Security threats come from inside

May 16th, 2012

It’s common to see companies showing confidence in their security systems. Their networks are protected from external threats, which can often lead to a false sense of being secure. With this attitude, they may stop thinking about security and fail to establish internal measures within their networks, and this is a grave mistake.

In recent years the majority of security threats and compromises have come from within the company. A common threat to companies is the logic bomb - malware that targets IT systems and deletes data. As a logic bomb is introduced from within the network, the blame often lies with a disgruntled employee with full access to internal systems.

Insider threats Giving employees full access to the network when they don’t need it is a common mistake often made by companies. There’s little need for an employee who does graphic design to have access to weekly sales records. This practice could set your company up for a considerable security problem in the future.

Dawn Cappelli, an insider-threat expert at the Carnegie Mellon Software Engineering Institute stressed, "These types of insider attacks happen to businesses of all sizes, from small companies to very large corporations." This is an important issue businesses should be aware of if they want to remain secure.

Take Precautions Security threats can be a particularly harsh nightmare for small businesses, as many don’t have an IT department or staff with the technical expertise needed to maintain a secure network. If you’re one of these organizations, it’s a good idea to hire an outside consultant to help you with your network security. With consultants, it’s important that you maintain close contact with them to ensure any issues that crop up are dealt with expeditiously.

If you don’t work with an external company there are a few things you should do when you have an employee leave the company. First, their accounts should be deleted immediately and their access privileges should also be revoked. Second, if you have accounts with shared passwords, you should change them to ensure an ex-employee can’t gain access to the system.

If you’d like to learn more about internal security, and measures you can take to ensure you are safe, we are ready to help you. Please contact us.

Published with permission from TechAdvisory.org. Source.

May 16th, 2012

If the past 10 years has taught us anything, it’s that many managers are woefully underprepared for disasters of any kind. We’re resilient though, and will always find a way to survive. One of the keys to a business’s survival during times of hardship is the Business Continuity Plan (BCP). A vast majority of organizations have one and believe it to be effective, but is it?

Here are six key non-IT functions and processes that need to be in place to ensure your company is ready to effectively execute your BCP.

Easy to use plans Many continuity plans have been developed mainly for the IT department, as such, they can be a little complicated to understand and follow if employees don’t have a technical background. You should aim to have a plan that’s easy to follow and can be understood by all employees.

Communicate plans Remember that your plan encompasses all facets of your organization. It’s crucial that every employee knows their role and the relevant actions to take when the plan is executed. To do this, you need to ensure that all employees have access to a copy of the plan and any changes or updates are clearly communicated.

Test plans Beyond communication, it’s important to conduct regular tests, with every quarter being sufficient. The tests should be as real as possible and span all departments within the organization. This will ensure that employees are aware of how they, and the systems, will react under duress. It’ll be beneficial to your business if the first time the employees execute the plan isn’t during an emergency.

Short term and long term plans Your BCP should consist of both long term and short term elements that can be easily adapted to meet changing business environments and the emergence of new threats. You should aim for an even mix of short and long term solutions that cover as wide a variety of situations as possible.

Ensure buy-in from all levels If you’re in the process of instituting a BCP you should ensure that the whole organization is onboard with the plan. If an employee is unsure about the validity of a part of the plan, take the time to find out why and ask for suggestions. An uninformed or uncooperative employee could be the difference between survival and failure in a disaster situation.

Update and Review After every test, staff turnover and technological update, you should review the plans and make changes if necessary. Essentially, if anything in the company changes, review and update the plan. Remember: just because you have an effective plan this month, doesn’t mean it’ll be so in the future.

Continuity plans are only as strong as the weakest link. In an emergency, the last thing you want is an employee following the wrong process or be unsure of what they should be doing. If this happens, you could see an exponential growth in recovery time and costs. We’re ready to tell you more, so please contact us if you would like to talk continuity planning.

Published with permission from TechAdvisory.org. Source.

