Close-up of a phone with different icons branching out: representing the different aspects that small business cyber security will protect.

Why Cyber Security Is Still Important for Small Businesses

Cyber attacks of recent years have grown in number and size, making it crucial to alert the computing world at large of the need to protect data assets and network infrastructure. Large corporations, small businesses, and even private individuals are all subject to attack from criminal-minded hackers who are bent on profiting from illegal penetration into your computing system.  Many of the most high-profile cyber attacks of recent years targeted large corporations, simply because of the potential for extracting more substantial sums of money from them in exchange for the safe return of business assets (ransomware). While attacks against small businesses (SMB’s) have not garnered the headlines nor the high visibility of major attacks against big corporations, that doesn’t mean they aren’t taking place. In fact, small businesses now are being hit much more frequently because hackers have realized that, all those small profits from SMB’s do add up to big money in total. Statistics show that over the past several years, more than half of small businesses have had network security breached in some way by hackers. This alarming development should clearly point out the need for small businesses to be on the alert, small business cyber security should be taken seriously.

Managing the Risk of Cyber Attacks Against Small Businesses

In addition to the cumulative appeal of profits from small business attacks, there is another reason why criminals have been turning their attention to SMB’s. With fewer resources allocated to cybersecurity, and less formalized training and education against the potential for cyber attacks, small businesses often present very inviting targets for the criminal-minded.

It’s also true that limited budgets make small businesses cyber security not as readily accessible. However, even with limited resources, there are at least a few necessary steps that all small businesses can take, which will reduce the likelihood of an attack, and at least provide some measure of security for valuable business assets.

For instance, at least one person in every small business can be designated to stay abreast of all known cyberattack threats, so that it’s at least possible to take preventive measures against specific threats and risks. This would typically be an I.T. person who’s also responsible for keeping system software updated with any security patches made available by vendors. Soon after the newest cyberattacks appear, software gurus are at work developing fixes to patch whatever weakness allowed the attack to take place, and these should be applied to your software system as soon as they are made available.

It’s also imperative to take regular backups of business-critical data so that in the event of an attack like ransomware, there is always a safe and current version of data to fall back on, without surrendering to the demands of a hacker.

A person with a laptop and phone: representing the implementation of small business cyber security.

To implement effective small business cyber security, it’s important to train all employees on different types of cyber attacks and how to resolve them.

Education and Training on Small Business Cyber Security

It’s fair to say that the biggest vulnerability for small business cyber security is the lack of employee education and training. This, of course, is not limited to SMB’s, because even corporate giants are frequently exposed to cyber threats by the weakest point in their networks, which is the actions of employees.

Hackers are naturally aware of this, and much of their time and effort is spent trying to dupe unsuspecting company employees into providing them with crucial information like passwords or account data which will allow them to carry out attacks against the company network. All this should make it clear that one of the top priority investments in small business cyber security is to properly educate and train employees about cyber threats, and how they’re carried out and resolved.

Every employee needs to be aware of the potential for cyber attacks and should treat anything suspicious with extreme caution. At the bare minimum, all employees should be educated about the necessity for safeguarding passwords, credentials, and account information. Such attacks can be carried out through email phishing scams, or possibly social media, where cyber attackers are known to be listening, and waiting to exploit unsuspecting employees to obtain vital security information in a seemingly harmless environment.

Hackers can also obtain business details information from employees via social engineering, wherein cyber attackers manipulate employees by pretending to be clients, banking institutions, or other characters of authority or importance. Some of these attacks are made through phone calls where a supposed colleague requests to know changes made to account information need to be reminded of specific passwords to gain access to system software. Hackers posing as managers from other departments have also exploited unwary employees with phone calls asking for similar information, which can then be used to breach the computing system and hijack valuable company data assets.

Some small businesses in the country have gotten the message, and have taken whatever steps they can to prevent cyberattacks, or at least reduce the potential for them. If awareness is the first big step toward improving your small business cyber security, educating employees about cyber attacks can be said to be an essential second step. Hackers these days are determined to victimize small businesses as well as corporate giants, and that means SMB owners and managers have to be just as committed to preventing those attacks.

 

Text with highlighted red words reading "data breach" and "cyber attack", related to a security breach.

Why a Security Breach Could Destroy Your Brand

A study recently conducted by RiskVision, a respected developer of Risk Management software, determined that more businesses today are concerned about company reputation than they are about potential breaches of security which might impact them. It has long been known that companies consider a brand name to be one of their most significant assets, even though it’s an intangible that has value to no one outside the company itself.

In this survey, damage to a brand name was considered to be potentially more damaging than security breaches, even though the two often go hand-in-hand today. Hackers who successfully penetrate into a company’s computing network often do inflict serious damage to the reputation of the business, and subsequently its brand name. It should, therefore, be kept in mind by all business owners that security breaches need to be taken seriously, to prevent damage to the company brand-name, as well as all the usual financial ramifications.

