The Newberry Group Blog RSS Feed
http://www.newberrygroup.com/feedGen.aspxThe latest Blog Entries from The Newberry Group.(c) 2016The Newberry Group.5Technical Considerations When Working With Lawyers - Part 5 in a 6 Part Blog Series<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">As a forensic consultant, the phone is constantly ringing. Calls come from law firms and from corporations; you never know who you will be talking to when you pick up the phone. <span style="mso-spacerun: yes;"> </span>More importantly, the other unknown when you pick up the phone is the level of technical knowledge the person you are talking with has. <span style="mso-spacerun: yes;"> </span>Over the years, we have worked with people that we have had to educate on technology and in other instances we have dealt with technologically savvy individuals. I am not saying that your legal team needs to understand technology at the same level as your forensic consultant, but it is critically important to your case that whoever is involved, knows how to properly work a theft of IP case.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">One of the first cases that I ever worked on for a theft of IP was with a senior partner of a mid-sized law firm.<span style="mso-spacerun: yes;"> </span>While talking with him, it was readily apparent that his understanding of technology was fairly low. He would never ask questions and wanted me to believe that he completely understood technology he was dealing with.<span style="mso-spacerun: yes;"> </span>As we worked together, I realized that I would have to mix case details with technology education, without making him realize I was teaching him.<span style="mso-spacerun: yes;"> </span>Lucky for us, the lawyer on the other side knew even less about technology than the lawyer I was working with. My client won their case and everyone was happy, but I have to share one last question that I was asked by the lawyer I had been working with after the case was completed.<span style="mso-spacerun: yes;"> </span>He asked - “What is a hard drive?”<span style="mso-spacerun: yes;"> </span>I was shocked.<span style="mso-spacerun: yes;"> </span>I didn’t know if I should laugh or cry, as we had been talking about data being stolen from hard drives throughout the entire case.<span style="mso-spacerun: yes;"> </span>From that moment on, I paid very close attention to the technical knowledge level of everyone that I worked with.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">Before I continue, a disclaimer. I’m not here to tell you which law firm or specific lawyer you should work with.<span style="mso-spacerun: yes;"> </span>I’m not talking negatively about any specific firm or specific lawyer. <span style="mso-spacerun: yes;"> </span>But as my years of experience have shown me, I have found it very important that when you are selecting counsel for a case; make sure to retain lawyers that truly understand technology and that your case is not the first time that they have been involved with theft of IP.<span style="mso-spacerun: yes;"> </span>I would encourage asking for a list of theft of IP cases that they have taken to trial and ask for references.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">And here is why.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><b style="mso-bidi-font-weight: normal;"><span style="font-size: 13px;">Home Based Employee Case Study Continued:<o:p></o:p></span></b></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">I’m going to jump back in to our home based employee case study that we have been discussing in previous blog posts.<span style="mso-spacerun: yes;"> </span>Again, I am not here to say this is a bad firm, nor am I hear to say that the lawyers at the firm that I worked with should not be used again for cases like this.<span style="mso-spacerun: yes;"> </span>I want to point out opportunities to work the case differently, allowing the case to move along faster.<span style="mso-spacerun: yes;"> </span>Perhaps more importantly, potentially reduce and maybe even eliminate legal fees for our client.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">Let’s recap a few of the key things that happened after we gave our initial findings report to the original law firm:<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1;" class="MsoListParagraphCxSpFirst"><span style="font-size: 13px;"><span style="mso-fareast-font-family: symbol; mso-bidi-font-family: symbol; mso-list: ignore;">·<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>Our client thought they would be better represented by having a law firm that was based in the location of the two employees that left.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-fareast-font-family: symbol; mso-bidi-font-family: symbol; mso-list: ignore;">·<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>The firm that they chose was a very large international firm.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-fareast-font-family: symbol; mso-bidi-font-family: symbol; mso-list: ignore;">·<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>The transition to the new law firm for our part of the case was not smooth. Weeks passed and no contact was made even though we were the only ones with “smoking gun” evidence in this case.<span style="mso-spacerun: yes;"> </span><o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-fareast-font-family: symbol; mso-bidi-font-family: symbol; mso-list: ignore;">·<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>Knowing that time was of the essence in order to get a TRO; concern was growing that I had not heard from the new law firm for weeks after I was told about the change.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-fareast-font-family: symbol; mso-bidi-font-family: symbol; mso-list: ignore;">·<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>When the new law firm called us, it as an associate of the senior partner that the corporation had hired, and we were told that they had received the report and that someone would get back to me.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-fareast-font-family: symbol; mso-bidi-font-family: symbol; mso-list: ignore;">·<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>Weeks went by and I received another call to “understand” the findings of the report.<span style="mso-spacerun: yes;"> </span>To the law firm’s defense, because of the home based network that one of the employees had, it was not your typical report and the complexity of the report would have been difficult for all but the most technical lawyers to understand.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-fareast-font-family: symbol; mso-bidi-font-family: symbol; mso-list: ignore;">·<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>In the end, the new law firm opted not to pursue a TRO against the two departed employees.<span style="mso-spacerun: yes;"> </span>They wanted to “play nice” assuming that the employees would just turn over their personal devices when requested to do so.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-fareast-font-family: symbol; mso-bidi-font-family: symbol; mso-list: ignore;">·<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>The employees each retained their own lawyers to fight turning over their personal devices and instead of heading to court to fight this battle of stolen IP, it was decided to opt for arbitration instead.<span style="mso-spacerun: yes;"> </span><o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-list: l2 level1 lfo1;" class="MsoListParagraphCxSpLast"><span style="font-size: 13px;"><span style="mso-fareast-font-family: symbol; mso-bidi-font-family: symbol; mso-list: ignore;">·<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>Upon the decision to go through arbitration, we did not hear from the new law firm for the next 8 months.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">So we pick up the story 8 months later. To be honest, we thought the case had settled and we were not notified, as our emails and phone calls were going unanswered.<span style="mso-spacerun: yes;"> </span>Then out of the blue, I got a phone call from the associate at the firm.<span style="mso-spacerun: yes;"> </span>We were told that they were in settlement discussions with both of the former employees and they needed our help finishing up writing a settlement agreement. I asked them to send what they had up to this point and I would make changes and recommendations to it. <span style="mso-spacerun: yes;"> </span>What she told us next was very alarming.<span style="mso-spacerun: yes;"> </span>We were told that the agreement was actually in final stages of development and both the arbitrator and the lawyers for the other sides had already seen it.<span style="mso-spacerun: yes;"> </span>At this point, we knew we had a potential problem.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">From the discussions 8 months prior, I had already figured out that both the associate and the senior partner at this firm had limited knowledge about technology.<span style="mso-spacerun: yes;"> </span>Because of the very technical details of this case with this large home network, concern was growing over what we might see in a settlement agreement that had been drafted without our help.<span style="mso-spacerun: yes;"> </span>When the document arrived, my suspicions were correct.<span style="mso-spacerun: yes;"> </span>It was one of, if not the worst settlement agreement that I had seen in 20 years being a forensics examiner.<span style="mso-spacerun: yes;"> </span>Here are some of the highlights:<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;" class="MsoListParagraphCxSpFirst"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">1.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>One employee admitted that he still had the virtual machine (VM) that contained corporate email but yet the settlement agreement stated that they agreed to take at face value the word of the former employees that they had no data in their possession. <o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">2.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>The employees agreed to send the computers to check for IP, but there was no timeline for when the machines needed to arrive at our facility for forensics investigation.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">3.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>In the initial reports, we listed countless devices that were used and might contain stolen IP, and they didn’t ask for most of those devices to be sent to be investigated.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">4.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>We were prohibited from telling our lawyers and our corporate client what devices were actually coming in.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">5.