May 15th, 2012

Smartphones are one of the tools that have been instrumental in blurring the lines between our personal and professional lives. While we’re at home, we access our work email and while we’re at work, we’re checking our personal email, all on the same device. As such, we tend to have a large amount of confidential information on our phones and should be taking steps to secure them.

Whether you have an Android, iPhone or Windows Phone 7, here are two tips to keep your smartphone secure:

Lock your screen If you have data or information on your phone you would like to keep secure, the first thing you should do is lock your screen. Most smartphone users lock their phone with a 4 digit number combination, but it’s recommended you use a password for higher security.

  • On Android. To establish a password on your device go to Settings and select Security. Press Screen lock. On Ice Cream Sandwich, you have six options for security, with the least secure at the top and most secure at the bottom. Many users select Pattern or Password. Enter the password twice and press Confirm.
  • On iPhone. Select the Settings app followed by General. From there select Passcode Lock and turn it on. You’ll be asked to set your passcode and confirm it.
  • On Windows Phone. To set a passcode go to the home screen of your device. Open Settings from your Application list and select Lock & Wallpaper. Press Password, enter your password and then press Done.
It’s recommended that you set a password that’s unique. Don’t use your birthday, address or phone number. At the same time, you have to make it easy to remember. If you’re having trouble coming up with a password, this video by Mozilla is a big help.

Enable remote wipe While passwords and other security codes will go a long way in preventing others from accessing your phone, it often isn’t enough. The next step in device security is to set up the ability to remotely wipe your device.

  • On Android. At this time there is no native remote wipe option on your phone. You’ll have to download an app from the Play store. The apps work by using a push service - you “push” the commands to your phone from another source i.e., a website. When you install the app, you’ll have to register your phone and access it from a website.
  • On iPhone. The iPhone has remote wipe capabilities which can be accessed through iCloud. On your device select Settings, iCloud and turn on Find my iPhone. If you lose your phone log into iCloud and select Find my iPhone. From there you’ll be able to remotely wipe your device.
  • On Windows Phone. If you lose your phone you can remotely wipe it by going to the Windows Phone website, logging in and selecting My Phone. From there you’ll be able to wipe your phone.
Even if you don’t have confidential information on your phone, it’s a good idea to, at the very least, set a solid passcode on your phone. Adding the ability to remotely wipe your phone will ensure the information won’t be viewed by other people. If you’d like other ways to keep your mobile phone secure, please contact us.
Published with permission from TechAdvisory.org. Source.

May 14th, 2012

In 2009, the video game industry recorded revenues of USD 60.4 billion dollars, double that of the movie industry. One of the biggest draws to games is not the story or gameplay, it’s the competition and sense of achievement one gets when they beat their friend’s score, or a hard level. Many businesses have started applying game mechanics to non-game situations.

The term to describe this trend is gamification, but what is it, and how can businesses use it?

What is gamification Gamification is the application of game design techniques and mechanics to non-game applications. Foursquare and its badges is a good example of this - users check in at locations to earn points, unlock badges and compete with their friends. Do they win anything? Nothing physical, but there’s something satisfying with competing with other people to be the best.

While gamification got its start with technological related operations, it has since been integrated by businesses of all sizes. Business that have adopted elements of gamification have seen improved user engagement and ROI.

How can businesses leverage gamification? Gamification is interesting because it can be applied in a variety of different business situations. For example, here are three such uses:

  • To increase employee engagement. It can be hard at times to keep your employees engaged while they’re doing mundane tasks. One of the most common uses of gamification is deploying badges to act as a motivator to encourage employees to put effort into their job. When an employee reaches a predetermined level they are recognized for their achievement. This will go a long way in improving engagement.
  • To create brand advocates. You can use gamification to turn your customers and fans into brand advocates. Before they start singing your praises, they need to be given a reason to do so. The best way to do this is to create a points/reward system. For actions such as purchases or reviews, customers gain points that can be spent on other services. Think of it as akin to the points system used by credit card companies.
  • To generate traffic. Many SMBs are dependent on their websites for revenue but struggle to get traffic to their site. Gamification techniques can be employed to encourage people to spend more time on, and return to, your website, almost like a modern loyalty program.
There are many uses for gamification and we’ll continue to see new and innovative ways to deploy it in organizations. If you’re interested in ways you can implement aspects of gamification in your business, or would like to learn more, we are here happy to sit down with you for a chat. Please contact us.
Published with permission from TechAdvisory.org. Source.