How a Security Breach Can Damage Your Brand Name

Typically, the first thing a customer considers when thinking about brand names, about products or services, is whether or not the product or service provides quality and value, and whether the cost is in line with the levels of quality and value delivered. However, any company which has suffered a known security breach often falls into an entirely different frame of evaluation.

Consumers will often think that any business which has allowed itself to be hacked by criminals is not worthy of their trust and patronage. After all, if their business practices were lax enough to permit the cyberattack in the first place, that may be a sign that other important aspects of the business are also conducted with inadequate attention to detail. This fact is borne out powerfully in a poll jointly conducted by CSO and OnePoll, which attempted to determine the connection between insufficient security and a company’s brand name, as perceived by consumers.

In the survey, a whopping 86% of customers declared that they were unlikely to patronize a company which had suffered a severe security breach, especially if the breach was related to customer information. This represents a definite shift in consumer thinking from the early days of cyber attacks when businesses were perceived as victims entitled to understanding and sympathy from the public. In the now-famous cyberattack against department store giant Target, sales for the entire quarter after their security breach dropped like a rock, falling almost 50% from the prior quarter.

A red button on a keyboard reading "data protection," as related to preventing a security breach.

Keeping your customers’ and clients’ information safe should be your top priority, since it affects the way the public perceives how trustworthy your business is.

Impact of Security Breaches on Small Businesses

Major security breaches perpetrated against small companies can have an enormous effect and can cause irreparable brand-name damage from which recovery is either very difficult or downright impossible. In 2016, a study was conducted by KPMG which determined that almost 90% of small businesses had suffered serious brand name damage in the immediate aftermath of a security breach.

In a white paper published by the National Cyber Security Alliance, figures were released which showed that as many as 60% of all small businesses completely collapse less than six months following a significant cybersecurity breach. Interestingly, both of the studies referenced above reported that less than one-quarter of all small businesses considered cybersecurity to be a top priority. The fact that there has historically been relatively little concern about cybersecurity breaches may account for the often devastating impact that attacks have had on those business entities.

Taking Steps to Secure Your Business

A cyber security plan doesn’t need to be especially elaborate, and it doesn’t need to be funded to the hilt, with every conceivable kind of virus detection software. There just needs to be a well thought out plan for cybersecurity, and a legitimate effort to enforce that strategy. There are some straightforward but very cost-effective measures which can be adopted to thwart the vast majority of cyber attacks.

Using strong passwords on all company computers is a good start, followed up by installing security software on company devices. It’s always best to keep hardware and software updated with the latest available security patches and to periodically back up business-critical data. The weakest point of any company’s network should not be overlooked, which means employees need to be educated about the risks of cyber attack.

The important thing to remember about any cybersecurity policy is just to implement as many of the simple steps listed above as possible and to do it immediately so that your system is not left vulnerable to penetration by cyber attackers. As some of the survey results mentioned above make clear, every kind of business from the corporate giant on down to the mom-and-pop retail outlet must take all steps possible to avoid the possibility of major security breaches. Failing to do this can cost you a lot more than money – it can cause irreparable harm to your company’s reputation.

A Wi-Fi symbol with computer binary code in the background, to signify the hackers who exploit insecure networks via key reinstallation attacks.

What You Need to Know About Key Reinstallation Attacks

If you haven’t heard about key reinstallation attacks yet, they’re the most recent form of Wi-Fi hacking. It’s also possible that you actually have heard about them under their media nickname, which is ‘Krack Attacks.’

Regardless of the nomenclature, key reinstallation attacks are attempts to exploit a flaw in the Wi-Fi encryption protocol which permits hackers to hijack all kinds of personal information, including photos, passwords, and account numbers. The first thing to know about key reinstallation attacks is that they’re not specifically targeting any particular hardware, but rather a weakness in the Wi-Fi protocol itself.

This means that all smartphones, mobile devices, routers, and desktop machines are subject to attack, and any or all of your personal data may abruptly come into the possession of someone with criminal intent. Today, we’re here to discuss what you should know about this new threat.

How Key Reinstallation Attacks Work

Researchers have uncovered a flaw in the WPA2 Wi-Fi protocol which allows hackers to replicate a user’s network entirely, and by falsely representing the Media Access Control (MAC) address, which is a device’s physical address, it can actually cause a switch in Wi-Fi channels.

When a bogus network is set up in this way, it can actually intercept signals from any remote device attempting to connect to the original system, causing such attempts to bypass the real network, and instead connect to the rogue.

The way WPA2 encryption is supposed to work, it would require a unique key for any encryption request, but the flaw uncovered in the WPA2 protocol does not always need that specific key, and instead, reuses a previous one. The problem is particularly acute with Linux and Android, because of the way they make use of the WPA2 protocol. In these operating systems, a unique encryption key is not demanded every time an encryption request is made, leaving the system vulnerable to hacking.

In layman’s terms, the Wi-Fi protocol can be exploited when hackers can find a vulnerable network and take advantage of the WPA2 weakness, ultimately directing users to the rogue network for data hijacking.