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>We were prohibited from telling our lawyers and our corporate client how much data we were searching on the devices that came in.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">6.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>We were prohibited from telling our lawyers and our corporate client if we were finding any stolen IP.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">7.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>We were prohibited from telling our lawyers and our corporate client how much stolen IP we had found.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">8.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>We had to redact our invoice to remove any identifiable information that would inform the lawyers or our corporate client anything relating to points 4-7.<span style="mso-spacerun: yes;"> </span>Basically we were only able to hand them an invoice with a dollar amount and no supporting documentation.<span style="mso-spacerun: yes;"> </span>Not the way we usually do business.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-list: l1 level1 lfo3;" class="MsoListParagraphCxSpLast"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">9.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>Most importantly, the company that had their IP stolen had to pay.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">Horrified does not even begin to describe how we felt about this agreement. <span style="mso-spacerun: yes;"> </span>This agreement failed to take in to consideration the type of technology in question and how that technology can not only be used to store IP but how we as a digital forensics company can identify our corporate client’s data contained on the machines and drives.<span style="mso-spacerun: yes;"> </span>We feared this agreement would end up being a very large and costly mistake. We raised our concerns with our client but they said they trusted the new law firm. <o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">We suggested corrections/changes to technical aspects of the settlement agreement and at the same time, we created an internal protocol for how we were going to be handling the data that arrived from these two former employees.<span style="mso-spacerun: yes;"> </span>We were able to change the settlement so that the individuals would have to turn over anything that they had in their possession or household that could store electronic information.<span style="mso-spacerun: yes;"> </span>Items that this included were:<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2;" class="MsoListParagraphCxSpFirst"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">1.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>All laptops/desktop computer (including ones belonging to kids/spouse)<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">2.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>All USB devices that were used at the former employer, their new employer and at home (including kids/spouse).<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">3.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>Cell/Smart phones that could store email or documents (including kids/spouse)<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">4.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>Cloud based storage accounts<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">5.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>Online email (ie, gmail, yahoo, etc)<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">6.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>All NAS and DAS devices<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">7.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>Their new work computer<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo2;" class="MsoListParagraphCxSpLast"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">8.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>Their new work email and network shares<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">The reason we created that list is that we had evidence that the stolen IP had been moved and stored on some of the first 6 types of devices listed.<span style="mso-spacerun: yes;"> </span>Based on our experience, we assumed that the data also made its way to the new work computer and network. It took a few more months, but the technical changes we suggested finally made their way into the settlement agreement.<span style="mso-spacerun: yes;"> </span><span style="mso-spacerun: yes;"> </span>Our requests to remove the language which did not allow us to effectively communicate was not granted so points 4-7 remained in the settlement agreement. I knew this was a disaster waiting to happen as we had never not been allowed to talk to our client about what was happening – especially when they were paying for the work.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">Jumping ahead, some of the devices from the large home network started to show up.<span style="mso-spacerun: yes;"> </span>Surprise! The devices we received had large amounts of storage space and they were all pretty full. We quickly realized that we would not be searching a few GB’s of data; we were going to be searching terabytes and terabytes of data (one device alone had 8 terabytes on it) blowing our price estimates out of the water.<span style="mso-spacerun: yes;"> </span>But now we have a problem – we can’t tell our client any of this, but they are asking for an estimate of what the cost would be.<span style="mso-spacerun: yes;"> </span>When we told them a dollar number, there was dead silence on the phone. Then there was anger.<span style="mso-spacerun: yes;"> </span>Then there was a demand to tell us how we got that number and all we could say was there is a lot of data but I can’t tell you anything else because of the settlement agreement. <span style="mso-spacerun: yes;"> </span>They had no idea the amount of data that we were being sent, and we had not even received 50% of the data yet.<span style="mso-spacerun: yes;"> </span>It was finally beginning to sink in to them that this might not have been a very good settlement agreement. The project was immediately put on hold due to cost considerations.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">We told them that there was not much we could do unless some part of our hands were untied.<span style="mso-spacerun: yes;"> </span>The attorneys went back and got part of the settlement agreement removed so I could now tell them how many devices had come in and how much data was on each device. When we told them – their jaws dropped. But yet, I still could not tell them how much IP I was finding.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">The law firm decided to have us search for very specific extensions to reduce costs.<span style="mso-spacerun: yes;"> </span>While this might sound like a reasonable idea to reduce cost, we had already found IP in file formats that were images, audio and video.<span style="mso-spacerun: yes;"> </span>The only way to search these types of documents is to actually put “eyes on the file”, meaning someone would have to take the time to review each one.<span style="mso-spacerun: yes;"> </span><span style="mso-spacerun: yes;"> </span>The law firm and the client decided in a cost benefit analysis it was not worth having someone review those non searchable files. <o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">The law firm also decided to reduce the number of devices that were going to be delivered to us.<span style="mso-spacerun: yes;"> </span>They had already agreed on doing the search and delete on a rolling production, meaning we would get a few machines to run the protocol on them and then send them back. Here is the problem with this scenario. If there were other machines still at their homes that were not sent to us, yet contained IP, they could very easily go ahead and move the files between machines.<span style="mso-spacerun: yes;"> </span>In our initial protocol, we would have looked for this type of file movement, but our original protocol was scrapped. The law firm had limited understanding of what technology could do and at what cost.<span style="mso-spacerun: yes;"> </span>They also decided not to take a look at all machines and devices in their household.<span style="mso-spacerun: yes;"> </span>This meant all the former employees had to do was say a computer belonged to their spouse, and they wouldn’t have to send it in for inspection, even if it contained IP.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">All along we were ringing alarms bells to our client as much as possible.<span style="mso-spacerun: yes;"> </span>I even asked our corporate client, if you are not going to do it right, why even do it at all.<span style="mso-spacerun: yes;"> </span>They went silent and couldn’t answer the question.<span style="mso-spacerun: yes;"> </span>They finally came back to us confirming their trust in their law firm. Here is the sad reality.<span style="mso-spacerun: yes;"> </span>We finished the project with the new protocol developed by the law firm, objected to by us. The law firm wasted their clients’ money and after all was said and done; we know that the two employees still have copies of IP that they took. <o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">The mistakes that were made by the new law firm because of their lack of understanding in both technology and IP theft cases were some of the worst we have ever seen. <span style="mso-spacerun: yes;"> </span>If you remember in my last blog post, the other case that I outlined had roughly 2000 documents stolen and they were awarded $14 million in damaged.<span style="mso-spacerun: yes;"> </span>In this particular case, there were millions of documents stolen (we assume well over 8 million files were stolen) and we believe that some of them are probably still in the employee’s possession. In the end, our client was awarded nothing due to the settlement agreement, yet they had more than $1 million in legal and third party fees that they had to pay for out of pocket.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">The choice not to listen to our expert advice and the decision to “play nice” backfired costing the corporation millions in legal and other associated fees and their competition is probably using their IP as we speak.<span style="mso-spacerun: yes;"> </span>Had the law firm worked the case differently, understood the forensics process, and understood the capabilities of the technology, the company would have been able to have all the IP identified and removed and have the other side pay for it.