On reviewing a few reports on the state of Internet Security, lately I have observed a pattern nobody seems to want to talk about. Perhaps the overuses of such issue and the constant reminders about it have become common and invisible signs for our IT-avert and strained eyes.
Here we go again: most security breaches both at home and at the workplace happen due mainly to human error.
Although I am also tired of repeating the same long list of safe actions on visiting Websites, opening email attachments, replying to certain messages and all that jazz; this time I would like to focus on something that should concern you: your personal information. Even better, these are only a few tips to protect your financial information.
1. Financial institutions will never contact you via email asking for your personal information, they already have it when you signed up the contract. Do not provide anything personal to messages that look legitimate; but are not.
2. Whether you receive electronic or printed statements for your credit cards and banking accounts, peruse them carefully every month, and clarify charges you don’t identify as soon as you review your statement.
3. Change passwords every few months, at least make an effort to change them every six months or annually. Select easy to remember passwords for you, but that are complex and difficult to guess for everybody else; a longer than 7 characters combination of numbers, uppercase and lowercase letters is best. Dare I suggest you base them on your name, the institution, a date and even perhaps a sequential number in a way that only you know? For example, I would set something like this for Uberbanken Bank: user name “hector_curiel” password “HC1999UberBank01”.
4. The same way you shred confidential paper based documents and expired credit cards, make sure no personal information is being given away when you dispose of external Hard Drives, USB flash drives, and obviously computers. Make sure the contents of such devices are erased and if at all possible, destroy the Hard Drives.
5. When connecting wirelessly to the Internet, make sure the signal you are using is encrypted. If not possible, at least make an effort not to transmit any confidential information in the form of email –or similar- messages; also avoid on-line banking when this is the case.
As you can see, all it really requires is a little bit of common sense. If you start educating yourself on best practices at work, at home, and when using public facilities; the virtual world will become a safer place for us all.
A simple search on the internet for what you want to know, and depending on your Internet literacy and needs, will take you to places such as these:
http://corp.support.com/blogs/post/7-common-sense-ways-protect-your-online-bank-account
http://www.tdameritrade.com/security/onlineSafetyTips/onlineSafetyTips.html
http://www.commonsense.com/internet-safety-guide/
http://ask-leo.com/how_do_i_stay_safe_in_an_internet_cafe.html
Enjoy and use the Web appropriately and you’ll help us all, starting with yourself.
Nothing Personal.
Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts
Saturday, July 31, 2010
Saturday, July 17, 2010
Extracts from Computer Crime and Security Survey
This week I received the 14th Annual Computer Security Institute’s Computer Crime and Security Survey, Executive Summary. It is a long document with plenty of tables and graphs; along with much IT and Information Security related jargon that in reality only IS Professionals fully understand.
However, a few figures catch my attention on the Types of Attacks Experienced by businesses: while some assaults that only technically-inclined individuals can perform vary year after year; some easier to understand for the average person are worth mentioning.
The Exploit of wireless networks reduced considerably to only 7.6%.
The three more prominent types of “attacks”:
3. Insider abuse of Net access or Email @ 29.7%, down from almost 60% in 2007
2. Laptop/mobile device theft @ 42.2%, down from 50.0% in 2007
and
1. Malware infection @ 64.3%. Up from 52% in 2007 and 50.0% in 2008
How are you protecting your data on these regards?
Are your personnel being trained on and constantly reminded of best navigation and Internet use practices?
Are your portable devices secured through strong authentication and encryption?
and
Most importantly, what type of malware protection does your business utilize?
Average losses due to these attacks, although lower than the US$345,000.00 in 2007; are still high at US$234,000.00
I’ve seen companies still using “free” products believing it is cheaper to have these packages instead of proper protection for their assets.
I’m sure yours is not one of them. Is it?
However, a few figures catch my attention on the Types of Attacks Experienced by businesses: while some assaults that only technically-inclined individuals can perform vary year after year; some easier to understand for the average person are worth mentioning.
The Exploit of wireless networks reduced considerably to only 7.6%.
The three more prominent types of “attacks”:
3. Insider abuse of Net access or Email @ 29.7%, down from almost 60% in 2007
2. Laptop/mobile device theft @ 42.2%, down from 50.0% in 2007
and
1. Malware infection @ 64.3%. Up from 52% in 2007 and 50.0% in 2008
How are you protecting your data on these regards?
