{"id":2782,"date":"2021-10-08T19:03:00","date_gmt":"2021-10-08T06:03:00","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=2782"},"modified":"2021-10-08T19:03:00","modified_gmt":"2021-10-08T06:03:00","slug":"fact-or-fiction-my-files-are-in-the-cloud-i-dont-need-to-worry-about-security-any-more","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=2782","title":{"rendered":"Fact or Fiction? My files are in the cloud, I don&#8217;t need to worry about security any more!"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; admin_label=&#8221;section&#8221; _builder_version=&#8221;4.16&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row admin_label=&#8221;row&#8221; _builder_version=&#8221;4.16&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.16&#8243; custom_padding=&#8221;|||&#8221; global_colors_info=&#8221;{}&#8221; custom_padding__hover=&#8221;|||&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.16.1&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p>If only life were so simple! \u00a0 We have some clients that ask us about file security in the cloud as if the answer is an absolute.\u00a0 Of course it isn&#8217;t.<\/p>\n<h2>The cloud is more secure than an on-premise system<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-2969\" src=\"https:\/\/new.kinetics.co.nz\/wp-content\/uploads\/2018\/09\/boycloud.jpg\" alt=\"\" width=\"416\" height=\"277\" \/>Assuming we\u2019re talking about a reputable mainstream cloud, the answer is an emphatic \u2018YES\u2019, mostly. It makes sense that a major provider can afford to put multiple layers of expensive protection around their platforms that an average business just can\u2019t afford. The physical security will be mission-impossible impressive, and the digital security equally so.<\/p>\n<p>Businesses like Microsoft are very aware of how they have to earn customer\u2019s trust and they know that security is an absolute bottom line. They go to town on this! Likewise, they are (successfully) fighting regulatory authorities to make sure they don\u2019t hand over your data when the boys in dark suits and shiny badges appear at the door (which to be fair isn\u2019t really a concern for most of us).<\/p>\n<p>So, cloud services like Microsoft 365, Azure, Amazon and Google are reasonably secure. We know Microsoft the best, and we\u2019re very impressed with their file security.<\/p>\n<p>&nbsp;<\/p>\n<h2>But people remain the main risk to file security<\/h2>\n<p><strong>But, and it is a big BUT, people remain the biggest risk<\/strong>.\u00a0 We have already <a href=\"\/beware-social-engineering-the-number-one-security-threat-to-business-is-your-people\/\" target=\"_blank\" rel=\"noopener\">warned about this in terms of social engineering<\/a>. But it\u2019s generally mistakes or aberrant behaviour that is the biggest threat. Nothing is more frustrating than getting a call on Monday from a client \u201cJack (or Jill) left on Friday and I need to check if they copied any files and took them with them\u201d. Generally, that\u2019s a case of closing the door after the horse has bolted.\u00a0<\/p>\n<p>So, the problem is the cloud makes it easier to access data anywhere, anytime. It\u2019s also incredibly easy to share files with external parties &#8211; which is great for collaborating on projects. That\u2019s it\u2019s great strength. But, its open to abuse. There are ways to monitor and alert for changes in your 365 behaviour such as<\/p>\n<ul>\n<li>monitor for email being auto-forwarded to external addresses<\/li>\n<li>account access from unusual or infrequent locations (e.g. eastern Europe)<\/li>\n<li>unusual file access volumes (eg. bulk copies or deletions)<\/li>\n<li>unusual &#8216;access privilege&#8217; elevation<\/li>\n<\/ul>\n<p>So we built this into our new <a href=\"https:\/\/new.kinetics.co.nz\/cybersecurity\/\">KARE for Security\u00a0<\/a>service.\u00a0 It includes quarterly reporting on available alerting parameters, external identities, full mailbox rights and Azure group membership.<\/p>\n<p>This is just the beginning. Office 365 includes a very rich set of file security and compliance tools. These range from a security assessment \u2018secure score\u2019 to a feature called \u2018Data Leak Protection\u2019 in which policies are created to protect content based on characteristics of that content. Setting that up varies immensely from business to business depending on their needs and we\u2019re very excited to work through the options that best suit you as mini-IT projects. The best way to start this is with our [wow_colorme]<a href=\"https:\/\/new.kinetics.co.nz\/flightplan\/\" target=\"_blank\" rel=\"noopener\">&#8220;FlightPlan&#8221;<\/a>[\/wow_colorme] that will define the requirements clearly.<\/p>\n<h2>What is the risk?