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">Moral of these stories - when you have a theft of IP case, do your due diligence. Do not assume that the law firm you currently utilize can handle a theft of IP case. Theft of IP is very serious and very costly. Make sure law firm treats it that way also.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><o:p><span style="font-size: 13px;"> </span></o:p></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><o:p><span style="font-size: 13px;"> </span></o:p></p> <br /><i><a href='/Blog/?id=61'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=61Jeremy WunschThu, 28 Jul 2016 16:32:00 GMTReverse IP Theft - Know What's Coming In To Your Organization. Part 4 in a 6 Part Blog Series<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">As you have been reading my blog series about theft of IP when an employee departs, I have mentioned that reports have said that about 50% of all departing employees take intellectual property with them to their new employer. After all, chances are great that they got their new job because of the work that they did at their previous employer. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">We have been talking a lot about that departed employee and how to detect if and what data they may have taken. But now let’s turn things around. Your company is the one that has hired an employee that stole Intellectual Property (IP) and they bring it inside your company. How do you know they brought stolen IP in? Do you have some type of legal exposure? When they end up leaving your company, will they also steal IP from you? The list of concerns with employees bringing stolen IP inside can go on and on.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Reverse Intellectual Property Theft is when a new hire brings stolen IP into your company. Chances are that in your hiring process, asking questions about stolen IP is not something that people think to ask about. Most companies that I have worked with rarely do much to discourage or stop IP from coming in until it is too late and they get caught. One simple measure to help discourage new employees bringing in stolen IP is to incorporate some documentation regarding n<span style="line-height: 115%;">o disclosure or use of Confidential Information of Others. The intent of this language is to make sure that the new employee is aware they are not to bring into your organization IP from another company. It should also address that they not use in the performance of their responsibilities at the Company any confidential or proprietary information, materials, trade secrets, intellectual property, or documents of a former employer or other third party that are not generally available to the public, unless the employee or the company has obtained written authorization from the former employer or third party for their possession and use</span><span style="line-height: 115%;">. </span> In addition, you might consider making random checks of new hires machines to make sure that other companies IP has not been brought in and outlining consequences if they do bring it in. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">While this won’t stop you from getting sued if data makes its way onto your network, it should make an employee think twice before doing it.</span></p>
<p style="margin: 0in 0in 10pt;"><b><span style="font-size: 13px;">Internal Employee Case Study Continued:</span></b></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Now, let’s get back to our case studies. We are going to go back to the case study of that internal employee that left and went to work for the competition. As you may remember we were able to prove multiple things up to this point. The departed employee:</span></p>
<ul>
<li><span style="font-size: 13px;">Used a sync function on some of the last days of employment. </span></li>
</ul>
<ul>
<li><span style="font-size: 13px;">The sync function appeared to sync IP to one or two USB devices. </span></li>
</ul>
<ul>
<li><span style="font-size: 13px;">Multiple USB devices (over 20) were used on the computer, and some were only used during his final days of employment. </span></li>
</ul>
<ul>
<li><span style="font-size: 13px;">We put in a request through the lawyers to get our hands on the 20+ USB devices, but only 4 arrived. </span></li>
</ul>
<ul>
<li><span style="font-size: 13px;">One of the USB devices that arrived was never used at his old work. </span></li>
</ul>
<ul>
<li><span style="font-size: 13px;">We asked for and received access to his home computer. </span></li>
</ul>
<ul>
<li><span style="font-size: 13px;">We identified that most of the USB devices had been used on both his home and old work computer. </span></li>
</ul>
<ul>
<li><span style="font-size: 13px;">The home computer showed us that the two USB devices that we were looking for where both used on the home computer after his last day of employment. </span></li>
</ul>
<ul>
<li><span style="font-size: 13px;">Data from his former company had been opened on his home computer after he started his new job. </span></li>
</ul>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">It was at this point that the judge gave us access to his new work computer. As I mentioned in the previous post, we performed the “New Hire Program” package on his new work computer. This type of analysis is virtually the same as we perform when an employee departs but there is a key difference. We are now looking for data artifacts that show that data is moving onto, and not off of, the device that we are investigating. We also continue to look for USB devices; we are still searching for IP. However this time we are trying to match things up between the old employer’s computer, his home computer and his new employer’s computer. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">To correctly match everything up, we created a timeline for the three machines. It is important to note that to do this correctly, you need to make sure that you take into account the time zone of the computer you are analyzing, as some data movement is not far apart.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">When we started to look at his new work computer, we quickly identified that the key USB device had been used on the new work computer. Knowing the date and the time that the key USB device was plugged in, we started searching the work computer for data that was created after that date. Looking for files created within an hour of the time the device was plugged in; we found copies of files that appeared to be the stolen IP had been copied down to his new work computer. While this was a nice nail in the coffin, we finish our investigation process and what we found shocked even the new company.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">In-between his start date at the new company and the date we received his new work computer, he had already changed the IP taken from our client, his former employer, and updated it with his new employers company information and logos. For example: he took his former employers’ divisions business plan and executed a “find and replace” of the old company name to the new company name. He opened presentations and changed all the footers and logos to the new company. It was determined that he had repurposed roughly 100 of the 2000 files that he had taken by just removing the old companies name and logo.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">We reported our finding to our client’s legal team and they reported what we had found to the new company. In turn the new company immediately fired the employee. You might think the story ends there, but it does not. We continued our investigation, as we needed to be able to confirm that the repurposed IP had not made its way to the corporate network or to anyone else inside this company. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Unfortunately, we were able to confirm that data that he had brought with him had already been copied up to the corporate servers and more importantly we found that the data had been emailed out to the team he worked with, his boss and to his peers. It was beginning to look like this data was spreading within the new company.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">All of this information was provided to the court. The judge in the case ruled that we needed to go into the new company and search their network shares, the computers of his boss, and all his peers to track down and delete all the IP that was stolen. Due to the volume and the extent of what was found, this deletion of IP took much longer than expected as we found that the people he had sent the data to had forward the data to others in addition to saving it to their network shares. Over time, the trail just kept growing and we kept on following it and deleting the data wherever it was found.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">As the search for stolen IP continues, we start the analysis on his boss’s computer and boy, were we surprised at what we found. An examination of the boss’s computer found that he had stolen IP from our client years prior to him starting at the company. We began to wonder if there was an insider that was sending the boss this information. Through deeper analysis of this newly found “old” IP, and from conversations with our client, we discovered that the boss had been an employee of our client. When he left, he also stole IP, brought it into and disseminated throughout the new company. Once this information was given to the new company, he too was fired.</span></p>
