An Important Reminder: Reflecting on the 2017 ATO Hack

Exploring best practices for the management of AUSkey data and access

It was just last year that the Australian Taxation Office (ATO), reported that the online ATO portals of countless Australian businesses had been targeted by malicious cybercriminals. The ATO quickly notified all businesses to review AUSkey access control after identity thieves gained unauthorised access in hopes of forging or changing business banking information.

Australian Cyber Attacks

For a little bit of business-tax background, an AUSkey allows businesses to securely access a central hub of government and tax services. In addition to ATO access, AUSkey data allows businesses to access Australian Securities and Investments Commission (ASIC) and Australian Business Register (ABR) portals.

ATO Warning: Maintain High Standards for AUSkey Access Control

It was on Monday 30 January 2017 that the ATO issued a warning to AUSkey holders that fraudulent activity has been detected. The ATO issued a formal statement and gave key recommendations for internal risk management and mitigation. The ATO also emphasised the immense risk to businesses impacted by fraudulent AUSkey activity.

“Once an AUSkey has been allocated,” the ATO statement reads, “access is gained to the Business Portal so that fraudulent Business Activity Statements can be lodged and bank details updated to accounts that are not controlled by the entity.”

The ATO offered one leading strategy for internal mitigation: AUSkey protocols must be stringent and well understood among the staff with access. The ATO went on to advise that businesses regularly document the team members who have access and ensure old employees no longer have functional login credentials. The overall extent of the 2017 ATO hack is impossible to know. However, the incident continues to serve as a reminder for businesses to better mitigate risk in today’s cybercrime climate.

A History of Attacks: ATO Frequent Target for Cybercrime Hits

In fact, this wasn’t the first time ATO portals had been subject to fraudulent AUSkey activity. The ATO reported similar attacks in both 2013 and 2015. Andrew Gardiner, a representative from the National Tax and Accountants Association told SmartCompany that the 2017 attack solidifies the true risk involved in an increasingly digital tax environment. Simply put, the financial risks to businesses are high, and professionals must be vigilant.

“Now that we deal with the ATO online on such a regular basis, people do become complacent,” Gardiner said. “People just need to be diligent – and businesses that are diligent treat their AUSkey like their credit card.”

Best Intentions Aren’t Enough: Creating A Well-Rounded Cybersecurity Approach

However, creating rigid internal standards and procedures isn’t the be-all-end-all solution to AUSkey cyber risks. Cyber-attacks happen and very often under conditions outside the control of impacted professionals. So, it’s critical to fully understand the scope of threats facing professionals in an increasingly digital finance environment. After all, these risks have the potential to impact every company’s most critical asset – their clients.

This means doing more than managing internal access and keeping track of AUSkey holders. Businesses must remain one step ahead of the increasingly sophisticated network of cybercriminals in the digital marketplace. The good news is, implementing thorough cybersecurity strategies and best practices aren’t as hard as it seems.

So, in addition to treating AUSkey data the same way as credit card data, here’s a list of strategies for keeping your team prepared and vigilant in the face of cybercrime:

  • Stay in the loop – Knowing what threats you are up against really is half the battle. Staying in touch with news of the latest and most dangerous cyber-attacks allows you to remain proactive and stay informed. Knowledge is power.
  • Communicate with your team – Make sure you’re talking to your team – especially those with AUSkey access – about the potential risks and cyber threats that exist. Create an environment where your staff feels comfortable to ask questions or report suspicious activity of any kind.
  • Make a plan – No matter what, be sure to put down your cyber security efforts on paper in some way. Maybe you’ll schedule regular meetings to check-in on cybersecurity missions and update staff. Perhaps you’ll create a list of cybersecurity standards that all staff members must be aware of. No matter which approach you take, planning ahead is critical.
  • Partner with an expert – If you’re struggling to get a concrete plan in place, reach out to experts. The initial step of asking for help can be tricky, but once you partner with a tech expert, cyber security challenges become much less daunting.

Many Australian IT service providers have extensive experience in providing cybersecurity services across Australia. They work alongside clients from Melbourne to Brisbane to ensure their networks stay secure and well-monitored.

Instead of just wondering if your business’ ATO protocol is powerful enough to stop cybercrooks, find out. Work with a professional managed IT provider and you can expect regular system check-ups. They will identify your company’s weakness and recommend security solutions designed to provide optimal protection for your network, servers, computers, and mobile devices.

Most companies today are not doing everything possible to stop cyber-intruders but if you’re ready to step up your game, then work with the best Outsourced IT services provider in your area.

Remember! Australian businesses are at risk! Don’t wait for disaster to strike. Most IT professionals offer free assessments of your current network in terms of the types and severity of cyber-attacks that might occur. Once you partner with an excellent IT services provider, they will work hard to make sure your systems are fully protected. They will also perform regular backups to all data so that if something does happen, you can quickly reinstall your programs and files and keep working.

What’s New in Microsoft Teams for 2018?

Celebrating its one-year anniversary, Microsoft reports that over 200,000 organizations have downloaded the Teams App. This chat-based workspace is part of Office 365 and developers consistently add new features to make the Teams App even more useful to businesses of every size across all industries.

Microsoft Teams is a great solution for meetings of any complexity and it’s available for all mobile devices, PCs and Mac computers.

Over the years, Microsoft has been successful by listening to their users. That means they stay up to date on the corporate culture all over the world. One of their strengths is to incorporate numerous useful tools into one app while integrating all their programs into an easy-to-access platform.