<\/h2>\n<p>The problem is that once data has leaked out, there is reputation risk and if you do have staff making errors of judgement, then the sooner you can identify it and address it, the better. \u00a0 You can cause people to cease before harm is done, and if there is a data breach, you have an obligation to report it, often with pretty severe penalties if you don&#8217;t.<\/p>\n<p><strong>KARE for Security<\/strong> complements your existing maintenance contract with an enhanced security package, designed for the modern cloud-anywhere world. It\u2019s a mixture of tools that go beyond traditional IT support to help you harden your ICT against intruders.<\/p>\n<p>What more can you do? \u00a0 Cert NZ is the NZ Government Cyber Security unit &#8211; it&#8217;s worth reading their top recommendations &#8211; <a href=\"https:\/\/www.cert.govt.nz\/it-specialists\/critical-controls\/\">https:\/\/www.cert.govt.nz\/it-specialists\/critical-controls\/<\/a> &#8211; you&#8217;ll see that a Kinetics KARE plan helps you minimise your risk<\/p>\n<p>&nbsp;<\/p>\n<h2 style=\"text-align: center;\">Want to know more about how Kare for Security can enhance your protection?<\/h2>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][et_pb_code _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<style type=\"text\/css\"><!-- [et_pb_line_break_holder] -->.label{font-family:Montserrat; font-size:14px; font-weight:bold; line-height:24px; color:#474747;}.ampfield{ width:100%; height:45px; border:solid 1px #dddddd; border-radius:3px; color:#999; font-size:12px; font-family:Montserrat; font-weight:bold; line-height:24px; padding:10px; cursor:text; outline:none; margin-bottom:14px;}.ampmsg{ width:100%; height:252px; border:solid 1px #dddddd; border-radius:3px; color:#999; font-size:12px; font-family:Montserrat; font-weight:bold; line-height:24px; padding:10px; cursor:text; outline:none; margin-bottom:16px;}.ampsubmit{ width:80px; height:43px; background-color:#3ec940; border-radius:3px; color:#ffffff; font-family:Montserrat; font-size:14px; font-weight:400px; padding-left:20px; padding-right:20px; padding-top:10px; padding-bottom:10px; text-align:center; outline:none; cursor:pointer; border:none;}<\/style>\n<p><!-- [et_pb_line_break_holder] --><script language=\"javascript\" type=\"text\/javascript\"> function validateform(){<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->var firstname = document.getElementById('FirstName').value.replace(\/\\s\/g,'');<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->               var lastname = document.getElementById('LastName').value.replace(\/\\s\/g,'');<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->               var email = document.getElementById('Email').value;<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->               var worknumber = document.getElementById('WorkNumber').value;<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->               if(firstname == \"\"){document.getElementById('FirstName').focus();alert('Please Enter Your First Name!');return false;}<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->               if(lastname == \"\"){document.getElementById('LastName').focus();alert('Please Enter Your Last Name!');return false;}<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->               if (!\/^\\w+([\\.-]?\\w+)*@\\w+([\\.-]?\\w+)*(\\.\\w{2,5})+$\/.test(email)){document.getElementById('Email').focus();alert(\"Please Enter a Valid Email Address!\")<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->return false}<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->               if(worknumber == \"\"){document.getElementById('WorkNumber').focus();alert('Please Enter Your Telephone Number!');return false;}<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->               return true;<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->   }<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/script><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --> <!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<form id=\"form_7e60be7dbf4346fe996bae072ee9c070\" action=\"https:\/\/msp.amp.vg\/public\/externalform2.ashx\" method=\"post\"><script language=\"javascript\" type=\"text\/javascript\" src=\"https:\/\/cmap.amp.vg\/track\/gloahbt8azdk\/webpl.js\"><\/script> <script language=\"javascript\" type=\"text\/javascript\"> function submitForm(){document.getElementById(\"form_7e60be7dbf4346fe996bae072ee9c070\").submit();} <\/script><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><input id=\"token_7e60be7dbf4346fe996bae072ee9c070\" name=\"tokenkey\" type=\"hidden\" value=\"\" \/><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><input id=\"templateid\" name=\"templateid\" type=\"hidden\" value=\"918939\" \/><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><input