Thursday, July 30, 2015

Data Security: A Formidable Task for Law Firms

Data Security: a Formidable Task for Law Firms
By the very nature of their business, attorneys generate data that is very sensitive. As a law firm, you carry a tremendous responsibility to guard that data. These days, technology enables you to store and access information very easily and it also allows you to retrieve it at a moment's notice from remote locations via a variety of different devices. Unfortunately, this convenience can pose a serious challenge to the security of that data. In particular, two security concerns are a breach of data by an unauthorized third party, and the accidental release by authorized users due to human error or carelessness. Of course, it goes without saying that any data breach means considerable liability and a damaged professional reputation. You need efficient IT management that can protect your data and defend your systems against cyber attacks. But who in-house is technically proficient to manage the systems to ensure you're protected 24/7 against all the latest hackers and viruses? Managed IT service companies, known as MSPs, are professionals who can provide solutions for these challenges. Let's look at some of factors that create risks for small- to medium-sized law firms.
  1. Accessibility: With digital storage, and the decrease in paper storage, legal professionals can now easily gain access to necessary information remotely using a variety of different devices. All of this 24/7 access boosts productivity but it creates new risks that didn't exist when paper files were on-site in locked cabinets. How do you support this remote access without opening up new doors for a data breach?
  2. Growing threats: As cyber criminals constantly devise new ways to hack into systems, your network firewalls have to be updated constantly. No technology, hardware or software can be installed and then forgotten. New viruses and software bugs prompt the need to develop new security patches that have to be installed quickly to keep ahead of with growing s. Staying ahead is a constant battle.
  3. Multiple locations: As the firm grows so does the IT infrastructure. Even small- to medium-sized law firms may have multiple offices. That means they now have a bigger IT network that becomes more difficult to manage and secure.
  4. Reliance on technology: With this increasing reliance on technology, your risk of serious business disruption grows if you have any kind of technology failure. Failure can arrive as a data breach, a virus, failed hardware or software, power outage or natural disaster. That means plans for disaster recovery developed by an IT team are very important.
  5. Limits of in-house support: For most small- to medium-sized firms, there are neither the resources nor the on-going need to have a fully trained support staff available 24/7. You may only have one or two people in this role. As a result, in-house staff may not be able to keep abreast of all the updates and regulatory changes all on their own. Finally, there is one additional limit to in-house support—your own time. You have to supervise them, and its unlikely you have either the background or desire to do that effectively.
  6. Lack of IT management expertise: Law firms specialize in practicing law. They are not IT specialists. Managing partners remain primarily legal professionals. Their background is not in the management of a technical staff.
Addressing issues: Now we can look for solutions to address the issues discussed above. When it comes to IT management, law firms should have three major goals.
  1. Data security: Managed IT services can ensure the security of your data because they keep up with new technologies. They will update their software applications as the updates become available. That allows them to meet new challenges posed by cyber criminals.
  2. Business continuity: Business continuity is very significant for the survival of a business. When your business is disrupted, your fixed costs don't stop, and neither do the demands of your clients. MSPs are full time professionals whose resources you can call on 24/7. They can also develop continuity and recovery plans to protect your business and defend against downtime and outages.
  3. Cost effectiveness: Like any other business, you are always looking to keep your cost of doing business under control. Since IT is an integral part of your business and you can't do without it, you need to address ways to manage it with the most efficient use of resources. Outsourcing some or all of your IT management can provide resources and availability that is just not possible with an in-house staff. MSPs can provide 24/7 monitoring, technology upgrades, and the depth of expertise and staffing that isn't feasible in the business model of a small- to medium sized business.
In conclusion, we have discussed important aspects of your business and six major issues that present IT management difficulties. You also know which goals you should keep in mind when having your IT networks managed. Managed Services Providers (MSPs) have a business model to help you meet those goals with a long term plan for data security and business continuity.