Little people browsing the internet on their laptops, perched on a laptop. Key reinstallation attacks take advantage of how ubiquitous Wi-Fi is.

Key reinstallation attacks take advantage of the fact that most of our world now runs on Wi-FI so it’s important to take precautions before connecting to an unfamiliar Wi-Fi network or an insecure one.

Researchers Proof of Concept

Previous minor flaws had already been uncovered in the WPA2 protocol, so researchers were already fearful that some even more significant problem might be lurking within the software. The key reinstallation flaw was discovered by those researchers, who then conducted proof of concept experiments to attack a theoretically vulnerable Wi-Fi system. On an Android system, the researchers were successful in intercepting and decrypting all the test victim’s data.

According to these penetration experts, the same kind of ‘success’ could not be achieved on a system setup with HTTPS secure socket layers but would wreak havoc on sites which have been poorly set up and missing HTTPS. While Linux and Android are most severely affected because of how they use WPA2, other operating systems like Windows, MacOS, and OpenBSD would also be compromised but to a lesser degree. How serious is the issue for Android? Experts recommend that owners of Android devices shut off Wi-Fi until known fixes have been applied to close up the weakness in the protocol.

What You Can Do to Avoid Krack Attacks

One of the best things you can do to avoid the possibility of a key reinstallation attack is to look for the ‘https’ at the beginning of any URL for websites which you visit. That ‘https’ is an indicator that the site uses secure protocols, and you would be safe in visiting. You can also simply avoid using Wi-Fi for the time being, while software gurus hurriedly develop a fix for the vulnerability. This may be inconvenient, especially when you’re away from home or the office and might need Wi-Fi, but it’s much safer than having your sensitive data fall into the hands of a criminal.

One of the interesting things about these attacks is that a hacker must be within the physical range of your machine before the attack can be carried out, and while that does serve to shield many users from harm, an actual attacker can’t be identified beforehand so you know if he’s close enough. So naturally, you can’t rely on remaining safe because you aren’t within range of a criminal – after all, what does a criminal look like?

Fortunately, the fix will be relatively easy to develop in this case and should be forthcoming relatively soon. All that’s necessary is a simple change to the firmware so that during the ‘handshake’ between devices, a unique key is requested every single time, rather than sometimes relying on previously used ones which can be exploited. Get in touch with your provider and ask when fixes will be made available, and as soon as those security updates are released, make sure they are applied to all your devices.

 

A large of amount of sand, to metaphorically represent the "sand" part of sandboxing security.

Sandbox Security: Why Do I Need It and How Is It Protecting My Computer?

A large of amount of sand, to metaphorically represent the "sand" part of sandboxing security.

Sandbox security is an important computer safety technique that helps keep malicious executables at bay.

A sandbox is an isolated environment that mimics an entire computer system.  This protected space can be used to test suspicious programs and analyze potential threats.  Sandboxing is a vital security feature that prevents malware and other viruses from entering and damaging your computer.

Much of the software you already use, like web browsers, have sandboxes that filter most of the code your system uses to perform daily tasks.  You can create your own sandboxes to test whether a piece of software is safe, in a controlled environment that won’t damage the rest of your computer’s system.

What Is Sandboxing? Why Is It an Essential Security Feature?

Sandboxes give specific permissions to a piece of code, allowing it to perform its functions, while restricting it to a tightly controlled environment.   Programs are then run within this environment, where no additional code permissions can be abused.

In everyday computer use, you come across many sandboxing security techniques.  Your web browser, if you use Chrome or Internet Explorer, runs the webpages you visit in a sandbox.  These webpages are limited to the access granted by this browser’s sandbox, meaning that this site can’t do things like open your webcam without your permission or snoop on your personal files.

Web Browsers With Sandboxing Capabilities

Browsers with sandboxing capabilities are especially useful for recognizing advanced persistent threats (APTs).  These APTs are designed to escape detection, breaking through conventional security barriers, and gaining access to Personally Identifiable Information (PII) on your computer.  Sandboxes help isolate these viruses and prevent them from spreading.

Sandboxing browsers don’t have access to your entire computer, because they run in a low-permission mode.  If a malicious webpage manages to take over your browser, it would still have to get past the browser’s sandbox to do any damage to rest of your system.

If a webpage happens to contain malicious code, a browser without a sandbox wouldn’t be able to protect the rest of your computer system.  This creates a security vulnerability through which malware or viruses can be introduced.  Most browsers, with the exception of Mozilla Firefox, have sandboxing capabilities.

For the most part, the fewer permissions granted to the browser or any other program, the more secure your system will be.

woman with smartphone and laptop, with security icons floating around her.  Sandbox security is important for keeping your computer's system safe from malware.

Most of your computer programs are already using sandbox security techniques, but it’s important to know which programs are already sandboxed to better understand how to protect your computer from the ones that aren’t.

Sandboxes Are Already Protecting You

Browsers are among the many sandboxed programs on your computer. There are plenty of other programs that are already being sandboxed for your protection.

