Wednesday, April 13, 2011

Protecting Your Business from Cyber-Criminals

If your company uses computers for things like email, web browsing, accounting, online banking, inventory management, or payroll, you need to know how to protect yourself from cyber-criminals. One recent government study showed that an unprotected Windows computer taken right out of the box and connected to the Internet was typically hacked within 20 minutes.
Many business owners don't realize that as a business, you don't have the same legal protection as a consumer.  If hackers break into your business network and drain your bank account because you didn’t implement adequate security, your bank is under no obligation to reimburse you.  There are numerous stories of banks refusing to reimburse businesses that lost hundreds of thousands of dollars to cyber-criminals because they didn't take sufficient security precautions to prevent the thefts.
The small business owner who recognizes the threat of computer crime and takes steps to prevent hackers from breaking in is less likely to become a victim. Here are seven things every business should do to protect its computer network:
1.       Use a firewall. This is the first line of defense for your system.  Firewalls scan all traffic into and out of your network to block unauthorized access.  There are two kinds of firewalls: software and hardware. Software firewalls such as Windows Firewall run directly on your computer.  Hardware firewalls are separate boxes that sit at the junction between the Internet and your local network. While hardware firewalls are preferred for business-grade security, either is much better than the alternative of doing nothing.  Your Internet Service Provider might include a firewall as part of their DSL or cable modem.
2.       Use anti-virus and anti-spyware software and keep it updated.  A firewall won’t block every threat.  Anti-spyware software looks for programs that secretly enter your computer and collect bits of information about you.  This could include such things as the websites you visit or the keys you type to enter a password.  Anti-virus software scans all your files, looking for known or suspected malicious code—viruses, worms, or Trojans.  Although each differs in its details, all can be serious threats.  The anti-virus software scans for them all.  Files considered threats are identified, where you can quarantine or delete them.  If you think the suspect file isn’t truly a virus, put it into quarantine.  Otherwise delete it.  In order to be effective, you need to keep anti-virus and anti-spyware software up to date.  New viruses are constantly being released by hackers, and the best AV and AS vendors issue updates to detect the latest threats at least daily.
3.       If you use a wireless network, be sure it is configured for secure encryption.  By default, a wireless router is not set up for encryption.  This means that once you turn on your WiFi, anyone with a computer who is in range of its signal can access your network.  Not only can they connect to the Internet and potentially slow down your system, they can also access your private files and secretly track your passwords, credit cards, and on-line banking information.  It is imperative you turn on encryption so that only authorized users can gain access.  Modern routers offer 3 different kinds of encryption: WEP, WPA, and WPA2.  Always use WPA2, as the others are more vulnerable to hackers.
4.       Use highly secure passwords. What are the worst passwords?  Here are a few of the most common: 123456, password, qwerty, letmein, abc123, and a few obscene words I won’t repeat here.  Do a Google search on “worst passwords” and you’ll see a complete list.  The best passwords are at least 14 characters long, don’t include any words found in the dictionary (including spelled backwards) and use a combination of uppercase and lowercase letters, numbers, and punctuation marks.  Some sources advocate using a different password for every account and changing it regularly.  At the very least you should use several different passwords for different kinds of business and personal accounts, and never share your passwords with anyone else.  If anyone else learns your password, change it immediately.
5.       Keep your operating system updated with the latest security patches. If you use a Windows computer, turn on automatic updates or go to www.update.microsoft.com/microsoftupdate to install the latest updates (but don’t turn on automatic updates for servers).  If you use a Mac, don’t assume you are invulnerable to hackers.  Accept all new security patches when they are issued.
6.       Be cautious opening email attachments and clicking embedded links.  Most viruses infect your computer because you opened an email attachment.  Don’t think an attachment is automatically safe just because it came from someone you know.  Scan it with an anti-virus software program before opening.  For the ultimate in security, use a remote anti-virus solution that scans all your emails and blocks any viruses before they ever get into your network.  Also be careful about clicking on a Web link in an email.  Rather than clicking the link, manually type the URL into your browser.
7.       Back up your data regularly.  You never know when a hard drive will crash or your laptop will get stolen.  Don’t wait for disaster to strike before you think about backing up your data.  You can purchase a hard drive specifically for backing up your data or you can use an online service.  Just make sure you do it regularly—at least daily for business data.  You might also consider doing what is known as a “full image” backup.  If your computer’s hard disk crashes or your laptop is stolen, this allows you to quickly restore your entire computer—programs and settings as well as data files—onto a new computer from the backup copy.
While there can never be a 100% guarantee that you won’t be hacked, following all seven of these steps will dramatically reduce the probability you will be a victim of a cyber-crime.  If you’re not sure how to do all this yourself, consider contracting with an expert like TeamLogic IT to assess your vulnerabilities and take appropriate steps to correct them.  TeamLogic IT is a nationwide network of computer consultation and managed services businesses that addresses the IT needs of small- to medium-sized businesses.  We provide customers with quick-response troubleshooting and repair of desktops, servers and online systems, and we offer a variety of consultation and maintenance services that previously have only been available to larger organizations.
In addition, TeamLogic IT focuses on preventing IT disasters through a proactive approach to managing IT services using state-of-the-art technology.  We provide networking services, security services, data services, email services, and we can procure hardware and software at competitive prices due to our national buying power.  In Sonoma County, find out more by contacting us at 707-293-9525 or emailing shinch@teamlogicit.com.

