The Newberry Group Blog RSS Feed http://www.newberrygroup.com/feedGen.aspxThe latest Blog Entries from The Newberry Group.(c) 2016The Newberry Group.5Keeping Student Data Secure in Education<div style="background-color: #ffffff; display: inline-block; font-family: 'helvetica neue',arial,sans-serif; color: #a7a7a7; font-size: 11px; width: 100%; max-width: 507px; min-width: 300px;"> <div style="overflow: hidden; position: relative; height: 0px; padding: 66.6667% 0px 0px; width: 100%;"><iframe width="507" height="338" frameborder="0" src="//embed.gettyimages.com/embed/187480288?et=cRFgXDrTRCd4srFKgE-dgQ&sig=IP8AXzmUYwUeswG2a7pPpwZImsJNK3ALhyVLf1NCbYs=" scrolling="no" style="display: inline-block; position: absolute; top: 0px; left: 0px; width: 100%; height: 100%;"></iframe></div> <p style="margin: 0px;"></p> <div style="padding: 0px; margin: 0px 0px 0px 10px; text-align: left;"><a href="http://www.gettyimages.com/detail/187480288" target="_blank" style="color: #a7a7a7; text-decoration: none; font-weight: normal ! important; border: medium none; display: inline-block;">#187480288</a> / <a href="http://www.gettyimages.com" target="_blank" style="color: #a7a7a7; text-decoration: none; font-weight: normal ! important; border: medium none; display: inline-block;">gettyimages.com</a></div> </div> <p>As students and teachers alike are embracing online learning tools, a need for better internet security in schools is becoming more apparent. The recent <a href="http://www.nmc.org/news/and-cosn-release-horizon-report-2014-k-12-edition" target="_blank">report</a> on tech adoption in education by the <a href="http://www.cosn.org/" target="_blank">Consortium for School Networking</a> (CoSN) and the <a href="http://www.nmc.org/" target="_blank">New Media Consortium</a> (NMC), highlights this trend of hybrid learning models that “blend the best of classroom instruction with the best of Web-based delivery.” However, the report also points out that the safety of student data is considered a “difficult challenge” and “<a href="http://www.nmc.org/news/and-cosn-release-horizon-report-2014-k-12-edition" target="_blank">solutions are elusive</a>.”</p> <p>While internet security is a pervasive issue for all industries, schools deserve some extra attention. Along with the increased need for bandwidth to access online courses and tools, students and teachers are all too quick to share personal information through the internet. Schools need to carefully plan their network security in much the same way they plan their physical security. There has to be a good balance between access and security.</p> <p>The solutions for balancing the security of student data with providing the right level of access required in today’s learning environment don’t have to be “elusive.” There is a full suite of solutions, such as network access controls or web filters, that are available at affordable prices and can offer the necessary protection for K-12 schools up through universities.</p> <p><strong>So what should you look for in a solution? Here are some good starting points:</strong></p> <ul> <li> <strong>URL Filtering</strong> – In 2013, <a title="Websense Threat Report" target="_blank" href="/data/files/White Papers/report-2014-threat-report-en.pdf">85% of malicious links used in web or email attacks were located on compromised legitimate websites.</a> Controlling which websites can be accessed can limit the possibility of malware infecting your network. </li> <li><strong>Secure Data Transfer</strong> – An estimated <a title="Barracuda Backup - The Value of Offsite Storage" target="_blank" href="/data/files/White Papers/Barracuda_Backup_WP_Value_of_Offsite_Storage.pdf">6% of all PCs will suffer at least one episode of data loss per year</a>. 20% of all laptops suffer hardware related data loss in the first three years. A good IT strategy implements an off-site backup solution for important data. In an education environment, that would include student records. Securing this transfer of data is necessary as not only can the physical data be accessed but the transmissions of that data can also be intercepted. </li> <li><strong>Mobile Device Security</strong> – On average, <a href="http://www.forescout.com/sans-analyst-report-your-pad-or-mine/">network administrators are only aware of 80% of the devices on the network</a>. In an educational setting, where nearly every student has a mobile device with the ability to connect to a local network, this figure is most assuredly much lower. Utilizing an agentless solution that discovers devices as soon as they access the network will protect vital information such as student records and institutional data while allowing the proper access necessary for the learning environment.</li> <li><strong>Bandwidth</strong> – With the inclusion of streaming media in today’s curriculum and the distribution of network resources across a geographically separated campus, load balancing bandwidth is essential to providing consistent access for both students and faculty </li> <li><strong>Efficient Configuration</strong> – School IT departments are minimally staffed. And often, the staff is simply challenged by time and resources just to maintain let alone implement and improve the network. Solutions that are easy to configure and maintain yet provide robust security features are a must. </li> </ul> <p></p> <br /><i><a href='/Blog/?id=56'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=56Gerald KennedyMon, 18 Aug 2014 18:45:00 GMTHow to Choose Security Solutions for Mobile Healthcare – Part 1<div style="background-color: #ffffff; display: inline-block; font-family: 'helvetica neue',arial,sans-serif; color: #a7a7a7; font-size: 11px; width: 100%; max-width: 507px; min-width: 300px;"> <div style="overflow: hidden; position: relative; height: 0px; padding: 66.6667% 0px 49px; width: 100%;"><iframe width="507" height="387" frameborder="0" style="display: inline-block; position: absolute; top: 0px; left: 0px; width: 100%; height: 100%;" scrolling="no" src="//embed.gettyimages.com/embed/156888012?et=NZQ2pjACS-prcIQMjtfTpg&sig=92yuaM-giXr2AbJVB3EBoeTHkJClktCtHXjRTIxHrpA="></iframe></div> <p style="margin: 0px;"></p> <div style="padding: 0px; margin: 4px 0px 0px 10px; text-align: left;"><a style="color: #a7a7a7; text-decoration: none; font-weight: normal ! important; border: medium none; display: inline-block;" target="_blank" href="http://www.gettyimages.com/detail/156888012">#156888012</a> / <a style="color: #a7a7a7; text-decoration: none; font-weight: normal ! important; border: medium none; display: inline-block;" target="_blank" href="http://www.gettyimages.com">gettyimages.com</a></div> </div> <p> <span style="font-size: 16px;"><strong>The last time I visited to the doctor, he recorded everything on a tablet device. </strong><span style="font-size: 13px;">While it’s convenient, mobile security is always at the forefront of my mind.</span></span> I was doing a bit of reading on mobile security and came across the Medicare and Medicaid (CMS) <a target="_blank" href="http://www.cms.gov/Regulations-and-Guidance/Legislation/EHRIncentivePrograms/index.html?redirect=/EHRIncentivePrograms/01_Overview.asp">Electronic Healthcare Records (EHR) Incentive Program</a>. This program gives healthcare providers a financial incentive for demonstrating the meaningful use of certified EHR technology or for adopting, implementing, or upgrading EHR technology. EHR technology allows providers to easily record and share patient data so that it’s consistent and readily available throughout the provider chain. This is certainly a great benefit to all healthcare providers as well as patients. No need to transfer records and records can be updated in real time through hand held devices, patient monitors, or diagnostic tools connected to the network.