8776363957
Connect with us:
LinkedIn link
Facebook link
Twitter link
YouTube link
Gigabit Systems logo
Link to home
Who We AreManaged ServicesCybersecurityOur ProcessContact UsPartners
The Latest News in IT and Cybersecurity

News

A cloud made of diagonal linesA cloud made of diagonal lines
A pattern of hexagons to resemble a network.
Cybersecurity
News
Tips

Social Engineering an Internet Crisis: How to Stop Internet Manipulation

January 29, 2019
•
20 min read

With the help of the Internet, anything that we could ever ask for is attainable at the touch of the button. Yet at what point should we begin to ask ourselves - is this all too good to be true? This can very well so become the case if the Internet is not mindfully navigated.

Mindfully navigating the Internet means understanding its negative externalities. Among these include social engineering, which describes the practice of manipulating others to give up confidential information and/or make a security mistake. The term is broad and encompasses a wide variety of malicious activities, but with one thing in common - the intent to use psychological manipulation to trick users. In order for businesses of all sizes to place a firm halt on social engineering, organizations must understand how these processes flourish and fail.  

The Prevalence of Social Engineering

How does social engineering take off? More importantly, how are attackers given a platform to identify and manipulate? In order to design a convincing attack, social engineering requires quite a deal of research on the intended victim. The attacker will gather necessary background information to determine a point of entry, or in other ways, just how they will gain the intended victim’s trust and legitimacy. Some examples of manifesting personal data to gain trust include an attacker introducing themselves as a life insurance salesman to a parent, or as a human resources representative to a young professional.

Attackers are often looking to gain any of the following from their victims: passwords, bank information, medical records, political affiliations, and the like. As previously stated, social engineering is rooted in psychological manipulation. This reliance on human error is an entirely unique layer of danger than the conventional cyber-hack; with this breed of attack, the victim is in the driver’s seat. By concluding what your implicit biases and internet patterns are ahead of time (via social media, public documents, and etcetera) attackers can effectively exploit your natural inclinations.

The Tactics of Social Engineers

Social engineering attackers often turn to e-mail use as a way to commit their crime. In this scenario, for example, let’s say there are two friends: Jane and Stephanie. The attacker has managed to access Jane’s entire contact list, and identified Stephanie’s information. Stephanie then receives a message with a download of pictures, musics, movies, documents, etc., or a link to a website that you’re curious to visit. If Stephanie clicks on any of the attachments that she thinks Jane sent her, she is now at risk of the same computer virus that Jane has. Falling into these traps can give the attacker access to your machine, e-mail, social network accounts, and etcetera, which can ultimately expose your entire network to the virus.

Another type of social engineering attack includes baiting. Baiting involves a false premise to scheme the victim into pursuing something they would presumably want. Digital bait can be found in peer-to-peer websites offering to download music and/or a movie, or a link to win a free vacation. If there is a purchase involved, victims might permanently lose the cost of that “item,” or in some extreme cases, their entire bank account. Physical baiting exists, too. Aside from enticing advertisements, some scenarios involve placing malware-infected flash drives in public. Similar to digital bating, physical bait is frequently labelled as something thought-provoking, i.e. salary information.

To begin the discussion of how best to halt social engineering, let’s first examine two very public examples: one involving BlackRock, and the other involving the Associated Press. Regarding BlackRock, the unidentified attackers sent a series of fake communications to convince employees of the world’s largest asset management firm that their company was making a huge shift in investment strategy. These communications included emails, press releases, and a detailed website all designed to “announce” CEO Laurence D. Fink’s dedication to environmental causes. In 2013, hackers gained access to the Associated Press’s twitter account. Tweets of fake frightening news catalyzed a tank the markets that confused investors, government leaders, and the general public. Both examples embody how any business, whether large or small, can fall short in defending themselves against social engineering attacks.

While one hacker’s motivation may vary compared to the next, there are a series of measures every organization can adopt to ward away social engineers. One tactic involves adopting best password practices. According to Bloomberg, 6 letter passwords with only lower case letters can be obtained by hackers within 10 minutes. Optimal password security should involve a mix of uppercase letters, lowercase letters, numbers, and symbols. It is also recommended not to use the same password for each and every one of your accounts, especially if you associate many different accounts with the same username/e-mail address. You may also want to maintain a physical copy of your username and password combinations as a means of staying organized and motivated to uphold password security.