The painless way to hold a meeting

One of the big changes to the way companies do business these days includes the manner in which their employees meet each week. Whether you run a small business or an enterprise organization, you’ve no doubt got lots of people in different departments with a strong need to get together on a regular basis. In fact, companies in every industry can’t function anymore without the ability to meet up and discuss their work. This has become crucial to a project’s success.

You may be building a new robot that can perform delicate medical procedures or you may be building an incredible concept car. But often, businesses are just involved in ordinary day-to-day activities like selling products and providing good customer service. No matter what your job, your teams will be more productive and more efficient when they can collaborate. And that’s one of the strong points of the Teams App.

New changes in the MS Teams App for 2018

One of the more popular features, Chat Message, has been improved to make communicating simpler. Any team member, including guests, can use the instant message feature. This is a great way to say hello to a new team member or ask someone a quick question. It works much the same as other popular instant messaging apps.

Now teams can have guests, as well as external members. These participants will have access to any features that the team leader permits them to have. And, they only have access to teams that they’ve received an invitation from. Microsoft makes it easy for team leaders to control the guest experience.

SaaS integration

There are a number of SaaS services that can be integrated for use into the Teams App. Go to the “Add a Tab” page and there you’ll find a list of useful apps that can be added at the top of the channel so that all team members can access them.

For instance, click on “Survey Monkey” to add this app and then instruct team members to complete a survey about a current project or other relevant topics. There are dozens of helpful apps that most users are already familiar with including Hootsuite, Jira, Quizlet, and Zendesk.

Another fun feature just added to MS Teams is the Bot. There are all types of bots available in Teams. Growbot lets the team leader give kudos to a team member who has done an exceptional job. This is a unique way to build camaraderie in any team.

Microsoft has made it easier for users to locate the many helpful features in Teams by adding a link called “Store.” Click on Store to view all the available apps. You can also search for an app by name or category. You may want to find an app that deals with analytics, Adobe, or your calendar. Type a word in the search bar and all the apps related to this topic will show up.

The Teams app allows users to view a personalized version of the app so they can see exactly what tasks have been assigned directly to them.  Completed tasks are shown as well.

The instant chat space now has the ability for users to include information from other apps. You may be chatting with a colleague and want to open a project from Visual Studio. Do this by clicking on the “More” dots located on the far right side of the icons at the bottom of the chat box. Once you click on More, this will open up all the apps, tasks, documents, and other items in your customized Teams app. Now you can attach these to your message. This feature is available for the channel or chat space.

Exciting Features

The developers at Microsoft understand the importance of creating a space where team members from all over the world can collaborate.  Though they originally designed Teams for business, this helpful app has found its way into classrooms and colleges, as well as casual get-togethers. Even individuals have discovered how easy it is to plan a birthday party or anniversary celebration using the Teams app. There’s really no limit to its usefulness.

Are virtual meetings the way of the future?

With so many companies now utilizing the power of remote workers, the Teams App can streamline meetings so it feels like everyone is “in the room.”  Whether employees are just down the street or on the other side of the world, they can participate. Virtual meetings have become the preferred way for teams and organizations to get together.

In the past, an organization’s employees would often go to great lengths to attend important meetings. But this is no longer necessary. Most companies have accepted the fact that it’s quicker and less expensive to host virtual meetings. Much research[1] has been completed to learn whether virtual meetings are just as effective as real meetings and the findings show that a virtual meeting can be even more effective than a real one.

Pros and cons of virtual meetings

In real meetings, people often feel uncomfortable. Maybe their chair isn’t set right or they should have dropped by a bathroom on the way to the meeting. When people can meet from their own location, they feel more energized and creative. This results in better meetings where important tasks are accomplished.

Virtual meetings save time and money and they reduce our overall carbon footprint, making them a big plus for the environment. It’s very simple to record a meeting so the contents are saved for later reference. And of course, you don’t have to worry about catching a cold from the guy sitting next to you.

If you need help with any of the new updates for MS Teams 2018, you can find that by searching online or navigating to the Microsoft website.

Microsoft Teams

[1] https://meetingking.com/face-to-face-meetings-vs-virtual-meetings/

How to Use Keyboard Shortcuts in Quickbooks Pro

Quickbooks offers users at every level, an enterprise-grade accounting program to track income and expenses. This software package was designed to enable businesses to track financial expenditures and income with the level of detail necessary for complete control of company finances. It is somewhat like a soft copy of accounting book. Some people may find it a bit hard to navigate using the mouse or the navigation pad of a computer while working on a given document. The good news is that there are alternatives to achieving the same results by using the keyboard.

Tune into our free Quickbooks Training
CLICK HERE

You may find that your mouse gets lost under a heap of paperwork. Wireless mice are great for today’s busy professionals but they often fall off a table and land in the floor. You may have urgent financial reports due and need a quick fix for these issues. You don’t need to worry because there’s a way to get your accounting work done using some keyboard shortcuts.

