Deals from Amazon

Showing posts with label Data Protection. Show all posts
Showing posts with label Data Protection. Show all posts

Wednesday, 25 May 2011

Data Backup Considerations

Data is vital to modern businesses.  Some say it's the life blood of a business.  After all we live in the information age.

But do we all protect data and information to the best of our abilities?  Do we ensure we can recover from its loss, corruption or theft?

In information security parlance are we properly protecting its CIA - Confidentiality, Integrity and Availability?

Most businesses take some steps to backup their data. This can be using traditional methods such as tape drives to newer techniques involving optical media, removable USB storage or even online backup solutions.

If you're not backing up your data then you should be. It's inexpensive and might just save your business one day.

But backing up your data is only half the story.  Having a backup is meaningless if you can't recover your data in the event of an incident.

You need to test that you can restore your data on a regular and random basis.  This exercises your solution and ensures it is actually doing what you expect of it.

Another consideration is the age and technology used.  If your infrastructure, devices and backup software are more than a few years old you may have other problems should you experience a significant incident or disaster with your systems.

If your incident takes out your current infrastructure can you replace it to actually recover your backups?

Without compatible technology and software your data may be inaccessible without expensive and time consuming 3rd party services.

Then there are online solutions.  There are many of them out there and they are fairly inexpensive but which one should you choose?

Depending on the data and the legal or regulatory requirements you may need to think very carefully. Your data may fall under one jurisdiction while it's residing on your servers and PCs in your office but whose jurisdiction is it under the control of on the backup storage?  What are their data protection, privacy and security laws like?

Is the data stored encrypted where only you can access it or can the staff at the service provider actually access your data, with or without your permission?

These are all things you need to consider when selecting a backup solution.  It isn't a simple choice based on price so think carefully and ask the questions above. They might just stop you going out of business.

In the meantime if you are looking for an online backup solution why not contact us on 0845 071 4690 or visit www.SecureThinking.co.uk and ask us these questions?

Wednesday, 11 May 2011

How's Your Business Continuity Plan?

Businesses are fragile things. They can be affected in their success by
a whole host of factors including market forces, consumer habits, and
changes in attitudes.
But many aspects of your business success are firmly held in your own
hands. You can develop an agile approach allowing you to change your
model based on market forces, you can adapt your products or services to
take into account consumer demands and you can keep track of people's
opinions to ensure you keep with current thinking and attitudes.
But how would you cope with a major incident that occurred to or in your
business?
Business continuity and disaster recovery are essential tools designed
to protect your business should the worst happen.
If you make use of technology in your business and particularly if it
forms the backbone of your operations you need to make sure you have a
Disaster Recovery Plan.
Disaster Recovery is the process of recovering your technical systems,
data and applications to a level which allows you to continue operating
your business.
Sometimes a DR solution will only recover key systems - just enough to
keep you going in the short term until a full recovery can be performed.
A technical disaster or incident can be caused by a number of internal
factors including technical faults, accidental damage caused by errors
or malicious activity.
Disasters can also be caused by external factors such as power cuts,
floods or property damage.
The key to an effective DR plan is to evaluate which systems,
applications and data are key to your operations and ensuring these are
recovered first. There is no point spending time and effort recovering
your marketing database when your customers aren't getting the products
they've ordered or the services they've bought.
Getting your DR plan right can mean the difference between having a
business in serious trouble and your customers not even knowing there
was a problem.
A Business Continuity Plan is similar in many ways to a Disaster
Recovery Plan. The main difference is that the BCP deals with more than
just technology.
Your BCP covers all aspects of your business, from offices and desk
space, communications, operations, to incident response, staff safety
and public relations.
Whether you decide your business needs a full BCP or merely a DRP you
should be aware that having one and making sure it is up to date and
tested can be the difference between your business surviving and growing
and it's complete failure.
There are many statistics out there but the general consensus is that
businesses experiencing a major incident and who don't have an effective
BCP will go out of business within 6-24 months of the incident.
You have insurance to cover you should the worst happen. A Business
Continuity Plan or at the least a Disaster Recovery Plan should help
protect you in the same way - by ensuring your business survives
whatever is thrown at it!
Our philosophy is simple - plan for the worst, hope for the best!
For more information or a free BCP/DRP consultation contact Secure
Thinking on 0845 071 4690 or visit http://www.securethinking.co.uk/

Friday, 24 December 2010

Merry Christmas

Secure Thinking would like to wish all our staff, customers and contacts a very Merry Christmas.

Let's hope Santa brings you everything you need, and protects your information, identities and finances!

Have a good one!

