Deals from Amazon

Thursday, 30 December 2010

New Year's Resolution

It's that time of year again when we all make new year's resolutions.  It's pretty much par for the course.  We will be all enthusiastic for the 1st few days or maybe even weeks (if you're really keen).  Then it will all tail off into nothing.

The same story happens every year - why should this be any different?

Well how about setting a New Year's Resolution you can stick to?  One that will enhance your professional and business reputation?  One that will bring huge benefits to your organisation?

The New Year's Resolution I'm talking about is to call Secure Thinking and let us see if we can help you improve the Information Security within your business.  We can look at your current  information security policies, procedures and controls and investigate whether they are effective and are protecting your business interests.

We can also help you out with ongoing information security management which can plague businesses and is frequently ignored by busy owner managers.

So whatever information and IT security needs you may have, whether you require help with business processes such as security policies, procedures and standards, with employee education  in the form of awareness, guidelines and training, or with technical solutions such as anti-virus, encryption and secure backups, contact Secure Thinking now and make this year's resolution one that truly benefits you and your business!




Friday, 24 December 2010

Merry Christmas

Secure Thinking would like to wish all our staff, customers and contacts a very Merry Christmas.

Let's hope Santa brings you everything you need, and protects your information, identities and finances!

Have a good one!

Lee


Wednesday, 24 November 2010

10 Information Security Tips for Businesses

Businesses are recognising the importance of the information they manage, and more companies than ever deal with sensitive information on a regular basis.  So whether you are a one-man-band or a multi-national corporate entity here are Secure Thinking's 10 Information Security Tips for Businesses:

1. Implement policies and guidelines
Implement policies, processes and guidelines - the rules of the game - that are appropriate for your organisation.  This means a top-down approach to information security showing that your organisation is committed and willing to invest in protecting it's data.  Remember that often, the simplest solution is the best so keep your rules simple because doing so makes them easier to follow.

2. Lead by example
Senior level buy-in is vital but business owners and senior management must also follow the same policies and guidelines, otherwise it becomes a pointless exercise as staff will bypass them in the same way.  That means it's vital to lead by example, showing your team that you take information security seriously.

3. Staff education and training
It may seem obvious, but if you don't educate your staff on their information security roles and responsibilities then you can't expect them to provide effective protection for your data.  You should not only teach your staff what they have to do and the rules they must follow but also why it is important to you, how they do it and who they should speak to if they have any questions or issues.  It is important here to make the process as entertaining and fun as possible as it is seen often as a very dry, if not dull topic.

4. Business processes
It is important to implement appropriate business processes in your organisation and to align them with your information security policies as much as possible.  Otherwise it may become easier to bypass the controls you have implemented in order to achieve your business goals.

5. Technical solutions
In the same way as it is important to have appropriate business processes, it is also vital to implement appropriate technical solutions.  Many organisations see IT as the driving force in protecting their data.  However, this is not the case.  IT is simply one of the tools available and you therefore have to ensure your technical solutions and IT systems provide your organisation with the protection it desires in line with your information security policies.

6. Spot checks
A good way to ensure your staff follow your information security rules is to employ a regime of spot-checks.  It is important that this should be done to raise awareness of issues and not as a method of punishing those that fail to follow the rules, after all you need your employees to buy-in to the spirit of the program not merely follow instructions like sheep.  A great way of achieving this is to encourage staff to come up with ideas for improving security and reward the best ideas.

7. Test and measure
In addition to performing your own spot-checks, it's a good idea to employ an external agency or consultancy to test your security controls on a regular basis.  Many corporate bodies have regular penetration tests of IT infrastructure and less frequent tests of physical security.  Smaller businesses might see this as overkill but unless you actually test your controls you have no idea as to their effectiveness!

8. Check your suppliers
Most companies make use of 3rd party service providers.  Whether it's for your IT, web hosting, accountancy or legal operations it's important to ensure your suppliers take the same care and consideration over their information security (and yours) as you do.  It's no use having fantastic information security controls only for every Tom, Dick and Harriet at XYZ IT Support Company to have access to your sensitive data because they provide your IT support services.  Take the time and ask questions - ask to see their policies, how they vet their staff, and what controls they employ to protect your data.  At the end of the day, protecting your data is your responsibility.