Below are a few Control key combinations to make your work not only easier but more efficient while working in QuickBooks Online:

To do this in QuickBooks: Press these keys together:
View a list of Shortcuts CTRL + ALT +?
Create an Invoice CTRL+ ALT + I
Create a check CTRL + ALT + W
Enter an expense CTRL + ALT + X
Open the Customer list CTRL + ALT + C
Open the Vendor list CTRL + ALT + V
Open the Help window CTRL + ALT + H
Find transactions CTRL+ ALT + F
Save and go to a new transaction CTRL+ ALT + S
To close any window Click Esc
Create an Invoice CTRL+ I
Create a check CTRL + W
Display Help in context F1
Open the Customer list CTRL + J
Find the History of any transaction CTRL +H (with transaction open)
Open the Memorized transaction list CTRL+T
Find Transactions CTRL+F
Delete Transactions or list Items CTRL+D
Create new list item CTRL+N (with list open)

Some of these shortcuts will work differently when using various browsers as explained below.

To open the second window in:

Internet Express: Press Ctrl + N (You will be logged into existing company on both windows.)

Firefox: Press Ctrl + N (You won’t be logged into the second window, but will remain logged into the first one. The second window will allow you to log into the existing company so that you may work using both screens.)

Chrome: Press Ctrl + N (If you go to QBO in that window, you will be logged into the existing company.)

Split Your Screen

There is a way to split your screen by using shortcut keys on your keyboard. This allows you to have all your information on one page for easy reference while working. Just press the windows key and the left arrow for the screen you want on the left, plus the windows key and the right arrow for the screen you want to appear on the right side. If you want to resume normal screen view, simply press the windows key and the up arrow.

Duplicate Your Screen Tabs

Press the Alt+D to copy the address then press Alt+Enter to open a new tab with the URL. All you need to remember is to keep your thumb on the Alt key. Press Alt key down and then hit D and Enter almost simultaneously in order to duplicate the current tab. This works almost like magic! You get to open your tab twice instead of going back to the browser.

Sending Reminders

You can send invoices reminding clients to pay their bills using your QuickBooks Online and the Navigation Bar. Select Overdue Invoices to view and then finally click on the Send Reminders. You can even track the sent invoices and learn whether the client has viewed them. This also allows you to see how many times the customer has viewed them and whether they have ever viewed your email. If not, you may want to check to make sure you have the right email address for this customer.

Choose items in drop-down lists:

  • Press Tab until you reach the field.
  • Press Alt + down arrow to open the list.
  • Press up arrow or down arrow to move through the items in the list.
  • Press Tab to select the item you want and move to the next field.

If you don’t want to open the whole list, but just want to scroll through the items in the text box, press Ctrl + down arrow or Ctrl + up arrow.

Wrap up

Using Shortcuts in QuickBooks Online can be less time consuming because navigating through your accounting books is much easier when you use simple clicks on your keyboard. Plus, you never have to search around under a table for your mouse again. Shortcuts are a quick, easy method of accomplishing any task. That can help you shave valuable time off your workday so you can get home a bit faster and who doesn’t like the sound of that?

Quickbooks Training

June 2018 Update for Office 365

This article will cover a quick overview of the Microsoft Office 365 for June 2018 updates. The first step to making use of monthly or periodical updates is knowing that they exist. Updates simply provide new capabilities to your software or make improvements on the already existing ones. The challenge is thus having the knowledge on how they work. In a business organization, it would be an expensive affair to conduct employee training every time there is an update. The good news is that Microsoft has already taken care of that. On May 21st it launched the Microsoft Training Service, which is basically a digital customized service for Office 365 and Windows 10.

The classes are designed to help customers learn about the new updates without having a financial impact on management. The pre-pilot phase of this program has been undertaken by twenty-five organizations to help leverage training which includes customizable up-to-date content, right-sized experiences to an organization’s needs, and consumption tracking. These new services by Microsoft will be available as a pilot program in late July 2018. Be on the lookout. Those interested need to register at Microsoft Training Services Pilot.

New Outlook Features.

Outlook features across MAC, Windows, Web, and mobile devices help you manage your time better. Finding a location for your meeting is made easy. When you go to Outlook, before typing your location, it gives you a list of suggestions such as the last meeting, recently used conference rooms, and also common locations. Once you start to type in the location field, Outlook brings up a list of suggestions that are powered by Bing and then finally completes your location with necessary information including full addresses for public locations.

This Outlook service is even better if you are using an iPhone Operating System because it will use your current location, your destination address, and traffic updates to send you notifications on when you should be ready to leave for your next meeting. This amazing feature will soon be coming to windows.

Meeting Invitation Made Accessible

It is now possible to know who has been invited and who is attending a certain meeting. Outlook allows you to see the tracked responses and RSVPs for meetings that you have been invited to. This way, it is easy for you to decide whether or not to go. Sometimes two meetings may overlap. Someone else in your organization may already be going. You can choose to attend the other meeting and then sync up with your colleague later. This is very important as it makes time management a much easier task.

Time Zone

Outlook has added more features on the Time Zone functionality that will help you plan meetings at optimal times across different time zones. It is now possible to display up to three time zones on your Windows calendar. This way you are able to see what is happening in other locations.

New Features in SharePoint and OneDrive

Several features were launched at the May SharePoint Conference in Las Vegas for both SharePoint and OneDrive. There were new improvements on the built-in scan feature in OneDrive for both iOS and Android mobiles. These are accessed through the dedicated icon in the tab bar. That makes it easy to add images, annotations, and even multiple pages to your OneDrive.

Now it is possible to automatically upload videos and photos captured on your camera roll in upload for Business OneDrive. There is also another great improvement that gives users the ability to require and set a password when you share a folder with other people. This feature basically prevents others from accessing your files if your intended recipient accidentally forwards a link. These new features now give you the ability to stop other users from downloading files or documents shared through the view-only links.