Monday, April 11, 2011

Major Security Breach at Epsilon Interactive

By now, many of you may have received emails alerting you to a security breach at Epsilon Interactive, an on-line company used by many major corporations to send marketing emails to customers. An outside hacker broke into the Epsilon network and gained access to numerous names and email addresses of their clients’ customers. Major corporations affected include Barclays Bank, Best Buy, Citibank, JP Morgan Chase, Marriott International, Target, Walgreens, Hilton Worldwide, and Disney Destinations, as well as a host of others. If you’ve received one of these emails, you might be wondering how it will affect you. I’ll try to answer that question here.

What Happened
Epsilon specializes in sending bulk marketing emails in the name of their client companies. It takes a certain amount of skill to craft personalized emails in a way that spam filters don’t block them, and this is Epsilon’s claim to fame. They send more than 40 billion emails on behalf of their clients annually to people who have provided an email address to the client company. Although Epsilon isn’t saying exactly what happened, it is clear that someone was able to hack into their network and obtain customer names and email addresses. Epsilon has stated that “approximately 2 percent of total clients” were hit, which would be about 50 companies. To date, Epsilon has not provided a detailed list of those companies, but the ones named above have notified their customers of the breach. Epsilon has made it very clear that the hackers only got names and email addresses, not any financial information. This means the information can’t immediately be used to do anything harmful, other than to send out more spam.

The Risk
Email addresses on their own aren’t all that valuable, but if you can tie a customer’s name and email account to a company they do business with, the problem becomes more serious. A hacker can create a customized email that appears to come from the client company to trick the customer into revealing sensitive information. Suppose, for example, you got an email from your bank encouraging you to sign up for a special offer. All you have to do is click on the link in the email, log into your account, and you’re all signed up. Of course the offer isn’t really from your bank, and the link takes you to a rogue website that captures your login information. Before you know it, the hacker uses it to break into your account and drain it dry.

How to Protect Yourself
The good news is that the stolen information by itself won’t let a hacker do anything harmful. As long as you practice due diligence in opening and reading emails, you should be safe. The first thing to remember is to never provide sensitive information—account names, passwords, social security numbers, etc., in response to an email request. Legitimate companies will never make such a request by email. Also be very cautious about clicking links in emails, and never enter any sensitive information onto a website you arrived at from an email link. Whenever you must enter sensitive information go to the company’s website by manually typing their web address into your browser (once you’ve done this, you can bookmark it for future use).
You may also want to consider investing in a strong spam filter for your email network, even beyond the anti-virus/anti-malware software you should all be using. There are two ways to do this, either by using a Cloud-based service or by using a hardware filter you add to your own network. Cloud-service companies such as AppRiver can filter almost all spam before it even gets into your network, or you can use a hardware email security appliance such as those offered by Barracuda Networks. Either option can significantly reduce the amount of unwanted spam clogging up your network.

Finally, make sure that access to your network is protected by strong passwords. Although we don’t know how the hacker got into the Epsilon network, we do know some of the techniques commonly used. One approach is to use a program that tries to brute-force its way into your network by automatically trying common usernames and passwords. Passwords like “1234” or the word “password” are easily hacked. At TeamLogic IT a new client recently asked us to repair damage to their network caused by a hacker. When we investigated, we discovered the break-in probably occurred because their server password was one of the most common and least secure passwords out there. Don’t let this happen to you.

To learn more about how to protect your network, including how to create strong passwords, read my previous blog entry, Protecting Your Business Against Cyber-Criminals.  And if you’d like TeamLogic IT to help improve the security of your network, just visit www.teamlogicit.com.