Why Do Law Firms Need Managed IT Services

Why Do Law Firms Need Managed IT Services
Every law firm has two major challenges. One of them is the storage of the sheer volume of data their business creates and the other one is the protection of that data. The last few decades' worth of technology has created a very solid solution for the first challenge. A small computer disk can hold terabytes of data inside an enclosed drive. If that seems like too much, the cloud has offered an off-site solution to the problem that eliminates hardware maintenance. Before these solutions came along, information could only be saved on paper that filled boxes and boxes.
Security is a much more complex challenge. Before, you could lock those boxes of papers in an office, turn on the burglar alarm and go home. Someone would have to physically go there and break into your office to steal that information, and it would be pretty noticeable when they walked out carrying boxes. Nowadays all someone needs is some knowledge of computers and software, and they can hack into that material from afar. They don't even have to be in the same country much less in the same city or neighborhood. Therefore, the unintended consequence of a solution for one problem turned out to be the creation of another, yet much more serious problem: the loss of security. Now the technology has to be managed systematically and monitored very closely. That is why law firms need managed IT services.
Here are a few advantages of having a Managed Service Provider or MSP handle your IT needs.
Accessibility: As an attorney, you need to have the ability to access your files anytime and from anywhere. Let's say you are in a court and suddenly you discover that an important document is needed. You should be able to retrieve that on-demand from any device you carry. Managed IT could have all the files available to you through in-cloud storage.
Security: Given the nature of information that law firms are entrusted with, security can't be overemphasized. Breach of that information can ruin lives, sometimes irreparably. That means damage to your professional reputation as well as the bottom line. So how can managed services prevent that from happening? By being proactive. Your core business is to provide legal services to your clients. Worries about the security of your systems should be the last thing on your mind. MSPs are there to prevent viruses and any other suspicious activity that might bring your systems down. Their software applications are capable of alerts whenever something unusual is taking place inside your networks.
Government Regulations: Law firms deal with a lot of client information that is protected by law. For example, HIPAA has very stringent regulations protecting medical records. Laws provide for stiff penalties and fines if the security of those records is breached. Outdated software and hardware may expose those records to hackers because your in-house IT team is behind with updates.
Multiple Offices: Many law firms operate from more than one location. IT managed services can bring uniformity and the necessary coordination between multiple sites. Your in-house IT team may not have the ability to do that or the budget to maintain it. Also, some firms that work in coordination with other organizations may allow access to some of their systems. Your IT management company can ensure that other firm's systems don't create risks for your network because of lack of compatibility or security flaws.
Lack of Technical Experience: You know the law, but you can't keep up with ever evolving technology. The new complexities emerging, such as Bring Your Own Device to work, must be implemented if businesses want to survive in a very competitive environment. It is also important for revenue growth due to the efficiencies it brings to your environment. As a law firm, it is in your best interest that you let an MSP take care of your IT needs.
Managing your Growth: Your law firm probably started with a couple of computers, printers, copiers and a fax machine. It was easy to take care of all your hardware. Also, during those good old days nobody was trying to hack into your computers. Your business is now growing. You have a staff of dozens and many desktops, servers, and software packages. Everyday it gets increasingly difficult to keep track of new technologies. So managed services is not an option. It has become a necessity for your revenue growth and business continuity.
Monitoring: One way to avoid critical breakdowns and security breaches is 24/7 monitoring. This is the surefire way to avoid and control security breaches, viruses and hacker attacks, but it isn't something a small firm can do on its own. It requires the presence of 24/7 labor plus investment in exceptionally sophisticated software and as well as hardware. This sort of investment is not practical for smaller firms.
Disadvantages of In-house IT Management: The break-fix approach is not very practical for highly sensitive networks. For one, it is expensive. The old adage 'prevention is better than cure' fits well here. In the long run it makes good financial sense to have someone who is proactively monitoring your systems day and night, preventing system breakdowns, especially with extremely sensitive information on your computers and servers. You do not want to wait for disaster to strike to fix the problem. Some of the damage may be irreparable. In addition, breakdowns are costly in terms of lost productivity and business disruption. MSPs specialize in BDR (Backup & Disaster Recovery), which is important for minimizing downtime and maintaining business continuity. The peace of mind that an MSP can provide will not come from someone on call or who works from 9 to 5.

Wednesday, June 17, 2015

Loss of Data: Causes and Prevention

Loss of Data: Causes and Prevention

Loss of Data: Causes and Prevention

The adoption of technology from the simplest of matters to the most complex problems has rendered us heavily dependent on it. We love paying our bills minutes before they are due. We enjoy seeing loved ones face-to-face on our computer screens. We can access and print our extremely sensitive records from government and financial websites in a matter of minutes instead of waiting for the mail for days. The time and resources that technology saves are invaluable, but this convenience has a very ugly side. This convenience brings costs, which could include irreparable financial, professional, and social damage. The technology that is designed to make life easier can also wreak havoc when criminals use it to breach secured, personal information. So how do we tame this beast called 'breach of data security'?