<p style="margin: 0in 0in 10pt;"><b><span style="font-size: 13px;">The Final Word of the Court:</span></b></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Let’s jump forward in time. This case was not just about making sure that the data was removed from the new company servers and laptops and those two employees getting fired. Our client wanted the other company to reimburse them for all that they had spent on legal fees and all third party fees, including for the forensic work that had been done over the entire time period of this case. They were also asking for damages in addition to expenses. After a long trial, the judge ruled in favor of our client and awarded them over $14 million in damages and fees. As you can imagine, our client was very happy with the outcome.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">The company that hired these two employees on the other hand was not happy at all. At no time did anyone in the organization think that hiring one individual would cost them over $14 million. So to answer one of my original questions, yes, you do have legal exposure if you hire someone that brings in stolen IP to your company.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Both companies involved in this matter have now taken additional steps during the hiring process to let all new hires know that bringing in outside data from previous employers is not allowed and it is cause for immediate termination. They have instituted simple forensic checks that give visibility to newly used USB devices and data that gets copied off of them. This data is randomly checked to make sure it is not from any of their previous employers. Utilizing the </span><a href="http://www.newberrygroup.com/Digital-Forensics/New-Hire-Program.aspx"><span style="color: #0000ff; font-size: 13px;">New Hire Program</span></a><span style="font-size: 13px;"> is how they are hoping to never have to experience a situation like this again.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">While you might think that awards like the court handed down are rare, they are not. In most cases that I have been a part of, if we prove that data was stolen, it is very common for legal fees and other third party expenses to be awarded back to the company that had their data stolen. We all know that legal fees are going up and cases like the ones I am presenting here are no longer considered anomalies. As I mentioned, employees will continue to take IP out of and bring it into organizations. And, with the increased legal action that is occurring as a result of the ease of identifying those malicious actions through expert forensic analysis, organizations are paying closer attention to the data flowing in and out of employees hands.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">The moral of this cautionary tale: Take precautions and make sure stolen IP isn’t being brought into your company. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Coming up – I will finish the story of the second case study. Stay tuned!<br />
<br />
<span style="widows: 1; text-transform: none; text-indent: 0px; letter-spacing: normal; font: 13px/21px arial, helvetica, sans-serif; white-space: normal; color: rgb(0,0,0); word-spacing: 0px; -webkit-text-stroke-width: 0px;">For more information on these services as well as other Forensic-related services we offer, please visit our website at</span><a href="http://www.newberrygroup.com/" style="widows: 1; text-transform: none; text-indent: 0px; letter-spacing: normal; font: bold 14px/21px arial, helvetica, sans-serif; white-space: normal; color: rgb(153,0,0); word-spacing: 0px; text-decoration: none; -webkit-text-stroke-width: 0px;border: medium none;"><b><span style="padding-bottom: 0in; padding-left: 0in; padding-right: 0in; color: rgb(5,99,193); font-size: 13px; padding-top: 0in;border-width: 1pt;border-color: windowtext;">www.newberrygroup.com</span></b></a><span style="widows: 1; text-transform: none; text-indent: 0px; letter-spacing: normal; font: 13px/21px arial, helvetica, sans-serif; white-space: normal; color: rgb(0,0,0); word-spacing: 0px; -webkit-text-stroke-width: 0px;"><span class="apple-converted-space"> </span>or email us at<span class="apple-converted-space"> </span></span><a href="mailto:[email protected]" style="widows: 1; text-transform: none; text-indent: 0px; letter-spacing: normal; font: bold 14px/21px arial, helvetica, sans-serif; white-space: normal; color: rgb(153,0,0); word-spacing: 0px; text-decoration: none; -webkit-text-stroke-width: 0px;border: medium none;"><b><span style="padding-bottom: 0in; padding-left: 0in; padding-right: 0in; color: rgb(5,99,193); font-size: 13px; padding-top: 0in;border-width: 1pt;border-color: windowtext;">[email protected]</span></b></a></span></p> <br /><i><a href='/Blog/?id=60'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=60Jeremy WunschMon, 27 Jun 2016 13:00:00 GMTTemporary Restraining Orders. Part 3 in a 6 Part Blog Series<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">In my last blog post, I began two case studies. In both instances, we found that intellectual property had been taken when the employees left the company. Following our process, we created the Departing Employee Report that outlined all of our findings. We gave the report(s) to our clients and their external counsel. It is at this point in the story that these two very similar cases went in completely different directions.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">In most cases, after our client and their law firm have a chance to review our findings and determine a course of action we are typically asked to write either an affidavit or a declaration. We take the information in our report(s) and put it into an accepted legal format (the affidavit or declaration) that can be presented in court. Which document we create depends on the law firm we are working with. Typically one of these documents is presented with a TRO (temporary restraining order). </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">When you hear TRO, many of you might immediate think of some type of harassment or abuse case. However a TRO has other purposes as well. One such instance that I have seen used over and over again in theft of Intellectual Property (IP) cases is requesting a TRO where the employee that left and took IP with them, not be allowed to go to work for the new company until the theft of IP case has been resolved in some manner. Typically in these cases where this type of TRO is requested, the law firm and the forensic company must move quickly so that the legal team has the information that they need to file for a TRO. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">I cannot stress enough how important speed is when working a case like this. Because if the new employee has already been working at the new company for a few months, there is a high likelihood that the information that was taken has already been disseminated around the new company and a TRO is less likely to be effective. While I am not saying that you can’t get a TRO after a few months, you can, but you will just have more hoops to jump through. This scenario alone is a great reason to have a relationship established with a forensic company that excels at investigating IP theft cases.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Let’s get back to those two case studies. While these two case studies are of two companies in completely different industries, they are very much alike from a forensic standpoint. Data was taken upon employee departure, the departing employees went to work for the competitor and the companies hired external law firm to help. In both of these cases we were initially hired by the same law firm, a law firm that we had worked with for years and had a well-established process with. </span></p>
<p style="margin: 0in 0in 10pt;"><b><span style="font-size: 13px;">Internal Employee Case Study Continued:</span></b></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">For this case, we wrote an affidavit to go with the TRO and the documentation went to both the departed employee and the departed employees “new” company. The “new” company was a Fortune 100 company, they were large enough that their first response back to the TRO was “if we wanted that companies IP, we would have just bought them”. At this point, the fun really started.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Along with the TRO, it was requested that the employee send all USB drives that they had used at our client’s company so that we could forensically examine them to find and remove our client’s IP. If our client’s IP was found on any of the devices, the court would uphold the TRO and the employee would not be able to work until the case was resolved.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Based on the request, the former employee sent four USB drives. As you may remember from the previous blog post, we were expecting over 20 to show up. So the fact that we only got four devices surprised us and angered the legal team. However, we still analyzed the 4 drives that we were given. Once the serial numbers were identified, we realized that only 3 of the devices that were sent to us had been used at the former company. The one extra USB drive was completely new to us. In addition, the key USB device that we were looking for was not one of the four that was sent to us.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">All of this information was sent to the court, along with a request to get access to the former employee’s home computer. When the court learned that only 4 USB devices had been turned over, the court ordered that the home computer had to be sent to us for analysis.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">A few days later, the home computer arrived and performed the full departing employee analysis on the home computer. Undertaking a USB analysis on the computer, we were able to identify that most of the 20+ USB devices that we were looking for were also used on his home computer, along with several other USB devices that were used at home but not on his old work computer. During this investigation, it was discovered that the one USB device that we didn’t have information on, showed up as being used on his home computer. What was the most shocking/concerning to our client, was that the key USB device had been used on his home computer just after he had resigned.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Since we had a lot of information about this key USB device, we performed some special searches for files that we knew had, at one time, resided on that device which belonged to his former employer, our client. We were able to determine that these files had been accessed and opened on his home computer, from that USB device after he had already started at the new company. These facts were presented to the court. The court did two things, first they granted the TRO and the employee couldn’t work anymore until the case was settled and secondly, the court gave us access to his work laptop. This upset his new company as they didn’t want to give up his work laptop. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">A few days after the court order, his new work laptop arrived in our forensic lab. Once the device was in our lab, we performed the New Hire Program package on his machine. Stay tuned to future blog posts to see what this uncovered and how both companies responded.</span></p>