Are your personnel being trained on and constantly reminded of best navigation and Internet use practices?
Are your portable devices secured through strong authentication and encryption?
and
Most importantly, what type of malware protection does your business utilize?
Average losses due to these attacks, although lower than the US$345,000.00 in 2007; are still high at US$234,000.00
I’ve seen companies still using “free” products believing it is cheaper to have these packages instead of proper protection for their assets.
I’m sure yours is not one of them. Is it?
Labels:
attacks,
data protection,
encryption,
infection,
losses,
malware
Saturday, May 29, 2010
Fortune 500 and Symantec
On May 3, 2010 Fortune Magazine released the Fortune 500 list. The volume (161, Number 6) is a heavy one; weighting more than any other magazine published this month, and more than any regular night time fiction novel.
On page 15, opposite to the “Welcome to the 2010 Fortune 500” Letter from the Publisher, the full page ad reads:
Are you prepared to face today’s biggest IT risks?
- Confidence in a connected world (S) Symantec.
Then from pages 211 to 237 (or F-1 to F-26) each footer ad is a Symantec one. Some of the main messages from those mini-ads alternate the following two sentences; along with brief paragraphs that contain and highlight these points:
PUT SECURITY FIRST –data loss prevention –encryption –Web security –endpoint protection –virtualization management
CONTROL YOUR DATA –archiving –deduplication –disaster recovery –green IT –storage software –Symantec Hosted Services
It is obvious that Symantec sponsored the list. For those of us not around technology names or new to the IT world; know that Symantec is the company that bought/merged with smaller and diversified ones that produced and sold products such as Norton Antivirus, System Works, WinFAX, Veritas Backup, pcAnywhere, and many others.
The Symantec Corporation now focuses exclusively on services, software and devices that have only one purpose: secure data (PUT SECURITY FIRST and CONTROL YOUR DATA).
The company is ranked 353 in the Fortune 500, and number 3 as a software company after Microsoft (36) and Oracle (105). Its 2009 revenues were US$6,150,000.00.
If a company of these qualifications is trying to -finally- convey the signature on each of those ads: Confidence in a connected world message to readers of such publication; what should we take from it?
The Confidence in a connected world translation is simple: Self- Assurance in an Internet based environment.
Or, using trendy words: Security (your data) in a Cloud-Computing environment.
Is it just coincidental that Computotal CSI has been focusing on Total Data Security for the past 15+ years?
Proud to be part of such a futuristic enterprise.
On page 15, opposite to the “Welcome to the 2010 Fortune 500” Letter from the Publisher, the full page ad reads:
Are you prepared to face today’s biggest IT risks?
- Confidence in a connected world (S) Symantec.
Then from pages 211 to 237 (or F-1 to F-26) each footer ad is a Symantec one. Some of the main messages from those mini-ads alternate the following two sentences; along with brief paragraphs that contain and highlight these points:
PUT SECURITY FIRST –data loss prevention –encryption –Web security –endpoint protection –virtualization management
CONTROL YOUR DATA –archiving –deduplication –disaster recovery –green IT –storage software –Symantec Hosted Services
It is obvious that Symantec sponsored the list. For those of us not around technology names or new to the IT world; know that Symantec is the company that bought/merged with smaller and diversified ones that produced and sold products such as Norton Antivirus, System Works, WinFAX, Veritas Backup, pcAnywhere, and many others.
The Symantec Corporation now focuses exclusively on services, software and devices that have only one purpose: secure data (PUT SECURITY FIRST and CONTROL YOUR DATA).
The company is ranked 353 in the Fortune 500, and number 3 as a software company after Microsoft (36) and Oracle (105). Its 2009 revenues were US$6,150,000.00.
If a company of these qualifications is trying to -finally- convey the signature on each of those ads: Confidence in a connected world message to readers of such publication; what should we take from it?
The Confidence in a connected world translation is simple: Self- Assurance in an Internet based environment.
Or, using trendy words: Security (your data) in a Cloud-Computing environment.
Is it just coincidental that Computotal CSI has been focusing on Total Data Security for the past 15+ years?
Proud to be part of such a futuristic enterprise.
Monday, May 24, 2010
Secure your Data
Where does your data reside? Do you carry it with you? How? Is it instead somewhere in what some people call “servers”? A combination of these?
Is your data important? Could you survive without it?
Wouldn’t it be nice not to carry your data around on laptops or storage units, and instead know exactly where it is and be able to access it at anytime from anywhere?