id=\"formid\" name=\"formid\" type=\"hidden\" value=\"906033\" \/><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><input id=\"doubleopt\" name=\"doubleopt\" type=\"hidden\" value=\"0\" \/><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><input id=\"successurl\" name=\"successurl\" type=\"hidden\" value=\"https:\/\/cmap.amp.vg\" \/><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><input id=\"failureurl\" name=\"failureurl\" type=\"hidden\" value=\"https:\/\/cmap.amp.vg\" \/><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div id=\"captcha_7e60be7dbf4346fe996bae072ee9c070\" style=\"display: none;\"><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div id=\"divReCaptcha7e60be7dbf4346fe996bae072ee9c070\" class=\"g-recaptcha\" data-sitekey=\"6LeQHR4UAAAAALnbi_6DE8IEoKMjYnZk3IawV-5t\"><\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div id=\"divInvisibleCaptcha7e60be7dbf4346fe996bae072ee9c070\" class=\"g-recaptcha\" data-sitekey=\"6LdTHh4UAAAAAHXtAKkvkcSmd-Zm_qdKgPUjMVsU\" data-callback=\"submitForm\" data-size=\"invisible\" data-bind=\"submit_7e60be7dbf4346fe996bae072ee9c070\"><\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div class=\"label\">Your First Name (required)<\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div><input id=\"FirstName\" class=\"ampfield\" name=\"FirstName\" type=\"text\" \/><\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div class=\"label\">Your Last Name (required)<\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div><input id=\"LastName\" class=\"ampfield\" name=\"LastName\" type=\"text\" \/><\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div class=\"label\">Your Email (required)<\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div><input id=\"Email\" class=\"ampfield\" name=\"Email\" type=\"text\" \/><\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div class=\"label\">Telephone (required)<\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div><input id=\"WorkNumber\" class=\"ampfield\" name=\"WorkNumber\" type=\"text\" \/><\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div class=\"label\">Mobile<\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div><input id=\"MobileNumber\" class=\"ampfield\" name=\"MobileNumber\" type=\"text\" \/><\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div class=\"label\">Your Message<\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div><textarea id=\"Comments\" class=\"ampmsg\" name=\"Comments\"><\/textarea><\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div><input id=\"submit_7e60be7dbf4346fe996bae072ee9c070\" class=\"g-recaptcha ampsubmit\" type=\"button\" value=\"SEND\" data-sitekey=\"6LdTHh4UAAAAAHXtAKkvkcSmd-Zm_qdKgPUjMVsU\" \/><\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><script src=\"https:\/\/msp.amp.vg\/public\/externalform2.ashx?formKey=7e60be7dbf4346fe996bae072ee9c070\" async defer><\/script><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --> <!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/form>\n<p>[\/et_pb_code][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If only life were so simple! \u00a0 We have some clients that ask us about file security in the cloud as if the answer is an absolute.\u00a0 Of course it isn&#8217;t. The cloud is more secure than an on-premise system Assuming we\u2019re talking about a reputable mainstream cloud, the answer is an emphatic \u2018YES\u2019, mostly. [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":2783,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"If only life were so simple! \u00a0 We have some clients that ask us about file security in the cloud as if the answer is an absolute.\u00a0 Of course it isn't.\n\n[header2 text=\"The cloud is more secure than an on-premise system\" align=\"left\" color=\"#336A40\" margintop=\"\"]\n\n<img class=\"alignleft wp-image-2969\" src=\"http:\/\/kinetics.co.nz\/wp-content\/uploads\/2018\/09\/boycloud.jpg\" alt=\"\" width=\"416\" height=\"277\" \/>Assuming we\u2019re talking about a reputable mainstream cloud, the answer is an emphatic \u2018YES\u2019, mostly. It makes sense that a major provider can afford to put multiple layers of expensive protection around their platforms that an average business just can\u2019t afford. The physical security will be mission-impossible impressive, and the digital security equally so.\n\nBusinesses like Microsoft are very aware of how they have to earn customer\u2019s trust and they know that security is an absolute bottom line. They go to town on this! Likewise, they are (successfully) fighting regulatory authorities to make sure they don\u2019t hand over your data when the boys in dark suits and shiny badges appear at the door (which to be fair isn\u2019t really a concern for most of us).\n\nSo, cloud services like Microsoft 365, Azure, Amazon and Google are reasonably secure. We know Microsoft the best, and we\u2019re very impressed with their file security.