</p> <p>However, broader access to electronic databases and the use of additional devices to access that data only adds to the already vulnerable IT environment within the healthcare industry. IT components within healthcare are already severely susceptible to hacking and advanced persistent threats. Medical device end points, such as monitors and diagnostic tools, could have severely outdated operating systems that don’t lend themselves to standard patching processes. Even personal healthcare devices, such as insulin pumps, have known vulnerabilities as demonstrated by Jerome Radcliffe when he <a target="_blank" href="http://www.darkreading.com/vulnerabilities---threats/getting-root-on-the-human-body/d/d-id/1136133?">hacked</a> his own insulin pump. These weaknesses, coupled with the fact that medical practitioners regularly bring their own smartphones and tablets and are often <a target="_blank" href="http://hitconsultant.net/2014/02/26/infographic-state-of-mobile-technologies-in-healthcare-today/">unregulated at many facilities</a>, leaves a provider network open and vulnerable.</p> <p>The <a target="_blank" href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/securityrule/">HIPAA Security Rule</a> provides standards for the securing of electronic health information. These rules are in place to protect patient data through access control, audit controls, integrity controls, and transmission controls. While important, they rely on the provider to select and implement the necessary security solutions to prevent a data breach. And without proper security for personal and medical end point devices, it is only one finger in a dam that has many holes.</p> <p>Stay tuned for <a href="http://newberrygroup.com/Blog/Default.aspx?id=55">Part 2</a> later this week where I discuss the factors to consider when looking at different security solutions.</p> <p>UPDATE: Part 2 is live! Check out: <a href="http://newberrygroup.com/Blog/Default.aspx?id=55">How to Choose Security Solutions for Mobile Healthcare - Part 2</a></p> <br /><i><a href='/Blog/?id=54'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=54Gerald KennedyWed, 23 Jul 2014 18:13:00 GMTHow to Choose Security Solutions for Mobile Healthcare - Part 2<div style="background-color: #ffffff; display: inline-block; font-family: 'helvetica neue',arial,sans-serif; color: #a7a7a7; font-size: 11px; width: 100%; max-width: 485px; min-width: 300px;"> <div style="overflow: hidden; position: relative; height: 0px; padding: 72.7835% 0px 49px; width: 100%;"><iframe width="485" height="402" frameborder="0" src="//embed.gettyimages.com/embed/172601351?et=KZfD29Y8RKJvP7VO91lAaA&sig=5jtQDiykEpY-twF09avom33gjuUmsY_QCLokXaE98GU=" scrolling="no" style="display: inline-block; position: absolute; top: 0px; left: 0px; width: 100%; height: 100%;"></iframe></div> <p style="margin: 0px;"></p> <div style="padding: 0px; margin: 4px 0px 0px 10px; text-align: left;"><a href="http://www.gettyimages.com/detail/172601351" target="_blank" style="color: #a7a7a7; text-decoration: none; font-weight: normal ! important; border: medium none; display: inline-block;">#172601351</a> / <a href="http://www.gettyimages.com" target="_blank" style="color: #a7a7a7; text-decoration: none; font-weight: normal ! important; border: medium none; display: inline-block;">gettyimages.com</a></div> </div> <p><em><strong>To read Part 1 of this series, <a target="_blank" href="http://newberrygroup.com/Blog/Default.aspx?id=54">click here</a>.</strong></em></p> <p>According to the <a target="_blank" href="http://hitconsultant.net/2014/02/26/infographic-state-of-mobile-technologies-in-healthcare-today/">HIMSS Analytics 3rd Annual Mobile Survey</a>, the top benefit to having mobile tech in facilities is increased access to patient information, and the ability to view data from a remote location. But this means there are thousands of devices accessing a provider’s network. In order to select a proper security solution that not only meets HIPAA requirements but offers the protection for medical device end points in use, medical IT Administrators must look at a number of factors:</p> <ul> <li> <strong>What is on my network?</strong> This is the first and most important step in providing a secure IT enterprise. Many IT administrators believe they know what devices are on their network. However, healthcare facilities are littered with transient devices such as personal phones and tablets, patient monitors and diagnostic tools that have unique and often antiquated operating systems. These devices may only show up on IT networks once a week or perhaps once a month. It can be a daunting task to know exactly what is connected to the IT enterprise.</li> <li><strong>Controlling BYOD.</strong> Practitioners, nurses, and administrative staff often use their own unregulated devices, such as phones and tablets, to record data and communicate with staff and patients. Add to that the fact that many facilities offer open WiFi to their patients and guests. This creates a massive amount of end points that are not monitored and leave the IT enterprise vulnerable to malware, viruses, and advanced persistent threats. Survey findings shows that <a target="_blank" href="http://hitconsultant.net/2013/04/12/infographic-the-state-of-wireless-networking-in-healthcare/http:/hitconsultant.net/2013/04/12/infographic-the-state-of-wireless-networking-in-healthcare/">32% of hospitals</a> are not even using technology to enforce their BYOD policies. </li> <li><strong>End Point Compliance.</strong> Knowing what is on the network is one thing. Keeping known devices compliant is something else entirely. Security of an IT Enterprise is only possible through awareness. Once the devices are discovered IT administrators must be certain that they remain compliant. Having the ability to confirm applications and disable those that are unauthorized, verify whether or not the devices meets established security policies, knowing if the device is compliant with the latest security patch and antivirus definitions is essential. </li> <li><strong>Cost vs. Risk.</strong> While the Federal Government provides some mandates that direct medical IT Administrators to protect patient data, the healthcare IT network remains largely susceptible to your average hacker. It is up to each healthcare IT Administrator to protect the physical network to the degree they feel necessary to secure data and network end points. Healthcare budgets, like many vertical industries, are balanced toward production vs. protection. In the HIMSS Analytics survey, <a target="_blank" href="http://hitconsultant.net/2014/02/26/infographic-state-of-mobile-technologies-in-healthcare-today/">lack of funding</a> was the most common barrier to implementing a security solution. An effective solution with low cost of ownership is necessary. And while incentive programs such as EHR Incentive Program may seem to add balance to this in favor of the healthcare facilities, the incentive received is certainly not equivalent to the cost of losing patient data. </li> </ul> <p>Network administrators can’t secure what they can’t see. It is imperative that administrators have access to <a target="_blank" href="http://newberrygroup.com/Technologies/ForeScout.aspx">real-time visibility</a> of everything on their network and be able to control what is on their network at all times. When choosing a solution that meets all of these requirements, look for one that is simple to install on your network, without the need for agents or client software.