Microsoft SharePoint Spaces

These are basically immersive, mixed reality experiences that enable users to view and interact with content from every angle. In addition, users can visualize and manipulate data and product models in real-time.

The Title Bar

It is now easy to quickly change your current document’s title, open the document’s location, share the document through an invitation link, and even access the document’s version history by simply clicking on the title bar and selecting the functions from a drop-down menu.

Security

Office 365 solutions ensure that you identify and manage personal data such as the prevention of data loss and advanced data governance. The New Office 365 is able to detect and protect against security threats. It helps users comply with the European Union Privacy law recently enforced, the General Data Protection and Regulation (GDPR).

To learn more about these helpful new changes, please visit: The Microsoft Blog.

Office 365 June Updates

Hackers Shortcut Microsoft Office 365 Security

Hackers Discover New Way to Bypass Microsoft’s Office 365 Security Protocols

Microsoft Office 365 Security

Hackers have discovered an innovative method of getting those malicious URLs in their emails past Office 365’s security protocols. This was first revealed by Avanan, a company that deals in internet security. Avanan says that cybercriminals are now using a <base> tag in the HTML header employed with a URL to by-pass security and infect a computer with malware.

Officials at Avanan explained further. “At one time, email clients did not support the <base> tag, so every link needed to be an absolute URL. Support for relative URLs in email is a recent development and the behavior is client dependent. Older email clients will ignore the <base> tag, but web-based email clients, recent desktop clients and most mobile apps will now handle the <base> tag and recombine the URL into a clickable link.”

How Microsoft Safe Links work

Office 365’s Advanced Threat Protection provides a feature called “Safe Links” that compares a link found in an email against those on a blacklist. This feature was designed to catch and stop a malicious link. It was working well for all MS products until hackers discovered this workaround.

The new technique has been dubbed “baseStriker” and it’s aimed at those using Microsoft Outlook. Malicious messages can now bypass the filters included in Microsoft products using the <base> tag.

The new baseStriker program splits the malicious URL so that Microsoft’s product, Safe Links, cannot detect that it points to a malicious URL. Safe Links checks the base domain, ignoring the rest, thereby allowing the user to move on to the phishing site. A few security solutions do protect users against these new cyber-threats, including Mimecast and Proofpoint.

As part of Microsoft’s Office 365 Advanced Threat Protection (ATP), Safe Links was designed to provide a strong layer of protection against malicious links embedded in documents and emails. Microsoft diligently updates the software so that it consistently protects against the latest cyber threats. The software works by determining if a link is malicious, then replacing the bad link and alerting the user. Up to now, ATP has been considered state-of-the-art protection against phishing scams.

Microsoft investigation underway

Officials at Microsoft were contacted by Security Week and they issued a brief statement that said, “We encourage customers to practice safe computing habits by avoiding opening links in emails from senders they don’t recognize.” They also said they were investigating the claims about the new hack.

In the meantime, all security experts discourage users from clicking links found in emails—even if they seem to be from a reliable source. Best Practice for internet security is to always navigate to a web page the old-fashioned way. Open a new browser page and type in the web address. Get in the habit of glancing up to the browser line and making sure it says what it should. Periodic security awareness training is also recommended. This is a good way to remind users about the many phishing scams and malware that constantly threaten users.

Other email clients may be vulnerable

The baseStriker hack may be used in other email programs as well. This has caused all email service providers to begin checking to make sure their security protocols are still intact and working as expected. This is a timely reminder to everyone that crooks are constantly searching for any vulnerability they can take advantage of. New types of malware, worms, viruses, and ransomware are developed each year. Experts believe that Gmail, along with a few other email clients already have built-in protection for splitting the URL and will not be at risk.

Better security training for employees

Though all software developers are now working toward shutting down cybercriminals, every type of cyber defense utilizing technology has its weaknesses. The best methods of cybersecurity usually involve training employees about what to look for and remind them often that hackers never take a break from their work.

Second Chance

A new product called Second Chance offers users a way to “roll back” a decision to click a suspicious link. If the user thinks they may have clicked a bad link in a phishing email, now they can stop the process from moving forward. The software checks out any potentially unsafe link the moment you click on it. Then it informs you that you may be navigating to an unsafe website. You can then abort your actions and return to safety. While products like this do help, there are a flood of new worms, ransomware, malware, and phishing scams developed each year by cybercriminals.

Why hackers always seem to be ahead of the game

Many hackers are now backed by governments the size of China or North Korea, so they have unlimited resources to work with. A Newsweek article[1] reports that Chinese hackers have stolen billions of dollars’ worth of secrets and data from businesses and individuals all over the world. Russia and North Korea are in second and third place when it comes to cyber-theft.

The Newsweek article states that Chinese cyber-aggression toward the United States has evolved rapidly over the last few years. Chinese hackers represent a growing threat to world economies due to their disruptive nature. Today’s battlefield is no longer on actual ground using weapons and artillery. The war is being fought online—on the internet where everyone’s data is sometimes exposed to vast criminal enterprises.

[1] http://www.newsweek.com/chinese-hackers-cyberwar-us-cybersecurity-threat-678378

Resolving Complexity: Office 365 Updates That Are Taking User Experience to New Heights

Many people usually turn to Microsoft’s online productivity suite, Office 365 because of the apparent breadth and depth of its features, which allow them to accomplish what they are unable to do with other similar products on the market.