Are you looking for an IT company that specializes in Cyber Security while staying within budget? Contact Gigabit Systems.

How to Halt Social Engineering

Furthermore, living in the digital age means acknowledging just how far reaching social media has truly become. Social media gives anyone and everyone a platform (in fact, on several platforms) to broadcast everything they say, think, or do. The more information available on an individual, the more likely that an attacker can manipulate what they know about you and encourage a detrimental choice. When using social media, be careful what you share and with whom. Some measures include turning your accounts on private, limiting what you share and when you share it, and most definitely keeping your personal information to yourself.

Conclusion

Our world in 2019 is dependent on the Internet. With no sign of slowing down, consumers must be aware of how and why their data might be used against them. Social engineering, the process that an attacker uses to psychologically manipulate their identified victims, must be recognized and addressed through password security, mindful social media use, and education. By understanding the circumstances that enable social engineering attacks to thrive, coupled with the strategies used to curb similar attacks, Internet users may combat social engineering without having to sacrifice the World Wide Web.


Learn more about the latest in cyber security by subscribing to our blog; https://www.gigabitsys.com/news  

Cybersecurity
News
Tips

Notable Cyber Security Certifications for 2019

January 22, 2019
•
20 min read

2018 proved that major cyber security breaches are on the rise. Complimenting this growing need to pay attention to how businesses address cyber security is its job market. According to Cyber Seek, there are approximately 302,000 cybersecurity job openings throughout the United States - 769,00 cybersecurity professionals are currently employed in the American workforce. By 2021, Cyber Seek reports that 500,000 Americans will be cybersecurity professionals, with 3 million jobs open in that same field for the rest of the year. As the cyber security job market expands, here are some top certifications to keep an eye out for.

Certified Information Security Manager (CISM)

The Certified Information Security Manager (CISM) is particularly useful for IT professionals interested in managerial-level responsibilities. Designed by the Information Systems Audit and Control Association (ISACA), those interested in applying for this program should be looking to refine their advanced skills in security risk management, program management, governance, and emergency preparedness. Those who hold this credential are usually experienced security professionals who have agreed to the ISACA Code of Professional Ethics, passed a comprehensive examination, comply with the organization’s education policy, as well as a minimum of five years security experience.

The credential is valid for three years, and holders must pay an annual fee that varies based on whether or not you are an ISACA member. The ISACA also offers several other credentials for IT managers. These include the Certified Information Systems Auditor (CISA), Certified in the Governance of Enterprise IT (CGEIT), and Certified in Risk and Information Systems Control (CRISC).

CompTIA’s Security+

Unlike the CISM certification, the Security+ certification is aimed towards entry-level professionals with at least two years of experience working in network security. Those interested in this program should be experts in areas such as threat management, cryptography, identity management, security systems, security risk identification and mitigation, network access control, and security infrastructure. This highly respected and vendor-neutral security certification is often preceded by the Network+ certification, also for entry level professionals.

CISSP: Certified Information Systems Security Professional

The Certified Information Systems Security Professional (CISSP) has a prestigious reputation worldwide. An advanced-level certification, CISSP credential holders are considered experts in managing security standards, policies, and procedures within their organizations. As the demand for highly skilled IT professionals grows, advanced job seekers in the field should expect to see this certification as a must-have on many position vacancies.

In order to receive the CISSP certification, professionals will need a minimum of five years of experience in at least two of Common Body of Knowledge (CBK) domains. These domains include: Security and Risk Management, Asset Security, Security Architecture and Engineering, Communications and Network Security, Identity and Access Management (IAM), Security Assessment and Testing, Security Operations, and Software Development Security. There is a steep $600 fee to take the exam and an annual fee of $85 to maintain the credential. All credential holders are required to recertify every 3 years, while earning 40 continuing professional education (CPE) credits annually.

Conclusion

As issues of cyber security dominate the public’s attention, it should come as no surprise that there is an exponentially growing job market for information technology professionals. To keep up with this demand, businesses should remain well-read on the various types of cyber security certifications, and how investing in employees and their continuing education may provide a rate of return.


