Technology Advisor Blog

Is your password 123456? Change it TODAY!

Posted by Ann Westerheim on Thu, Jan 22, 2015 @ 13:01 PM

computer_helpThe annual list of the worst passwords for 2014 has been posted.  Last year, there were over three million leaked passwords.  One of the interesting by-products of these leaks is the list of the top passwords.  SplashData posted their list of the top-25 (and therefore, worst!) passwords.  If you see any of your passwords on this list, change it!

1    123456 (Unchanged from 2013) 
2    password (Unchanged) 
3    12345 (Up 17) 
4    12345678 (Down 1) 
5    qwerty (Down 1) 
6    1234567890 (Unchanged) 
7    1234 (Up 9) 
8    baseball (New) 
9    dragon (New) 
10    football (New) 
11    1234567 (Down 4) 
12    monkey (Up 5) 
13    letmein (Up 1) 
14    abc123 (Down 9) 
15    111111 (Down 8) 
16    mustang (New) 
17    access (New) 
18    shadow (Unchanged) 
19    master (New) 
20    michael (New) 
21    superman (New) 
22    696969 (New) 
23    123123 (Down 12) 
24    batman (New) 
25    trustno1 (Down 1)

Interesting to note that the number one password has been unchanged for years.  I even saw it on a nationally televised game show a few years back.

Your security is only as good as your weakest link. Passwords should be "strong".  That is, passwords should be at least eight characters long, and contain uppercase letters, lowercase letters, and symbols.  At your next staff meeting, share this list with EVERYONE in your small business.

What is a Data Breach?

Posted by Ann Westerheim on Tue, Jan 20, 2015 @ 16:01 PM

Laptop Work-10Recently one of our clients got a system infected with a virus and worried about whether or not they needed to report it.  First, it IS possible to get a virus even though you're doing everything right, such as maintaining up-to-date anti virus protection, firewall protection, and security patch updates.  But in most cases, although viruses can create a lot of damage and disruption, no data is exposed to the wrong hands.

The Massachusetts Data Protection Law and many industry-specific standards such as HIPAA have rules regarding breach disclosure requirements.  To gain more insight into what actually constitutes a breach, here is a definition of a breach from the HHS.gov website (Health and Human Services).  In this case, the language specifically relates to protected health information, but similar guidelines can be used ot understand other protected information.

“Definition of Breach

A breach is, generally, an impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of the protected health information.  An impermissible use or disclosure of protected health information is presumed to be a breach unless the covered entity or business associate, as applicable, demonstrates that there is a low probability that the protected health information has been compromised based on a risk assessment of at least the following factors:

  1. The nature and extent of the protected health information involved, including the types of identifiers and the likelihood of re-identification;
  2. The unauthorized person who used the protected health information or to whom the disclosure was made;
  3. Whether the protected health information was actually acquired or viewed; and
  4. The extent to which the risk to the protected health information has been mitigated.”

In some cases, viruses can introduce key-logging software that could lead to a breach, but in general there is no “use or disclosure”.  The damage done by a virus may be thought of as analogous to someone physically damaging your computer with a hammer.  It's damaged, and harm was done, but no information was disclosed - more of an act of vandalism as compared to theft.

We strongly advise all clients to keep up to date with security training and make sure all employees understand the need for maintaining up to date security protection.

Tags: Security Requirements, breach,

New Years Computer Security Resolution - Lock your Computer!

Posted by Ann Westerheim on Wed, Jan 07, 2015 @ 08:01 AM

Windows-Key_L-1It's a new year and time for resolutions. With data security in the news almost every day, and several very high profile breaches last year (Sony, Home Depot, Staples), we recommend data security at the top of your technology plan for 2015.  
Here's a real simple tip to get started on the right path.  Get in the habit of ALWAYS locking your computer when you leave your work area even just for a few minutes.  Its quick - simpy hit the Windows Logo Key and the "L" key and your system will be locked. Raising awareness to all your employees will help keep your data safe.  This is one New Years resolution that's so simple there's no excuses!  Make it a company policy and at your next staff meeting remind everyone to take action. 

