If you don’t where it is, you can’t protect it.
Do you know where ALL your organisation’s data is – not physically, but on which web and cloud services?
Here’s the problem. If you don’t where it is, then you can’t protect it. The secondary problem is finding out, because not everyone in your organisation will be onboard. It is common for people to sign up to web services because they offer something useful that helps them do their job.
They sign up using their email address and creating a password. There is the first headache – how does anyone track what has been signed up to across your organisation, let alone who has access to it? If that person leaves, no one will change the account credentials if they don’t know about it, but your ex-colleague still has access.
Secondly, what data do they upload? Is that data that you have a legal or moral responsibility for?
There’s nothing noble about Nobelium.
This isn’t theory – it’s real. USAID is a pretty important US organisation – promoting democracy and human rights around the world. Turns out, someone there was using a well-known email database tool called Constant Contact. But their account wasn’t well protected. Worse still, their account had a huge mailing set up, and of course, it had all the official USAID templates.
So, these Nobelium people, allegedly a Russian state-sponsored hacker group, compromised the Constant Contact account and sent a bulletin out. The bulletin contained malware that allowed the hackers to take command and control over victims computers. Ironically the fake email alleged interference in the US federal elections.
So, what can you do?
The first step is knowing what SaaS tools your people are using. We call this SHADOW IT and it is inevitable. Rather than stopping it, the job IT has is to identify it and manage it. The second step is to secure those platforms. That’s why our KARE for Security S2 plan contains a useful tool to help you identify what services your people are using.
Refer : What We Know About The Apparent Russian Hack Exploiting USAID : NPR
Those scamming so and so’s
In September, Kinetics held a lunchtime IT security event focused around a presentation by our CTO Bill Lunam. After taking us though an abridged history of the internet, and an update on the current status of Internet crime, Bill explained some specific’s around the...
Microsoft Update – Backup Authenticator (Two-factor authentication tool) and Window 10 1909 ?
Firstly, unless you just delete our emails, or ignore what we (and every other tech professional) have been saying, you should now be using 2FA (two factor authentication) on pretty much everything, especially your Office365. The downside is that you don’t want to...
Bigger than Texas?
Its easy to think of security as something that’s only for larger organisations. They can afford the fancy systems that lock down networks, wireless connections and endpoint PCs & mobile devices. After all, aren't they the only organisations that hackers target?...
Compare two (near) identical Word files, without going insane
Of course, in a modern cloud world, this shouldn’t happen! We should share a link to a file and use versions to maintain it’s history. But we’re not in a perfect work, and we often get multiple people updating copies of the same file. Its all good until we have to...
Scamming your payroll
Keep an eye on your payroll! We're hearing about a bold new scam in the US, but it's bound to come to our shores soon. It's probably more likely to be effective in larger businesses or ones with an outsourced payroll. Essentially, the scammers try to intercept staff...
Would you click on either of these?
You are most vulnerable when you are busy, frantically jumping from call to call, meeting to meeting, distraction to distraction. So when you get a dodgy email, it's very easy to open it. This morning, that was me! And, even as hyper-aware as I am, I still...
Is your phone one of the 25M infected Android phones?
Watch your phone! Agent Smith is the name of the somewhat dry villain character in the Matrix movie trilogy from the late 90's. He appears everywhere, instantly, taking over legitimate personas and replacing them with himself. So is a well-named virus (actually...
Why old versions of Microsoft Windows and Microsoft SQL are putting you at risk
Modernise your infrastructure and future-proof your technology Prepare for Windows Server 2008 and SQL Server 2008 end of support With the end of support for Windows Server 2008 fast approaching, and SQL Server 2008 recently expired, now is the time to start...
Why you should care about BlueKeep
Regular readers will know that we are fanatical about updates and patches for all critical software. The world is more connected and the cyber-crime community is more organised and determined than ever. If you think cyber-criminals are teenage kids working from home,...
9 Common Excel Mistakes
We were reminded of the risks of messing up spreadsheets in a recent blog post at Oracle: The scary fact they quote is that 88% of all spreadsheets are wrong! The consequences of relying on bad information as a result can be insane! That reminded me of a couple of...