devices — vulnerabilities that are relatively easy to address.

 If you're a health care company, it's time to apply some preventive care. Our security guide,"The 5 Critical Elements of Risk Assessment," will help you develop a treatment plan. After reading it, contact us for next steps.

Monday, September 21, 2015

Office 365 Bests Google Apps as Cloud Productivity Champion

Google Apps were a game-changer when they first came out, and they've owned the market for productivity software as a service ever since — largely because Microsoft's cloud-based versions of familiar Office applications lagged so far behind their on-premise peers in terms of features and functionality. Now that Office 365 has stepped up its game, Google Apps' market dominance is slipping, at least according to a new study.

The survey by cloud access security broker Bitglass shows that Office 365 tripled its adoption rate from 7.7 percent in 2014 to 25.2 percent in 2015. By comparison, Google Apps' adoption rate only climbed from 16.3 percent to 22.8 percent. Regardless of platform, though, the survey shows that worldwide, businesses of all sizes are giving up on-premise productivity suites in favor of cloud-based alternatives. Adoption rates have doubled in the last year and more than half of global businesses have now made the switch.

If you're considering moving your office productivity tools to the cloud, Xantrion can help you decide which tools to use and how to make sure they deliver the functionality and security your users expect and need.

Monday, September 14, 2015

Hack Me Once, Shame On You. Hack Me Twice…

In 2008 and 2009, Wyndham Worldwide Corp. was hacked three separate times, exposing more than 619,000 customer credit cards to more than $10.6 million in fraudulent charges. As a result, the US Federal Trade Commission sued the hotel chain for failing to take reasonable steps to protect consumer information.

Wyndham claimed it hired five different security consulting groups to audit its systems, but that none were able to find and fix the security hole that let the hackers into the company's systems. Wyndham's lawyers argued that these were reasonable steps, even though they were ultimately unsuccessful, but an appeals court ruled in August that the FTC could proceed in bringing enforcement action against the chain.

This suggests that in the future, the bar for doing enough to keep your customers' data safe is going to rise. If you aren't sure whether you need to do more, download our guide to "The 5 Critical Elements of Risk Assessment" and call us for a security audit.