However, the business environment is always changing and organizations increasingly put a premium on agility, as staying competitive means being able to do more with less. Time is increasingly more valuable as well. Organizations need technology that requires very little training to reduce onboarding expenses for new employees.

With this understanding, Microsoft is rolling out updates to its Office 365 and the Office.com environment to simplify tasks and take the user experience to a higher level. Once this rollout is complete, users will be able to enjoy a much better experience across Word, Excel, PowerPoint, OneNote, as well as Outlook.

While these user experience updates are set to roll out slowly over the next couple of months, many of them are already available for Office.com users to experiment with. Microsoft has deployed new designs to a select customer group. These will be released in phases and carefully tested, so the tech giant can learn as they go.

A user centric approach

According to Microsoft, every change they are making on the user experience is focused on three key things: incorporating customer input, considering the context under which the feature will be best and most easily applied, and giving people control over their experience.

It is actually because of this user-centered approach that Microsoft is rolling out these updates gradually to allow room for incorporating the new feedback they obtain from customers during the process.

Shadow and depth on Office

As you scroll over the items on Office.com, you will notice that they pull forward with shadow and depth. This is because Microsoft is bringing its Fluent Design system to the web and to Office 365.

More importantly, Microsoft has rebuilt Office on a modern platform to be much faster and far more efficient than ever. So you’ll notice that every item you tap, such as a Word document, opens much faster than ever.

Simplified ribbon

Once you open your document, you’ll notice an updated, simplified, and better version of the ribbon. The new ribbon design will help users focus on their work and collaborate with others in a more natural and informal way.

For those who prefer to dedicate more screen space to showing commands, there is the option to expand the ribbon into the classic three-line view. This option will continue to be available to users so that everyone can choose the experience they prefer.

The simplified ribbon is first rolling out on the web version of Word. It will then become available to select consumers on Office.com and to Select Insiders in Outlook for Windows later on in July.

The simplified ribbon will not be available on Word, Excel, and PowerPoint for Windows yet. Microsoft intends to gather enough feedback from a broader set of users before implementing any changes that could disrupt people’s work. Upon rolling out the ribbon on these products however, users will still be able to revert back to the classic version of the ribbon with just a single click.

New animations

As part of the Fluent Design system, the ribbon has been improved with new animations. The user experience is improved with better speed and velocity to improve the overall look and feel. All these have been designed to be inclusive and accessible so that the user experience is streamlined.

New icons and color in the right places

Along with the new animations, users will enjoy a fresh array of new colors and icons. These will help people find the commands they’re looking for more easily. These new features were developed as scalable graphics. They render with precision on any screen size or type.

Users will be able to see the new icons and colors first in the web version of Word for Office.com. Select Insiders will see these new features in Word, Excel, and PowerPoint for Windows in late June. The new icons and colors will then roll out to Outlook for Windows in July, and ultimately to Outlook for Mac in August.

Personalized intelligent Search

Microsoft is also rolling out a new personalized, intelligent Search feature across its products. This will provide access to commands, content, and people in a more enhanced manner. This feature makes suggestions on actions you can take, the content you may be looking for, and people that you may want to connect with – all based on your past work patterns. For those who love Office 365 and even for those who may not yet be fans, these new updates promise a world-full of new possibilities.

All you have to do is place your cursor in the search box and all these recommendations powered by machine learning and the Microsoft Graph will show up.

This experience is already available to commercial users in SharePoint Online, Office.com, and the Outlook mobile app. Commercial users of Outlook on the web will also start seeing this experience in action in August.

Wrap up

These updates are a sign of Microsoft’s commitment to making its products more useful to its customers. Against this backdrop, we can expect nothing but the best user experience from these products as the tech giant continues to roll out innovative modifications.

Microsoft Office

The Ransomware Threat Is Growing and Here Are the Reasons Why

One of the biggest problems facing American businesses today is Ransomware. In fact, it is becoming a global threat. In 2017, a ransomware attack was launched every 40 seconds and that number has grown exponentially in 2018. What are the main reasons for this type of escalation? Why can’t law enforcement or IT experts stop the growing number of cyber-attacks?

Ransomware

Ransomware Trends

One of the reasons involves the latest trends. The art of ransomware is evolving. Hackers are finding new ways to initiate and pull off the cyber-attack successfully. Thieves rarely get caught. So, you have a crime that pays off big financially speaking and no punishment for the crime. The methods of attack expand almost daily. Attack vectors increase with each new breach. If cyber thieves can just get one employee to click on a malicious link, they can take over and control all the files and data for an entire company.

If you go to work in the morning and find that hackers have locked up all your data and are demanding a $2,000 payment in bitcoin, do you pay it or not? Most business owners pay the ransom. It’s easier and cheaper and it gets everyone back to work much faster. One of the major keys to this cyber-attacks success is the fact that criminals keep the ransom amounts fairly low. If you can simply pay $2,000, get all your files back and move on, then why not do so?

Contributing Factors

One of the most crucial contributing factors to this crime is the cryptocurrency revolution. If criminals had to rely on bank accounts and credit cards for payment, their crimes would soon be solved and they would be caught and placed in jail. But cryptocurrency is perfect for Internet-based crimes. It’s untraceable and that makes ransomware a practically unsolvable crime.