Browser Plug-ins

Content from plug-ins like Adobe Flash or Microsoft Silverlight are run in sandboxes.  An online game made with Flash is much safer when played on a web page than when it’s downloaded and opened as a standard program.  As a sandboxed plug-in, Flash contains the game within the browser, and severely restricts what it can do to the rest of your system.

PDFs and Other Documents

PDFs have become a common source of malicious executables.  PDFs and other documents can contain malicious embedded links, and without sandboxes, these viruses could compromise your system’s security. Adobe Reader now runs in a sandbox, and Microsoft Office also has sandboxing capabilities that keep unsafe macros from infecting your computer.

Mobile Apps

Smartphone apps run their code in a sandbox.  iOS, Android, and Windows mobile apps have far fewer permissions than their standard desktop counterparts.  In order to access functions like your location or camera roll, they must ask for the user’s permission.

By keeping mobile apps in low-permission mode, you’re able to keep the information on your smartphone safe. Sandboxes also isolate apps from each other, so one app can’t affect each another’s functionalities.

Windows Programs

If your computer runs on Windows, User Account Control is a form of basic sandbox security that you come across frequently.  Essentially, User Account Control restricts desktop applications from modifying files within your system without asking the user for permission.

This form of sandbox security offers very minimal protection, since desktop programs can still run in the background and log your keystrokes. User Account Control merely stops unwanted programs from accessing system files and system-wide settings.

How You Can Apply Sandbox Security to Your Programs

Sandboxing your own programs isn’t really something you need to worry about, since so many of the apps and programs you use on a regular basis are already sandboxed.  However, it’s useful to know that most desktop programs aren’t generally sandboxed by default.

If you want to run a program without letting it harm the rest of your system, you can sandbox any program. As mentioned before, User Account Control (UAC) doesn’t do much to protect your system.

Virtual Machines

Virtual machines like VirtualBox™ or VMware create entire operating systems within your existing OS to test programs. This simulated operating system is completely sandboxed, so it doesn’t have access to the rest of your system, and the programs you are testing within the virtual machine can’t access anything outside of its designated boundaries.

Virtual machines allow you to install programs on the virtual operating system and run them as if they were open on your actual OS.  You can then analyze the installed program to determine if it contains malware.

They also have snapshot features, which allow you to reset your virtual machine to state it was before malicious executables were installed. You can then continue to test programs in your virtual machine without worrying about crowding or damaging the virtualized operating system.

Sandboxie

Sandboxie, unlike virtual machines, is a program that creates a protective bubble around your existing computer system, effectively sandboxing the parts of your system you specify.  With Sandboxie, browsing the web is more secure.  Any cookies, cached files, and search history, can all be cleared from your browser when you close the sandbox program. You can even send apps directly to Sandboxie to be examined.

All Things Cyber Security With Geek Aid

If you’re still confused or just want to find out more about how to keep your computer absolutely secure, Geek Aid is here to help.  Our professional geeks know your computer system by heart, and can protect you against viruses and malicious content to keep all of your devices in working order. Call us at (877) Geek-Aid to speak with our geeks today.

A ridesharing customer holds their phone inside a car, worried about how ridesharing apps' privacy policies impact her.

Ridesharing Apps and Protecting Your Privacy

A ridesharing customer holds their phone inside a car, worried about how ridesharing apps' privacy policies impact her.

Ridesharing apps are a popular way for commuters to get to their destinations, but recent events have put ridesharing companies’ privacy policies into question.

 

Increasingly, people are choosing ridesharing apps like Uber and Lyft over traditional cab services.  This is partly because the rates are cheaper, but also because passengers can lower their fare further by carpooling with people traveling in the same area.

Anyone who has used an app like Uber knows that it uses GPS technology to show where drivers and passengers are, in real-time.  This in itself raises some questions about privacy.  But recently, ridesharing apps have given travelers even more to worry about.

Privacy Policy Precedents

Uber has granted its employees access to data on thousands of customers, including when and where each client travels.  This data even includes how long a customer stayed at a particular location. The implications of this are far-reaching.  Data breaches of this kind could leak the personal travel details of thousands of customers.  Additionally, this information could be used to spy on politicians and other high-profile figures.

Uber currently has 40 million users, claiming that these info distribution practices are in compliance with their legal responsibilities and offer sufficient protection for their users.  However, in 2014, Uber revealed a “God View” tool that displayed an aerial view for tracking customers in real time.  These examples raise suspicions about how much ridesharing apps care about customer privacy.

What Kind of Data Is at Stake?

The privacy policies of ridesharing apps bring to light how these companies store, employ and keep our personal data safe.  Most of these apps require that users connect their social media profiles to their account.  Sites like Facebook are giant databases of personally identifiable information (PII). If these details are leaked, customers’ personal, professional, and social lives may be at stake.

Facebook

Using-link Facebook accounts can be an easy method for new users to sign up and log in, but linking to social media accounts means that apps are also collecting information unrelated to getting a ride.  Birthdays, friend lists, which college or university you attend, and interests are also gathered.