<p style="margin: 0in 0in 10pt;"><b><span style="font-size: 13px;">Home Based Employee Case Study Continued:</span></b></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">In the case of the home based employee for this case study, things took a completely different spin once we delivered to outside counsel the report and they showed our client that had the employees leave. This company decided it would be in their best interest to change law firms and retain a firm in the state which the two former employees resided. I have worked many cases where our clients have changed law firms mid investigation, but this change did surprise me because the original law firm had a well know reputation for successfully litigating IP theft matters and I knew nothing about the new firm besides the fact that they were a very large international firm.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Our client and the now former law firm had told me that our report had been sent to the new firm and that I would be hearing from them shortly. Weeks passed and I had heard nothing. Knowing that we were initially going down the path of a TRO for both these employees I was getting concerned that I had not heard from the new law firm. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">I contacted our client and let them know that I had not been contacted by the new law firm. They were surprised and said someone would reach out to me within 24 hours. Not one hour later, my phone rang. It was an associate at the new law firm. She said the partner asked her to touch base with me just to let me know that they got the initial report and they were working their way through it.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">The clock was ticking for a TRO and it still took them two more weeks before they called again. This time they actually asked me to step them through the report so that they could better understand what IP had been stolen. This call ended up being the first of many phone calls to discuss the report and help better understand it.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">In the end, the new law firm opted not to pursue a TRO against the two departed employees. They decided to “play nice”, reasoning that the employees would willing turn over their personal devices for us to search and remove all IP associated with their former employer. As you can imagine, that was not what happened. The employees each retained their own counsel, which vigorously fought any request to turn over their personal devices. In the end, instead of utilizing the courts to litigate the stolen IP, the decision was made to continue the “play nice”. It was decided they would pursue arbitration instead. It would be 8 months before I would hear from the new law firm again.</span></p>
<p style="margin: 0in 0in 10pt;"><b><span style="font-size: 13px;">Where to Go From Here:</span></b></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">As you can see, two cases that were nearly identical at the start, have taken off in different directions. Is there are right or wrong way to take these cases? I would say yes… Over the next few blog posts, I will explain why as we continue with these two case studies. In addition, I will take a look at some things you can do to both prevent IP from being taken from your company and from new hires bringing stolen IP into your company.</span></p>
<p style="line-height: 15.75pt; margin-bottom: 10pt;"><span style="font-size: 13px;"><span style="color: #231f20; font-size: 11pt;">Newberry Group has services that can support all of your needs in these areas. Our experienced team can conduct investigations that cover both the departing employee as well as the new hire for a fraction of the cost that you could incur should the examples above play out. Our <a href="http://www.newberrygroup.com/Digital-Forensics/Departing-Employee-Program.aspx" target="_blank"><span style="text-decoration: underline;">Departing Employee Program </span></a>and <a href="http://www.newberrygroup.com/Digital-Forensics/New-Hire-Program.aspx" target="_blank"><span style="text-decoration: underline;">New Hire Program</span></a> are</span> <span style="color: #231f20; font-size: 11pt;">fixed fee programs that consists of defined computer investigation service packages that identify and report on employee data activity. The packages vary as to scope and cost in order to provide you with a level of assurance proportionate to the value of the employee and the access that the employee had to your IP.</span> </span></p>
<p style="line-height: 15.75pt; margin-bottom: 10pt;"><span style="color: #000000; font-size: 11pt;"><span style="font-size: 13px;">For more information on these services as well as other Forensic-related services we offer, please visit our website at </span><a href="http://www.newberrygroup.com/"><b><span style="padding-bottom: 0in; padding-left: 0in; padding-right: 0in; color: #0563c1; font-size: 13px; padding-top: 0in;border-width: 1pt;border-color: windowtext;">www.newberrygroup.com</span></b></a><span style="font-size: 13px;"><span class="apple-converted-space"> </span>or email us at<span class="apple-converted-space"> </span></span><a href="mailto:[email protected]"><b><span style="padding-bottom: 0in; padding-left: 0in; padding-right: 0in; color: #0563c1; font-size: 13px; padding-top: 0in;border-width: 1pt;border-color: windowtext;">[email protected]</span></b></a></span></p>
<p style="line-height: 15.75pt; margin: 0in 0in 10pt;"><span style="color: #000000; font-size: 11pt;"> Next Blog: Reverse IP Theft</span></p> <br /><i><a href='/Blog/?id=59'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=59Jerermy WunschWed, 08 Jun 2016 12:06:00 GMTWhen The Threat Strikes. Part 2 of a 6 Part Blog Series<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">As I mentioned in my first blog post, the internal threat is very real and it strikes ALL companies. (Yes, even forensic companies that investigate internal threats.) The smallest company that I have identified theft of IP during employee departure had 5 employees. The largest client was a Fortune 100 company whose name all you would instantly recognize. Even forensics companies are not immune. When I was the CEO at LuciData, I had a former forensic investigator leave and “take” IP with him to start a competing company. It happens all the time. Numerous articles quote statistics that over 50% of departing employees take IP when they leave.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">50% is a pretty large percentage of people. Think of how many employees have left your company. Think about what information they had access to. Now assume that 50% did actually take information and brought it to a competitor. What would a competitor be able to do once they got their hands on that data? What would the impact be to your company should that happen? Loss of revenue, loss of competitive advantage?</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Theft of your IP has happened to you with or without your knowledge. It might be happening right now and you don’t know it. In this blog and other blogs to follow; I am going to step through two examples of internal theft: an internal employee working at the office and a home based employee that was granted remote access to the network. The blogs will address what was done right and what could have been done better. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">There are always lessons to learn with departing employees, and most of those lessons deal with controlling your data better.</span></p>
<p style="margin: 0in 0in 10pt;"><b><span style="font-size: 13px;">Internal Employee Case Study:</span></b></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">This was not the first time that our client had called us to investigate a potential theft of IP from a departing employee. We had put in place a protocol to cover the first initial steps to investigate any departing employee that they suspected of taking IP.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">As with all the other cases with this company, a “key employee” had departed, moved across the country to work for a competitor. What caused our clients suspicion was that the competitor did not have a marketable “product” like the employee had been working on for our client, but the competitor was trying to get a foothold into that space. The data that this employee had access to was incredibly valuable to the competitor.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">As we were completing the initial first steps of the protocol and started digging into the data, there were red flags that we discovered that started to raise questions for us. The first red flag we found was the sheer number of USB devices that had been used on the computer; including a few devices that were used during the last few days of his employment with our client. While devices used on the last few days of employment don’t always point to a problem, for some of these devices, it was determined that it was the first time that they had ever been used. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">The next red flag we saw was that a special folder sync function had been run. This function was setup to sync multiple folders from the employee’s computer to what was labeled as “other device”. This meant that it could sync to something like a network share or to a USB device, basically anything that wasn’t internal to the computer.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">What was helpful to us was that this sync function left a log of the folders that it was syncing with, along with the last time that the sync took place. Unfortunately, the folders that were synced were deleted by the former employee. Not to be deterred, using our forensics capabilities, we were able to recover the deleted folders and found just over 2,500 files in those folders that had been synced to other devices. A copy of the recovered files list was given to the client to review and determine the “value” of the data. We determined that most of the files contained documents that had “confidential” or “internal use only” written on the documents, leading us to believe these indeed would be very valuable documents to a competitor – a fact that was quickly confirmed by the client.. Our client asked us to immediately start working on determining if we could tell them where these documents went to (other devices, network share etc.)</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Using time information from both the USB and the sync function logs we were able to determine that the data went to one or two USB devices on the same day the employee turned in his resignation notice. We were able to determine the common name of the USB devices (like one gigabyte SanDisk) and we also had the serial number of the devices we could now start searching for. This information was given to our client so their Information Technology department could determine if the devices still resided in the former employee’s office or some other place within the company. When it was determined that the company did not have possession or access to these two USB devices and that the former employee most likely took them when he left, we helped our client’s counsel write the request for the former employee to turn over all USB devices that he used while employed at the company on that computer. Based on our initial USB analysis, we were expecting 24 USB devices to be turned over. With that request, the hunt for stolen IP began in earnest.</span></p>