9. Plan for the worst, hope for the best
In the same way that it's a good idea to have business insurance, all companies should invest in a Business Continuity Plan.  This means looking at the threats to your business, the risks posed by them and how you respond in order to continue operating should the worst happen.  Your Business Continuity Plan needs to cover all the high risks to your business and should be tested and reviewed on a regular basis to ensure it meets your changing operational requirements.  Obviously, testing a Business Continuity or Disaster Recovery Plan completely may be prohibitively expensive but there are ways of assessing the plan without necessarily having to buy hardware or pay for office space.

10. Incident response
Although having all the policies, processes and guidelines, the correct technical solutions, and excellent staff awareness will give you the best chance of not having an information security breach, it doesn't guarantee it.  Therefore, it is essential that you have a clearly defined process for responding to an incident.  This should include reporting points, escalation, evidence gathering and media management.  It should also clearly define the roles and responsibilities for relevant personnel and how your organisation reports the breach to the relevant authorities - be they law enforcement, the Information Commissioner or regulatory bodies - and of course how you inform the individuals or companies concerned.




Thursday, 11 November 2010

10 Social Networking Security Tips

Social Networking is the biggest thing to hit the internet since it began.  The sheer numbers involved are staggering.  If Facebook was a country it would be the 3rd largest in the world behind India.  It can be a massive force for good, yet it comes with inherent dangers, not least of which is to your security.

As such Secure Thinking have produced our 10 Social Networking Security Tips, to keep you safe and secure whilst chatting with your mates!

1. Don't publish too much
Don't publish too much information about yourself, your personal life, and your family online.  Things to avoid if possible are full dates of birth, mother's maiden name, 1st pet's name, 1st school, or make sure you lie to these types of things.  After all, they are all used by major institutions as "security" questions, so don't make it easy for someone to target you.

2. Assume everything is public
Always assume that everything that you post on the internet will at some point become public domain.  The rules and settings employed by the service provider now might change in the future.  Never post or say anything online that you wouldn't want your mum, your boss, future employers or future partners to find out about!  This includes "chats" with other people and "status updates", all of which have the potential to be public or become visible to others.

3. The internet never forgets
Unlike you an I, who have a habit of forgetting things on a regular basis, the internet won't forget.  That means the embarrassing photo's from your stag/hen party will still be hanging around the next time you get married!  And even if you delete images or remove content, there's a good chance it's been copied, backed-up or cached by another internet service.  This is an important fact that people tend to forget.

4. Don't "connect" with people you don't know
Don't accept "friend" or "connection" requests from just anybody unless you're aware of the risks.  Accounts of users are regularly monitored and targeted for malicious purposes with the intention of gaining something - either identity information or more often money in some way.

5. Don't trust even your "friends"
Remember, unless you can verify the identity of a user account without simply trusting they are who they claim to be don't trust them!  A genuine friend could have had their account compromised or someone may have set-up an account in their name with the intention of gathering information on you and others you know.

6. Don't announce your plans to the world
If you're going on holiday to Thailand for a fortnight, that's great, but don't tell the world and his wife when you're going, when you're returning, which hotel you're staying in and who's traveling with you!  This information is brilliant for burglars, muggers, identity thieves and anyone else who fancies free board and lodgings in you home while you're away.  Remember points 4 and 5!

7. Be wary of "apps"
"Apps" are great fun, what harm could they do, they're all provided by the site?  This isn't true.  Many "apps" are developed by individuals and companies external to the social network you're using and they often re-use code segments from other apps.  As such there's no guarantee the apps you're using are simply there for your enjoyment and aren't harvesting your data.  Now some harvesting is done for legitimate marketing and research purposes, but some of it is also done with not so innocent intentions.  As such be wary and don't download/install/add the "app" unless you really need to.

8. Avoid location based services
I know they're the new up and coming "thing", but I personally don't like the idea of having my movements tracked, even if it means I save a few quid at Starbucks.  Again, like point 6, you don't know who else has access to the information and who knows if the terms of service might change at some point in the future?