Credit Card Account Information

In addition to these concerns, how ridesharing apps handle our payment credentials has also come into question. These apps are usually cashless and require their users to link credit card accounts to pay for rides.  While this seems like a more convenient payment method, our account numbers are only as safe as these companies’ privacy policies.

How Your Personal Information Can Be Leaked

What does this mean for ridesharing passengers at large? Generally, a bulk of the information is collected for marketing, general usage statistics, and app functionality purposes (service improvements).  This information can also be sold to advertisers or third parties.

There are three ways in which a data breach could occur: the information could be leaked during the transmission of it to third parties, the ridesharing company itself may mishandle the information, or the data might be mismanaged by advertisers or third parties.

Two woman stand on the side of the road, having used a ridesharing app to order a ride.

It’s undeniable that ridesharing apps are convenient and combatible with busy lifestyles, so it’s important to protect your privacy while taking advantage of ridesharing apps’ features.

What Can You Do to Protect Your Privacy?

Ridesharing apps are obviously an innovative idea; in an increasingly interconnected world, the concept of using technology to facilitate carpooling is incredibly useful.  Ridesharing is both a green way to go about your daily commute and an inexpensive way to reach destinations inaccessible via public transit.

But because extremely sensitive personal data is at stake here, choosing a ridesharing app is not a trivial matter.  These companies’ privacy policies are available on their websites and should specify what individual user data is being collected.  All apps collect usage statistics and other general facts, but privacy policies tell you which companies send out user specific details (credit card numbers, birthdays, emails, etc.) to third parties.

You can also read other users’ reviews to see what they have to say about their experience.  Reviews are very telling of how a company handles their business, how much they value their customers, and how their policies affect the end-users.

The Future of Ridesharing Apps

Conventional car services like taxicabs and black cars/limos are regulated by law.  With the emergence of apps like Uber taking over the car service scene, questions have been raised concerning legality and classification. Institutions of political power, like the U.S. Senate, have come to ask companies like Uber about their privacy policies.  This industry is still fairly new, and comprehensive security standards have yet to be put in place.

Until then, it’s always a good idea to keep yourself updated on the privacy policies of the services you are using.  Today, data breaches carry the weight of bank robberies in decades past.  Because all of our information can be accessed in one place, it must be properly safeguarded.

While app developers should be obligated to make sure their software protects the data being collected, it is still the responsibility of the user to educate themselves on how their data is being handled.

 

 

 

Moving your business' data to the cloud can be daunting, so understanding the benefits and security measures of cloud computing services is important.

The Cloud: Understanding More About Its Benefits and Security

Moving your business' data to the cloud can be daunting, so understanding the benefits and security measures of cloud computing services is important.

The cloud is a convenient and cost-effective means of elevating your business’ resource allocation processes.

What Is the Cloud?

“The cloud” is one of those popular tech topics people talk about but can’t always define.  The cloud is essentially a network of servers that does two types of things.  One kind of cloud server stores data and while the other uses its computing power to help applications run.

We all come across the cloud frequently in everyday life, especially for storage.  Every time you use an app like Instagram, a cloud server is what holds the pictures uploaded to your account.  These photos are not saved in your phone’s internal memory, but rather in Instagram’s network of servers.  Dropbox is also an example of a cloud server. Every time you save something on your computer that doesn’t take up your computer’s memory, you are using the cloud.

Other companies like Adobe use the cloud to deliver services.  Previously you could buy the Adobe Creative Suite™ in a physical box.  Now, all of these tools exist in the cloud and users pay a subscription fee to access them in the Adobe Creative Cloud™.

How the Cloud Benefits You

When businesses decide to move their resources to the cloud, overhead costs can be reduced.  Before cloud technology became widespread, businesses would have to purchase hardware and computer applications that lost their value over time.  With the cloud, applications previously downloaded on physical computers are now run and updated through the Internet.

Businesses can also be more flexible with their resources.  The cloud allows them to pay for only what they use since cloud computing is a subscription-based service.  It can also accommodate for businesses that have growing bandwidth demands since cloud capacity can be scaled up and down easily.  This kind of agility makes these services cost-effective and adaptive.

The cloud can make your business more secure in a variety of ways.  Lost laptops are a security breach for companies every year because many of them contain highly sensitive information. Not only that, valuable documents may be lost forever when devices are misplaced.

With cloud computing, you can access files at any time via your Internet connection.  This allows you to remotely wipe the memory of lost devices and not have to worry about information falling into the wrong hands.

The cloud benefits the environment by decreasing your carbon footprint, by reducing unnecessary hardware and only using the required amount of cloud storage.  Even in the digital age where more and more companies are going paperless, sustainability is important.

This image shows three different types of cloud securities, "private," "hybrid," and "public." How secure the cloud is depends on the measures you take to protect your data.

How secure the cloud is depends on the security measures you take to protect your data.

Is the Cloud Secure?