May 12th, 2012

VMware is a company that has historically focused on virtualization solutions that make conducting business easier and more efficient. With the company’s purchase of SlideRocket, an online presentation collaboration tool, VMware provides another valuable feature to any business. With integration with a new cloud storage app, this tool has become even more beneficial to businesses.

Google has recently released its cloud storage and collaboration app, Google Drive. What does this have to do with SlideRocket? Well, SlideRocket’s full set of content authoring tools have been integrated into Google Drive. This means that users of SlideRocket can use Google Drive as another way to create, collaborate on, and store presentations.

Chuck Dietrich, Vice President of SlideRocket by VMware, commented, “Together with Google, VMware is helping individuals and businesses embrace new technologies for collaboration in the cloud era.” He went on to note that SlideRocket and Google Drive provide users with a great way to do just that.

If you use SlideRocket and would like to work with other users over Google Drive, simply log into both services with the same account and in Google Drive select Create and More followed by SlideRocket. Once you log in and integrate your accounts, you’ll have access to your presentations without having to log in to SlideRocket.

If you’d like to know more about how you can virtualize your business, or the different products offered by VMware, we’re ready to tell you more. Let’s talk virtualization.

Published with permission from TechAdvisory.org. Source.

May 9th, 2012

There’s no doubt in the value of using social media to build your brand. But opinions differ in the use of social media by employees. It seems that companies are polarized in the issue, but are being slowly awakened to the fact that allowing employees to access social media at work has great benefits. Do you allow employees to access social media in your office?

There are four distinct advantages to allowing social media:

  • Increased productivity. There have been a number of studies that have found that judicious use of social media in the workplace will actually increase productivity. A study conducted by the University of Melbourne found that employees with access to social media are 9% more productive than those without.
  • Increased buy-in. Employees like to feel trusted and empowered. If they don’t you can expect to experience higher turnover and lower morale. A good way to gain trust is to allow employees to use social media in the workplace. If an employee feels like they are trusted, they’ll be more likely to stay with the company.
  • Recruiting. Small businesses have started to use social media for recruitment, but limit efforts to one account. If you have 10 employees in your organization, each with a social media account with 100 friends, you have the potential to reach 1,000 people. This is achievable if employees are allowed to access social media at work and are encouraged to share posts.
  • Identification of business opportunities. Through the use of social media, employees in charge of sales and business development can source new clients and build fruitful relationships.
There are many advantages to allowing access to social networks at the office. If you‘re hesitant to completely open the social media floodgates, try doing so in short periods, like the final three hours of the working day.

No matter what you decide, allowing access to social media is a good practice for your business. If you would like to learn more about social media and how you can leverage it in your business, we are happy to talk with you.

Published with permission from TechAdvisory.org. Source.

May 5th, 2012

With the explosion of technological devices in recent years, companies have been given a golden opportunity to foster a more collaborative environment. This has not been lost on business owners, who have adopted tools that work best with a joint effort en masse. There’s a drawback to this however, many teams simply don’t gel well in the first place, and this makes the tools redundant.

Here are seven tips on how to improve collaboration within the office environment.