Background: The gravity of the problem: To look for a solution, we first need to understand how serious this problem is. Breaches in data security and loss of data could spell imminent demise for many small companies. According to the National Archives & Records Administration in Washington, 93% of companies that have experienced data loss resulting in ten or more days of downtime have filed for bankruptcy within a year. 50% wasted no time and filed for bankruptcy immediately and 43% that have no data recovery and business continuity plan go out of business following a major data loss. In the past, small- to medium-businesses (SMBs) thought that data security problems were reserved for large corporations, but cyber criminals are finding out that SMBs are more complacent in securing their data thus making themselves easier targets. More importantly, the lightly guarded SMBs can provide backdoor access to the large entities hackers really want to hit. Fewer than half of the SMBs surveyed said they back up their data every week. Only 23% have a plan for data backup and business continuity. That is why the number of cyber attacks on SMBs has doubled in the recent past.

Causes of lost data: Loss of data can be attributed to two factors.

  • Breach of data security: As we discussed above, theft is the main reason for loss of data. Hackers can get into networks by installing their own software hidden inside emails and other Web content. They take over PCs and networks and then access files containing personal information. They can then use that information to empty people's bank accounts and exploit data for other purposes.
  • Human error and employee negligence: Humans still have to instruct technology to perform as desired. Examples of negligence include unattended computer systems, weak passwords, opening email attachments or clicking the hyperlinks in spam and visiting restricted websites. Fortunately, this type of loss of data is easily preventable, but it is just as detrimental and can bring your business to a halt. Downtimes can be very harmful to your business continuity and revenue.

Five ways to minimize data loss

  1. Enforce data security: More than technology, this is the management of human behavior. SMB management must communicate data protection policy to the entire staff and see to it that the policy is adhered to. Rules and policy must be enforced very strictly regarding the use of personal devices. Tell employees to create passwords that are hard to crack and change them frequently.
  2. Stress the consequences: Rules are only good if there are consequences for not following them. Define what those consequences mean for the both the individual and the organization.
  3. Mobile device management: Mobile devices may be the weakest link in data security. "Mobile device management" refers to processes that are designed for the control of mobile devices used within the company. Devices tapping into company systems are identified and monitored 24/7. They are proactively secured via specified password policies, encryption settings, etc. Lost or stolen devices can be located and either locked or stripped of all data.
  4. Snapshots: Fully backing up large amounts of data can be a lengthy process. The data being backed up is also vulnerable to file corruption from read errors. This means sizeable chunks of data may not be stored in the backup and be unavailable in the event of a full restoration. This can be avoided by backing up critical data as snapshots.
  5. Cloud replication and disaster recovery services: For SMBs who consider data backup to be too costly, time consuming and complex there is an answer. The Cloud provides a cost-effective, automated off-site data replication process that provides continuous availability to business-critical data and applications. Cloud replication can often get systems back online in under an hour following a data loss.

To conclude our conversation, it is very important to understand the causes and consequences of data loss. Be proactive and minimize the likelihood of a data breach and data loss, so you can stay in business without interruption. Make sure you have a solid data recovery and business continuity plan so you don't become another statistic about small firms who didn't make it.

Wednesday, May 20, 2015

5 Ways SMBs Can Save Money on Security

5 Ways SMBs Can Save Money on Security

Small-to-medium sized businesses and large enterprises may seem worlds apart, but they face many of the same cyber-security threats. In fact, in recent years, cyber-criminals have increasingly targeted SMBs. This is because it’s widely known that SMBs have a smaller budget, and less in-house expertise, to devote to protection. Thankfully, there are several things SMBs can do today to get more from even the most limited security budget. And, no, we aren’t talking about cutting corners. Far too often, SMBs cut the wrong corners and it ends up costing them more money in the long run. It’s a matter of taking a smarter approach to security. Here are five smart approaches to take

  • Prioritize - Every business has specific areas or assets critical to its core operations. Seek the input of valued staff and team members to determine what these are. Is there certain data that would be catastrophic if it was lost or stolen? If hackers compromise a network, or prevent access to certain applications, how disruptive would it be to daily business operations? What kind of potential threats or vulnerabilities pose the greatest risk to the company or your customers/clients? Focus on the most likely risks, not theoretical risks that "could happen." Asking such questions gives you a clearer more complete perspective as to where to focus available security resources.

  • Develop and Enforce Policies - Every SMB needs to implement a security policy to direct employees on appropriate and inappropriate workplace behaviors relative to network, systems, and data security. Merely drafting this document isn't enough. Employees must be held accountable if they fail to adhere to policy. Such policies should be updated regularly to reflect new technology and cultural shifts. For example, a document written before social media took off, or before the BYOD (Bring-Your-Own-Device) movement, doesn't necessarily apply today.

