NEXT Generation Technology Support
July 2018
YOUR END-USERS ARE THE FIRST LINE OF DEFENSE MEET THE TEAM: JOSH LAEMONT
LEADINGIT CULTURE HACKERS WARN CONGRESS ABOUT THE INTERNET 20 YEARS AGO
GoLeadingIT.com
(815) 496-6300
YOUR END-USERS ARE THE FIRST LINE OF DEFENSE Phishing is one of the main cybersecurity risks that organizations of any size face, and it’s a major way in which an organization can become compromised. However, many organizations still don’t have a cybersecurity plan despite the growing threats that they are facing every day. Many organizations’ corporate cultures truly lack the security basics of working in this digital age. For example, do your employees know not to click on links that people send to them unless they’re sure the links are coming from trusted sources? Your cybersecurity starts with your employees/end-users. Majority of cybersecurity attacks target end-users and thus, end-user education is critical when it comes to cybersecurity. To help with the end-user education, Office 365 comes with a cool feature that allows you to send fake phishing emails to your employees/end-users to test whether or not they’d click on a malicious link, or engage in other unsafe behavior. These emails are a fully-customizable. You can send a customized, fake phishing email and get a reporting on the end-users that failed the test. Not educating your end-users in cybersecurity initiatives is like trying to keep a flood at bay using a screen door. Your end-users are the first line of against cybersecurity attacks (like phishing scams).
someone in a basement jumps past a company’s firewalls to compromise their network, namely because it’s too time-consuming and expensive. From the hacker’s perspective, it’s far easier to send a phishing email to your employees and let them do all the hard work for them (i.e. clicking on that link). This is why education is paramount to building a successful strategy. Almost every employee has an email address and access to the Internet. These simple services that you provide to your employees, unfortunately, account for about 90% of the breaches that are seen today. 3) Have cybersecurity tools in place to help prevent the potential for compromise. Cybersecurity protection doesn’t just come from making sure your end-users don’t click on the link or visit a site they shouldn’t. We’re human after all, and as humans, we can always make mistakes. To mitigate that, it’s vitally important to make sure that you’ve got the tools in place (like, for example, Advanced Threat Protection) for when your end-users do inevitably slip up. 4) The Importance of Continuous Cybersecurity Training One-time education is just not enough. Just like with fire drills, everyone needs to practice what they’ve learned, on a regular basis, so they can be ready for when something happens. Continuous cybersecurity training, therefore, is vitally important to be able to make your end-users into that first line of defense for your organization. After you are done educating on how your end-users can detect the most common attacks and practicing, here are two options to ensure that your efforts are fruitful: Use a tool that creates a fake phishing email and see how many of your end-users open it. As our case study above proves, Office 365 can really help in determining which end-users in your organization could fall victim to phishing attacks and other malicious activities. This type of reporting becomes critical to understanding how effective your cybersecurity program is – if you see a lot of your end-users failing the test, perhaps you need to put more into their training.
HERE ARE THREE STEPS YOU CAN TAKE TO MAKE CYBERSECURITY TOP OF MIND IN YOUR ORGANIZATION: 1) Implement a cybersecurity policy and procedure document. It doesn’t matter if you’re a one-person organization or a 10,000-person organization – you need to detail your action items long before a threat is identified, or else you won’t be able to cover all your bases when you’re under pressure. Therefore, if you don’t already have a cybersecurity policy and procedure document in place, you need one. This document should contain a section that details action items, in case your end-users encounter perceived or real compromises. 2) Build your cybersecurity strategy around educating your end-users. Very rarely do we see the “Hollywood version”, where
Deploy a cybersecurity awareness certification program as a part of your continuing education process. This certification process could be implemented in many different ways, depending on how you want to build it out. The idea behind it, however, would be that every person should be tested at regular intervals to ensure that they are understanding the training they’ve been given. For example, you could create multiple choice evaluation questions to understand how your end-users are absorbing what lessons you set up for them. They’ll also help you identify what additional training might be required based on the frequency of wrong answers. When your employees pass the tests given, they are re-certified for that set period of time. Stay safe out there~ Stephen Taylor Content from CIO.com
Meet the Team: Josh Laemont
LeadingIT Culture
Josh Laemont always gets the last word...and it's usually sarcastic. Humor in the IT world is much appreciated. Josh celebrated one year of tech support and laughs with us earlier this year.