Team Collaboration - Sync and Share in the Cloud

Posted by Ann Westerheim on Thu, Dec 11, 2014 @ 09:12 AM

Sync_-On-Line_ViewWith remote working and team collaboration now commonplace, employees demand anytime, anywhere access to their work files.  When the workplace lacks these tools, employees take productivity into their own hands using their personal mobile devices and free or low cost consumer grade productivity apps to get stuff done.  What they may not know is that these devices and consumer grade solutions typically lack the rigid security requirements that businesses demand and therefore are unintentionally introducing risk into the workplace.  In order to minimize risk and maintain a secure environment, you need to standardize and develop use policies around data access.  A good place to start is to standardize on your file sync and share solution.  Let us help you make that transition easily and securely.

Remote access to an on-premise server has been the standard "business class" way of collaborating for years. However, in today's mobile world, it gets complicated to maintain and its time for reinvention - "Server 2.0" in the cloud.  Sync247 was built for business with enhanced security features designed to protect information security , with an easy-to-use intuitive interface to ensure adoption and compliance for your employees.

Its easy to use.  Access a folder on your desktop where you can drag and drop files just like any other folder on your desktop, or access files on line through a web browser.

Sync_-_Send_FileUsers can set "permissions" to share information to different people or groups of people in their workplace, and alsos send files to outside users with a link.  This is great when you're working with large files and email won't handle them.  You can also set the link to expire in a fixed amount of time and password protect the link.

 

 

Key features are summarized below:

Ensure Fast Employee Adoption with Easy-to-Use Service

•   Intuitive and elegant design requires little to no training

•   Impressive file rendering across multiple devices

•   Easy to use files and folders with convenient full text search

 

Enable Simple, Secure Team Collaboration

•  File locks, change tracking and notifications and commenting

•  Permission based share folders (full access, modify or read-only)

•  Protect public links with passwords and expiration dates

•  Unlimited file size support

 

Sync, Store and Access Files from Anywhere, From Any Device

•   Undelete feature offers fast file recovery

•   Desktop application support: Mac and Windows

•   Mobile apps support: iOS and Android

•   Web access to your files when you are away from your devices

 

Built for Business with Advanced Admin Control and Permissions

•   Audit trails about users, devices, and files for compliance and security purposes

Contact us for a demo at support@ekaru.com.  

Homeland Security Posts Alert for Windows 2003

Posted by Ann Westerheim on Mon, Nov 17, 2014 @ 10:11 AM

The Department of Homeland Security has issued an Windows_Server_2003alert for Windows Server 2003 (TA14-310A).   Microsoft is ending support for the Windows 2003 Operating System on July 14, 2015. After this time you will no longer receive security patch updates to protect against viruses, malware and other security threats.  There will also no longer be any software updates or technical support available from Microsoft after this time.

After July 14, 2015 systems running Server 2003 will be at risk for many cyber-security threats.  In addition, your business will be out of compliance for the MA Data Security Law, HIPAA, and other industry security compliance protocols.  Because of this, we're asking all clients to start planning NOW to prepare for the migration to a new server.

All products have a life-cycle and this is part of the standard Microsoft product life cycle management.  Last Spring, Windows XP was retired and now Windows Server 2003 is the next major operating system on the list.  As of July of this year, there were an estimated 12 million servers running Windows Server 2003 worldwide, so there will be a lot of work to bring systems up to date.  In general, if server hardware more than five years old, we recommend refreshing the hardware.

 

 

Is my UPS a Generator? Power Management for your Business

Posted by Ann Westerheim on Wed, Sep 10, 2014 @ 08:09 AM

LighteningIs my UPS a Generator?  This might sound like a crazy question, and we're not talking about the delivery service with the brown trucks, we're talking about an Uninterruptible Power Supply (UPS). With last weekend's severe thunder storms in the area (and winter on the way), it's a good time to think about Power Management.

As a general rule, all computers, servers, and network equipment should be protected with a UPS.  In some cases, you may need a big battery to keep a system on for short outages, or just enough to enable a safe shutdown, and protect from spikes/variations in power.  