Learn more about the latest in cyber security by subscribing to our blog; https://www.gigabitsys.com/news    

Cybersecurity
News
Tips

The Potential Risks of 2-Factor Authentication

January 9, 2019
•
20 min read

Many cybersecurity experts recommend 2-Factor Authentication (2FA) as an up-and-coming, innovative tactic to combat incoming hackers. Traditionally, a user only needs to provide both their username and a password to access data. 2FA instead requires an additional code that only the user should have access to, via another device and/or application. There are still, however, ways for hackers to bypass the barriers to entry that 2FA attempts to create. Before your business brings 2FA into their cybersecurity strategy, here are some worst-case scenarios to be on the lookout for.

The Dangerous Side of 2-Factor Authentication

As told by Kevin Mitnick, a tool that allows hackers to pull off attacks against firms that employ 2-Factor Authentication can be easily downloaded online. Kevin, who is the chief hacking officer at KnowBe4 (a cybersecurity company which trains people to spot phishing attempts), explained to CNBC that these attacks start with a fraudulent email. The email will usually ask the receiver to click on a link that directs them to log into a website with a code sent to their cell phone. While this is happening, the log in goes to the hacker’s server; the hacker is then able to get the session cookie, allowing them to take on their role without any username, password, or two-factor necessary.

This type of attack falls under the umbrella of social engineering. Social engineering entails when hackers manipulate human behavior in a manner that encourages a certain decision, such as clicking on a link or sending a message. To prevent yourself and your business from tactics such as these, it should be encouraged to pay close attention to any message you receive. IT departments should also be looped into the conversation if uncertainty looms.

How to Secure Your 2-Factor Authentication

To protect yourself from attacks such as these, consider a tool called security keys. A security key resembles a keychain, but contains a hardware chip. The key then uses Bluetooth or USB as the second factor needed to log in. Mark Risher, Google’s director of product management for security and privacy, recently spoke on behalf of his company’s own security key - the Titan Security Key. Their security key stores their own password and requires the site to prove its legitimacy before sign-in.

Yet even when all elements are in tact with two-factor authentication, your account information may still be compromised. An example of this came in 2014, when hackers broke through two-factor protection to gain access to user accounts for Google, Instagram, Amazon, Apple, and etcetera. This case study supports the idea for organizations to move towards modern authentication. Modern authentication would entail adaptive access control solutions that reposition themselves by using metadata captured via an authentication workflow that prevents hackers from carrying out successful attacks. This model improves security posture, but not as a detriment to user experience.

Nothing is Perfect

While 2-Factor Authentication does provide an extra layer of screening before a user can access their account, it is not bulletproof. Intelligence exists online for hackers to train themselves on how to carry out a malware that bypasses 2FA, raising a real cause for concern. In light of this, businesses using 2FA should consider evolving their cybersecurity strategy. While this may include security keys and/or a modern authentication technique, this case study stresses the importance of keeping a cybersecurity strategy up-to-date with modern trends and crises in the technology realm.


Learn more about the latest in cyber security by subscribing to our blog; https://www.gigabitsys.com/news 

Cybersecurity
News
Tips

Is There Such a Thing as "Ethical Hacking?"

January 15, 2019
•
20 min read

How can someone put the words “ethical” and “hacking” in the same term without creating an oxymoron? Believe it or not, ethical hacking exists. Often referred to as Penetration Testing, ethical hacking or “white hat hacking” describes the act of intruding/penetrating into system or networks to discover threats that a hacker could potentially find and use to steal data, cause financial loss, or other major damages. Some attribute ethical hacking with improving network security, and allowing businesses to detect vulnerabilities that a hacker might have taken advantage of.

The Growing Popularity of Ethical Hacking

With 71% of cyber criminals able to breach a perimeter within 10 hours, the need for people who can spot gaps in a business’s cyber security strategy grows. As the need grows, so does the salary. One “bug bounty” company Bugcrowd found that some ethical hackers ask for up to $500,00 per year to test security flaws for companies and/or organizations such as Tesla and the Department of Defense. When contracted, white hat hackers operate under a clearly defined contract. Under these rules, the hacker’s salary depends on if they were able to find a flaw in the cyber security infrastructure, and how serious that flaw actually was.

It should come as no surprise that even while this line of work used to be freelance, many ethical hackers are now looking to turn this function into a full-time career. According to a study by Bugcrowd, half of ethical hackers reported having-full time jobs. On the other hand, 80% reported that an ethical hacking task helped them land a job in cybersecurity. Of this sample, the top 50 hackers had an average yearly payout around $145,000.

