Tag

Windows 10

Data with Lock

Top 5 Sources of Security Incidents in Retail

By | Security, Tech Tips for Business Owners | No Comments
by Calyptix, April 13, 2016

computer-security-incident-oopsPeople tend to assume that hackers or other malicious actors are behind the security incidents and data breaches we hear about in the news.

While it’s true – thousands of criminals try to steal data every day – it’s also true that many security incidents are caused by employees.

Employees are the number-one cause of security incidents in the retail and consumer industries, according to the results of the Global State of Information Security Survey (GSISS) 2016 from PwC.

The survey, conducted from May to June 2015, is comprised of responses from more than 10,000 executives of security practices from 127 countries.

Before we dive in, it’s worth noting that the chart applies to security incidents and not data breaches. The terms are slightly different:

  • Security incident – An event that violates a security policy or otherwise puts an asset (such as customer data) at risk. This is a general term and can include network scans, malware infections, or a breach of customer data.
  • Data breach – A confirmed disclosure of sensitive data to an unauthorized party.

security-incident-sources-retail-chart

The top 5 sources of security incidents

Source #1. Employees

Current employees were reported as the greatest perpetrators of security incidents in the retail and consumer industries by those surveyed. The number was 30%, down 12% from 2014.

Employees pose both an intentional and accidental security risk.   They have an insider advantage if they choose to steal data.  But they often compromise their company’s cybersecurity unknowingly.

spear-phishing-security-incidentSpear phishing

Many retail and consumer industry cyber-attacks are initiated when an employee opens an email sent from a villainous source, who tries to trick the recipient into providing personal information, such as logins and passwords.  The act is called spear-phishing, and it arrives as an email that appears to be sent from someone an employee knows.

When the employee opens an attachment, or clicks on a link embedded in the email, associated malware instigates a cyber-attack.  When high-level employees are targeted by this technique it is sometimes called “whaling.”

Spear-phishing has been the point of entry for cyber-attacks on Anthem and Sony.  Stolen data included personal health information, employee social security numbers, and thousands of leaked internal documents.

A 2012 paper by Trend Micro Incorporated found that spear-phishing was involved in 91% of targeted attacks.

Careless or poorly trained?

In 2013 Deloitte reported that up to 90% of user passwords were easily hackable. Splashdata’s 2015 “Worst Password List,” comprised of the 25 most common passwords on the internet, are easily guessable, and therefore highly vulnerable.  They include “123456,” “baseball,” and “password.”

Employees of retail and consumer organizations often put their company’s data at risk by performing work tasks on their own personal devices, often accessed through unsecure WIFI.  They might send work documents to personal email accounts, bypassing security precautions initiated by their employers.

A perceived decrease in retail and consumer employee security incidents could be due to increased employee training.  In addition, more companies are paying vigilance to firewalls, and many businesses require employees to change their passwords on a regular basis.

former-employee-security-incidentSource #2. Former Employees

Former employees are ranked 2nd in the GSISS for security incidents in retail and consumer organizations. Down to 26% in 2015 from 30% in 2014, its share fell 13%.

If employment ends on unhappy terms, it’s easy to imagine an employee with inside information, a grudge to bear, and a lack of morality could be a danger to the company’s security.

A 2009 survey by the Poneman Institute found that 59% of ex-employees surveyed claimed to have taken company data with them when they left their position.

The phenomenon is not limited to retail organizations.

In January 2015 a former employee of the U.S. Nuclear Regulatory Commission and the Department of Energy (DOE) was charged with sending 80 spear-phishing emails to DOE employees seeking sensitive information in exchange for money from a foreign embassy.  He had been terminated by the NRC in 2010.

A former employee of the U.S. Embassy in London was charged in August 2015 with seven counts of computer hacking to extort, one count of wire fraud and nine counts of cyber-stalking.

Those surveyed could be responding to increased company diligence to eliminate logins and passwords of employees immediately upon their termination.  Companies are also improving their data encryption, and many have dedicated IT security personnel that help prevent former employees from taking information with them when they leave.

Source #3. Service Providers, Consultants, Contractors

The survey respondents reported a 21% increase, from 19% to 23%, in retail security incidents caused by current service providers, consultants, and contractors, also known as third parties.

Third party contractors include any outside organization hired by a company.  Third parties run the gamut from lawyers, to electricity providers, to security providers.

As reported by Krebs on Security, the 2013 Target heist that compromised the credit and debit accounts of millions of people was orchestrated through network credentials stolen from one of their Heating, Ventilation and Air Conditioning Contractors.

Cloud security risks can also rise when a retailer uses a third party vendor, since the retailer rarely knows the veracity of the vendor’s employees and partners.

security-incident-source-hackersSource #4. Hackers

The GSISS attributes 21% of retail security incidents to hackers in 2015, up from 20% in 2014.

Hackers perpetrate direct attacks.  Their goals are as numerous as they are varied.  They can be nation-states, lone wolves, and hacktivists, who break into databases on what they see as benevolent missions.