The five major cryptocurrencies worldwide in order of their popularity are:

  1. Bitcoin
  2. Monero
  3. Zcash
  4. Ether
  5. Litecoin

A recent article in The Motley Fool[1] reports that there are currently 1,658 cryptocurrencies available worldwide. That number grows each day. People love the anonymous nature of cryptocurrency. There are a growing number of questionable businesses on the Dark Web and most only accept cryptocurrency as payment. That’s because much of the sale of goods and services on the Dark Web is illegal. The only safe way to pay for illegal materials is to use a completely untraceable form of payment. The answer is cryptocurrency.

But there are other contributing factors as well:

  • Social engineering
  • Both known and unknown software vulnerabilities
  • Poorly configured servers and workstations

Most of these vulnerabilities do have a workable solution. It’s just a matter of finding out where you are most at risk and taking steps to close up those weaknesses. A good IT managed services outfit can assess your current IT infrastructure and make recommendations for improving it. Consider it an investment in your company’s future.

It would be nice to speculate that the whole world will suddenly wake up and decide to be honest and upright in all their dealings; but that is not a realistic viewpoint. Instead, we must move forward with the resolve to create and support global internet police agencies who have the power to track down and arrest cyber-criminals. When there’s no punishment for a crime, it’s a proven fact that it will increase and even flourish.

What Can You Do As a Business Owner?

Knowing that all these things are true and things are not going to just suddenly get better, you have to ask yourself how you can protect your company from cyber thieves. The number one way that all security experts agree on is better employee training. Thieves most often trick an employee into clicking on a bad link. The human factor is the weakest link in the cyber-security chain.

But the good news is that training your employees doesn’t have to be expensive or time consuming. Ask a local security expert to come out once a month and address all your employees. The experts can educate everyone about the latest cyber threats. They can share helpful information about what phishing scams are and how to spot a suspicious email. If you don’t have the budget for it, you could even ask the security expert to do his talks on YouTube and then send links to everyone in your organization. Make watching these security briefs mandatory for all employees.

There are plenty of good resources online now about cyber theft and best practices for cyber security. If you can afford to have a local IT guru come out quarterly and speak to employees about Internet security, this will reinforce what employees have already learned.

Head in the Sand?

The problem with many organizations today is that their leaders are living in a bubble. They think ransomware attacks only happen to other people. They don’t really think they will ever be a victim of a cyber-crime. This isn’t true. Statistically speaking, your company will eventually get caught in the web that cyber thieves weave. The question is not “whether” your company will be a target, but “when” this will occur. The best course of action is simply to prepare for it.

  • Educate your employees.
  • Hire the best IT experts you can afford to test your network.
  • Spend the money on whatever new improvements are needed to fortify your IT infrastructure.
  • Make sure all software and hardware is patched and up-to-date.

Sadly, the Crypto Crime Wave is backed by huge communist governments. These countries are earning billions of dollars each year by stealing data from businesses, hospitals, charitable organizations, individuals or whoever falls prey to their scams. They sell the information online and there are always plenty of buyers for this type of data.

However, knowledge is power. Now that you know a few things about ransomware attacks and what you can do to stop them, take action! Don’t wait around until you get that awful message on your computer screen that says:

“You’ve been Hacked! Your files are frozen. Here’s what you need to do to get your computer access restored!”

Don’t wait for that day to come. Take action now to protect your company from the threat of ransomware, malware, and all the other forms of internet piracy. When business owners become more proactive about their internet security, the threat of these attacks should start to diminish. Today, American businesses are making it all too easy for cyber criminals to succeed. But as company owners become more savvy, these criminals will find it harder to earn a living stealing.

[1] https://www.fool.com/investing/2018/03/16/how-many-cryptocurrencies-are-there.aspx

Hmmmmm…What Is Yam Jam?

Yam Jam – The Virtual Town Hall Experience That Brings Your Organization Together

If you are an avid user of Office 365 or have in some way expressed interest in Microsoft’s online environment, then you’re probably familiar with Yammer – the freemium enterprise social networking service that is used for private communication within organizations.

Yam Jam

Also, chances are that you have come across terms such as “Yammer Town Hall,” “Yammer Power Hour,” or “Yammer Time.”  They all refer to the same thing: Yam Jam.

What is Yam Jam?

This is simply a digital meetup on the Yammer network. It provides a unique space for real-time Yammer discussions where people can exchange ideas and learn from one another. One of its strong points is that an organization’s employees have the opportunity to break the typical organizational chain of command and interact directly with senior leaders alongside fellow staff.

As such, you can look at Yam Jam as a curated virtual town hall event that is held within a designated group in the Yammer network.

Attendees within Yam Jam get the rare opportunity to interact directly with subject matter experts, company leaders, or executives as well as with one another (fellow employees). Anyone can participate in Yam Jam because it is actually an open environment on the network. They can ask questions related to the topic of discussion, learn from the experts, and share ideas with one another.

Every Yam Jam event typically lasts about an hour but they continue on after the live event is finished, which is the best part. This makes global engagement much easier and more inclusive, which can be extremely helpful for organizations with remote staff. It brings them together regardless of where they are on the planet. Yam Jam events are also scalable and measurable, in addition to being low cost and focused.

The fun thing about Yam Jam

Yam Jam is not restricted to a single shape and size. The type of event you hold on this network is determined by your specific need. There is also the option to @mention someone on the Yam Jam environment so that they get notified about an ongoing event that they can benefit from.