Lee


Wednesday, 3 November 2010

10 Client Site InfoSec Rules

If you're working on a client site, in addition to obeying their rules and policies on information security here are Secure Thinking's 10 Client Site InfoSec rules you should employ  to keep yourself and your information safe and protect the client.

1. Never leave equipment unattended
Laptops, phones, disks, memory sticks etc., should be taken with you, locked away securely or, in the case of laptops, locked to something solid with a Kensington style lock if they have to be left unattended.

2. Use encryption
Encrypt laptops, external disk drives, USB sticks to protect the data on them whilst on the move.  This will help to protect your data should you lose an item of equipment or it is deliberately targeted.

3. Operate a clear desk policy
Even if the client doesn't operate a clear desk policy, you should.  Never leave papers or other media on unattended desks.  Lock it away or carry it with you.

4. Leave sensitive information where it belongs
Don't carry sensitive information in bags, briefcases or laptop cases unless it's directly relevant to the work you're engaged in. If you do carry sensitive information, keep it in a secure bag and don't leave the bag unattended.

5. Never send unencrypted data or emails over public or client wi-fi networks
Just because your client trusts their wi-fi network doesn't mean you should.  Only send non-sensitive information over non-secure networks.

6. Never directly connect to client networks
Unless it is essential for your role never directly connect your systems to their network.  This is to protect them and you!  You don't know their network is secure and virus free and they don't know your system is.

7. Always lock your screen
When not working on your computer or laptop make sure it is locked and set a low timeout value for the automated screen lock.  This helps to prevent your system being accessed should you become distracted.

8.  Only work on that client's data
Never work on another client's data while on-site at a different client.  There are a whole host of potential legal and regulatory issues you could be opening yourself up to and you've no idea who might be interested in snooping over your shoulder.

9. Keep your equipment up-to-date and secure
I know it's a common one but you should ensure your Anti-Virus, Anti-Spyware, Operating System and other software packages that you use are patched up-to-date, you should also disable all unnecessary applications and services, and have your firewall enabled.

10. Don't use removable media
Unless it's essential to your work, don't use removable media to transfer data between your system and client systems.  If you do have to use a USB stick or other device, ensure you have auto-run functionality disabled (preferably on both systems) and ensure the device is virus scanned at both ends.  Use a brand-new device where possible and encrypt it if it's practical.





Thursday, 12 August 2010

Information Security for SMEs

If you run a small or medium sized enterprise, then you’re probably up to your eyes in government red-tape, and legal and regulatory obligations, and that’s before you start to actually run and operate your business in order to make a living.

A key component in the smooth running of your business is information. That information may take on many forms – customer or supplier details, financial data or secret recipes for the perfect carrot cake – whatever it is, it is vital to your organisation. As such you need to make sure it is protected, kept from your competitors, guarded against public disclosure and available as and when you need it.

This is why good information security management and practices are as important to you as they are to the ‘big boys’. The major banks and corporations employ dedicated staff to manage their information security risks. You probably don’t have that luxury, but you still need someone to take responsibility for information security.

At this point, many SME managers and business owners claim they don’t have the time for information security, they don’t have the resources, it isn’t important to them, or they can’t afford it. After all, you’re only a small business, your IT people take care of that side of things, and you’re not at risk.

The information and data you use on a daily basis is the lifeblood of your business. Can you imagine if you had none of it? If one day you turned up at the office and all of your paperwork was blank? All of your computers had been wiped? Where would that leave you?

But it isn’t just the total loss of information that is of concern in the modern world. Criminals, including the so-caller ‘cyber’ criminals, want your information and my information. They want personal and financial details from as many people as they can for a variety of reasons, including identity theft. Even corporate data is now a target for the unscrupulous members of society.

So how would your company survive, particularly in the current economic climate, if it was discovered that your customers’ bank accounts were being drained, that identity thieves had access to personal data that could only have come from your business?

Apart from the obvious, potentially fatal, legal and regulatory fines, a well publicised incident of this nature would have a disastrous effect on your brand and business reputation. Even accidental disclosure of sensitive personal information is jumped on by the press, and that is without any direct criminal involvement.

If you hold personal information relating to living individuals, you fall under the jurisdiction of the Data Protection Act (DPA), if you handle financial information for individuals or other businesses you are very likely regulated by the Financial Services Authority (FSA), and if you handle credit and debit card payments you will almost certainly have to comply with the Payment Card Industry Data Security Standards (PCI-DSS). All of these mean you must adhere to minimum standards for information security for regulatory and/or legal reasons.

At the end of the day, information security is as important to SMEs as it is to anyone, so the question isn’t really “why do you need to worry about information security?” but “can you afford NOT to worry about information security?”