\n\n[header2 text=\"But people remain the main risk to file security\" align=\"left\" color=\"#336A40\" margintop=\"\"]\n\n<strong><img class=\" wp-image-2970 alignright\" src=\"http:\/\/kinetics.co.nz\/wp-content\/uploads\/2018\/09\/horse-bolting.jpg\" alt=\"\" width=\"525\" height=\"359\" \/>But, and it is a big BUT, people remain the biggest risk<\/strong>.\u00a0 We have already [wow_colorme]<a href=\"\/beware-social-engineering-the-number-one-security-threat-to-business-is-your-people\" target=\"_blank\" rel=\"noopener\">warned about this in terms of social engineering<\/a>[\/wow_colorme]. But it\u2019s generally mistakes or aberrant behaviour that is the biggest threat. Nothing is more frustrating than getting a call on Monday from a client \u201cJack (or Jill) left on Friday and I need to check if they copied any files and took them with them\u201d. Generally, that\u2019s a case of closing the door after the horse has bolted.\n\nSo, the problem is the cloud makes it easier to access data anywhere, anytime. It\u2019s also incredibly easy to share files with external parties - which is great for collaborating on projects. That\u2019s it\u2019s great strength. But, its open to abuse. There are ways to monitor and alert for changes in your 365 behaviour such as\n<ul>\n \t<li>monitor for email being auto-forwarded to external addresses<\/li>\n \t<li>account access from unusual or infrequent locations (e.g. eastern Europe)<\/li>\n \t<li>unusual file access volumes (eg. bulk copies or deletions)<\/li>\n \t<li>unusual 'access privilege' elevation<\/li>\n<\/ul>\n&nbsp;\n\nSo we built this into our new [wow_colorme]\u201c<a href=\"http:\/\/kinetics.co.nz\/kare-for-security\/\">KARE for Security<\/a>\u201d<span style=\"display: inline !important; float: none; background-color: transparent; color: #333333; cursor: text; font-family: Georgia,'Times New Roman','Bitstream Charter',Times,serif; font-size: 16px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;\">[\/wow_colorme]<\/span> service.\u00a0 It includes quarterly reporting on available alerting parameters, external identities, full mailbox rights and Azure group membership.\n\nThis is just the beginning. Office 365 includes a very rich set of file security and compliance tools. These range from a security assessment \u2018secure score\u2019 to a feature called \u2018Data Leak Protection\u2019 in which policies are created to protect content based on characteristics of that content. Setting that up varies immensely from business to business depending on their needs and we\u2019re very excited to work through the options that best suit you as mini-IT projects. The best way to start this is with our [wow_colorme]<a href=\"http:\/\/kinetics.co.nz\/flightplan\/\" target=\"_blank\" rel=\"noopener\">\"FlightPlan\"<\/a>[\/wow_colorme] that will define the requirements clearly.\n\n[header2 text=\"What is the risk?\" align=\"left\" color=\"#336A40\" margintop=\"\"]\n\nThe problem is that once data has leaked out, there is reputation risk and if you do have staff making errors of judgement, then the sooner you can identify it and address it, the better. \u00a0 You can cause people to cease before harm is done, and if there is a data breach, you have an obligation to report it, often with pretty severe penalties if you don't.\n\n<strong>KARE for Security<\/strong> complements your existing maintenance contract with an enhanced security package, designed for the modern cloud-anywhere world. It\u2019s a mixture of tools that go beyond traditional IT support to help you harden your ICT against intruders.\n\nWhat more can you do? \u00a0 Cert NZ is the NZ Government Cyber Security unit - it's worth reading their top recommendations - <a href=\"https:\/\/www.cert.govt.nz\/it-specialists\/critical-controls\/\">https:\/\/www.cert.govt.nz\/it-specialists\/critical-controls\/<\/a> - you'll see that a Kinetics KARE plan helps you minimise your risk\n\n&nbsp;\n\n[col size=\"6\"]\n<h1 style=\"text-align: center;\">[wow_colorme]Want to know more about how Kare for Security can enhance your protection?[\/wow_colorme]<\/h1>\n[\/col]\n\n[col size=\"6\"]\n<p style=\"text-align: center;\">[contact-form-7 id=\"1838\" title=\"Kinetics contact form\"]<\/p>\n[\/col]\n\n&nbsp;","_et_gb_content_width":"","footnotes":""},"categories":[4],"tags":[],"class_list":["post-2782","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/2782","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2782"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/2782\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2782"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2782"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2782"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}