In-House Ethical Hacking

Are you interested in bringing ethical hacking to your business? Ethical hacking can be outsourced to consulting firms at “bug bounty” companies such as Bugcrowd, HackerOne, Synack, and Cobalt. Alternatively, some companies also allow their own employees with hacking skills to carry out parallel missions. This is done through in-house penetration testers, where employees are asked to play the role of a malicious hacker looking to shut down servers and/or steal information. Since IJet and Tesla pay hackers up to $1,000 to $15,000 per issue discovered, in-sourcing these assignments may lead to a raise in pay grade for those willing and able to take on the task.

Don’t wait for a cyber criminal to attack. Contact Gigabit Systems today.

Conclusion

For information technology professionals looking into continuing education in ethical hacking, several courses and certifications exist. These certifications include, but are not limited to, EC-Council’s Certificate Ethical HAcker (CEH), SysAdmin, Networking, and Security (SANS) Institute, and McAfee’s Foundstone Ultimate hacking courses. Businesses that are looking to grow their ethical hacking capabilities may look to consider tuition reimbursement programs as a means of encouraging IT professionals to continue their education in this discipline.

The answer is yes - there IS in fact such a thing as ethical hacking. Having a third party take on the role of a white hat hacker, or otherwise hack into a system or network to identify a threat before someone malicious does, is a deeply proactive cyber-security tactic. For those looking into ethical hacking in order to steer clear against the projected number of attacks in 2019, businesses should consider “bug bounty” companies as consultants or investing in-house in ethical training certifications.


Learn more about the latest in cyber security by subscribing to our blog; https://www.gigabitsys.com/news 

Cybersecurity
News

The Relationship Between Privacy and Security in the Cyber-World

January 2, 2019
•
20 min read

Privacy: when information is available for a select number of eyes and hears only

Security: the true test of whether or not you are free from danger or threat

Issues surrounding data privacy on the World Wide Web dominated headlines in 2018. These headlines, such as news of the Facebook data breach in March and the European Union’s General Data Protection Regulation in May, signal changes to how the world values data privacy and security in the digital age. Harvard Business Review recently shared that privacy and security are converging due to the rise of big data and machine learning. Keeping this in mind, it is now more critical than ever to treat privacy and security as one of the same.

Defining Privacy versus Security

While the two appear as two different sides of the same coin, privacy and security each describe two different concepts. Privacy ensures that your personal information, often including corporate confidential information, is to be collected, used, protected, and destroyed in a manner that is both legal and fair. On the other hand, security limits the access to personal information while also protecting against unauthorized use and acquisition.

One example of how privacy functions versus how security functions is within a virtual private network. A VPN is a security product that encrypts any and all data that you send or receive on your device. Regarding privacy, a VPN helps block websites, internet browsers, cable companies, and internet service providers from tracking your information, browser history, and etcetera. Security, however, protects you from unauthorized intelligence accessing your personal information and other data for their own use.

The Convergence of Privacy and Cybersecurity

Harvard Business Review recently discussed how the threat of unauthorized access to data used to exist as the biggest scare to digital users. With the rise of big data and machine learning, privacy and security are no longer separate functions. We instead should pivot our attention towards the fear of unintended inferences. These inferences threaten anonymity and allow individuals to learn more about us than we intended to share. Examples include when machine learning techniques identity authorship based on language patterns, or when our information is used to assume our political leanings.

When privacy and security converge to prevent these harms, we will begin to see privacy as measurable. While this might not be through a specific, definitive figure, there will be identifiable impacts on businesses’ bottom lines should privacy be at risk. For example, Facebook lost $119 billion in market capitalization following the Cambridge Analytica scandal due to privacy concerns.

To ultimately measure privacy and keep businesses accountable, privacy and security will essentially begin to become on of the same. Organizational leadership should anticipate that legal and privacy personnel will become more technical, and technical personnel will be well acquainted with legal and compliance mandates. As privacy and security converge, these two teams will no longer be able to operate as separate entities - businesses will now be held more accountable for upholding privacy than ever before.

Conclusion

Privacy and security used to exist as two separate entities: Privacy ensured that your personal information is legally used, and security limits access to personal information. With widespread machine learning techniques on the rise, it is now more possible than ever for hackers to absorb and assume certain outcomes from our data. In 2019, businesses should therefore expect privacy and security to converge as the most powerful means of addressing these growing threats.