</p> <p>If you’d like to talk more about end point security solutions or need help, <a href="http://newberrygroup.com/Contact-Us.aspx">get in touch</a> with us!</p> <br /><i><a href='/Blog/?id=55'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=55Gerald KennedyWed, 23 Jul 2014 16:03:00 GMTThe Responsibilities of Cleared Personnel<p><img style="margin-bottom: 20px; float: left; margin-right: 20px;" alt="Newberry Blog | image of cyber hand" src="/data/images/NewberryBlog/10-2013_NewberryBlog_Banner_v1.jpg" />With October being <a href="http://newberrygroup.com/News/default.aspx?ID=146" title="National Cyber Security Awareness Month | Newberry News">National Cyber Security Awareness Month</a>, this is a good time to think about the responsibilities that come with having a security clearance. It’s especially timely with the recent high profile security events of <a href="http://articles.washingtonpost.com/2013-08-21/world/41431547_1_bradley-manning-david-coombs-pretrial-confinement">Chelsea Manning</a>, <a href="http://www.politico.com/story/2013/08/edward-snowden-timeline-of-events-95057.html">Eric Snowden</a>, or <a href="http://articles.washingtonpost.com/2013-09-25/local/42380094_1_navy-yard-shotgun-shooting">Aaron Alexis</a>. We may seem surprised by their actions, but if we think back to <a href="http://www.fbi.gov/about-us/history/famous-cases/aldrich-hazen-ames">Aldrich Ames</a> or <a href="http://www.fbi.gov/about-us/history/famous-cases/robert-hanssen">Robert Hanssen</a>, we see that these events are not the first of their kind. </p> <p>When we obtain security clearances as government employees or contractors, we take on a multifaceted obligation: protect the technology and information that we have access to, ensure that others are doing the same, and ensure that we and our colleagues remain fit to work in a secured environment. </p> <p>Once we complete the background investigation and possible polygraph process, we are given strict guidelines in how we handle and protect information from both a technological and a philosophical perspective. No matter how obvious it may or may not be, the information we access is directly or indirectly related to the safety and well-being of our warfighters abroad, our allies, our state department representatives, and even civilians. Even if you encounter information or programs that you disagree with from a philosophical, moral, or legal perspective, there are internal government avenues to voice your concern without jeopardizing the information to the general public. Choosing the avenue of public disclosure only serves those who wish to harm our interests or freedoms. That route is very treacherous, possibly traitorous and most likely illegal. </p> <p>Even though you may be confident and diligent in your efforts to protect information, that doesn’t mean those around you are thinking the same way. It is equally your responsibility to be observant of the actions taken by others working with sensitive information. When suspicions arise, muster the moral courage to approach the appropriate personnel and report your concerns.  Quick action could result in stopping a serious security incident.</p> <p>Lastly, we must be cognizant that we and our colleagues are displaying the mental capacity to operate in a secure environment. Working in a secure setting can easily create a false sense of security and we assume that individuals around us are just as fit to be there as we are. However, secure areas are just as susceptible to criminal activities as an urban street corner, including anything from theft to shootings. There appears to be a growing number of mentally unstable individuals who have somehow slipped through the security screening process or co-workers who are upset by a life event that feel impelled to pursue indiscriminant or directed attacks against co-workers. We must be alert to suspicious signs and have the moral courage to approach or report those who may no longer be fit to work in a cleared environment. </p> <p>Some view the Mannings and Snowdens of the world as whistleblowers or even heroes. However, the information they released was not theirs to disclose or release and may ultimately seriously affect the freedoms of Americans. Conversely, attacks within a cleared setting, such as the recent Navy Yard shooting attack, raised concerns about the security screening process.  These unfortunate recent events can serve to reiterate that protecting information and maintaining a secured environment is an ongoing responsibility for everyone with a security clearance. By following tried and true policies and procedures the right outcome can be achieved.</p> <br /><i><a href='/Blog/?id=46'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=46Steve CadoganWed, 30 Oct 2013 14:30:00 GMTEmployee Data Protection: Securing Your Most Valuable Asset<p><img src="/data/images/NewberryBlog/08-2013_newberry_employeedata.jpg" style="float: left; margin-right: 20px; margin-bottom: 20px;" alt="Graphic Folder with Lock | Newberry Group Blog" /><strong>Protecting employees’ personal data is a big responsibility that falls on the shoulders of anyone who has access to create, store, handle or view personal information that is contained within Personnel and/or Accounting records.</strong>  Federal regulations in the <a href="http://www.hhs.gov/foia/privacy/" target="_blank" title="www.hhs.gov/foia/privacy/">Privacy Act of 1974</a> hold government agencies accountable for the proper management of personal information, which raises the concern for how private employers protect their employees’ personal information. </p> <p> Personnel files should always be maintained with utmost care and confidentiality and only shared with others on a need-to-know basis, and with the express written consent of the employee, as required by law. </p> <p>While there is an endless host of actionable possibilities to protect our employees’ personal data, it is important for employers to adapt some commonsense practices, which may include:</p> <ul> <li> Never respond to outside inquiries, other than job title, dates of employment, and employee status, for employment verification without prior written consent from the employee.</li> <li> Develop policies and procedures with your IT department and use up-to-date technologies to protect personal information that is maintained in electronic format. Develop internal controls, such as limiting the number of people who can access personal information, as well as limiting which data each individual can view.</li> <li> Safeguard all paper copies of personal information under lock and key with restricted access</li> <li> Only collect information from each employee that is required to pursue the company’s business operations and to comply with government reporting and disclosure requirements.</li> <li> Always keep  the medical history of an employee in a separate file with restricted access</li> <li> After employees are terminated, keep their files in your records in accordance with applicable state and federal laws. You can learn more about federal requirements by visiting the <a href="http://www.dol.gov/" title="www.dol.gov">US Department of Labor’s website</a> or by searching individual state Department of Labor sites.</li> <li> Have a written code of ethics and a confidentiality policy, and require every employee to sign an acknowledgment of having read the policy.  Place the signed acknowledgment in each employee’s personnel file.</li> <li> Develop a procedure for the confidential reporting of breaches such as an ethical hotline.