<p style="margin: 0in 0in 10pt;"><b><span style="font-size: 13px;">Home Based Employee Case Study:</span></b></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">In this case, we have a home based sales employee that was allowed to use his own personal computer for work purposes. His request to use his home based computer was granted by management even though it was in violation of company policy. Because his personal laptop was a Mac, a request was made by the employee for a virtual machine partition to be placed on the machine so that he could use “normal” Microsoft Outlook for work related email. Again, a request granted by management and a violation of company policy.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">When the employee left our client’s employment to go to work for a competitor, the company wisely asked for his computer to “image” it to make sure they had access to his email that was in the virtual partition. However, this image was not a traditional forensic image. Luckily the image did capture all the data on the disk; which included all the Mac data and all the data in the Windows virtual machine. Confident that they now had a copy of his email allowing them to answer any customer questions that might arise, they returned his personal computer back to him without deleting the virtual machine that contained years of corporate email. They put the image on the shelf and did nothing with it.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Shortly after this first resignation, a 2<sup>nd</sup> sales employee resigned. This employee was going to the same competitor as the first employee that left and this employee would reportto the first employee. Concern was rising that something nefarious might be going on as the competitor they went to work for was the number one competitor of our client. Losing both of these top sales people, was a grave concern in the very tight market that both these companies were in. For the purpose of this blog post and so we can keep them straight, we will name the home based employee with the Mac, Bob and the employee that left second, Steve.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">We were sent the work computer (which was a Windows computer) from Steve and we were sent the image of the home Mac computer that Bob used for work. We initiated our departing employee protocol to determine if there might have been any visible signs of solicitation and to determine if any confidential data may have been taken by either of them.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">While we did find signs that they were both communicating with each other, we didn’t find any signs that Bob asked Steve to leave and bring data with him. At that point, our investigation turned strictly into theft of IP and we began to look at each of them individually.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Investigating both former employees’ computers, we determined that they both had USB drives hooked up to their computers. Both of them used those USB drives on their final days of employment. There were also signs that data may have been transferred over to those devices. We worked with our client and their legal team to request that Steve hand over all the USB drives that he had used during his employment. This process was pretty straight forward with Steve’s computer, Bob and his computer was another story.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">As we mentioned, Bob used his personal laptop for work. This a machine was also used by family members. Because of this, we were not completely sure the best way to ask for access to the devices, given the high likelihood that we would not be granted access to family member’s devices unless we could clearly prove that data had been transferred to that specific device. This computer had been used for years and not only were there traditional USB storage devices that had been hooked up to it, but there were also iPhones, iPads and iPods that had been attached to this machine. These devices, while traditionally used for other reasons, also have the ability to store data. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Which devices were his, which belonged to his wife’s and his kids? As the investigation continued into Bob’s computer, we started to notice references to network storage devices, like network attached storage (NAS) and references to Apple’s Time Machine backup, which appeared to backup his entire laptop. Remember, Bob had the virtual machine that contained all his work email containing confidential information on this machine. We realized that the work email was in the Time Machine backup, so we had to make sure to request access to that backup as well. As it was becoming clear the type of home network that Bob had established, we realized that one of his NAS devices was syncing on a regular basis with his Mac. If you are able to follow the trail - we now know that work email is stored in at least three locations – on his personal Mac in the company provided VM, the Time Machine Backup and on the NAS. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">We gave our client a file list of some of the files on the Mac image that contained the word “confidential”. We handed over copies of documents, spreadsheets, PowerPoints and PDFs for them to look through. It was quickly determined by our client those files were very key to the company, and Bob should never have been allowed to leave with that data still on his personal Mac that he used for work. Like with Bob’s email, we were assuming that these files containing the documents, spreadsheets, PowerPoints and PDFs etc. were also on the Time Machine Backup and the NAS and potentially other USB devices.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">At that point, the lawyers knew what we needed access to, but with Bob’s non-traditional home network this wasn’t going to be your normal legal request. This was going to be a case with many unexpected twists and turns.</span></p>
<p style="margin: 0in 0in 10pt;"><b><span style="font-size: 13px;">Hurry up and wait.</span></b></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">As with all cases, once we find that IP may have been taken during employee departure we provide our reports, declarations and/or affidavits. The lawyers then take over and it is hurry up and wait while the legal process runs its course. Stay tuned to the next blog post to see what happened with these legal requests and the corresponding TROs (Temporary Restraining Order).</span></p>
<p style="line-height: 15.75pt; margin-bottom: 10pt;"><span style="color: #000000; font-size: 9pt;"><span style="font-size: 13px;">Newberry Group has services that can support all of your needs in these areas. Our experienced team can conduct investigations that cover both the departing employee as well as the new hire for a fraction of the cost that you could incur should the examples above play out. Our<span class="apple-converted-space"> </span></span><a href="http://www.newberrygroup.com/Digital-Forensics/Departing-Employee-Program.aspx"><b><span style="padding-bottom: 0in; padding-left: 0in; padding-right: 0in; color: #0563c1; font-size: 13px; padding-top: 0in;border-width: 1pt;border-color: windowtext;">Departing Employee Program</span></b></a><span style="font-size: 13px;"><span class="apple-converted-space"> </span>is a</span></span><span style="font-size: 13px;"><span style="color: #231f20; font-size: 9pt;" class="apple-converted-space"> </span><span style="color: #231f20; font-size: 9pt;">fixed fee program that consists of defined computer investigation service packages that identify and report on employee data activity. The packages vary as to scope and cost in order to provide you with a level of assurance proportionate to the value of the employee and the access that the employee had to your IP.</span> </span></p>
<p style="line-height: 15.75pt; margin-bottom: 10pt;"><span style="color: #000000; font-size: 9pt;">Our Incoming Employee Package consists of 2 services. 1<sup>st</sup>, it verifies that policies and procedures are appropriate so new employees understand that under no circumstances should any IP from previous employers be brought with them. 2<sup>nd</sup>, at a predetermined time (usually 30-60 days after the employees start date), we will check the new hire’s drive for signs of external IP. If data is found, you can take immediate steps to remediate the data before any litigation commences. </span></p>
<p style="line-height: 15.75pt; margin-bottom: 10pt;"><span style="color: #000000; font-size: 9pt;"><span style="font-size: 13px;">For more information on these services as well as other Forensic-related services we offer, please visit our website at </span><a href="http://www.newberrygroup.com/"><b><span style="padding-bottom: 0in; padding-left: 0in; padding-right: 0in; color: #0563c1; font-size: 13px; padding-top: 0in;border-width: 1pt;border-color: windowtext;">www.newberrygroup.com</span></b></a><span style="font-size: 13px;"><span class="apple-converted-space"> </span>or email us at<span class="apple-converted-space"> </span></span><a href="mailto:[email protected]"><b><span style="padding-bottom: 0in; padding-left: 0in; padding-right: 0in; color: #0563c1; font-size: 13px; padding-top: 0in;border-width: 1pt;border-color: windowtext;">[email protected]</span></b></a></span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;"> Next Blog: Temporary Restraining Orders (TRO)</span></p> <br /><i><a href='/Blog/?id=58'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=58Jerermy WunschWed, 08 Jun 2016 11:41:00 GMTThe hacker, the departing employee, the new hire. Which one can cost you more?
Part 1 of a 6 Part Blog Series<p style="margin: 0in 0in 10pt;">After almost 20 years of doing computer forensic investigations, and specializing in investigating data breaches and IP theft, I have realized a few things. Hackers are here to stay and those employees you trust the most can hurt you the most.<b></b></p>
<p style="margin: 0in 0in 10pt;"><b>The Hacker</b></p>
<p style="margin: 0in 0in 10pt;">Let’s start where most organizations are mistakenly focused, hackers. </p>
<p style="margin: 0in 0in 10pt;">Hackers are malicious but most are only looking to steal usernames and passwords but some do try to steal personally identifiable information (PII) to sell or they are looking to run some other type of scam with the stolen information. Rarely, do hackers steal data to create a competing product or service.</p>
<p style="margin: 0in 0in 10pt;">Yes, hackers cause harm. They steal identities; people fall for their scams. Hacks have been a daily occurrence for some time now. Most firms spend a lot of time and money trying to prevent them and have a budget set aside for investigating them. </p>