Thinking about hosting a Yam Jam? Here’s why you should

There’s so much your organization stands to gain from hosting Yam Jam. For starters, the events enable your employees to engage with multiple participants on Yammer, which can promote the culture of cooperation.

Participants on Yam Jam share ideas and insights with one another and receive valuable information that they can use to better their performance and productivity of the organization overall.

More importantly, Yam Jam is a means for the employees to break hierarchy and interact directly with company leadership. Participants can not only gain richer insights from subject matter experts but also get a chance to address pressing matters with the company leadership and reach solutions that may benefit them and the organization as well.

Employees can build a great deal of confidence in their senior leadership from interacting in the Yammer Town Hall. Leaders also get a good opportunity to interact directly with practitioners in a way that helps them remain connected to the massive pool of talent within the organization.

Yam Jam best practices to ensure you make the most of your events

One interesting thing about Yam Jam is that they are rather easy to organize or set up; anyone can do it. To host a successful Yam Jam, here are some tips to ensure you have your best foot forward.

Ensure your participants are Yammer savvy

Yam Jam participants need to have sufficient Yammer knowledge to effectively participate in any event on the platform. As such, it will help to do some due diligence beforehand to be certain that your team or the audience you’re targeting is well-versed on the network. Otherwise, consider offering a Yammer training session before taking the plunge.

Choose an appropriate time and topic

Participants are bound to contribute properly if the time is right and the discussion involves pertinent topics or ones with varying viewpoints. The time is right when the participants are in a position to take part. As such, it is best to consider time zones and days of the week when jobs and other similar engagements are not likely to stand in the way.

Advertise the event properly

People easily forget schedules, so it is important that you keep them properly informed about the event and the exact time, date, and topic of discussion so everyone can prepare appropriately. Remember, the more engaged the participants are, the more interaction the event is likely to achieve. The more interactive the event, the more likely it is to be productive.

Wrap up

Yam Jam can be hugely beneficial to any organization that seeks to improve and become more productive, especially if they provide participants with a proper feedback loop, or means to give feedback at the end of the live event. If you haven’t tried it yet, then no time is better than the present.

Sensitive Data Stolen From Naval Contractor By Chinese Hackers

US Navy Data Breach

Officials recently revealed that a data breach occurred involving a Navy Contractor where hackers working for the Chinese government gained access to highly sensitive data regarding submarine warfare. Included in the breach were top secret plans for the design of a supersonic anti-ship missile system that was to be used in U.S. submarines by the year 2020.

US Navy Data Breach

American officials have confirmed that these breaches occurred in January and February of 2018, but would say very little else about the breach, citing the secret nature of the stolen plans. An investigation into what happened and exactly how the breach occurred is ongoing and the government is reluctant to speak of the incident while the investigation unfolds.

Though the naval contractor was not identified, U.S. officials confirmed that he worked for the Naval Undersea Warfare Center. This military organization is located in Newport, R.I. They conduct research on underwater weaponry and develop weapons specifically for submarines.

The Sea Dragon Project

The stolen data consisted of 614 gigabytes of information closely related to a project called Sea Dragon. In addition, radio room materials related to cryptographic systems were stolen along with, signaling and sensor data. The Washington Post has obtained more detailed information about this breach but, at the request of the U.S. Navy, they have agreed not to publish those facts. The military believes releasing these documents could further harm national security and put other military projects in jeopardy.

One of the more alarming details of the breach was that this naval contractor had highly sensitive information about Sea Dragon stored on his personal computer and phone. These devices did not have the necessary security protocols for storage of classified government documents. The contractor was using a normal unclassified network for his phone and computer despite knowing that the information he was privy to was of top-secret nature. Charges may be filed against the individual for not taking basic steps to secure the data and following NIST guidelines.

Problems with Naval Contractors

This incident has sparked highly-charged discussions about the Navy’s ability to properly oversee its vast network of contractors. Many of these people have access to the designs for America’s latest weaponry. Loss of these plans and blueprints could result in a devastating effect on America’s military capabilities.

Last week, the inspector general’s office at the Pentagon confirmed that Jim Mattis, Defense Secretary, was currently reviewing the handling of all military contractors. Mattis and his team will investigate whether there are other blatant cybersecurity issues that could possibly leak classified information to the Russians, Chinese, or North Koreans.

The Navy, working in conjunction with the FBI, is currently leading the investigation into what happened.

The naval spokesman, Cmdr. Bill Speaks, commented saying, “There are measures in place that require companies to notify the government when a ‘cyber incident’ has occurred that has actual or potential adverse effects on their networks that contain controlled unclassified information.” He added that “It would be inappropriate to discuss further details at this time.” The FBI has declined to comment.

Is the Sea Dragon Project Sunk?

Little is known about the Sea Dragon project, except that the project was designed to provide a “disruptive offensive capability” by “integrating an existing weapon system with an existing Navy platform.” In addition, the Pentagon said that the project has to date, cost over $300 million. The Navy had plans to begin underwater testing as early as September of 2018, but those plans will now most likely be placed on hold.

Military experts believe that China will now be able to develop technology that will render the Sea Dragon project ineffective. There is some speculation that other weaponry projects could also be compromised.

The government has set in place an extensive array of security protocols and guidelines to ensure that events like this do not happen.