9.  Check your settings
All of the current social networking sites come with some form of privacy or security settings.  Now these might seem confusing and a bit pointless, but it's worth taking some time to go through and understand them to ensure you're protecting yourself to the best of your abilities.  If you need help then see if there's an FAQ, speak to someone who understands how they work or simply stay off the site.  Either way, make sure you have the settings at the level you feel comfortable with and that protects your data.

10.  Never post anything sensitive
The last point is almost the same as point 2, but here we're emphasising the need to avoid posting potentially sensitive personal or business information which could cause you or your company/employer harm.  This could be something as innocuous as a tweet saying "Off to meet XYZ corp now, back in an hour".  There is the potential that this could be privileged information and might allow your competitors to see who you're dealing with or who your clients are.  It could provide them with a competitive advantage or it could land you in trouble with your bosses, regulators or courts, depending on the issue at hand.


Now all of this might seem a little to paranoid for some of you, but as "they" are out to "get you" surely it's not paranoia!?




Wednesday, 3 November 2010

10 Client Site InfoSec Rules

If you're working on a client site, in addition to obeying their rules and policies on information security here are Secure Thinking's 10 Client Site InfoSec rules you should employ  to keep yourself and your information safe and protect the client.

1. Never leave equipment unattended
Laptops, phones, disks, memory sticks etc., should be taken with you, locked away securely or, in the case of laptops, locked to something solid with a Kensington style lock if they have to be left unattended.

2. Use encryption
Encrypt laptops, external disk drives, USB sticks to protect the data on them whilst on the move.  This will help to protect your data should you lose an item of equipment or it is deliberately targeted.

3. Operate a clear desk policy
Even if the client doesn't operate a clear desk policy, you should.  Never leave papers or other media on unattended desks.  Lock it away or carry it with you.

4. Leave sensitive information where it belongs
Don't carry sensitive information in bags, briefcases or laptop cases unless it's directly relevant to the work you're engaged in. If you do carry sensitive information, keep it in a secure bag and don't leave the bag unattended.

5. Never send unencrypted data or emails over public or client wi-fi networks
Just because your client trusts their wi-fi network doesn't mean you should.  Only send non-sensitive information over non-secure networks.

6. Never directly connect to client networks
Unless it is essential for your role never directly connect your systems to their network.  This is to protect them and you!  You don't know their network is secure and virus free and they don't know your system is.

7. Always lock your screen
When not working on your computer or laptop make sure it is locked and set a low timeout value for the automated screen lock.  This helps to prevent your system being accessed should you become distracted.

8.  Only work on that client's data
Never work on another client's data while on-site at a different client.  There are a whole host of potential legal and regulatory issues you could be opening yourself up to and you've no idea who might be interested in snooping over your shoulder.

9. Keep your equipment up-to-date and secure
I know it's a common one but you should ensure your Anti-Virus, Anti-Spyware, Operating System and other software packages that you use are patched up-to-date, you should also disable all unnecessary applications and services, and have your firewall enabled.

10. Don't use removable media
Unless it's essential to your work, don't use removable media to transfer data between your system and client systems.  If you do have to use a USB stick or other device, ensure you have auto-run functionality disabled (preferably on both systems) and ensure the device is virus scanned at both ends.  Use a brand-new device where possible and encrypt it if it's practical.





Friday, 1 October 2010

Mobile & Social Networking Apps

The subject of 3rd party "Apps" has raised its head again - this time on Google Android smart phones.

Apps on smart phones and on social networking sites are becoming ever more popular, but are the intentions of the App developers always in the best interests of the users?

A recent study of the apps on Android mobile phones has shown that the data they access and how they use it does not always tally with what the user authorises when they install the app.

This becomes even more of an issue where apps are downloaded or installed from other, shall we say less reputable sources.

There has also been occurrences of apps being developed reusing code segments created by other developers. This could lead to all kinds of unauthorised or malicious use of personal data which even the app creator doesn't know about.