</li> <li> Communicate to your employees the types of data that are not considered confidential such as partial employee birth dates, (i.e., day and month only, but not year), an employee’s company anniversary or service recognition information, etc.</li> </ul> <p>The bottom line is that employers should take every reasonable precaution to protect the personal data of their employees, whether that information is held in a government database or not. Not only is it the right thing to do, it’s just good business. After all, our employees are our most valuable asset, and taking extra precaution to protect our most valuable asset is an investment that contributes directly to the company’s bottom line. </p> <br /><i><a href='/Blog/?id=44'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=44Brinda BeasleyWed, 14 Aug 2013 11:35:00 GMTSocial Media in the Cyber Security Space<p><img src="/data/images/NewberryBlog/06-2013_NewberryBlog_Banner_v2.jpg" style="float: left; margin-right: 20px; margin-bottom: 10px;" alt="Social Media in the Cyber Security Space | Ryan Steinbach | Newberry Blog" />Last fall, I started as an intern at the Newberry Group with objectives of assessing the impact of growing a social media presence, developing a strategy for social media use and executing on that strategy. After nine months, my team and I accomplished these objectives and learned a great deal about the cyber security digital community in the process. </p> <p>In my relatively short, but deep dive into social media strategy and development over the last two and a half years, I’ve witnessed how different the digital communities can be. The cyber security digital community is particularly fascinating. My team found that cyber security professionals tend to fall into two buckets when it comes to social media. There are those who embrace social media due to their above average understanding of its utility, and there are those who avoid it at all costs due to their above average understanding of the risks associated with it. </p> <p>This creates an interesting obstacle when engaging with the cyber security digital community. The space expects a sophisticated level of engagement, yet can also feel fragmented and reserved. It seems most companies have accepted that they need to be present on social media but there are huge disparities in utilization. Some online presences are merely place holders while others are hosting weekly webinars. </p> <p>My team at Newberry decided the greatest value was between these two extremes. We saw opportunities for talent sourcing, service promotion, and partnership development, but we also needed to be realistic about the amount of capacity we could commit to these efforts. The value is there to be had, but only with the people and buy-in to capture it effectively. </p> <p><img src="/data/images/NewberryBlog/06-2013_NewberryBlog_EngagingInSocial.jpg" style="float: right; margin-bottom: 10px; margin-left: 20px;" alt="Social Media Engagement | Newberry Blog" />We knew we didn’t have the capacity to be active in every space or create a large amount of unique content so we focused our efforts on building out the spaces we felt had the most value and created a content strategy that balanced quality and thought leadership with consistency and practicality. </p> <p>Creating a social media policy also became a critical element of our strategy. The greatest enemy of engagement is uncertainty and, in a space as sensitive as the cyber security community, assessing the appropriateness of a 140 character tweet will likely lead to abandonment. We want to be as explicit as possible about our internal expectations for social media because we believe it will remove that uncertainty and foster greater internal engagement.</p> <p>The development of a social media strategy and policy that balanced value with capacity is the product of what has become my biggest take away from my time at Newberry. I’ve learned that the benefits of social media do not appear over night. Early wins can be few and far between. But, sustainable and consistent execution of social media builds equity in a digital community that eventually translates into real company value. </p> <p>This kind of sustainability requires a hard look at where a company can be most effective and then tailoring that to the company’s internal capacity. Instead of leaving social media to the intern as many companies do, my team decided early on that there was no point in me doing any of the day-to-day social media work. Instead, I focused on strategy and setting up Newberry’s internal structure – things that once set in place can be utilized with minimal maintenance.</p> <p>I’m confident that as I leave Newberry my work will be appreciated, not missed. I’ve helped give Newberry the tools to continue to build value in the cyber security digital community on their own. While this was not part of the three original objectives I had going into the internship, I believe it is by far the most valuable and can serve as an example to others in the space.</p> <br /><i><a href='/Blog/?id=42'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=42Ryan SteinbachTue, 11 Jun 2013 10:26:00 GMTSocial Engineering through Social Networking: Defending Your Organization<p><img style="width: 275px; margin-bottom: 20px; float: left; height: 197px; margin-right: 20px;" alt="Newberry Blog - Defending Your Organization graphic" src="/data/images/NewberryBlog/04-2013_Blog_Banner.jpg" /><strong>Human beings are the weakest link in data protection.</strong> Social networking has made this weakest link, even weaker.  Social engineering continues to be one of the most leveraged attack vectors for targeting an organization’s electronic data or IT systems.  Historically, a social engineering attempt would consist of an unsolicited phone call or e-mail. Attackers would attempt to obtain reconnaissance-related information from an unsuspecting employee or get them to click a link, or download an e-mail attachment, that would introduce malware to the system, potentially allowing backdoor access to the network.  As users have become more educated on information security, they have learned not to open attachments or click links from individuals they do not know or trust.  However, with the continued growing popularity of social networking, potential attackers can perform a more targeted social engineering attack that exponentially increases their level of possible success.   </p> <p>One piece of information typically found in social networking profiles is employment information.  A quick search on LinkedIn or Facebook can reveal a list of potential social engineering targets for just about any organization.  By using the information found in the target’s profile, the attacker can craft an e-mail that looks legitimate and includes an attachment or link containing malicious software.  If an attacker determines the target worthy, they may even establish a false profile reflecting similar interests and befriend the employee, allowing them to eventually introduce the malware through an e-mail or link.  </p> <p>Since it is not feasible to control and monitor what employees put on their personal social networking profiles, how can an organization appropriately defend against this type of attack?</p> <p><strong><span style="font-size: 16px;"><img style="width: 100px; float: left; height: 100px; margin-right: 20px;" alt="Newberry Blog - User Education graphic" src="/data/images/NewberryBlog/04-2013_NG_UserEducation.jpg" />1. User Education:</span></strong>  This has been, and always will be, the most effective tool for combating social engineering.  In addition to the typical IT security training provided by most organizations today, users should be educated on what company information is appropriate for disclosure on social networking sites and how this information could be used to exploit them.  