Sam Wiszowaty Jul 13 - 3rd Anniversary Jul 14 - Happy Birthday!
Josh with his (adorable) daughter Raegan.
I WAS BORN IN… Rolling Meadows WHAT DO YOU DO AT LEADINGIT? Instant Support Group (ISG) DESCRIBE LEADINGIT IN THREE WORDS… Driven, Evolving, Fun IF YOU KNOW ME YOU KNOW…
Andy Latos Jul 19 - Happy Birthday!
No situation can’t be made worse with a sarcastic comment. WHAT WOULD YOUR SUPERPOWER BE? Mimic, I could copy and retain up to 5 other people super powers WHERE WOULD YOU BE FOUND 4PM ON A SATURDAY? Going for a walk with my toddler and wife IF YOU WERE A DRINK, WHAT WOULD YOU BE? White Russian, the dude abides TECH TIP YOU WISH EVERYONE KNEW? Everyone knows it but, doesn’t do it… Reboot your computer WHY DO IT GUYS GET A BAD REP? People are often already irritated at their issue when they contact IT and then associate that feeling with the person helping them
Dave Gregory Jul 22 - 5th Anniversary
These hackers warned Congress the internet was not secure. 20 years later, their message is the same.
Twenty years ago this week, a collective of young hackers came to Washington with a warning for Congress: Software and computer networks everywhere were woefully insecure. During that now-infamous hearing in May 1998, one told senators that “any of the seven individuals seated before you” could take down the Internet in just half an hour. In a return trip to Capitol Hill on Tuesday, the same hackers offered a similarly bleak assessment: Digital security is hardly any better. Four members of the collective known as L0pht reunited on the 20th anniversary of what is now referred to as the first congressional cybersecurity hearing to talk about what has changed since then. Yet in a wide-ranging panel discussion hosted by the Congressional Internet Caucus, they lamented how the technology is vastly different but many of the underlying vulnerabilities still exist. “At L0pht we tried to be the voice of reason in raising awareness for problems,” said Joe Grand, who went by the hacker name Kingpin in his L0pht days. “Nearly all of what we said 20 years ago still holds true. Yes, there have been improvements, but the general class of problems are the same.” Here are a few of them: • The same exploit the L0pht hackers could have used to take down the Internet in 1998 is still around today. • It's called Border Gateway Patrol hijacking, and it takes advantage of a fundamental weakness in the Internet's infrastructure -- essentially preventing routers from being able to talk to each other and get Web traffic where it needs to go. • Just a few weeks ago, hackers used this to steal more than $150,000 in cryptocurrency, said Chris Wysopal, who goes by the hacker name Weld Pond. “We’re still building new technology like cryptocurrency and blockchain, with all its promise of being secure, on old network foundations,” he said. “We keep building new things on old infrastructure that never seems to get fixed.”
• People are often unwilling to take better security precautions even when they know they are available. • If a security measure is too complicated, people won’t use it, Grand said, “and that’s just human nature.” • The landscape of digital threats is much more diverse, with all kinds of bad actors trying to take advantage of the Internet. • State-sponsored hackers and international criminal organizations, once just a hypothetical menace, have emerged as a top digital threat to governments and companies around the world. • Back then the threat was the teenage hacker,” Wysopal said. “It was like, ‘Yeah, they’re kind of ankle-biters’... Now it’s nation-states. So every vulnerability got a lot more risky.” • The federal government still isn't setting security standards. • Standards and certifications created by industry groups are "largely based on what feels right, rather than data showing what makes something strong in a security sense," said Peiter Zatko, who went by the name Mudge. • He asked: “Where’s the equivalent of the National Transportation Safety Board crash test results” for software? Cybersecurity is a public safety issue, “so why has this been almost entirely left to the free market to secure and make safe?” • The hackers raised similar concerns in their 1998 hearing, telling lawmakers that companies couldn't be trusted to police themselves. "At this point it's time for the government to step in and step up," Zatko said Tuesday. Luckily cybersecurity companies and the IT industry is stepping up. With an array of safety precautions and software implementations, we're well on our way to setting a standard. Is your company thinking about cybersecurity?