Contrary to popular belief, the cloud is quite secure.  However, it requires you to take measures to personally secure your company’s data.  When businesses “move to the cloud,” it requires that you have knowledgeable security staff that understands what that entails.  Your team must know that the data you are moving is sensitive, and apply end-to-end encryption to the data during both storage and transfer process.

A recent study found that 82% of public databases are not encrypted.  Make sure the cloud provider you are using suits your data needs and has what it takes to keep your files secure. Whatever service you choose, it is still the job of the user to define who can access the data, move it, add data, etc., and how those permissions change with each cloud provider.  Defining these terms is known as Identity Access Management (IAM).

In addition to these steps, it is wise to back up your data in separate fault domains.  Fault domains are basically stacks of servers.  They include features that, in the case of a network failure, make sure only the server with the failure would stop working.  This means you have multiple copies of your data, achieving maximum file resiliency.

Cloud Computing Creates a Level Playing Field

Anyone can utilize cloud computing services since they are inexpensive and require only an Internet connection to access.  It also allows small and growing companies to use enterprise-level technology, and even make faster business decisions than larger, more established companies.

Cloud networks facilitate collaboration from your team members, meaning that they can work and share files with everyone, from anywhere.  Cloud-based workflow applications allow real-time remote collaboration and streamline communication.  Gone are the days of attaching files to emails and ending up with incompatible file formats, and ineffective version-control.

Moving data to the cloud means that even the smallest companies are becoming more globally involved. Since growing businesses can be financially nimble using cloud computing services, they can now disrupt a market dominated by Fortune 500 corporations.

If you need assistance in moving data to the cloud, don’t hesitate to contact Geek-Aid. We’re here for all of your technology needs and computer repair questions.

Network security on home computers is just as important as keeping networks on work computers secure.

Network Security: Tips on Keeping Your Home Computer Safe

Network security on home computers is just as important as keeping networks on work computers secure.

Good network security practice can keep the files on your home computer safe.

 

Network Security on Your Home Computer

No matter how much time you spend on your work computer, your home computer contains some of your most important files.  Our personal machines help manage our finances, social relationships, and professional lives, but we often don’t put in as much effort into keeping them secure.  Our computers contain a variety of personally identifiable information (PII), and it’s important to maintain sound computer and network security to protect your files.

Connecting Your Computer to a Secure Network

A network router is your first point of contact with the Internet.  Don’t just rely on your ISP (Internet Service Provider) or cable modem to perform comprehensive security monitoring.  An Internet connection starts with your modem, connects to your router, and feeds this information into your computer. Your router should be secure before connecting to the Internet.

Here are a few tips to maintaining network defense, once you are connected to a secure network.  First off, use a web browser with sandboxing capabilities. A sandbox is an isolated environment that mimics an entire computer system, which targets suspicious programs and analyzes potential threats.

Browsers with sandboxing capabilities are especially useful for recognizing advanced persistent threats (APTs).  These APTs are designed to escape detection, breaking through conventional security barriers, and gaining access to PII on your computer.  Sandboxes help capture these viruses and clear them out.

When you own a business, you want to keep your home computers well-defended because any crossover information between work and personal machines, through email or messaging apps, can cause a data breach.  A recent study found that 60% of small companies fail due to poor network security measures.

Sandboxing can be applied to a number of different programs, such as PDF readers.  A common means for viruses to attack your computer is through embedded URLs, where malicious executables can gain entry via PDF files.

Keep Everything Up-To-Date

While this may seem self-explanatory, many malware attacks occur because personal computers are not as diligently updated as company devices.  Make sure your computer has current versions of all software you run.

Updating programs like Microsoft Office to the 2007 version or a more current iteration is a good idea, since word-processing is a common function on home computers.  Microsoft Office 2010 offers a “Protected View” that opens documents in read-only mode, which blocks any viruses embedded in unfamiliar files.

Many applications have a feature that enables automatic updates.  Updating frequently is a good network security practice, since attackers typically exploit hosts that don’t have their software applications fully patched. Additionally, evaluate which programs you use most frequently and those you never seem to use.  Do some research on the software you wish to delete, and determine if removing them is possible.   Fewer applications on your computer workstation mean fewer channels for hackers.

Man holding credit card, sitting in front of his computer. Practicing good network security techniques is important for safeguarding personal information, like credit card account credentials.

By practicing good network security techniques, you can avoid phishing attacks and social engineering traps that can steal personal information like your credit card account credentials.

Social Engineering and Phishing Attacks

Some of the most common attacks are executed through email.  A social engineering attack uses human interaction to obtain sensitive information on computers with vulnerable network security.  In these infected emails, a person can claim to be an employee, cleaning service, or someone else offering qualifications that would allow them to gather your confidential information.

Phishing tactics also use emails from attackers masquerading as reliable organizations to obtain personal details.  Often, these phishers will take advantage of events in the news (i.e. fake natural disaster fundraisers) and holidays (i.e. Christmas shopping deal scams) to steal account information.  They even go so far as to pose as reputable banks to issue fraudulent warnings, hoping that alarmed card holders will hand over their account credentials.