Employees should understand that individuals they make contact with online should not be considered a trusted contact.  E-mail attachments or hyperlinks from these online contacts should not be accessed from company-owned computers.  </p> <p><strong><span style="font-size: 16px;"><img style="width: 100px; float: left; height: 100px; margin-right: 20px;" alt="Newberry Blog - Policy and Procedures graphic" src="/data/images/NewberryBlog/04-2013_NG_Policy.jpg" />2. Policy and Procedures:</span></strong>  Organizations should prohibit employees from using, or listing, their company e-mail addresses on social networking sites.  If the social networking sites are a means for networking or marketing and part of official job duties, then look at establishing a generic e-mail account with increased security restrictions that the employee can utilize.  This will allow the employee to identify any contact that is made through the site and treat it as untrusted.  </p> <p><strong><span style="font-size: 16px;"><img style="width: 100px; float: left; height: 100px; margin-right: 20px;" alt="Newberry Blog - Security Infrastructure graphic" src="/data/images/NewberryBlog/04-2013_NG_SecurityInfrastructure.jpg" />3. Security Infrastructure:</span></strong>  A reputable web proxy with malware scanning capabilities should be utilized to scan web traffic for potential malware.  URL filtering should be enabled and sites that contain known malicious code or malware blocked.   Social networking sites should also be restricted for users that do not have a business purpose for visiting them.   URL filters typically have groups of sites that are categorized and updated to make this process easy.  Finally, a spam filter device or service should be used to scan inbound e-mail for malware and filter unwanted e-mail.  Some spam filtering devices also have the capability to scan outbound e-mail for sensitive information such as social security or credit card numbers; this is commonly referred to as Data Loss Prevention (DLP).  </p> <p>With employees advertising more personal information on social networking sites, we can expect to see a continued increase in targeted social engineering attacks.  As with any security threat; a layered defense strategy is the best defense against social engineering attacks.  </p> <br /><i><a href='/Blog/?id=40'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=40Steven CarneyTue, 16 Apr 2013 12:15:00 GMT5 Tips for Building a Cyber Security Career<p><strong><img style="width: 245px; margin-bottom: 10px; float: left; height: 175px; margin-right: 25px;" alt="IT career seeker" src="/data/images/NewberryBlog/11-2012_NG_Blog_Banner.jpg" /><span style="font-size: 16px;">The cyber security field is rapidly expanding to deal with the accelerated risks of changing technology and now is a great time to make the move into a security career.</span></strong> However, not only do you need the qualifications, but also an analytical mindset and good communication skills to effectively convey your expertise to the wide range of customers. Cyber security experts are always chasing an elusive problem and you have to think outside the box quite a bit to find that advanced persistent threat. Here are five tips on how to build your successful career: </p> <h2><span style="color: #000000;">1. Develop a Solid IT Foundation</span></h2> <p>In the case of cyber security, it's really beneficial to have a strong background in information technology. A lot of universities have modified curriculum to provide security focused-degrees. Previously you might have been restricted to computer science or information technology, but now there are actual degrees tailored around computer security.  These programs are often sponsored by entities that are focused on cyber security and want to help build the workforce. For example, currently the U.S. government has a shortfall of cyber security professionals. So they have started working with universities to establish these programs to help grow the cyber security field and fill the jobs that they know will be out there.</p> <h2><span style="color: #000000;">2. Get Certifications and Training</span> </h2> <p><img style="margin-bottom: 20px; float: right; margin-left: 20px;" alt="Certifications" src="/data/images/NewberryBlog/11-2012_NG_Certifications.jpg" />Certifications are necessary because they establish a foundation. They identify the individuals that have put in the time and effort to understand the fundamentals of cyber security.  The <a href="https://www.isc2.org/cissp/default.aspx" title="CISSP certification website" target="_blank" shape="rect">CISSP</a> certification is a well-known and internationally recognized security certification and is a great starting point. But with all the different domains of expertise within the security field, you should hone your craft and acquire certifications for your specific area. </p> <h2><span style="color: #000000;">3. Use Your Past Military Experience</span></h2> <p>Today, information technology in the military is no different than it is in the corporate world. There are disciplines within the military that focus on IT and cyber security, so veterans have an opportunity to directly transfer their experience from military service into commercial cyber security work.  </p> <h2><span style="color: #000000;">4. Use Your Existing IT Career</span></h2> <p>If you've been in IT for a long time and you have a strong background, you have most likely been exposed to security issues. In all reality, you probably have a level of experience that would qualify you to easily transition and adjust to cyber security work without having to start from the ground up. Talk to your peers or managers about what security opportunities are available to you. Also take some personal initiative to start working on a certification in your area of interest. </p> <h2><span style="color: #000000;">5. Build Up Practical Experience</span></h2> <p><img style="margin-bottom: 20px; float: right; margin-left: 20px;" alt="Icon - Build Practical Experience" src="/data/images/NewberryBlog/11-2012_NG_Experience.jpg" />At the end of the day, just like in any field, you need the qualifications and the practical experience.  And you have to work your way up. Unless you have a lot of applicable experience, expect to start at the bottom and prove yourself so that you have the evidence to put in your resume. Certifications are great because they establish a foundation through the training, but practical experience is just as important. If you don't have the experience, be forthcoming about it, but also have the wherewithal to press forward with developing your career.   </p> <h2><span style="color: #000000;">Are there jobs out there?</span></h2> <p>There is a wide range of cyber-related jobs and almost every industry will have availability whether it's on the commercial side or federal side. In some cases, a cyber opportunity might be there, it just might be coupled with 2 or 3 other roles at the same time; You might be the cyber expert and the IT guru. Newer fields within information technology or security, such as cloud security, mobile security, digital forensics, and malware analysis, are all hot domains so you'll see a lot of opportunities advertised. However, no area in cyber security has lost momentum. Cyber security as a whole is a hot industry to be in, and I predict it to be so for the next couple of decades. It's not slowing down. </p> <p> </p> <br /><i><a href='/Blog/?id=35'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=35Phillip Justice, Jr.Mon, 19 Nov 2012 09:57:00 GMTOctober is National Cyber Security Awareness Month (#NCSAM)<p><a href="http://www.staysafeonline.org" target="_blank" shape="rect"><img style="margin-bottom: 20px; float: right; margin-left: 20px;" alt="National Cyber Security Awareness Month" src="/data/images/NewberryBlog/banner%20300x250.gif" /></a>We’re one of the official champions of National Cyber Security Awareness Month (NCSAM) and there’s still time to get involved!  