<p style="margin: 0in 0in 10pt;">But when we look back, what is the real cost to the organization of a hack? Google “cost of a hack” and you will find countless examples of what it costs organizations. But the numbers are all different. The real answer is that nobody knows. Realistically, unless you are part of some of the largest breaches in the world, the cost of a hack does not create a very large dent on the organizations profit and loss statement. The “official statement” says, sorry we were hacked, change your passwords and move on.</p>
<p style="margin: 0in 0in 10pt;"><b>The Departing Employee</b></p>
<p style="margin: 0in 0in 10pt;">This is my favorite person in the company. They are leaving for that new job. Why did they get that job? You guessed it, because of what they did at your company. </p>
<p style="margin: 0in 0in 10pt;">Organizations as a whole are still a trusting bunch. “Oh, my employees would not maliciously take information with them.” We hate to be the bearer of bad news – they will and it is probably happening a lot more than you realize. In the thousands of cases we have done over the years, I can count on one hand the number of times during an investigation where we didn’t find the employee stealing intellectual property (IP) and taking it with them.</p>
<p style="margin: 0in 0in 10pt;">If the departing employee left to start their own competing business or worse yet – went to your #1 competitor – more than likely they have taken some of your IP (think customer lists, pricing data, product development details, business planning details to name a few) with them to help them hit the ground running. It is time to start an investigation to see what they took.</p>
<p style="margin: 0in 0in 10pt;">When do you pull in legal? It all depends on the organization and if legal is in-house or not. But most pull in the legal team after it has been identified that IP may have been taken. Another key question when pulling in the legal team is to ask “do you have an experienced legal team to help you during the investigation?”</p>
<p style="margin: 0in 0in 10pt;">The “experienced legal team” is a delicate subject, but it must be brought up. While the organization is going through the investigation, it cannot be stressed enough: make sure your legal counsel – both inside and outside counsel understand the technology, the terminology and the forensics process.</p>
<p style="margin: 0in 0in 10pt;">Beware of what I refer to as the “Legal Tech Lawyer”. These are attorneys from firms that got their experience from going to a few conferences and listened to a few webinars yet consider themselves experts in technology cases. In addition, beware of outside counsel that does not have any actual experience in conducting cases that had computer forensics examinations in the area of IP theft. </p>
<p style="margin: 0in 0in 10pt;">Having an experienced legal team; especially experienced outside counsel that understand the process and what forensics technology can and cannot do will cost more per hour than an attorney that doesn’t, but in the end, it will be worth it. Not understanding the life cycle of an investigation; the differences in terminology, understanding the limitations of technology and what to ask for during the investigation will most likely cause the organization to incur additional downstream investigation fees because the investigation is not streamlined. Uneducated attorneys are less likely to ask pertinent questions, will have to do additional research to understand what they need to have done, may ask for things to be done that are not necessary, or miss finding critical evidence that is germane to your case. All of this will likely result in increased legal fees.</p>
<p style="margin: 0in 0in 10pt;">Legal expenses tend to be a very large chunk of the total cost of an IP theft investigation. Choosing the right attorney (s) is critical not only to the success of your investigation; but also to keeping your costs from spiraling out of control, especially when you are going after a temporary restraining order (TRO), and requesting access to both their home and “new work” computers. </p>
<p style="margin: 0in 0in 10pt;"><b>Your New Hire</b></p>
<p style="margin: 0in 0in 10pt;">Let us introduce you to your most expensive hire; the new employee that you just hired away from your #1 competitor. The employee that took IP from their previous employer, who brought IP with them and is currently using that IP in their new job with you.</p>
<p style="margin: 0in 0in 10pt;">You didn’t ask them to steal IP from their previous employer, but they did. You hired them because of their experience and their past contacts and connections. They told you they can help you beat their former employer; what they didn’t inform you about is they are bringing data with them that will be housed inside your walls. </p>
<p style="margin: 0in 0in 10pt;">This data now resides someplace on your network. It could be a little, it could be a lot. For example, maybe they took a PowerPoint presentation. They changed a few words and logos and now your next project is the exact same project they were working on at their previous company. They shared a copy with their boss. Their boss shared it with their boss who presented it at the national sales conference. You get the picture.</p>
<p style="margin: 0in 0in 10pt;">Now imagine this scenario. Their previous employer knows you have hired their employee and suspects that they have taken IP – lots of it. They hire a forensic company to look at the former employee’s work machine and they find IP was taken. They suspect you now have it. They want it back or eradicated and they want monetary damages. </p>
<p style="margin: 0in 0in 10pt;">The next thing you know, you are served with a TRO and litigation hold. You are getting sued by your new hires former employer for theft of IP. You know nothing about this, you didn’t ask them to take it, but they did. Courts are starting to open up the doors to allow forensic companies to investigate inside the “new company” to verify that the previous company’s data is or is not inside the new company. The Forensics Investigation Team has been allowed full access to email servers, network servers and storage, laptops and desktop, cell phones, tablets and cloud accounts that may have the stolen IP on them. </p>
<p style="margin: 0in 0in 10pt;">If that happens to you; more than likely your organization will be responsible for the cost of that investigation. If IP is found, the costs ramp up even further. The IP will have to be remediated and most likely the courts could issue some pretty large judgment against you. We have had cases where the judgment in 1 IP theft alone was upwards of twenty ($20) million dollars that the “new company” had to pay the “former company” because the departed employee took IP with them and used it at the new company. While judgements of this amount are not common, they do happen. It is becoming more common to get judgements against the new company of a few million plus all third party fees (legal, computer forensics, court costs, etc).</p>
<p style="margin: 0in 0in 10pt;"><b>What Can You Do To Be Proactive?</b></p>
<ol>
<li>Have an appropriate IT budget to spend on and implement monitoring solutions that watch internal employees in how they use the organizations data. Whether it is device control, DLP solutions or BYOD technology – having monitoring technology is a must these days. </li>
</ol>
<ol>
<li>Have current AUP (acceptable use policy) and any other corporate policies governing the use of corporate data. Nothing is more painful than learning that you allow employees to take whatever they want. </li>
</ol>
<ol>
<li>Be consistent in enforcing those policies. Precedent is a big word in the legal community and I have seen many cases lost on precedent. </li>
</ol>
<ol>
<li>Ask the right questions of legal team on their experience level in conducting forensics investigations. </li>
</ol>
<ol>
<li>Get an experienced Digital Forensics team that understands IP theft considerations for departing and incoming employees. </li>
</ol>
<p style="margin: 0in 0in 10pt;"><b>How can you protect yourself?</b></p>
<p style="margin: 0in 0in 10pt;">There are economical ways to forensically determine what data and or IP was taken from an organization or brought into an organization. An excellent program will:</p>
<ul>
<li>Have a well-defined AUP covering both incoming and outgoing IP. </li>
</ul>
<ul>
<li>Consist of defined computer investigation service packages that identify and report on employee data activity </li>
</ul>
<ul>
<li>Be able to identify data that was taken from your network as well as brought in to your network. </li>
</ul>
<p style="margin: 0in 0in 10pt;"><b>Conclusion</b></p>
<p style="margin: 0in 0in 10pt;">Hackers are here to stay. Most companies are well prepared to defend against hacks and have budgeted for such an event.</p>
<p style="margin: 0in 0in 10pt;">Employees will also continue to take IP. It is not a question of if IP theft will happen, it is a matter of when and at what cost to the organization. Most companies are not as well prepared to investigate theft of IP. Nor have they budgeted for what the potential investigation might cost them or what the effects of a theft might be – loss of revenue, loss of clients, loss of productivity, business interruption – the list goes on and on.</p>
<p style="margin: 0in 0in 10pt;">Does an investigation have to break the bank to learn what IP might be taken? No, it does not. Investigations can be streamlined, simplified and be cost effective if an organization has the proper team and services in place prior to kick off of an event.</p>
<p style="margin: 0in 0in 10pt;">As to the initial question that we started with, “The hacker, the departing employee, the new hire. Which one can cost you more?” Stay tuned to future posts to learn, but I can tell you, it isn’t the hacker.</p>
<p style="margin: 0in 0in 10pt;">Newberry Group has services that can support all of your needs in these areas. Our experienced team can conduct investigations that cover both the departing employee as well as the new hire for a fraction of the cost that you could incur should the examples above play out. Our <a href="http://www.newberrygroup.com/Digital-Forensics/Departing-Employee-Program.aspx"><span style="color: #0000ff;">Departing Employee Program</span></a> is a<span style="color: #231f20;"> fixed fee program that consists of defined computer investigation service packages that identify and report on employee data activity. The packages vary as to scope and cost in order to provide you with a level of assurance proportionate to the value of the employee and the access that the employee had to your IP.</span></p>
<p style="margin: 0in 0in 10pt;">Our Incoming Employee Package consists of 2 services. 1<sup>st</sup>, it verifies that policies and procedures are appropriate so new employees understand that under no circumstances should any IP from previous employers be brought with them. 2<sup>nd</sup>, at a predetermined time (usually 30-60 days after the employees start date), we will check the new hire’s drive for signs of external IP. If data is found, you can take immediate steps to remediate the data before any litigation commences. </p>