  • Education - Ongoing end user training must be provided. Many security breaches happen because employees fail to recognize phishing schemes, open emails from unknown sources, create poor passwords that are seldom changed, and don't take proper precautions when using public Wi-Fi connections on personal mobile devices also used for work.

  • Take to the Cloud - Running applications and servers in-house is a costly endeavor. Leveraging the cloud today allows SMBs to cut costs while also strengthening their security. Cloud operators typically have built-in security features, alleviating SMBs of the burden of maintaining security themselves. Today, not only can SMBs shift much of the burden of IT to the cloud, but they can also outsource much of their security by taking advantage of the remote monitoring, maintenance, and security tools provided by Managed Service Providers (MSPs).

Don't Aim for Perfection - There is no such thing as perfect security. Striving for perfection is expensive and can prove to be more costly in the end. Improving protection and response would be a more ideal allocation of funds. It can take a hacker several months to figure out your systems and do real damage. Having the ability to quickly detect their presence, and mitigate any potential damage they may cause, is a more realistic and less expensive approach than thinking you can completely remove any probability whatsoever of a hacker breaching your system.

Contact us at Computer Troubleshooters

Wednesday, May 13, 2015

Four Key Components of a Robust Security Plan Every SMB Must Know

5 Things SMBs Can Do Right Now to Preserve Their Network and Systems

Four Key Components of a Robust Security Plan Every SMB Must Know

Most businesses are now technology dependent. This means security concerns aren’t just worrisome to large corporate enterprises anymore, but also the neighborhood sandwich shop, the main street tax advisor, and the local non-profit. Regardless of size or type, practically any organization has valuable digital assets and data that should not be breached under any circumstances.

This makes it the responsibility of every business, especially those collecting and storing customer/client information, to implement a multipronged approach to safeguard such information.

Yes, we’re looking at you, Mr. Pizza Shop Owner who has our names, addresses, phone numbers, and credit card information stored to make future ordering easier and hassle free.

Today’s SMB Needs a Robust Security Plan
Protecting your business and its reputation comes down to developing, implementing, and monitoring a robust security plan that adequately addresses everything from physical access and theft to the threat of compromised technology security.  This involves defining and outlining acceptable uses of your network and business resources to deter inappropriate use.  Here are four key components to consider.

Network Security Policy: Limitations must be defined when it comes to acceptable use of the network.  Passwords should be strong, frequently updated, and never shared.  Policies regarding the installation and use of external software must be communicated.

Lastly, if personal devices such as laptops, tablets, or smartphones are accessing the network, they should be configured to do it safely, which can be done easily with a reliable Mobile Device Management (MDM) solution.

Communications Policy:  Use of company email and Internet resources must be outlined for legal and security reasons.  Restricting data transfers and setting requirements for the sharing or transfer of digital files within and outside of the network is recommended. Specific guidelines regarding personal Internet use, social media, and instant messaging should also be clearly outlined. If the company reserves the right to monitor all communication sent through the network, or any information stored on company-owed systems, it must be stated here

Privacy Policy: Restrictions should be set on the distribution of proprietary company information or the copying of data.

Inappropriate Use: Obviously, any use of the network or company-owned system or device to distribute viruses, hack systems, or engage in criminal activity must be prohibited with the consequences clearly noted. Any website that employees cannot visit should be identified if not altogether blocked and restricted. For instance, downloading an entire season of True Blood from a Bit Torrent site isn’t an acceptable use of company Internet resources.

Every employee must know these policies and understand the business and legal implications behind them.  Companies must also make sure these policies are clear and understood by all, and most importantly, strictly enforced.

Contact us at Computer Troubleshooters

Wednesday, May 6, 2015

Just Because You’re Not a Big Target, Doesn’t Mean You’re Safe

Understand How Data Loss Can Happen…

Just Because You’re Not a Big Target, Doesn’t Mean You’re Safe

Not too long ago, the New York Times’ website experienced a well-publicized attack, which raises the question – how can this happen to such a world-renowned corporation? If this can happen to the New York Times, what does this bode for the security of a small company’s website? What’s to stop someone from sending visitors of your site to an adult site or something equally offensive?

The short answer to that question is nothing. In the New York Times’ attack, the attackers changed the newspapers’ Domain Name System (DNS) records to send visitors to a Syrian website. The same type of thing can very well happen to your business website. For a clearer perspective, let’s get into the specifics of the attack and explain what DNS is.