National Cyber Security Awareness Month is a campaign focusing on the need for improved online safety and security for all Americans. The National Cyber Security Alliance has sponsored National Cyber Security Awareness Month every October since its founding in 2003.  </p> <h2>This year’s theme is “Our Shared Responsibility.”  So how can you help?</h2> <h3>1. Share Tips and Resources with Your Friends and Family</h3> <p>The <a href="http://www.staysafeonline.org/" target="_blank" shape="rect">National Cyber Security Alliance</a> (NCSA) website is full of tips on how to protect your personal information, teach online safety, and keep your business safe online. Would you know what to do if your <a href="http://www.staysafeonline.org/stay-safe-online/keep-a-clean-machine/hacked-accounts" target="_blank" shape="rect">accounts were hacked</a>? Do you need resources to help <a href="http://www.staysafeonline.org/teach-online-safety/" target="_blank" shape="rect">teach cyber security</a> in your classroom?  Does your small business have a <a href="http://www.staysafeonline.org/business-safe-online/implement-a-cybersecurity-plan/" target="_blank" shape="rect">Cyber Security Plan</a>?<br /> <strong>Find resources and tips on</strong> <a href="http://www.staysafeonline.org" shape="rect">www.staysafeonline.org</a>.</p> <h3>2. Attend An Event and Share It!</h3> <p>Organizations all across the United States are hosting cyber-related events to help raise awareness. </p> <ul> <li>Find an event in your area on the Events page: <a href="http://www.staysafeonline.org/ncsam/events" shape="rect" originalPath="http://www.staysafeonline.org/ncsam/events" originalAttribute="href">www.staysafeonline.org/ncsam/events</a> </li> <li>Stay at your computer and check out these FREE Webcasts from SANS: <br /> <strong>Securing The Human  <br /> Oct 16th</strong> and  <strong>Oct 30th<br /> </strong>Register on their website: <a href="http://www.securingthehuman.org/blog/2012/09/06/three-security-awareness-webcasts-for-oct/" shape="rect">http://www.securingthehuman.org/blog/2012/09/06/three-security-awareness-webcasts-for-oct/</a> </li> </ul> <p>Newberry Group is proud to be a part of National Cyber Security Awareness Month. Anyone can help raise awareness in their community, let’s continue to help others stay safe online!</p> <p>To learn more about the National Cyber Security Alliance, visit <a href="http://www.staysafeonline.org" shape="rect">www.staysafeonline.org</a>.</p> <br /><i><a href='/Blog/?id=34'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=34Newberry Marketing TeamMon, 15 Oct 2012 17:55:00 GMT5 Tips to Get Your Data and Computer Storm-Ready<span style="font-family: helvetica;"> <p><img style="margin-bottom: 20px;" alt="Newberry Group Blog - storm image" src="/data/images/NewberryBlog/08-2012_Blog_Banner.jpg" /><br /> Hurricane season is upon the southern United States and now is a good time to make sure your data and computer is prepared for an emergency too. Here are some tips to get you started:</p> <ol> <li> <p><strong><span style="color: #0070c0;">Backup your data with an online backup service</span></strong> - There are many online backup services to choose from. This <a href="http://www.pcmag.com/article2/0,2817,2395766,00.asp" target="_blank" shape="rect">article</a> by <a href="http://www.pcmag.com/article2/0,2817,2395766,00.asp" target="_blank" shape="rect">PC magazine</a> does a great job of outlining the different options available. </p> </li> <li> <p><strong><span style="color: #0070c0;">Copy your User folder (the folder named "Username") to an external hard drive</span></strong> – This will ensure that all of your documents, photos, videos, music, desktop, and application data such as email archives and application preferences are saved. For the ultimate backup, consider making a "snapshot" of your entire computer with a program such as <a href="http://www.acronis.com/" target="_blank" shape="rect">Acronis True Image</a> (PC) or <a href="http://www.bombich.com/" target="_blank" shape="rect">Carbon Copy Cloner </a>(Mac). The "snapshot" will allow you to boot from that hard drive if you had to completely restore your files.</p> </li> <li> <p><span style="color: #0070c0;"><strong>Use a battery backup + surge protector</strong></span> – If you use a desktop computer, a battery backup will provide some buffer time for you to save your files when there is a power outage. Most battery backups also give you the benefit of a surge protector.</p> </li> <li> <p><strong><span style="color: #0070c0;">Plug your cable modem’s coaxial cable into a surge protector</span></strong> – If you use a cable modem and your computer is directly connected to it via an ethernet cord, be sure to plug the coaxial cable into the battery backup. This will help prevent power surges being transferred from the cable, through the ethernet cord, and on into your computer.</p> </li> <li> <p><span style="color: #0070c0;"><strong>Unplug your computer when not in use during a storm</strong></span> – The most certain way to avoid power surge damage is to simply unplug your computer from its power cord.</p> </li> </ol> </span> <br /><i><a href='/Blog/?id=32'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=32Breanna Cooke & Nicholas Trifiletti, contributorFri, 31 Aug 2012 12:19:00 GMTWhy do Nigerian scammers say they are from Nigeria?<span style="font-family: helvetica;"> <h1 style="text-align: left;"><img style="margin-bottom: 20px;" alt="Image of binary code and password" src="/data/images/NewberryBlog/07-2012_Blog_Banner.jpg" /></h1> <p>Far-fetched tales of West African riches strike most as comical. So why do Nigerian scammers say that they are from Nigeria? Why so little imagination? Why don’t Nigerian scammers claim to be from Turkey, or Portugal, or Switzerland? Stupidity is an unsatisfactory answer: The scam requires skill in manipulation, considerable inventiveness and mastery of a language that is non-native for a majority of Nigerians. </p> <p>We’ve all seen some form of this "too good to be true" chopped up English type of technique designed to part us from a significant amount of money. However, the <em>initial reaction</em> of a scam-savvy person is just what the attackers are looking for. This scam method relies on a vast numbers game and is examined in <a href="http://research.microsoft.com/pubs/167719/WhyFromNigeria.pdf" title="Cormac Herley's whitepaper: Why Do Nigerian Scammers Say They Are From Nigeria?" target="_blank">Cormac Herley’s whitepaper</a>, <em><a href="http://research.microsoft.com/pubs/167719/WhyFromNigeria.pdf" title="Why Do Nigerian Scammaers Say They Are From Nigeria?" target="_blank"><em>Why Do Nigerian Scammers Say They Are From Nigeria?</em></a>.</em> A researcher at Microsoft, Herley’s analysis delves into the numbers that make these scams work and the gullibility of the victims. Make no mistake, these scammers are smart and they know what they’re doing.</p> <h2attacks /> <p><img style="margin-bottom: 20px; float: right; margin-left: 20px;" alt="Image of target and money" src="/data/images/NewberryBlog/07-2012_money.jpg" /></p> <h2><span style="color: #a01c33;">Attacks are seldom free.