Cybersecurity
News

What Germany's Hacks Mean for Cybersecurity

December 26, 2018
•
20 min read

Last month, hackers leaked sensitive data from hundreds of German politicians. The hackers distributed the information via the Twitter platform, and did not discriminate what they leaked based off of rank; the data pertained to members of the European parliament, German parliament, and regional state parliaments. Not only does this hack reflect just how global of an issue cybersecurity now is, but also points to some potential new patterns for governments to look out for in 2019.

The Revelation of Deeply Personal Information

The criminals and hackers involved in these cyber-attacks not only exposed and endangered their opponents, but borderline slandered them. This overexposure included deeply personal details about high profile figures and their families, including Chancellor Angela Merkel. The information release took place over several days, but were not formally removed until the following Friday.

Overall, it is fair to assume that the intent was not aimed at exposing state secrets, but more on exposing deeply personal information about particular Germans in the spotlight. This data includes internal political communications, credit card information, home addresses, phone numbers, personal identification card details, private chat logs, and voicemails from relatives and children. To make matters more difficult in finding a motive, the leaks contained information from almost all political parties across Germany, except from the far-right group Alternative for Germany.

Don’t wait for a cyber criminal to attack. Contact Gigabit Systems today.

What Could Have Prevented the Attack?

Warning signs indicating that a cyber attack loomed over Germany existed long before last December. In 2015, Germany security services uncovered a breach in their parliaments servers. While the parties represented did share a commitment to stop outside interference in German politics, no concrete action was taken to ensure that a similar attack would not be as successful. This example should serve as a reminder for governments across the world to invest in robust cyber-security infrastructure, especially if there have been signs of trouble in the recent future.

As previously mentioned, these attacks took place throughout the month of December. However, the public did not become fully aware of just how much damage had been done until several weeks later. To make matters worse, Germany’s Federal Office for Information Security (BSI) did not inform the Federal Crime Office until the rest of the general public received word of the attacks. The BSI then backtracked, and said that they only knew about five isolated cases - only when they were able to connect the dots did they decide to share with the public and the Federal Crime Office. This lack of communication exemplifies how all bodies and entities related to cybersecurity need to work closely with one another in order to prove their effectiveness.

The Future of Cyber Attacks

By failing to share the cyber attacks with the Federal Crime Office until the public was fully aware, Germany implies that they were not fully equipped to recognize matters of cybersecurity as a serious criminal concern. In sum, the Germany’s hacks not only demonstrate that cyber criminals will continue to play a role in international politics during 2019, but also the imperativeness of reacting to a threat as soon as it is realized.


Learn more about the latest in cyber security by subscribing to our blog; https://www.gigabitsys.com/news

Cybersecurity
News
Tips

Global Cyber-Terrorism: What Businesses Can Learn

November 21, 2018
•
20 min read

It is no secret that global cyber terrorism dominated headlines this year. In an era of “fake news,” and overall media skepticism, how should the international community interpret this attention? What explains this growing discussion lies in just how global cyber terrorism has truly become. Cyber-attacks, formerly covered as small incidents carried out by criminal organizations, are now associated with total war maneuvers leveraged by national governments to bring calculated, widespread devastation towards major businesses. Here are some causal trends associated with the growing global cyber terrorism crisis, and how your business can learn from these headlines.

The Expanding Cyber Landscape

Everything we seem to use, from personal to professional, has begun to go digital. One example includes traditional physical processes; even infrastructure industries (i.e. power utilities, water treatment services, and health and emergency systems) have shifted to online use. For example, imagine how a power grid interruption might affect your business. Now imagine if that power grid interruption was the result of a cyber-attack. What might this do to your bottom line?

To elaborate, some innovations within the electricity industry include automated controls; these are implemented through interconnected network systems. This automation, though efficient, creates a new opportunity for cyber-criminals to manipulate a business from within. If an attacker had access to these controls and effectively interrupted a power grid, the affected business should expect lost revenue, additional expenses to restore operations and improve cyber security defenses, regulatory fines, and reputational damage.

While the growing use of connected devices may be compatible for economies of scale, businesses should also consider how a digital world centralizes risk. How do we balance a need for more efficiency with the need to protect our systems and operations? These debates surrounding technology and the internet will likely continue throughout the decade as we become more connected. However, businesses need not choose, and can do both by investing and evaluating in an optimal cybersecurity infrastructure on an annual basis.

Don’t wait for a cyber criminal to attack. Contact Gigabit Systems today.