 

Keeping Your Home Computer Safe From Attacks

To avoid these attacks, install anti-virus and anti-spyware software, firewalls, or email applications that filter your inbox.  Whenever you are asked for sensitive information such as your credit card number or even your birthday, verify that your information isn’t falling into the wrong hands.

If you suspect that you’ve received a phishing email, call the organization the message claims to be from.  Use the contact info on the legitimate website, and ask about the email.

In general, don’t open unfamiliar links or messages with attachments, especially from email addresses not in your contacts.  Also, find out how to build a strong password and employ those methods for all of your accounts.  Secure and complex passwords should not only be used for WLANs but also for any devices in your home and work that use web interfaces (i.e. printers, self-automated light switch systems, etc.)

When it comes to protecting your personal information, there’s no such thing as taking too many precautions.  At Geek-Aid, we specialize in every kind of cyber security.  We all rely heavily on personal computers to manage many aspects of our lives, and keeping these devices secure is a top priority.

 

 

An billboard against a blue sky with clouds that says, "Internet Neutrality: Straight Ahead," the opposite of what will happen if practices like zero-rating become a widespread standard.

Zero-Rating: Net Neutrality and What You Can Do to Protect It

An billboard against a blue sky with clouds that says, "Internet Neutrality: Straight Ahead," the opposite of what will happen if practices like zero-rating become a widespread standard.

Zero-rating is a sneaky way that ISPs try to control the way we consume data on the web.

 

At the end of the day, the Internet is just a network of tubes.  So who’s to say which tubes cost money to use and which don’t? Without net neutrality, Internet service providers and other companies can use strategies like zero-rating to forever change the way we browse the web. In a world where most television networks are controlled by a few major companies, the Internet is really one of last level playing fields out there.

What Is Net Neutrality?

Net neutrality is the concept that all Internet traffic should be treated equally. That means that ISPs (Internet Service Providers) do not have the right to block, slow down, or use paid prioritization to favor one website over another.

Essentially, a world without net neutrality is a world of censored knowledge. An open internet benefits everyone. Medical professionals in developing areas can search for critical information to treat patients.  Small family-owned businesses have the opportunity to expand into multi-national companies, servicing millions. People around the globe deserve an equal chance at success.

The Internet is and should always be an open forum for the free exchange of ideas.  In fact, the UN recently deemed Internet access a human right. In the digital age, it is important to discuss and determine the ethicality of Internet usage control.

Zero-rating

One sneaky way that ISPs are controlling the way we use the internet is through zero-rating.  When you use data to browse websites on your smartphone, your service provider keeps track of your data usage.  To prevent users from maxing out their data caps on the first day, say by watching two hours of YouTube on their daily commute, they zero-rate some sites.

With zero-rating, certain sites or apps don’t count towards the total amount of data you’ve used.  For example, a video streaming company can pay your service provider in advance to join this “zero-rating club.” This makes their services more appealing than another streaming site that fills your data cap more quickly.

If you think about it, there is no need for data caps or zero-rating.  If networks already have enough bandwidth to unlimited data to zero-rating sites, then there is enough for everyone.  On top of being highly illogical, this practice is violating net neutrality.  The Netherlands, Slovenia, and Chile have already banned this practice, but the FCC remains silent on zero-rating regulation.

A World Without Net Neutrality

If ISPs continue to offer preferential treatment, strong service companies will become even more powerful.  Not only that, ISPs will dictate how you surf the Internet in your free time.  Right now, the web is composed of mostly streaming sites, blogs, games, social media, and email services.

Service providers will want to control which sites cost more to visit, and will also want additional fees from every website to show their content to customers. They can also choose to block certain sites and make visiting certain sites more expensive than others.

For those who argue that abolishing net neutrality can increase service provider competition, a free and open internet also stimulates ISP competition.  It also is the backbone of entrepreneurship in the digital age.  It promotes freedom of speech innovation.  Lack of net neutrality can lead to monopolies, which are already a big issue in free market economics.

What Can You Do About It?

To speak to your local legislators about this issue, or to contact members of the FCC like Chairman Ajit Pai, Mignon Clyburn, and Michael O’Reilly, here are some tips:

The first and easiest way to contact them is via email. Their email addresses are located on their website. You can also call them.  Legislators take their call appointments seriously.  If you are interested in tech and have educated opinions to provide on the issue, they are eager to listen.  Since they themselves are not tech experts, they want to be as informed as possible when creating tech policies.

If you are a DC local, you can choose to speak with them in person. If you are not, you can even make appointments to video chat with FCC commissioners or local legislators.

The Internet is a utility, not a commodity. Under the Obama administration, it was deemed a telecommunications service, meaning that it receives the same treatment as water, gas, and electricity services.  However, under the Trump administration, these rules are projected to reverse.  If you are a net neutrality supporter, it is your job to voice your opinion.

If you would like to receive more news on the latest in cyber security, Internet happenings, and general technology buzz, stayed tuned on our Geek-Aid blog.