</span></h2> <p>Malicious software can accomplish many things but few programs output cash. At the interface between the digital and physical worlds, effort must be spent. Turning digital contraband into goods and cash is not always easily automated. For example, credentials may be stolen by the millions, but emptying bank accounts requires recruiting and managing mules. The end game of many attacks require per-target effort. Thus when cost is non-zero each potential target represents an investment decision to the attacker. He invests effort in the hopes of a payoff. Therefore, he must "qualify" his victims prior to expending significant amounts of resources (time and money) to attain the prize.</p> <h2><span style="color: #a01c33;">Who is a target and how are they chosen?</span></h2> <pto /> <p><img style="margin-bottom: 20px; float: right; margin-left: 20px;" alt="Image of target with holes" src="/data/images/NewberryBlog/07-2012_target.jpg" />There are several models of human behavior that illustrate the theory that when large numbers of communications are cast to random recipients, there is a direct relationship to the number of viable targets harvested. The attacker is looking for people gullible enough to respond to the communication. These people make the "short list" and the attacker continues to nurture these targets until all false positives have been eliminated and there are only true positives left. True positives represent a tiny subset of the initial list of random recipients. In addition to a high gullibility trait, true positives must also have money and an absence of any factors that would prevent them from following through all the way to sending the money. </p> <p>Since gullibility is unobservable, the best strategy is to get those who possess this quality to self-identify. These are the communication recipients who respond. An email with tales of fabulous amounts of money and West African corruption will strike all but the most gullible as bizarre. It will be recognized and ignored by anyone who has been using the Internet long enough to have seen it several times. Therefore, shrewd recipients are in a sense, helping the scammers by inadvertently classifying themselves as non-viable targets merely by the absence of their response.</p> <p>So how does this approach answer the question in <a href="http://research.microsoft.com/pubs/167719/WhyFromNigeria.pdf" title="Why Do Nigerian Scammers Say They Are From Nigeria">Herley’s title</a>? His answer: By sending an email that repels all but the most gullible, the scammer gets the most promising marks to self-select and tilt the odds in his favor.</p> <h2><span style="color: #a01c33;">So what…?</span></h2> <p>You say, "I don’t fall for these Nigerian scams so this won’t affect me." That’s great… AND keep in mind all that was discussed in this article was only one type of scam. There are millions more scams relying on the same gullibility factors of human behavior with the same end game. <strong>We are the weakest link.<br /> <br /> </strong></p> <span style="color: #000000;">Read the full whitepaper by Cormac Herley here: <br /> </span><span style="font-family: helvetica;"><a href="http://research.microsoft.com/pubs/167719/WhyFromNigeria.pdf">http://research.microsoft.com/pubs/167719/WhyFromNigeria.pdf</a><br /> </span></span> <br /><i><a href='/Blog/?id=31'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=31Diane McClainWed, 11 Jul 2012 09:49:00 GMTJune is National Internet Safety Month<p style="text-align: left;"><img style="margin-bottom: 20px;" alt="Image of padlocks" src="/data/images/NewberryBlog/06-2012_Blog_Banner.jpg" /></p> <p>Like wearing a bike helmet, staying safe on the Internet is all about taking the right precautions. In celebration of National Internet Safety month, we’re directing you to some resources from the National Cyber Security Alliance’s (NCSA) website. The National Cyber Security Alliance is a non-profit organization that collaborates with the government, corporate, non-profit and academic sectors to empower citizens to use the Internet securely and safely. Visit their site, <a href="http://www.staysafeonline.org" target="_parent">www.staysafeonline.org</a>, for more information and resources.</p> <h3>Tip Sheets from the NCSA</h3> <p>The NCSA has put together some tip sheets that are great reminders and can help facilitate Internet safety discussions with your family.  Some of the sheets include:</p> <pncsa /> <ul> <li><a href="http://www.staysafeonline.org/sites/default/files/resource_documents/Gaming%20Tips%20for%20Parents%20STC.pdf" target="_parent">Online Gaming Safety – Tips for Parents:</a><strong> </strong>Most video games are connected to the Internet whether they are played through an Internet browser or a computer or gaming console. NCSA gives steps on how you can help keep your child’s information safe and be an informed parent. </li> <li><a href="http://www.staysafeonline.org/sites/default/files/resource_documents/Mobile%20Devices%20Safety%20Tips%20STC.pdf" target="_parent">Mobile Device Safety Tip Sheet:</a><strong> </strong>With apps that access your location, public wi-fi hotspots, and text messages with suspicious links, mobile safety is just as important as on the home computer. These tips serve as a good reminder about how to safely manage your mobile devices. </li> <li><a href="http://www.staysafeonline.org/sites/default/files/resource_documents/Social%20Networking%20Safety%20Tips%20STC.pdf" target="_parent">Safe Social Networking Tip Sheet:</a><strong> </strong>Taking time to set your privacy settings and being conscious of the personal information you share is what helps keeps social media enjoyable. Go over these tips with your family so that everyone is on the same page about what information should be shared and how to keep accounts secure. </li> <li><b>For <a href="http://www.staysafeonline.org/tools-resources/tip-sheets" target="_parent">more tip sheets</a>, visit </b><a href="http://www.staysafeonline.org/tools-resources/tip-sheets" target="_parent">www.staysafeonline.org/tools-resources/tip-sheets</a> </li> </ul> <h3>Free Security Checkups</h3> <p>NCSA has provided a list of security vendors who offer <a href="http://www.staysafeonline.org/tools-resources/free-security-check-ups" target="_parent">free online security checkups</a>. Most of these will search for viruses and spyware and will help you keep a clean machine. Check out the list of vendors here: <a href="http://www.staysafeonline.org/tools-resources/free-security-check-ups" target="_parent">www.staysafeonline.org/tools-resources/free-security-check-ups</a></p> <p>Also, check out the <a href="https://survey2.securestudies.com/wix/p122560761.aspx" target="_parent">Microsoft Computer Safety Index survey</a>. The survey will ask you some questions about your online habits, then will walk you through some steps to check the settings on your computer. (For PC only)</p> <br /><i><a href='/Blog/?id=30'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=30Breanna CookeFri, 22 Jun 2012 10:38:00 GMTYour Digital Footprint: What can you control?<p><img alt="" style="margin-bottom: 10px;" src="/data/images/NewberryBlog/05-2012_Blog_Banner.jpg" /></p> <h4>Do you know how much of your private information is available to strangers?</h4> <p>We may be in a digital world but that doesn’t mean that we shouldn’t take precautions with our information.  Many of us do not realize how much of our personal information is available to outsiders and how it contributes to our digital footprint.</p> <h4>What is a Digital Footprint?</h4> <p>Your Digital Footprint is the information about you or from you (activities, comments, public records) that can be accessed via a digital environment.