According to the Nist.gov website:

All Department of Defense (DoD) contractors that process, store or transmit Controlled Unclassified Information (CUI) must meet the Defense Federal Acquisition Regulation Supplement (DFARS) minimum security standards by December 31, 2017, or risk losing their DoD contracts.[1]

Stopping Hackers in their Tracks

DFARS regulations were created to stop cyber breaches like Sea Dragon from taking place. All government contractors and sub-contractors are required to use high-level security protocols anytime they store, process or transmit sensitive government data.

According to a study done by IBM in 2014[2], human error is involved in as many as 95 percent of all data breaches. Cyber breaches are successful because hackers prey on human weaknesses. Most commonly, hackers lure an unsuspecting victim into giving access to the cyber thief believing him to be a legitimate person or company. Hackers are able to sell the information they obtain on the Dark Web.

Many governments around the world now employ a staff of hackers who work continuously to steal data from large companies, individuals, hospitals, various government organizations, non-profits and many others. The stolen information will fetch a high price on the Dark Web. In the case of Sea Dragon, the data loss could place an advanced Naval weapons systems into the hands of the Chinese.

[1] https://www.nist.gov/mep/cybersecurity-resources-manufacturers/dfars800-171-compliance

[2] https://securityintelligence.com/the-role-of-human-error-in-successful-security-attacks/

Why Your Company Should Switch to Office 365

Undoubtedly, Office 365 has taken the business world as we know it by storm. With each update that Microsoft makes to Office 365, more and more companies are jumping on the Office 365 bandwagon, and for good reason. This enterprise software has something to offer for just about every business. Some business owners have even identified Office 365 as a major factor behind the success they’ve experienced.

Microsoft Office 365

If you’re thinking about making the switch to Office 365, here is some information about the features of this enterprise software that should help you make a concrete decision.

Available on the Cloud

As a business owner, your primary concern should be perfecting your products and services. Unless your business operates within the IT industry, you and your employees shouldn’t have to worry about servers and maintenance. Fortunately, if you decide to switch to Office 365, you and your employees won’t have to.

Office 365 is a cloud-based software. Therefore, you and your employees can use this software primarily on the cloud. However, if needed, you also have the option of integrating Office 365 with the on-premises solutions of your company. Not only will you save money on maintenance costs by using Office 365 on the cloud, but you will also enjoy peace of mind knowing that your data is safe and secure.

Scalability

If you foresee your business growing significantly in the near future, it is in your best interest to consider switching to Office 365. Scalability is one of the most lauded features of Office 365. With Office 365, you only need to pay for the features that you get.

Therefore, in the early stages of your business, you don’t need to worry about wasting money on features that you won’t use. As your business grows, you won’t be forced to switch to another enterprise software to ensure your growing needs are met. Instead, all you will need to do is pay for more services and data storage. By choosing Office 365 from the beginning, you will save yourself a lot of time and trouble.

Access Anywhere and Anytime

In many organizations, the productivity of employees is limited significantly by the lack of access to documents and data anytime and anywhere. If you want your employees to be able to access anything required for work from home, coffee shops, and elsewhere, you should consider getting Office 365. Since Office 365 is available on the cloud, this software will make it possible for your employees to be productive hundreds of miles away from their desk in the workplace. Also, your employees won’t be forced to work from a laptop or desktop computer. Office 365 makes it possible to be productive working from a tablet or even an iPhone.

Simplified Migration

One concern that many business owners have when it comes to switching to Office 365 is the migration process. If you also have this concern, you will be happy to know that Microsoft has made migrating to Office 365 incredibly easy. This is true no matter what storage tools your business is using currently. Also, once you make the switch to Office 365, you will never need to worry about migrating your data once more in the future because Microsoft is constantly making updates to Office 365. Microsoft strives to make timely updates to Office 365 to ensure this enterprise software continues to meet the needs of businesses across the world.

Unification of Your UI

Another issue that many businesses have is needing to use a plethora of software and apps to accomplish various tasks. If you want your employees to be able to enjoy a more unified UI, you should consider switching to Office 365. Office 365 has a business app for just about everything your employees need to do. Microsoft regularly releases new business apps on the Windows Store and quite a few of these apps are free. If you don’t want your employees to have to deal with a crowded home screen, you can pick and choose the apps you know your employees will need to use and add them to the Office 365 home screen. That way, your employees will be able to access these apps easily.

Another advantage of having your employees use Office 365 for all their needs is that they don’t need to worry about compatibility between apps. Since all of these apps are developed and/or managed by Microsoft, these apps will be compatible with each other. Not having to deal with compatibility issues on a regular basis will boost the productivity of your employees.

New Bug Updates and Features

If you’ve used other enterprise software in the past, chances are you’ve been frustrated with the lack of bug updates or new features. In some cases, you may have had to wait a few years for the release of a new product or update. Fortunately, if you switch to Office 365, you won’t have to deal with this frustrations anymore. As stated above, Microsoft releases updates and bug fixes regularly and you will have access to these updates as soon as they’re released.

Data Loss Prevention

As you probably know, data is the lifeline of most businesses. Accordingly, most businesses do everything in their power to secure their data and prevent data loss. One reason many businesses are switching to Office 365 is that this enterprise software makes data loss prevention so easy. Office 365 comes with a multitude of backup and data protection features that will allow you to enjoy peace of mind.

With each passing day, more and more companies make the switch to Office 365, an enterprise software that is frequently lauded as an all-in-one package. Switching to Microsoft’s Office 365 can put your business on the path to success and prosperity in the near future. For more information about why your company should switch to Office 365, don’t hesitate to contact us.