  1. Open communication. One of the keys to successful teams is the adoption and encouragement of an open communication culture. With this, teams are better able to grasp what’s going on within the company, and be more efficient contributors and team players.
  2. Use the right technology. It seems like there are a million different software and technology options out there. Some of the tools available offer some fantastic features and it’s easy to get sucked in by a flashy component. It’s important that when choosing a tool you pick one that meets your company’s needs and is easy to use.
  3. Collaboration tools must play well with others. It’s beneficial to select systems that can be seamlessly integrated with other tools and software used by your employees. If your solutions don’t work together, all parties won’t be able to work together.
  4. Employee learning is key. When you find the perfect tool to use, be careful to take time and learn how to effectively use it. Training for the users of the tool is equally important.
  5. Work hard, play harder. Teams and departments should step away from their computers and actually have face-to-face meetings at least once a week. These meetings should be a mixture of formal and informal, and offer employees a chance to come together as a team, unwind and share ideas. A team that can interact well will always work together with greater efficiency.
  6. Mobilize. The smartphone is here to stay and with each passing year the number of users grows exponentially. It’s beneficial to encourage the use of these devices, and look for mobile solutions that allow users to be a part of the group while out of the office. If you do allow mobile devices, be sure to establish a clear usage policy so employees know how and when they should be using their phones.
  7. Don’t just focus on internal collaboration. One of the most common mistakes companies make is that they focus on group participation within the business, but don’t provide adequate support for external interactions. Be sure you integrate tools that provide stakeholders with a way to connect and work with teams within the company.
With a team that interacts effectively you’ll see happier employees and higher profits: a win-win situation. If you have any questions regarding collaboration tools, or other ways to increase business value please don’t hesitate to contact us.
Published with permission from TechAdvisory.org. Source.

May 4th, 2012

One selling point of the Mac is that the OS, OSX, is more secure than a computer running Windows. Many Mac users have been lulled into a sense of complacency and have been taking inadequate steps to protect their systems. A recent trojan has shocked these users into reality and left many of them wondering if their systems really are secure.

If you mention “OS X” and “virus” in the same sentence, you’ll get some weird looks from Mac users. Traditionally viruses and trojans on OS X were near non-existent, but there’s a Mac specific trojan, codenamed Flashback, that has affected more than 600,000 computers. This is big news as it shows that machines running OS X may not be as secure as first thought.

Many Mac owners are unsure of what exactly the Flashback trojan is, what it does and how to ensure they’re not infected. We’re here to help clarify the situation.

What is a Trojan and What Does Flashback Do? In general terms, a trojan is a piece of malicious software that infects a computer and gives control of part, or the whole computer to hackers. The Flashback trojan takes advantage of an OS X Java vulnerability and infects computers by tricking them into downloading a fake Java update.

When the program is installed, Flashback will download and install the main trojan code without the need for permission from the administrator. From there it proceeds to hijack your browser, redirect search queries to websites developed by hackers, and then take advantage of pay-per-click advertising.

Why Should I be Worried? While this version hijacks your browser, there are far more sinister things it could do. As this trojan acts as a downloader, there’s nothing stopping the developers from updating the malware to steal passwords, banking information and other confidential information.

How do I Ensure My Mac is Clean? Apple has released an update for machines running OS X 10.6 and later. The first step you should take is to update your computer to patch the vulnerability. To update your Mac:

  1. Press the Apple logo, located in the top right hand of your screen.
  2. Select Software Update...
  3. Press Install and Restart.
While the patch will prevent Flashback from working, it won’t delete the program if you’ve been infected. The Internet security company F-Secure has developed a script that scans your computer and removes Flashback if found. Once you have downloaded the script, open and run it. The script will search your computer and place the infected files in an encrypted ZIP folder labeled Flashback_quarantine.zip.

Flashback has infected a higher number of Macs than any other trojan to date and goes to show that Macs also have security flaws. This also serves as a reminder that you should have a virus scanner and security program running on your Mac. If you have any questions regarding the security of your Mac or other devices, please don’t hesitate to contact us. We are here to help keep your machines secure.

Published with permission from TechAdvisory.org. Source.