Internet of Things banner with icons.

Protecting the Internet of Things

Internet of Things banner with icons.

Can the government protect Internet of Things devices?

Forbes describes the Internet of Things (IoT) as “the concept of basically connecting any device with an on and off switch to the Internet (and/or to each other). This includes everything from cell phones, coffee makers, washing machines, headphones, lamps, wearable devices and almost anything else you can think of. This also applies to components of machines, for example, a jet engine of an airplane or the drill of an oil rig.”

This concept plays a big part in the future of technology and the devices we use. The biggest concern surrounding the topic of the IoT is security. How do we protect these internet-connected devices from threats and hackers? As the components of important machines are left vulnerable, this issue becomes more and more prevalent.

Now, the government is getting involved. A new Senate bill seeks to improve the security of government devices. Many IoT devices, like cameras, computers, and more are vulnerable to attack. Recent attacks have even allowed hackers access to popular services. As more IoT devices are attacked, the government wants to make sure that they meet basic standards of security.

Internet of Things Cybersecurity Improvement Act

Several senators, including Mark Warner, Cory Gardner, Ron Wyden, and Steve Daines, introduced the Internet of Things Cybersecurity Improvement Act. The new IoT Cybersecurity Improvement Act wants to add better security to devices purchased by the U.S. government. It mandates that devices support patches and password changes, which would help decrease their vulnerability. The senators also want government devices free of known exploits. These standards allow government officials to keep their devices updated and prevent future attacks.

“While I’m tremendously excited about the innovation and productivity that Internet-of-Things devices will unleash, I have long been concerned that too many Internet-connected devices are being sold without appropriate safeguards and protections in place,” said Sen. Warner. “This legislation would establish thorough, yet flexible, guidelines for Federal Government procurements of connected devices. My hope is that this legislation will remedy the obvious market failure that has occurred and encourage device manufacturers to compete on the security of their products.”

What This Bill Could Mean for IoT Devices

Updating the security of these devices could mean a lot for the safety of government information and services. Sen. Gardner notes that “The Internet of Things (IoT) landscape continues to expand, with most experts expecting tens of billions of devices operating on our networks within the next several years.” The more IoT devices that we have available, the more opportunities hackers have to access or interfere with valuable information and services.

Hopefully, the bill will affect all IoT devices, not just the ones used by the government. Manufacturers could raise the standards of their security overall to gain government contracts. If it is passed, only researchers, who are meant to test security exploits, will be exempt from purchasing devices that don’t meet the new standards of security. If you wish to learn more about the Internet of Things Cybersecurity Improvement Act, you can find out here.

Business man and woman using a computer.

Checking Your Computer Security

Business man and  woman using a computer.

Checking your computer security settings can keep your information safe.

Last week, we discussed a couple of habits that will help you protect your computer’s security. Hopefully, you now know how to navigate the internet better and protect your data. In order stay vigilant and protect your computer, there is more that you need to know. After all, there is only so much you can do to keep hackers from trying to access personal information. Let’s discuss how you can check if your computer’s own security methods are in working order.

Keep Your Computer Updated

Computer companies know how troubling hackers can be, for both them and their consumers. They do not want hackers infiltrating the private information of the people who buy their machines. That’s why they constantly update their computer security system to fight off all sorts of viruses, malware, and trojans. The first thing you should do is check if your computer is running the latest update. This will ensure that it is up-to-date and ready to fight off anything trying to penetrate your system.

Scanning Your Settings for Better Protection

There are plenty of useful tools that computer manufacturers release as well. These tools are able to scan your computer for potential problems like weak user passwords or if you are using all of your security features. They can also educate users on the proper security setting for protection against threats. Just remember to download this kind of software straight from your computer’s manufacturer and not untrustworthy sites.

Secure Your Internet Browser

The number one way that hackers gain access to your computer is through the internet. Accidentally opening suspicious emails, clicking random links, or browsing unfamiliar websites can leave you at risk. In order to avoid downloading something malicious, you have to secure your browser’s own security settings. You’ll find that your browser does more than just block pop-up ads. Like your computer, your browser needs to stay updated to protect your system. Your plugins need to stay updated as well. If they remain out of date, then your system is vulnerable.

Make Sure You Have a Strong Firewall

The biggest defense against hackers is your system’s own firewall. Most computers come with a built-in firewall. They block others from penetrating your computer’s files and prevent them from seeing your system online. You have to make sure this computer function is working at optimal efficiency. Try running a port test service. These services are meant to test your firewall and make sure the world cannot see your computer. If it can detect your computer, then it’s very likely that your firewall settings are not correct or that you have a virus.

Make Sure Your System Is Secure With Geek Aid

Confused? Want to make sure that your system is absolutely secure? Well, Geek Aid is your best bet. Our geeks are trained to know the ins and outs of your system. That way they can not only protect you against viruses or threats but keep your system in working order. We make house calls and service offices as well. So, call us at (877) Geek-Aid to speak with one of our geeks today.

Go to Top