It's important to know that a UPS isn't a generator - it doesn't keep your power running for extended periods of time such as when the power is out for hours or days.  The UPS will keep your system running for typically for a few minutes (depends on the battery size), and if the power isn't restored, the software will trigger a safe shutdown of your computer or server. The UPS also protects you against power surges and spikes, voltage sags, and frequency differences (when the power is not at 60Hertz).  Features to consider when selecting a UPS is the size of the battery, and software capabilities to enable a safe shut down. Some units also provide the ability to power cycle equipment over a network.   Longer run times will greatly increase cost (bigger battery).  

As a quick check of your technology,  servers, computers, or network gear should be never be plugged directly into the wall.  In addition, any printers or other electronics should, at a minimum, be protected with a surge protector power strip.  Note that power strips should not be connected to a UPS, they should only be plugged into the wall.  

Should my monitor be connected to the UPS or just a surge protector?, If you're just interested in safe shutdown, your monitor doesn't need to be connected to the UPS, but if you intend to run for a period of time, then your monitor should be connected.   Long power outages are rare, but you may also consider a generator for your business.

And always remember to save your files frequently and close them when you're done working, and make sure you have a robust backup. 

 

Tags: Power management, UPS, Surge protector

What's a "Patch Policy" and why do I need one?

Posted by Ann Westerheim on Tue, Aug 26, 2014 @ 07:08 AM

Security Patch PolicySecurity is the top technology concern among small business owners, and the flood of information about new security threats can seem overwhelming at times.  Just about every week we see a new headline about a new threat or breach.  

One of the most important actions to protect against threats is to keep your software up to date.  In fact, the Massachusetts Data Security Law and other industry-specific compliance rules require up to date security updates:  "For files containing personal information on a system that is connected to the Internet, there must be reasonably up-to-date firewall protection and operating system security patches..."  

Every month, Microsoft releases new security updates on "Patch Tuesday" which is the second Tuesday of the month.  These security updates are free with your licensed products, but they need to be installed to be effective.  As you may know, you can turn on "automatic" updates with Microsoft, and get all the updates, but in many cases, blindly installing the updates can be a problem in a business environment and we don't recommend Automatic Updates. This is why our "best practice" is to test updates before installation and create a "patch policy" to manage installation.  Just last week, Microsoft repealed security updates that were linked to blue-screened systems.  The software is so complex, and occasionally a patch gets released that has unintended interactions.  One of the most common is that many line-of-business applications won't run with the latest version of Internet Explorer, and a blind update will cause problems.  

We get a lot of questions about this, and we thought it would be useful to explain the reasoning behind the generation of a patch policy.  As a general rule, we'll install all Microsoft Operating System, Office, and other critical patches after testing.  In general, critical patches will be tested within 24 hours, and lower priority patches will be tested within one to two weeks.  

Sometimes customers look at the Automatic Updates information from Microsoft and become alarmed that they are not getting automatic updates, and the reason is that we test patches first.  Our software monitors for patch compliance, and we are automatically notified when there is a problem and we can report back to users as needed.  Each month, we review the list of installed patches and have a person on our team who specifically reviews sites every day for compliance.

Additional patches that are installed include Apple operating system patches (for MACs), and also "third party" patches such as Adobe Acrobat, Flash, Reader, Safari, Mozilla Firefox, Java, among others.  As a general rule, we install hardware drivers on an as-needed basis as these are very specific to different systems and configurations.

The next most important feature of a patch strategy is to manage reboots.  Many security patches require reboots for installation, and some patches are sequential in that the next patch can't install before the first installation is complete.  For servers, we generally program a scheduled reboot after security patch installation at a scheduled time to minimize disruption to the office (generally in the midnight to 5am window).  In a few cases, some line-of-business applications are known to not gracefully start after a reboot, and instead we schedule attended reboots so that the server and applications can be checked after the reboot.  We'll call the office and schedule a specific time that works.

For desktops, we generally don't schedule forced reboots because of the potential disruption this can cause a user.  If someone forgets to close an important document, or they're working at an odd time, a scheduled reboot can be annoying.  Also, if a system is "asleep" during the scheduled time, the reboot will be attempted when the computer is "awake" again, and this can be annoying as well.  We monitor reports of systems in need of reboot, and typically communicate with the office to let them know who needs a reboot.  Also we ask all users to reboot at least weekly.  In a few cases, we have scheduled site-wide reboot times, and if we see consistent problems with reboot compliance, we will strongly recommend this.