The perpetrators of the New York Times’ attack targeted the site’s Internet DNS records. To better understand this, know that computers communicate in numbers, whereas we speak in letters. In order for us to have an easy-to-remember destination like nytimes.com, the IP address must be converted to that particular URL through DNS.

Therefore, no matter how big or small a company’s online presence is, every website is vulnerable to the same DNS hacking as the New York Times’ site. The good news is the websites of smaller companies or organizations fly under the radar and rarely targeted.  Larger targets like the New York Times, or LinkedIn, which was recently redirected to a domain sales page, are more likely targets.

For now…
There is no reason to panic and prioritize securing DNS over other things right now. But there is a belief that DNS vulnerability will be something cybercriminals pick on more often down the road.

Here are a few ways to stay safe

Select a Registrar with a Solid Reputation for Security

Chances are, you purchased your domain name through a reputable registrar like GoDaddy, Bluehost, 1&1, or Dreamhost. Obviously, you need to create a strong password for when you log into the registrar to manage your site’s files. Nonetheless, recent DNS attacks are concerning because they’re far more than the average password hack.

It was actually the security of the registrars themselves that was compromised in recent attacks. The attackers were basically able to change any DNS record in that registrar’s directory. What’s particularly frightening is the registrars attacked had solid reputations. The New York Times, along with sites like Twitter and the Huffington Post, is registered with Melbourne IT. LinkedIn, Craigslist and US Airways are registered with Network Solutions. Both had been believed to be secure.

So what else can be done?

Set Up a Registry Lock & Inquire About Other Optional Security

A registry lock makes it difficult for anyone to make even the most mundane changes to your registrar account without manual intervention by a staff registrar. This likely comes at an additional cost and not every domain registrar has it available.

Ask your registrar about registry locking and other additional security measures like two factor authentication, which requires another verifying factor in addition to your login and password, or IP address dependent logins, which limits access to your account from anywhere outside of one particular IP address.

While adding any of these extra safeguards will limit your ability to make easy account change or access your files from remote locations, it may be a worthwhile price to pay.

Contact us at Computer Troubleshooters

Wednesday, April 29, 2015

Stay Secure My Friend... More Hackers Targeting SMBs

7 Must Haves for Your Small Business Website

Stay Secure My Friend... More Hackers Targeting SMBs

Many SMBs don’t realize it, but the path to some grand cybercrime score of a lifetime may go right through their backdoor.  SMBs are commonly vendors, suppliers, or service providers who work with much larger enterprises. Unfortunately, they may be unaware that this makes them a prime target for hackers. Worse yet, this may be costing them new business.

Larger companies likely have their security game in check, making it difficult for hackers to crack their data. They have both the financial resources and staffing power to stay on top of security practices. But smaller firms continue to lag when it comes to security. In many cases, the gateway to accessing a large company’s info and data is through the smaller company working with them. Exposed vulnerabilities in security can lead cybercriminals right to the larger corporation they’ve been after.

Cybercriminals Target Companies with 250 or Fewer Employees

In 2012, Symantec research confirmed that cybercriminals are increasingly targeting smaller businesses with 250 or fewer employees. Attacks aimed at this demographic practically doubled from the previous year. This news has made larger enterprises particularly careful about whom they do business with. This means that any SMB targeting high-end B2B clientele, or those seeking partnerships with large public or government entities, must be prepared to accurately answer questions pertaining to security. This requires an honest assessment of the processes taken to limit security risks.

View Security Measures as Investments

CIOs must start viewing any extra investment to enhance security as a competitive differentiator in attracting new business. Adopting the kind of security measures that large enterprises seek from third-party partners they agree to work with will inevitably pay off. The payoff will come by way of new revenue-generating business contracts that will likely surpass whatever was spent to improve security.

Would-be business partners have likely already asked for specifics about protecting the integrity of their data.  Some larger entities require that SMBs complete a questionnaire addressing their security concerns. This kind of documentation can be legally binding so it’s important that answers aren’t fudged just to land new business. If you can’t answer "yes" to any question about security, find out what it takes to address that particular security concern.

Where a Managed Service Provider Comes In

Anyone who isn’t yet working with a Managed Service Provider (MSP) should consider it. First, a manual network and security assessment offers a third-party perspective that will uncover any potential business-killing security risks. A good MSP will produce a branded risk report to help you gain the confidence of prospects to win new business.

A MSP can properly manage key elements of a small company’s security plan. This includes administrative controls like documentation, security awareness training, and audits as well as technical controls like antivirus software, firewalls, patches, and intrusion prevention. Good management alone can eliminate most security vulnerabilities and improve security.

Contact us at Computer Troubleshooters