We’ll get there soon. Actually, some companies are already there: from documents to full databases to email and more, there are a lot of providers that already offer all kind of services for us to have all of our data –and processes- living “on-the-cloud”. This is, Cloud-Computing or SaaS: Software as a Service.
Some of us are still reluctant to do this, or we are worried about the fact that we could lose control over our data not knowing exactly where it is. Or rather, we are so used to “feeling” our data in our hands that the simple thought of not having it with us is like not having it at all.
So, in this “felt” scenario we are also used to backing our data up to even more physical devices so that we sleep well knowing our data is safe.
Until the day comes when we make the mental switch and convince ourselves that the cloud is more secure than our portable devices, we will continue to have the need to back it up, either to more devices (or to the cloud!)
In brief, until all our data resides on the cloud, it is necessary to save it and keep it secured.
There will also come a time when it will be cheaper to replace than to fix laptops, whether those are Windows based, Macs, Linux based, iPads or Blackberries. It will be as common as replacing cellphones was by the end of last century.
Some of us already interchangeably use a smartphone, a laptop or any computer’s Web browsers to access our email. As simple as it is now to do this, it will also be to access the rest of our data: whether it is proposals, spreadsheets, diagrams, movies or books. calendars, to-do lists and contacts too. All we need is a device that connects to the Web and presto! We are productive. No need to carry data, no need for briefcases, no need to be in the same cubicle every day.
So, before we make the full move to a Cloud-based business, we still have to protect our data. How?
Here is a very basic summary of the most important data protectors in your office:
1. UPS. But not the delivery company. UPS stands for “Uninterruptible Power Supply”.
If you have servers, you certainly have UPSs around. What these units do is protect equipment from electricity spikes, low and high voltage changes and even outages.
2. Computer storage redundancy/resiliency. Most common in desktops, workstations and (mandatory in) servers than in regular laptops, hard drives and storage units are mirrored so that if one of them is damaged, the other makes the whole system operate normally; the idea is to replace the damaged unit as soon as possible so that redundancy is attained again.
3. Operating System: MS Windows, Mac OS X, Ubuntu Linux, Google Chrome OS… whichever makes your computer/device be able to run software such as calendars, email programs or Web browsers is an OS. The newer it is and the more bits it operates on the better. For example, Windows 7 (version is 6.1! -not 7.0-) is better than Windows Vista (version 6.0) and even more than Windows XP (version is 5.1). And Windows 7 64-bit is better than Windows 7 32-bit.
4. Encryption. Barely used for its many “complications”. We only tend to encrypt very specific and important files and/or email messages. It is getting easier to implement and use, and nowadays we can encrypt not only individual files, but also entire folders; and even external memory units and hard drives, both internal and external.
5. Internet Security Suite. Of paramount importance: what most of us still refer to as “anti-virus” is most of the times a combination of anti-virus, anti-spam, anti-spyware… in brief: anti-malware.
Most suites also offer depending on vendor and package acquired a firewall, some kind of identity protection, browsing advisor features, et cetera.
6. VPN. Or similar technologies. So that whoever connects remotely to your network does so in a secure way. VPN stands for Virtual Private Network: there are no direct lines connecting offices or individual computers, rather the Internet is the conduit: by compressing and encrypting the information traveling so that prying eyes can’t do much to interpret what is being sent over “open wires”.
7. Email access. Local vs. Web based… this is getting complicated now: it is very likely that your company email is not in your physical servers. It might be, but it’s becoming easier, cheaper, faster and more ubiquitous to simply connect to the email servers on the cloud than having resources put in place to manage company’s email. Anyway, the more on-the-cloud email services you have, the better.
Are we there yet?
8. Data Backup (its main purpose: data recovery). Fortunately for all of us, on-line data backup is mature enough so that there are many options nowadays, and so are the different levels of services attached to those. From pricing to likes to features. There was a time long ago when we used to back up our data with no encryption and awkward compression using external devices such as Hard Drives, Disks, and –believe it or not- tape cassettes!
Go over the list again. Please bear in mind this is in reality an oversimplification of the terms and technologies around each of the points listed. However, if any of these is missing in your environment, better to start asking your IT department questions.
Is your data important? Could you survive without it?
Wouldn’t it be nice not to carry your data around on laptops or storage units, and instead know exactly where it is and be able to access it at anytime from anywhere?