Advanced Threats: The Difference and the Significance

One commonly held myth among involves the intelligence of cyber hackers. While some define all hackers as evil geniuses, others maintain a more grounded thought in assuming that these are merely individuals trained by other individuals how to perform and complete a criminal task for profit. As the cyber landscape grows and grows, so does the scale of these attacks. Since many of these attacks now involve nation-states and their respective governments, 2018 has consequently seen an upsurge of highly skilled hackers.

This backing not only makes a hacker’s criminal intent more politically feasible, but fiscally feasible. With national backing, these hackers are not limited to their past tendencies of merely implementing knowledge passed on from their so-to-speak “colleagues.” As global cyber terrorism and its association with nation-state war tactics expands, so will the access to more sophisticated resources. Businesses must prioritize comprehensive internal IT training, complemented by external consultations, should their cyber security infrastructure remain equipped to combat contemporary threats.

The Future

The expanding cyber landscape is reflected in everything we see and do. With total war tactics identifying targets using the World Wide Web, businesses should understand their role as a potential victim and plan accordingly. It is with little-to-no doubt that we may assume the international community’s continued reliance on the internet in the decades ahead of us. In light of this reality, all businesses must realize that cyber security is more than just online protection, but a critical means of survival.

Learn more about the latest in cyber security by subscribing to our blog; https://www.gigabitsys.com/news

Cybersecurity
News

The Worst of the Worst: 3 Common Types of Cyber Attacks

November 25, 2018
•
20 min read

Cyber Attack: A cyber or internet based criminal stealing your private information

On the World Wide Web, the potential to fall victim of a cyber attack exists at every turn. Of these likely threats, what differentiates one from another? Here are some of the most common types of cyber attacks and how you can recognize one from another.

Ransomware

Ransomware is a type of malware that prohibits users from accessing either the system and/or personal files. In order to regain access, users are coerced into making a ransom payment. The first ransomware developed in 1980s; to regain access, users needed to send payment via snail mail. The malware has since evolved to keep up with the times, as authors now demand that payment be sent either via cryptocurrency and/or credit card.

Some common tactics used to spread ransomware involve malicious spam, otherwise known as malspam. You can identify a malspam message by an unsolicited email with foreign attachments used to entice the reader. These attachments could include PDFs, Word Documents, or malicious websites. Through social engineering, hackers are able to trick potential victims into a ransomware attack vis-a-vis clicking on attachments, links, and etcetera. For example, some cyber criminals will disguise themselves as a powerful entity, such as the Federal Bureau Investigation (FBI), in order to trick individuals into paying a large sum of money towards regaining file access.

DoS Attacks

Denial of services (DoS) cyber attacks flood a website with frivolous traffic in order to slow a website’s speed. The ultimate goal of these attacks are to take a website completely offline, and should be taken very seriously in their potential to threaten your business’s bottom line. By discouraging visitors, potential consumers will likely become frustrated, leave the website, and could even give competitors an upper-hand in acquiring new business. Making matters worse, these attacks are simple to execute and comparatively inexpensive. They are consequently one of the most common among cyber criminals. In fact, the average organization understandably faces approximately eight DoS attacks per day.

Businesses can detect a DoS attack by monitoring their website’s speed. Customers expect a website to load in 3 seconds or less, but any deviation of the norm should be noted and reported internally. While most servers completely crash during a DoS attack, error messages may also point to danger as well. Those looking to improve their DoS detection should explore the “Netstat” command, an evaluation tool found on any Windows or Linux operating system. The command yields detailed information about how your computer communicates with other computers or network devices. Such information is incredibly useful in identifying and troubleshooting any and all networking issues, especially when explored by well-skilled IT professionals.

Man-in-the-Middle Attack

Due to its inconspicuous nature, a man-in-the-middle attack is especially dangerous. Hackers are able to insert themselves into a two-party transaction and steal sensitive data from each party involved. There are specific circumstances that must be in order for a man-in-the-middle attack to thrive - acknowledging how these attacks are successful can become a preventative measure in and of itself. When a network is insecure, i.e. on a public Wi-Fi, attackers are seamlessly able to enter a two-party transaction. Hackers are also able to conduct Man-in-the-Middle attack if they were previously successful during a malware attack. If these hackers breached a device by using malware, the same hacker can install software that enables them to process any and all of the victim’s information.

