Deals from Amazon

Friday, 18 February 2011

Protecting Your Information - Laptop Encryption

At Secure Thinking, we are being asked more and more about how busy professionals can protect the business critical and often sensitive information they carry around on laptop and netbook computers.

The simple solution to this problem is to encrypt the laptop disk drive so that only the owner of the computer can access the data.

Most computers have a password which is used to prevent access to the software, applications and data in a casual fashion.  Passwords, and particularly strong passwords* are a vital component in preventing unauthorised access to information and applications.  However, they only protect systems that remain in the physical possession of the owner.

Once physical possession is compromised, as in the case of a lost or stolen computer, then there are ways of bypassing the logical access controls imposed by usernames and passwords.  Such bypass techniques can be as simple as using a brute-force password cracking tool or just simply removing the hard disk drive from the machine and plugging it in to another computer.

This can be a particular problem in the case of mobile computers, where the opportunity for loss or theft is far greater than machines protected by a secure physical environment.

Encryption of the hard drive can protect against the dangers highlighted above.  It means that, in effect, if the computer is lost or stolen, the data cannot be accessed by the new owner without the password or pass phrase used to perform the encryption.  In addition, where whole disk encryption is utilised, the system cannot even be started unless it is completely reinstalled - overwriting any data on the disk drive.

So if you want to protect your mobile computers, or even your office based ones should you feel the need, then contact Secure Thinking and we will be more than happy to go through your requirements and help you decide on the best solution for your business.


* Strong Passwords should be at least 12 characters long and consist of upper- and lower-case letters, numbers and special characters such as !'#@"£$ etc.  They should not be made up of dates, names or dictionary words - even obscure ones!

Wednesday, 2 February 2011

Secure Thinking When Online

If you run a small business or you manage the HR department of a large organisations you may well be aware of some of the issues surrounding staff use of social networking sites.

Social networking sites such as Facebook, professional networking sites like LinkedIn, and the various personal and professional blogging facilities, not to mention the micro-blogging sites like Twitter provide everyone with an opportunity to communicate with others with whom they have an affinity, voice their grievances and raise awareness of issues.

The problem for businesses and employers is when employees over-step the professional/social boundary.

If employees use social networking to make comments about the company, fellow employees, management or customers it can have a dire effect on business, perceptions and relationships both inside and external to the organisation.

Whilst many companies are aware of this and take some steps to mitigate the risk, it is often only done using a stick.  The general approach appears to be to discipline anyone who oversteps the mark - even when those marks aren't clearly defined.  This leads to further frustration and ultimately a breakdown in relations between employer and employee.

At Secure Thinking, we believe that this approach is wrong and have now decided to do something about it.  We are therefore offering a new awareness service - Secure Thinking When Online - where we will come on site at your company, or other location, and present to your staff about the risks of online behaviour, why the rules exist and how to protect themselves in their everyday internet based activities.