We’ll get there soon. Actually, some companies are already there: from documents to full databases to email and more, there are a lot of providers that already offer all kind of services for us to have all of our data –and processes- living “on-the-cloud”. This is, Cloud-Computing or SaaS: Software as a Service.
Some of us are still reluctant to do this, or we are worried about the fact that we could lose control over our data not knowing exactly where it is. Or rather, we are so used to “feeling” our data in our hands that the simple thought of not having it with us is like not having it at all.
So, in this “felt” scenario we are also used to backing our data up to even more physical devices so that we sleep well knowing our data is safe.
Until the day comes when we make the mental switch and convince ourselves that the cloud is more secure than our portable devices, we will continue to have the need to back it up, either to more devices (or to the cloud!)
In brief, until all our data resides on the cloud, it is necessary to save it and keep it secured.
There will also come a time when it will be cheaper to replace than to fix laptops, whether those are Windows based, Macs, Linux based, iPads or Blackberries. It will be as common as replacing cellphones was by the end of last century.
Some of us already interchangeably use a smartphone, a laptop or any computer’s Web browsers to access our email. As simple as it is now to do this, it will also be to access the rest of our data: whether it is proposals, spreadsheets, diagrams, movies or books. calendars, to-do lists and contacts too. All we need is a device that connects to the Web and presto! We are productive. No need to carry data, no need for briefcases, no need to be in the same cubicle every day.
So, before we make the full move to a Cloud-based business, we still have to protect our data. How?
Here is a very basic summary of the most important data protectors in your office:
1. UPS. But not the delivery company. UPS stands for “Uninterruptible Power Supply”.
If you have servers, you certainly have UPSs around. What these units do is protect equipment from electricity spikes, low and high voltage changes and even outages.
2. Computer storage redundancy/resiliency. Most common in desktops, workstations and (mandatory in) servers than in regular laptops, hard drives and storage units are mirrored so that if one of them is damaged, the other makes the whole system operate normally; the idea is to replace the damaged unit as soon as possible so that redundancy is attained again.
3. Operating System: MS Windows, Mac OS X, Ubuntu Linux, Google Chrome OS… whichever makes your computer/device be able to run software such as calendars, email programs or Web browsers is an OS. The newer it is and the more bits it operates on the better. For example, Windows 7 (version is 6.1! -not 7.0-) is better than Windows Vista (version 6.0) and even more than Windows XP (version is 5.1). And Windows 7 64-bit is better than Windows 7 32-bit.
4. Encryption. Barely used for its many “complications”. We only tend to encrypt very specific and important files and/or email messages. It is getting easier to implement and use, and nowadays we can encrypt not only individual files, but also entire folders; and even external memory units and hard drives, both internal and external.
5. Internet Security Suite. Of paramount importance: what most of us still refer to as “anti-virus” is most of the times a combination of anti-virus, anti-spam, anti-spyware… in brief: anti-malware.
Most suites also offer depending on vendor and package acquired a firewall, some kind of identity protection, browsing advisor features, et cetera.
6. VPN. Or similar technologies. So that whoever connects remotely to your network does so in a secure way. VPN stands for Virtual Private Network: there are no direct lines connecting offices or individual computers, rather the Internet is the conduit: by compressing and encrypting the information traveling so that prying eyes can’t do much to interpret what is being sent over “open wires”.
7. Email access. Local vs. Web based… this is getting complicated now: it is very likely that your company email is not in your physical servers. It might be, but it’s becoming easier, cheaper, faster and more ubiquitous to simply connect to the email servers on the cloud than having resources put in place to manage company’s email. Anyway, the more on-the-cloud email services you have, the better.
Are we there yet?
8. Data Backup (its main purpose: data recovery). Fortunately for all of us, on-line data backup is mature enough so that there are many options nowadays, and so are the different levels of services attached to those. From pricing to likes to features. There was a time long ago when we used to back up our data with no encryption and awkward compression using external devices such as Hard Drives, Disks, and –believe it or not- tape cassettes!
Go over the list again. Please bear in mind this is in reality an oversimplification of the terms and technologies around each of the points listed. However, if any of these is missing in your environment, better to start asking your IT department questions.
Labels:
backup,
cloud,
cloud-computing,
encryption,
Internet Security Suite,
on-line,
OS,
protection,
redundancy,
resiliency,
SAAS,
safe,
total data security,
VPN
Subscribe to:
Posts (Atom)