So here are some simple rules to follow to enhance your security and protect your data:
  • Don't use apps unless you really need to
  • Only install apps from reputable sources
  • Only install apps that are essential for you
  • Remove apps you no-longer use
  • Always read what data will be collected by an app
  • If in doubt don't install it
  • Don't provide an app with access to sensitive information or don't place sensitive information in a location an app has access to

Tuesday, 28 September 2010

Location Based Services & Security

It seems that more and more location based services are surfacing, jumping on the Social Media bandwagon.

Now, I'm not an old fuddy-duddy, and I can see how some of these services might be of use to businesses and potentially to individuals. I do however, have massive concerns over the privacy and security of these services.

Firstly, there is the physical security aspects. The information about where you are could be used to target you personally for malicious intent. This could range from mugging you as you leave a venue to burgling your home while you're out.

Then there are the issues of who has access to this information. There are various rules and laws which apply to data protection but under what jurisdiction are you accounts being managed? Who both from a staffing point of view and a company point of view has access to the information? Are your locations, movements and habits being observed, monitored and assessed for other reasons - some of these may be purely for targeted marketing but others could be for more insidious purposes?

I have been critical in the past of individuals who post on Twitter, Facebook and other social networking sites with too much detail about where they are and what they are doing. Now we have services specifically designed to post and collect this information.

The simple fact of the matter is that people will leave themselves open because there are multiple, complicated options on the security settings page - will every user truly understand them all? And how do you know all of your "friends" are the only ones viewing your information? It could be that their accounts have been compromised or that you have mistakenly added a "friend" who isn't who you think it is.

My philosophy is this - whatever you share on the internet, even just to "friends" you should consider it public domain. Don't tell anyone anything, say you are or have been anywhere, or opine about something you wouldn't want your mother, your boss or the rest of the world to know! That way, you can protect yourself, your identity and your information.




Thursday, 23 September 2010

Poll: Protecting sensitive business information....

Please help with our latest poll for SME Business Owners - Protecting sensitive business or customer information is vital to my business......Complete Poll




Thursday, 12 August 2010

Meet Tim - A Social Engineering Story

There's a new guy working in your office. You haven't seen him around before and he keeps switching desks, using those of people who are out of the office, or work different shifts.

He has a nice smile and seems really friendly. You guess he works in IT because he always has a laptop and fiddles with peoples desktop PCs quite a bit, but you haven't spoken to him directly yet.

As time goes by you work out he's a bit of a charmer. He has a way with people, makes them feel comfortable with him around and some of the ladies in the office have taken quite a shine to him. He's witty, amusing and likes to bring in buscuits or doughnuts for everyone.

Eventually you find out his name is Tim and he is something to do with IT – you were right! You pluck up the courage to chat to him, and he tells you about his family, his wife and kids, his favourite sport and the team he supports. You get chatting about common interests, he's a really nice bloke and can talk well about almost any topic – not your typical IT geek then, phew!

The following Monday you see no sign of Tim, but you think nothing of it. He's probably off today or working at your other site.

By Wednesday, you have realised he must be off on holiday – you hope he's not ill or anything, especially that lovely wife of his.

The next Monday morning arrives and still no Tim. You don't worry too much because your PC is playing up and you can't log in to the network.

After logging a call with the Helpdesk, you notice that there seems to be a lot of senior managers and directors in various meetings, all looking very serious. Oh god, not more redundancies. So you knuckle down and look busy – as much as you can without your computer, putting the lack of Tim to the back of your mind.

When you turn up on Tuesday morning you see that everyone is being taken into a room with some gentlement in suits – you were right, it is more redundancies. Your turn to go in the room comes and you enter with some trepidation.

The rather stern looking gentleman in front of you says, “My name is Detective Seargent Jim Gallows. What can you tell me about someone working here recently called Tim....”

And that's when you find out that Tim didn't work in IT, he didn't actually work for your company, or a supplier. In fact it's very doubtful his name was even Tim.

You also find out that your company computer systems are offline beacause they have been infected with a virus which has deleted all your corporate data, but not the police suspect, before “Tim” took copies of all your essential information – personnel records, bank account & credit card details, sensitive customer records, financial data, etc. “Tim” and whoever he worked for now knows more about your company, it's employees, suppliers and customers than your company does!

That's all because you, your colleagues and managers didn't check who “Tim” was, didn't make sure he had the permission and the authority to be where he was, doing what he was doing.