Hackers break into databases to steal personal identities and financial information as an act of theft. Most hacking is done for profit, but some people hack for the personal challenge of breaking into systems that are thought to be secure.

The collective “Anonymous” hacks to fight perceived internet censorship. Hackers might have political motivations, and target electrical grids or other civic infrastructure.

In 2015, 21.5 million people had information stolen from the U.S. Office of Personnel Management by hackers.  The New York Times reported the suspect is China, but it is unknown whether the crime was committed by the government or individuals.

Hackers also target intellectual property, or business secrets.  As various segments of government and corporations have become more sophisticated in their ability to fend off cyber-attacks, hackers have sought to invade industries with less sophisticated cyber defenses.

In 2014 hackers compromised the point of sale system at Home Depot with custom built malware that breached the integrity of 56 million unique payment cards.  It’s estimated the cost to Home Depot will be approximately $62 million.

In addition to retail and consumer firms, U.S. law firms have suffered increased hacker attacks in the United States because they are in possession of potentially lucrative information, and lag other professions in cyber security.

In a recent survey reported by Legal Tech News, less than half the law firms surveyed had intrusion detection systems, email encryption on all their services, or logs of employees who accessed public health information.

Source #5. Organized Crime

Those surveyed identified a minor increase, from to 18% in 2015 from 17% in 2014, of retail and consumer organization security incidents by organized crime, the final group identified in the GSISS report.

According to the report, some in the financial industry believe that increasingly, cybercrime is a collaborative effort between foreign nation states and organized crime.

The FBI reports a sampling of the organized criminal threats to the U.S. include groups from Africa who perpetrate financial schemes, Russian mobsters who moved to the U.S. after the collapse of the USSR, and Asian groups including the Japanese Boryokudan.

A white paper written by The RAND Corporation notes that black markets where data is sold are growing in complexity and size, and that hackers are morphing from random individuals to sophisticated, financially driven groups, often associated with traditional crime groups such as mafias and drug cartels.

The dangers are real, and the smart money is on those who exercise continuous vigilance on the cyberfront.

Managed Services

Maintaining HIPAA Compliance with Online Data Storage

By | Backup News | No Comments

Keeping patient records secure and private is the concern of every hospital and health care provider, but they are often overwhelmed with years and years of patient information and the lack of adequate storage space. Destroying these health records in order to make room for more storage is often not an option. Patients want access to all of their health care records, and physicians need them in order to better diagnose patients. Online data storage is a way to satisfy all of these issues.

Using online data storage for these records allows easier access for patients, and offers easier sharing of patient information from hospital to physician, as well as from physician to physician. Storing health records online isn’t, however, without security concerns. Patients, hospitals, and physicians want assurance that these confidential records will remain safe, private, and secure, and will only be accessed by those authorized to do so.

What is HIPAA?

HIPAA or the Health Insurance Portability and Accountability Act of 1996 was created in order to protect health information and give patients certain rights regarding their private health information. It also allows for disclosure of health information necessary for patient care. This act specifies safeguards necessary for administrative, and physical and technical handling of patient health information.

According to the U.S. Department of Health and Human Services (HHS.gov) HIPAA has many requirements and restrictions. It requires safeguards for:

  • Access Control
  • Audit Controls
  • Person or Entity Authentication

Access control is defined in the HIPAA Privacy Rule as “the ability or the means necessary to read, write, modify, or communicate data/information or otherwise use any system resource.” It should allow authorized users to only access the minimum amount of information necessary to complete job functions. The Access Control specification also requires the implementation of an exclusive user identification or user ID, and immediate access in case of an emergency.

What Type of Security is Necessary?

When dealing with patient records in an office, maintaining privacy and security usually involves storing patient files in locked cabinets where the files can be physically secured and visibly monitored at all times. When you are storing patient information online, certain precautions must be met in order to maintain the same security and privacy guaranteed each patient.

While HIPAA permits patient records to be transmitted over the Internet, businesses will want a service that offers file encryption, authentication and password protection in order to secure the information. Although HIPAA does not require online data storage services to have encryption, it does require that patient information be adequately protected and accessible only to authorized persons. Encryption is the best way to protect that information and ensure authorized access to those records. It is also important to offer backup services in case of a virus attack, flood, or fire. Finally, the service must offer a method of tracking any security breach, as well as the ability to lock out former employees after they have left or been terminated.

When storing patient information, it is important to stay HIPAA compliant, as the fines for not doing so are expensive. While online data storage for health care businesses guarantee less worry, work, and expense for health care providers, the service is only as good as the security offered. Remaining HIPAA compliant is vital in order to continue a good business relationship with the health care industry.

Identity Theft

The High Cost of Recovery from a Security Breach

By | Security | No Comments

Small to medium size businesses are what keep this country moving. Unfortunately, for many of these business owners, budgetary needs force them to make cuts that the mammoth corporations do not have to consider. These budget cuts can often result in reduced security and sub par IT services that in the long run can end up costing the company even more money. Reacting to; and the recovery from, a security breach or attack always costs more after it has happened than what it would have cost to prevent it.