Data security is critical for protecting your business, and security updates are the first line of defense.  Every month we get questions about security patches, and we hope this post has addressed some of your questions.  Let us know!

 

Tags: Microsoft Security Patches, Patch Policy, Compliance

Thank You! Customer Survey and a Sock Drive

Posted by Ann Westerheim on Mon, Aug 04, 2014 @ 10:08 AM

BHCH Sock Drive - Thank you!Thank you!  Thanks to everyone who sent in a customer survey card back in June!  As promised, in appreciation for getting cards back, we donated a big box of socks to Boston Healthcare for the Homeless:  122 pairs of socks were donated! 

In the survey, we asked clients: "How likely is it that you'd refer Ekaru to a colleague or a friend?"   The overall core values repeatedly cited in the responses are responsiveness, knowledge, and friendly service, and we were pleased with the overall response (80% of cards were a 9 or 10 and over ½ of the cards were a 10).  We want to keep improving our strengths, and of course we need to correct things when we fall short of expectations. 

The key areas we are working on strengthening are better communication and follow-through on open issues.  We’re working on call flow to get a faster response to support calls and a faster resolution including full root cause resolution.  We’re also working on team coverage so that more resources can help you get faster resolution.  Typically one person on the team works with you regularly and gets to know you very well, but to provide better coverage, we need other team members ready to step in seamlessly when needed. 

Another thing a few people have asked for is simplified billing.  Instead of hourly billing, we will also be offering fixed priced engineering support contracts based on the number of users at your site.  Call us if you’re interested in exploring this.

Tags: customer survey, Sock Drive, BHCHP

Is your desktop buried?

Posted by Ann Westerheim on Tue, Jul 15, 2014 @ 13:07 PM

Windows KeyQuick Tip:  During a busy work day you may find your computer desktop cluttered with many open browser tabs and applications.  Need to quickly get to your uncluttered desktop?  Remember the Windows shortcut:  Windows Key + D.  Hit the Windows Key and then the "D" key and your desktop will appear.

If only this would magically work for the rest of a cluttered office!

Keep in mind that if your computer starts running slow, you probably need to actually close out the things you aren't actively using, but the shortcut is great for seeing the desktop fast.

Tags: Windows Shortcut, Desktop

Did I really reboot my computer?

Posted by Ann Westerheim on Fri, Jun 20, 2014 @ 10:06 AM


Restart Computer 400Every day we review security patch compliance for all our clients with managed services coverage with us.  Often, we see systems with security patches pending reboots.  Many security patches require a reboot to install, and some security patches are sequential, so the next one won't install before the previous patch is complete.  This can result in a system that isn't fully protected.

Server reboots are handled on a scheduled basis, but with desktop reboots, often we leave it to the user to reboot at their convenience to reduce the risk of disruption or lost files that aren't saved.  As a general rule, we ask users to reboot (at least) weekly.

One thing we've noticed recently, is that many users think they're rebooting, but they're not. To clarify, here are the steps (in Windows 7).  

  • Click on the "Start Button" (Windows colorful flag in the lower left hand corner).
  • Click on the arrow next to "Shut Down", and select "Restart" from the list. This closes all programs, shuts down Windows, and then restarts Windows again
If you see a yellow icon on the "Shutdown" button, then you need to select this option instead of "Restart", to completely power off your system.  Keep in mind that you will need to manually restart the system with the power button with this option.  If you're leaving for the day and want to remote in later, or you have a backup that runs over night, it's important to remember to power on your system again. 
You'll also see many different choices - "Switch User", "Log off", "Lock", "Sleep", and "Hibernate".  None of these is a reboot.  A common mistake for laptop users is to always put the laptop to "sleep" by closing the lid and never rebooting.  Some users mistakenly believe they did a reboot because they need to enter a password to log in again.
Remember to reboot your computer at least weekly!  If you'd like us to set up an automated schedule for reboots, we can implement that for you, but keep in mind that all users need to get in the habit of not leaving files open and unsaved.

Tags: Reboot, security patches

Subscribe by Email

Browse by Tag

Connect With Us

Older Blog Posts

For older Ekaru blog posts, go to ekaru.blogspot.com.