Your company has just been the victim of a social engineering scam. “Tim” had essentially conned his way into your company, planted key-loggeers on peoples PCs to collect their user Ids and passwords. He had then connected his laptop to your corporate network and hacked into various systems, using the credentials he'd collected, to steal all you vital business data. At the end of this he had uploaded his virus to the network, ensuring you didn't have access to your systems for at least a few days.

Now imagine if there was no virus, no tell-tale to let your IT people know something was wrong. Would you even know this had happened?

Why Website Security is Important for Everyone

Most websites, whether owned by an individual, an organisation or a business, are never security tested. Many see it as an irrelevant or unjustified expense, citing the fact that it’s mainly static content, there’s no sensitive information held on the site, it doesn’t accept financial transactions, etc., so there’s no point in potentially expensive web security testing, as the business or organisation can’t be affected by insecurities.

Well, to put it simply, this is not true!

Whilst your website might not contain sensitive information, might not accept any financial or personal transactions, and may be purely static content, you are still putting your clients and website visitors at risk.

Cyber criminals, of which there are many, are not necessarily interested in gaining access to your business and its information – although you are always a likely target – but they ARE after your customers. They want access to their computers and their details and they can use the vulnerabilities in your website to get that access.

More and more often, we are seeing ordinary websites used to load malicious software onto the computers of unsuspecting victims. Cyber criminals are scanning the internet, looking for any websites which are insecure and are loading them with malicious software (called ‘malware’). This in turn is then passed on to the computers of every visitor to your site in what is known as a “drive by attack”, exposing them to all kinds of issues such as identity theft, bank account skimming and credit card fraud.

So whilst your organisation may not be affected directly by your website security problems, there is a huge amount of damage that can be inflicted on your customers and passing visitors, for which you are at least partly to blame.

This has now reached a point in the US where victims of such incidents are taking the website owners to court for compensation. And whilst this may not be likely to happen in the UK or elsewhere, there is certainly the potential for it, particularly where an incident can be traced back to a specific website.

If every person who merely looked at your premises was in danger of some injury, you would rightly take steps to prevent it. So why wouldn’t you take such a course of action in the virtual world of the internet, where such damage can be just as serious?

The importance of having an Information Security Awareness Programme

Most businesses are starting to recognise the importance of information security, both from the perspective of regulatory or legal responsibilities, and from a viewpoint of good business practice and brand protection.

But information security policies, procedures and practices are only as good as the people and systems that operate them. If the people who work in the system don’t understand their role, their responsibilities and why the controls are in place, then the results can be as bad for your organisation as not having them there in the first place.

Over the last few years there have been many stories in the press about information security failures within major organisations and government bodies. These organisations almost certainly had information security policies in place at the time of the failure. So why did it still occur and what can we learn from the mistakes of others?

As already stated, information security policies are only any use if they are understood, are adhered to and ultimately enforced as part of the culture within an organisation. Many of the well publicised information security failures have occurred because either the staff involved didn’t know their responsibilities, weren’t aware they were breaching the policies, or were operating without adequate supervision.

Another common failing is that information security policies do exist but are complex documents, unlikely to be thoroughly digested and understood by staff, even where they have apparently ‘signed them off’. This often means that staff ignore, or at best pay lip-service to the policies and the only time they are truly understood is following a security failure.

In most cases, a programme implemented to raise awareness of information security may well have prevented the failure, either partially - reducing the impact of the failure; or completely, by preventing the breach from occurring in the first place.

A carefully implemented information security awareness programme, encompassing properly documented, easy to understand security policies, standards, procedures and staff guidelines, along with ongoing training and evaluation, is a proven method for reducing information security failures.

It ensures your staff are aware, not only that the policies exist and that they are expected to adhere to them, but also why they exist, what their responsibilities are and how to operate on a day-to-day basis to maintain the required level of security. It also allows management to understand the levels of awareness within the organisation and provides them with the ability to target any specific issues which may arise.

Finally, even a good information security awareness programme needs to be backed up with a policy of open reporting. Having a ‘blame culture’ is not a good environment in which to raise information security issues. Staff need to feel they can report actual or potential problems without the threat of some kind of retaliation or witch hunt!