Of course, businesses can effectively mitigate the opportunity of a successful Man-in-the-middle attack by making sure each and every one of their networks are secured. Such practices should be clearly communicated both inside and outside office premises - for example, if a company has a remote work policy for their employees, leadership must convey the necessity of conducting business on a secure, private network. By preventing malware, businesses can also prevent Man-in-the-middle attacks. Several external IT providers offer anti-malware software, however, such security can be compounded by keeping all operating systems up-to-date and free from unused software and applications.

Staying Ahead on Cyber Security

Several types of cyber attacks exist - while each have devastation in common, each type is unique. Understanding just how commonplace ransomware, DoS, and Man-in-the-Middle attacks thrive is a necessary part of any cyber security strategy. In sum, businesses should support continued education and learning about the different types of cyber attack threats that exist for the purpose of exploring all possible security alternatives.

Cybersecurity
News

New Year, New Me: How to Learn from 2018’s High-Profile Data Breaches

November 18, 2018
•
20 min read

From year to year, cybersecurity attacks continue at an exponential rate. In fact, the Identity Theft Resource Center reported that U.S. data breaches increased by 44.7% since 2016. Each and every business can learn from the shortcomings highlighted by specific 2018 cyberattacks in order to strengthen and progress their cyber-security. Below are three lessons to consider applying your business’s cybersecurity strategy and how other companies learned them by example.

Securing Your Security Department: Why Evaluation Measures are Viable

Earlier this year, Panera bread suffered from a data breach that leaked millions of customer records. The attackers captured this information from individuals who had placed their orders online. To make matters worse, the journalist who broke this story (Brian Krebs) was dismissed by the company’s information security team. In fact, the team deemed his findings as a “scam” when initially presented with them in August of 2017. Little did they know that eight months later, the company would need to take their website offline to patch the issue once and for all. Estimates reveal that 37 million customer records were compromised from this breach.

Don’t wait for a cyber criminal to attack. Contact Gigabit Systems today.

This case study ultimately revealed the flaws of Panera’s security approach. Although the company had an entire department devoted to implementing their cybersecurity strategy, the team failed to effectively identify an imminent threat in a timely manner. Had the company placed evaluation measures to assess the department’s approaches and measures, perhaps they would have mitigated some of the damage associated with the breach. Moving forward, businesses can evaluate their cybersecurity strategy by involving a third party. Involving a neutral, third party insight increases the likelihood of uncovering shortcomings that have internally gone unnoticed. Identifying and attacking these gaps through regular, scheduled security tests should be considered for all businesses looking to up the ante with their evaluation measures.

Keeping it Consistent: The Importance of Third Party Vendors

To elaborate on the topic of third parties, it should come as no surprise that a vendor’s strength should mirror their client’s. For example, Delta Airlines, who outsources some aspects of their customer service engine to an online chat services platform known as [24]7.ai, was forced to notify thousands of customers that their sensitive information had been exposed. This information almost exclusively was limited to payment information that customers had shared via the [24].7ai platform. Other companies who contract with [24].7ai, including Best Buy and the Sears Holding Corporation, also announced that they had customers potentially affected by this same breach.

To share your business’s data and services with another is to share the same values. For this reason, the security controls and measures of your vendors should be of the same or greater quality of your own business. As we transition in 2019, one important strategy to take away from this 2018 incident includes understanding how your vendors implement cyber security. Businesses should read up on each of their provider’s security protocols, and how compatible these are with your own team’s.

Maintaining Cyber Security

With data breaches showing little-to-no sign of slowing down in 2019, we’ve now approached a pivotal moment in cyber security. Within your business’s networks, ask yourselves - we have a strategy, we have an understanding of the issue, but how do we maintain its effectiveness? Overall, the data breaches of [24]7.ai and Panera Bread emphasize the need for quality control and maintenance in cyber security. Cyber security is no longer a foreign concept in 2018; it is reflected in security approaches across all industries and all markets. In sum, keeping these approaches effective and useful requires robust evaluation measures and value consistency when working with third party vendors.

Learn more about the latest in cyber security by subscribing to our blog; https://www.gigabitsys.com/news

Previous
Next
About
Managed ServicesCybersecurityOur ProcessWho We AreNewsPrivacy PolicyTerms & Conditions
Help
FAQsContact UsSubmit a Support Ticket
Social
LinkedIn link
Twitter link
Facebook link
Have a Question?
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Copyright © {auto update year} Gigabit Systems All Rights Reserved.
Website by Klarity
Gigabit Systems Inc. BBB Business Review