*</p> <h4>The 3 Main Sources of Information</h4> <p>Our personal information is available from a variety of sources and much is out of our control: we don’t have any say in who can access our information.</p> <h3><span style="color: #c00000;"><strong>1. Public Records</strong></span></h3> <p><img style="margin-bottom: 15px; float: right; margin-left: 15px;" alt="Newberry Group | Digital Footprint: Image of columns" src="/data/images/NewberryBlog/05-2012_public.jpg" />The Freedom of Information Act was first enacted in 1966 by President Lyndon B. Johnson and supplemented by President Bill Clinton with the Electronic Freedom of Information Act Amendments in 1996.** Some of the information available to anyone as a public record includes: </p> <ul> <li>Census records </li> <li>Consumer protection information </li> <li>Court dockets </li> <li>Criminal records </li> <li>Government spending reports </li> <li>Legislation minutes </li> <li>Professional and business licenses </li> <li>Real estate appraisal records </li> <li>Sex offender registration files </li> <li>Voter registration </li> </ul> <h3><span style="color: #c00000;"><strong>2. Web Searches</strong></span></h3> <p><img style="margin-bottom: 15px; float: right; margin-left: 15px;" alt="Newberry Group | Digital Footprint: Image of search bar" src="/data/images/NewberryBlog/05-2012_search.jpg" />Have you ever Googled yourself? Almost anyone can be found online. Someone can find information about you through:</p> <ul> <li><strong>Simple search</strong> by name, e-mail or phone number (it gives thousands of results!) </li> <li><strong>Companies that help you look up anyone</strong> if you can provide some basic information.  Many of the results will come back as free searches and then they offer more in-depth information for a fee. </li> <li><strong>Companies who maintain massive databases</strong> that troll public and government websites for information and sell it to anyone willing to pay. </li> </ul> <h3><span style="color: #c00000;"><strong>3. Social Websites</strong></span></h3> <p><img style="margin-bottom: 15px; float: right; margin-left: 15px;" alt="Newberry Group | Digital Footprint: Social Media" src="/data/images/NewberryBlog/05-2012_social.jpg" />Do you have a Facebook, Google+ or LinkedIn account?  Even with extensive privacy settings, there is no guarantee that the information you share won’t get into the wrong hands.  A simple status update about being away from home can be an open invitation for a thief.  Some of the information you may have shared includes:</p> <ul> <li>Home <strong>address</strong> and <strong>phone</strong> number </li> <li><strong>Dates</strong> for vacation and travel </li> <li>Photos or “check-ins” of <strong>where you are</strong> </li> <li><strong>Names</strong> of your family members </li> </ul> <h4>What do you want your Digital Footprint to be?</h4> <p>Take steps to protect yourself and the information that you can actually control.  Privacy controls are an important component when interacting with online resources.  Regularly reviewing and setting your privacy controls helps limit what is available to the general public. Not everyone will look at the pictures, posts, blogs, likes/dislikes or comments without evil intent.  Being aware of what you are putting online and who might see it is the best step in protecting yourself.</p> <p>* <a href="http://en.wikipedia.org/wiki/Digital_footprint">http://en.wikipedia.org/wiki/Digital_footprint</a><br /> ** <a href="http://en.wikipedia.org/wiki/Public_records">http://en.wikipedia.org/wiki/Public_records</a></p> <br /><i><a href='/Blog/?id=29'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=29Valerie RootWed, 09 May 2012 09:59:00 GMTIdentifying and Reporting Suspicious E-mail<p><img alt="" style="margin-bottom: 20px;" src="/data/images/NewberryBlog/04-2012_Blog_Banner_700px.png" /><br /> <span style="font-size: 13px;"><strong>If you are like me, you receive the occasional e-mail that just doesn’t look quite right.</strong></span> It may be from an anxious individual looking for your help to move their recent monetary windfall out of their impoverished country. Or it’s from someone who has a “can’t miss” investment opportunity that just needs some additional capital.  Or it’s from someone who is simply looking for a sales quote for a business that just doesn’t look right.  While I am sure that none of us have taken that bait, we shouldn’t ignore these suspicious e-mails.  We should be reporting them to the Defense Security Service (DSS) and the Federal Bureau of Investigation (FBI). </p> <h4>How do I know if it’s suspicious?</h4> <p><img alt="" style="width: 125px; margin-bottom: 15px; float: left; height: 125px; margin-right: 15px;" src="/data/images/NewberryBlog/04-2012_Blog_Virus.png" />Most of us understand that phishing is the act of someone trying to elicit personal information from you so they can exploit you or IT systems/accounts that you have access to. However, what if these e-mails do not ask for anything other than your simple response?  Many of the examples above only ask you to respond and, if you do, they will “send you further information.”  Once you respond and essentially confirm your e-mail address is active, these devious folks commonly do a number of things.  They do as they promise and send a response back that is typically malware or spyware that infects your computer or network.  They also typically sell your e-mail address to hackers or spammers who inflict their own damage to your systems.</p> <br /> <h4>What does DSS and the FBI do?</h4> <p><img alt="" style="width: 125px; margin-bottom: 15px; float: left; height: 125px; margin-right: 15px;" src="/data/images/NewberryBlog/04-2012_Blog_DSS.png" />The DSS and FBI depend heavily on leads and information from the general public. It is rare for Federal investigation cases to be initiated by the DSS or the FBI. The sources of many of their investigations stem from reports from the general public. To aid in their data collections, we can forward suspected e-mails to them. DSS and the FBI then track these to the source, compile it with other data on file, and determine if an investigation is required.</p> <br /> <h4>Should I report everything?</h4> <p><img alt="" style="width: 125px; margin-bottom: 15px; float: left; height: 125px; margin-right: 15px;" src="/data/images/NewberryBlog/04-2012_Blog_Reporting.png" />It is important to keep in mind that not all unsolicited e-mail is malicious. Legitimate companies often send mass e-mails hoping to gather customers. And those lengthy “Terms and Conditions” that we all ignore when signing up for an online service or purchasing software often gives the recipient authority to use your e-mail address as they see fit.  Always remember that you should never open any attachments that come from unknown or unexpected recipients.</p> <br /> <h4>How do I report suspicious e-mails?</h4> <ol> <li>Seek the advice of your company’s <strong>Security Officer or IT Department</strong> on how to handle and report malicious e-mails. <br /> <strong><span style="color: #c00000;">OR</span></strong> </li> <li>Visit the <strong>FBI</strong> website for instructions: <a href="http://www.fbi.gov/scams-safety/e-scams">http://www.fbi.gov/scams-safety/e-scams</a> </li> </ol> <br /><i><a href='/Blog/?id=28'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=28Jerry KennedyWed, 18 Apr 2012 15:45:00 GMTDeeply Embedded Metadata <br/><i><a href='/Blog/?id=27'>Click here</a> for more information.</i><br/><hr />Archivedhttp://www.newberrygroup.com/Blog/?id=27Mon, 01 Jan 0001 00:00:00 GMT