Information Security for SMEs

If you run a small or medium sized enterprise, then you’re probably up to your eyes in government red-tape, and legal and regulatory obligations, and that’s before you start to actually run and operate your business in order to make a living.

A key component in the smooth running of your business is information. That information may take on many forms – customer or supplier details, financial data or secret recipes for the perfect carrot cake – whatever it is, it is vital to your organisation. As such you need to make sure it is protected, kept from your competitors, guarded against public disclosure and available as and when you need it.

This is why good information security management and practices are as important to you as they are to the ‘big boys’. The major banks and corporations employ dedicated staff to manage their information security risks. You probably don’t have that luxury, but you still need someone to take responsibility for information security.

At this point, many SME managers and business owners claim they don’t have the time for information security, they don’t have the resources, it isn’t important to them, or they can’t afford it. After all, you’re only a small business, your IT people take care of that side of things, and you’re not at risk.

The information and data you use on a daily basis is the lifeblood of your business. Can you imagine if you had none of it? If one day you turned up at the office and all of your paperwork was blank? All of your computers had been wiped? Where would that leave you?

But it isn’t just the total loss of information that is of concern in the modern world. Criminals, including the so-caller ‘cyber’ criminals, want your information and my information. They want personal and financial details from as many people as they can for a variety of reasons, including identity theft. Even corporate data is now a target for the unscrupulous members of society.

So how would your company survive, particularly in the current economic climate, if it was discovered that your customers’ bank accounts were being drained, that identity thieves had access to personal data that could only have come from your business?

Apart from the obvious, potentially fatal, legal and regulatory fines, a well publicised incident of this nature would have a disastrous effect on your brand and business reputation. Even accidental disclosure of sensitive personal information is jumped on by the press, and that is without any direct criminal involvement.

If you hold personal information relating to living individuals, you fall under the jurisdiction of the Data Protection Act (DPA), if you handle financial information for individuals or other businesses you are very likely regulated by the Financial Services Authority (FSA), and if you handle credit and debit card payments you will almost certainly have to comply with the Payment Card Industry Data Security Standards (PCI-DSS). All of these mean you must adhere to minimum standards for information security for regulatory and/or legal reasons.

At the end of the day, information security is as important to SMEs as it is to anyone, so the question isn’t really “why do you need to worry about information security?” but “can you afford NOT to worry about information security?”

Why information security is NOT just an IT issue

Time and again, when I talk to business owners and managers about information security, I get the line “that’s an IT issue” or “our IT guys look after that”.

Whilst I’m well aware that IT and IT security plays a significant role in information security, it is not the Holy Grail many people seem to think it is.

IT is not some kind of magic wand, to wave over your information assets to suddenly make them secure. The careful and appropriate use of IT solutions is an enabler of information security. It is a method of securing your information and data whilst being used or accessed electronically.

Information is available throughout your organisation in a whole host of formats. Hardcopy printouts, hand-written documents and notes, and doubtless shelves of folders and binders, all make up a substantial element of your business information.

This information needs to be kept secure also.

But, by making information security and IT issue, many senior managers feel they have done their duty, and allocated it some someone who can deal with it. The problem here is that without senior management buy-in, and a top-down culture of security and security awareness among non-IT staff, the ‘IT Crowd’ can only achieve so much.

Often, IT security controls and processes, implemented without the understanding and buy-in of non-IT staff, will be circumvented. If staff feel that IT is getting in their way, they will do everything they can to work around it or subvert the controls. This is how we end up with users sharing logins or passwords, or documents being emailed to large groups of people because “Joe can’t access them”.

To successfully implement an information security programme, managers and business owners need to take ownership themselves. They need to be involved in writing the policies and procedures. They need to educate their staff and system users as to WHY they need to adhere to the policies, HOW to do it and WHAT the consequences will be if they are not followed. They can then use the available IT solutions to assist with the businesses information security policies, approach and objectives.

Information security is NOT an IT issue, but done properly IT can help you achieve your information security aims. You just need to make sure you’ve defined your business objectives beforehand, and educated your staff along the way.