May 4th, 2012

Multitasking has become common in the workplace. We often have our Web browsers using multiple tabs, switch between email, social media and work. Our attention is pulled in 50 different directions and we’re having trouble focusing on one task for more than five minutes. This lack of focus has led to longer, and less productive days.

It’s time to reclaim our focus at work and here are seven tips to help you do so.

  1. Practice productivity wind-sprints. While at work, we’re normally doing work while browsing Facebook or chatting. This can be harmful for productivity and shifts your focus from important work related activities. Interval training is a great way to increase your focus. Get a timer, set it for ten minutes, and focus solely on your work. When the timer goes off take a two minute break.
  2. Defensive scheduling. Our days are filled with commitments and we struggle to keep up with our projects or find time to work uninterrupted. Schedule a meeting with yourself at a convenient time. Treat this meeting like a real meeting, no interruptions. This is your time to focus on important tasks or projects.
  3. Socialize with your tablet. Separate work from social activities with a tablet. We’re often just hitting our stride with work when BING, we get a chat message. What do we do? Immediately reply to the message. When we do that we lose our focus and struggle to regain it. Why not use use your tablet for all social activities and work computer strictly for work? Combined with tip one, this could really help you focus.
  4. Realize your unconscious focus. The vast majority of managers often aren’t sure what the top issue in their mind is. It comes with multitasking, we’re always making less important ideas critical, and this takes our focus off the most important issues. To realign your focus take some time, let your mind wander, and make note of the ideas you keep returning to. These are your most critical issues.
  5. Focus on most important tasks first. When you get into the office in the morning switch off your phone and email alerts. Focus on your most important priorities, this will give you time to get your most important work out of the way, before you shift your focus onto other less important projects.
  6. Disconnect. Many of us don’t take time to give our brains a rest, we’re always thinking and possibly worrying about work. It’s beneficial to your mental and physical health if you take time each day to disconnect from the office. Temporarily sever all ties with the office and focus on something you enjoy doing. Remember, this is your time don’t think of work, focus on the activity.
  7. Can’t focus? Consider if what you’re doing is right for you. If you find that you really can’t focus, even with the previous techniques, it might be time to consider that what you’re doing is actually something you don’t care about or enjoy. If this is true for you, then it’s time to start looking for a change.
With these tips you should see an increase in your focus and productivity. If you would like to know more about how to improve your productivity please contact us, we can help.
Published with permission from TechAdvisory.org. Source.

May 4th, 2012

Skype is the most well-known Voice over Internet Protocol (VoIP) program and is used by businesses all over the world. It offers many benefits including cheaper calls, a solid instant messaging platform that allows employees to communicate as a group, and the ability to conduct video calls with any user.

Skype has some excellent features but many businesses stick to the basics. Here are four ways you can better utilize Skype.

  • Call forwarding. If you’re expecting an important call but have to step away from the computer for a bit you can forward any calls to your phone. To set up call forwarding: open preferences and select Calls. You will see the option to set up call forwarding at the top of the page. Press the Forward calls radio followed by Set up Forwarding. Be aware that regular call rates will be charged.
  • Screen sharing. Skype is a terrific collaboration tool and many businesses take advantage of it by holding virtual meetings. You can take this one step further by sharing your screen with other parties you are chatting with. This is a fantastic way to give virtual presentations. To share your screen while in a chat press the plus symbol at the bottom of your screen, or right click, and select Share Screen.
  • Customer service tool. Using Skype is a convenient way to get in contact with your customers. Ask your website developer to put a Skype button on your website. Be sure to add when you or your employees are available to be contacted.
  • Add-ons. Skype has solid features but there are a multitude of add-on apps that can make it even better. Some apps allow for closer collaboration, let you broadcast pre-recorded messages, or record video and audio calls. The apps can be downloaded from the Skype Shop.
Skype has many useful features that when utilized allow businesses’ clients and employees to communicate with ease. If you would like to know more about using Skype or other VoIP services in your company please give us a call.
Published with permission from TechAdvisory.org. Source.