This fact has been supported by recent surveys, and may come as a surprise to many small and mid-size companies who are under the false impression that hackers and other security threats target larger corporations. It has been discovered that companies that have less than 500 employees are actually more likely to be at risk of an attack or security breach than a larger corporation. Of course, this becomes a problem when the larger corporation has the resources to maintain higher levels of security at a time when smaller companies are dealing with restricted or; in some cases, frozen IT budgets.

The benefits of hiring a Managed IT Services Provider in preventing attacks and security breaches

With a security breach a real concern for small business owners, many are making the decision to bring on outside providers to address their IT needs. Managed services providers can offer an affordable solution to small business owners who are struggling to manage an internal IT staff. In some cases there isn’t even an IT person on staff, which can be just as costly for the small business when they have to bring in a professional on an as needed basis. Considering the money and time spend recovering from a security attack or breech, more business owners are realizing the cost of not having this level of protection is too high to pay. Here we look at how managed services providers can help business owners level the playing field against those who would infiltrate their security systems.

  • Increased knowledge- Managed services providers are in the business of technology. They have trained staff who are able to prevent security breeches and spot any activity that could be perceived as a threat. Moreover, they have the expertise to stop threats and prevent the loss of sensitive and private information that can lead to costly recovery measures.
  • Less expensive than in-house IT- Other IT professionals can provide the same security but it will cost much more to the business owner. What many owners are realizing is paying a flat monthly fee for security and other services provided by msp’s is actually much more cost effective than paying an internal IT staff or outsourcing based on incident.
  • Proactive is better than reactive- The biggest benefit of having a quality managed services provider in your corner is the fact that you are acting in a proactive manner to ensure all of your systems are managed properly. This is less expensive and less time consuming than waiting for something bad to happen and then reacting.

Any small business can benefit from the security provided by a Managed IT Services provider. They can do so at a fraction of the cost, therefore eliminating the fear and unnecessary cost of trying to recover from a breech in security or attack.

Click here to learn how Kubicek Information Technologies can help you prevent attacks and security breaches with our Network Security Services for your business in Cumming, Suwanee, Alpharetta, Johns Creek and surrounding Metro Atlanta.

Benefits of Outsourcing for Technology Services

By | Business Tips, Tech Tips for Business Owners | No Comments

Most business entrepreneurs have great talent and the means to run a very successful business. The snag they most often run into is the belief that they can do it all. This mindset can be detrimental to the overall success of their business. Trying to do it all can lead to hindered growth, lower profit margins and in some cases failure. Outsourcing for things like technology services creates an opportunity for both the business entrepreneur to focus on what they do best.

In order to create a business that is structurally sound, expandable and profitable, business owners should focus the majority of their time and energy on their personal talents and skills that are most important to the growth of their business and those skills that will most help in the generation of income. Instead of trying to do it all they can most benefit by delegating certain tasks – and outsourcing for technology services is one of them.

Outsourcing has become very popular and with technology today like the Internet, outsourcing is easy and accessible. Companies can find extremely qualified candidates from around the world right at their fingertips. Many highly trained individuals have left the corporate world and are available for hire as contractors. Expertise in just about any area a business may need is available. Examples include virtual assistants, graphic designers, IT specialists, accountants, marketers, Public Relation specialist, writers and so much more.

Some of the best tasks to outsource include those that are highly skilled tasks or those have that require trained expertise. For example if you have no knowledge of your IT needs or how to build and maintain a company website, hiring a specialist will be much more cost effective that you spending hours trying to teach yourself. Initially, your cost for this type of work might be a bit high, while the contractor helps to access your needs and builds your site. Down the road however, you most likely will be able to outsource our IT needs on a maintenance basis.

Highly repetitive tasks are also good ones to outsource. Data entry or accounts payable and receivable are jobs that you most likely can do, but they will only slow down your own productivity. Many times you can hire a virtual assistant to help you in these areas for just a few hours a week. This will not be overly costly and will inevitably free you up to work on other areas of the business that would most benefit from your attention.

Executive expertise is another area to consider outsourcing, especially if the business owner does not have great knowledge in this area. Someone that can take a hard look at your business plan, profitability margin and any ideas you have for expansion can be of great insight. Many times businesses will hire someone to come in and look over these items just once a month, quarterly or yearly. Their consultations can lead to new innovative ideas that could lead your business to new expansions, higher productivity and higher profit margins.

Most often, the cost advantage far outweighs what you will actually pay out to contractors. Most companies that rely on outsourcing do much better than their competitors.

Click here to learn how Kubicek Information Technologies can help you focus on running your business with our Staff Augmentation and Onsite Placement Services for your business in Cumming, Suwanee, Alpharetta, Johns Creek and surrounding Metro Atlanta.