<p style="margin: 0in 0in 10pt;">For more information on these services as well as other Forensic-related services we offer, please visit our website at <a href="http://www.newberrygroup.com/"><span style="color: #0000ff;">www.newberrygroup.com</span></a> or email us at <a href="mailto:[email protected]"><span style="color: #0000ff;">[email protected]</span></a></p>
<p style="margin: 0in 0in 10pt;">Next Blog: Newberry Group’s Departing Employee Program.</p> <br /><i><a href='/Blog/?id=57'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=57Jeremy WunschFri, 26 Feb 2016 11:06:00 GMTKeeping Student Data Secure in Education<div style="background-color: #ffffff; display: inline-block; font-family: 'helvetica neue',arial,sans-serif; color: #a7a7a7; font-size: 11px; width: 100%; max-width: 507px; min-width: 300px;">
<div style="overflow: hidden; position: relative; height: 0px; padding: 66.6667% 0px 0px; width: 100%;"><iframe width="507" height="338" frameborder="0" src="//embed.gettyimages.com/embed/187480288?et=cRFgXDrTRCd4srFKgE-dgQ&sig=IP8AXzmUYwUeswG2a7pPpwZImsJNK3ALhyVLf1NCbYs=" scrolling="no" style="display: inline-block; position: absolute; top: 0px; left: 0px; width: 100%; height: 100%;"></iframe></div>
<p style="margin: 0px;"></p>
<div style="padding: 0px; margin: 0px 0px 0px 10px; text-align: left;"><a href="http://www.gettyimages.com/detail/187480288" target="_blank" style="color: #a7a7a7; text-decoration: none; font-weight: normal ! important; border: medium none; display: inline-block;">#187480288</a> / <a href="http://www.gettyimages.com" target="_blank" style="color: #a7a7a7; text-decoration: none; font-weight: normal ! important; border: medium none; display: inline-block;">gettyimages.com</a></div>
</div>
<p>As students and teachers alike are embracing online learning tools, a need for better internet security in schools is becoming more apparent. The recent <a href="http://www.nmc.org/news/and-cosn-release-horizon-report-2014-k-12-edition" target="_blank">report</a> on tech adoption in education by the <a href="http://www.cosn.org/" target="_blank">Consortium for School Networking</a> (CoSN) and the <a href="http://www.nmc.org/" target="_blank">New Media Consortium</a> (NMC), highlights this trend of hybrid learning models that “blend the best of classroom instruction with the best of Web-based delivery.” However, the report also points out that the safety of student data is considered a “difficult challenge” and “<a href="http://www.nmc.org/news/and-cosn-release-horizon-report-2014-k-12-edition" target="_blank">solutions are elusive</a>.”</p>
<p>While internet security is a pervasive issue for all industries, schools deserve some extra attention. Along with the increased need for bandwidth to access online courses and tools, students and teachers are all too quick to share personal information through the internet. Schools need to carefully plan their network security in much the same way they plan their physical security. There has to be a good balance between access and security.</p>
<p>The solutions for balancing the security of student data with providing the right level of access required in today’s learning environment don’t have to be “elusive.” There is a full suite of solutions, such as network access controls or web filters, that are available at affordable prices and can offer the necessary protection for K-12 schools up through universities.</p>
<p><strong>So what should you look for in a solution? Here are some good starting points:</strong></p>
<ul>
<li>
<strong>URL Filtering</strong> – In 2013, <a title="Websense Threat Report" target="_blank" href="/data/files/White Papers/report-2014-threat-report-en.pdf">85% of malicious links used in web or email attacks were located on compromised legitimate websites.</a> Controlling which websites can be accessed can limit the possibility of malware infecting your network. </li>
<li><strong>Secure Data Transfer</strong> – An estimated <a title="Barracuda Backup - The Value of Offsite Storage" target="_blank" href="/data/files/White Papers/Barracuda_Backup_WP_Value_of_Offsite_Storage.pdf">6% of all PCs will suffer at least one episode of data loss per year</a>. 20% of all laptops suffer hardware related data loss in the first three years. A good IT strategy implements an off-site backup solution for important data. In an education environment, that would include student records. Securing this transfer of data is necessary as not only can the physical data be accessed but the transmissions of that data can also be intercepted. </li>
<li><strong>Mobile Device Security</strong> – On average, <a href="http://www.forescout.com/sans-analyst-report-your-pad-or-mine/">network administrators are only aware of 80% of the devices on the network</a>. In an educational setting, where nearly every student has a mobile device with the ability to connect to a local network, this figure is most assuredly much lower. Utilizing an agentless solution that discovers devices as soon as they access the network will protect vital information such as student records and institutional data while allowing the proper access necessary for the learning environment.</li>
<li><strong>Bandwidth</strong> – With the inclusion of streaming media in today’s curriculum and the distribution of network resources across a geographically separated campus, load balancing bandwidth is essential to providing consistent access for both students and faculty </li>
<li><strong>Efficient Configuration</strong> – School IT departments are minimally staffed. And often, the staff is simply challenged by time and resources just to maintain let alone implement and improve the network. Solutions that are easy to configure and maintain yet provide robust security features are a must.
</li>
</ul>
<p></p> <br /><i><a href='/Blog/?id=56'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=56Gerald KennedyMon, 18 Aug 2014 18:45:00 GMTHow to Choose Security Solutions for Mobile Healthcare – Part 1<div style="background-color: #ffffff; display: inline-block; font-family: 'helvetica neue',arial,sans-serif; color: #a7a7a7; font-size: 11px; width: 100%; max-width: 507px; min-width: 300px;">
<div style="overflow: hidden; position: relative; height: 0px; padding: 66.6667% 0px 49px; width: 100%;"><iframe width="507" height="387" frameborder="0" style="display: inline-block; position: absolute; top: 0px; left: 0px; width: 100%; height: 100%;" scrolling="no" src="//embed.gettyimages.com/embed/156888012?et=NZQ2pjACS-prcIQMjtfTpg&sig=92yuaM-giXr2AbJVB3EBoeTHkJClktCtHXjRTIxHrpA="></iframe></div>
<p style="margin: 0px;"></p>
<div style="padding: 0px; margin: 4px 0px 0px 10px; text-align: left;"><a style="color: #a7a7a7; text-decoration: none; font-weight: normal ! important; border: medium none; display: inline-block;" target="_blank" href="http://www.gettyimages.com/detail/156888012">#156888012</a> / <a style="color: #a7a7a7; text-decoration: none; font-weight: normal ! important; border: medium none; display: inline-block;" target="_blank" href="http://www.gettyimages.com">gettyimages.com</a></div>
</div>
<p>
<span style="font-size: 16px;"><strong>The last time I visited to the doctor, he recorded everything on a tablet device. </strong><span style="font-size: 13px;">While it’s convenient, mobile security is always at the forefront of my mind.</span></span> I was doing a bit of reading on mobile security and came across the Medicare and Medicaid (CMS) <a target="_blank" href="http://www.cms.gov/Regulations-and-Guidance/Legislation/EHRIncentivePrograms/index.html?redirect=/EHRIncentivePrograms/01_Overview.asp">Electronic Healthcare Records (EHR) Incentive Program</a>. This program gives healthcare providers a financial incentive for demonstrating the meaningful use of certified EHR technology or for adopting, implementing, or upgrading EHR technology. EHR technology allows providers to easily record and share patient data so that it’s consistent and readily available throughout the provider chain. This is certainly a great benefit to all healthcare providers as well as patients. No need to transfer records and records can be updated in real time through hand held devices, patient monitors, or diagnostic tools connected to the network.</p>
<p>However, broader access to electronic databases and the use of additional devices to access that data only adds to the already vulnerable IT environment within the healthcare industry. IT components within healthcare are already severely susceptible to hacking and advanced persistent threats. Medical device end points, such as monitors and diagnostic tools, could have severely outdated operating systems that don’t lend themselves to standard patching processes. Even personal healthcare devices, such as insulin pumps, have known vulnerabilities as demonstrated by Jerome Radcliffe when he <a target="_blank" href="http://www.darkreading.com/vulnerabilities---threats/getting-root-on-the-human-body/d/d-id/1136133?">hacked</a> his own insulin pump. These weaknesses, coupled with the fact that medical practitioners regularly bring their own smartphones and tablets and are often <a target="_blank" href="http://hitconsultant.net/2014/02/26/infographic-state-of-mobile-technologies-in-healthcare-today/">unregulated at many facilities</a>, leaves a provider network open and vulnerable.</p>
<p>The <a target="_blank" href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/securityrule/">HIPAA Security Rule</a> provides standards for the securing of electronic health information. These rules are in place to protect patient data through access control, audit controls, integrity controls, and transmission controls. While important, they rely on the provider to select and implement the necessary security solutions to prevent a data breach. And without proper security for personal and medical end point devices, it is only one finger in a dam that has many holes.</p>
<p>Stay tuned for <a href="http://newberrygroup.com/Blog/Default.aspx?id=55">Part 2</a> later this week where I discuss the factors to consider when looking at different security solutions.</p>
<p>UPDATE: Part 2 is live! Check out: <a href="http://newberrygroup.com/Blog/Default.aspx?id=55">How to Choose Security Solutions for Mobile Healthcare - Part 2</a></p> <br /><i><a href='/Blog/?id=54'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=54Gerald KennedyWed, 23 Jul 2014 18:13:00 GMTHow to Choose Security Solutions for Mobile Healthcare - Part 2<div style="background-color: #ffffff; display: inline-block; font-family: 'helvetica neue',arial,sans-serif; color: #a7a7a7; font-size: 11px; width: 100%; max-width: 485px; min-width: 300px;">
<div style="overflow: hidden; position: relative; height: 0px; padding: 72.7835% 0px 49px; width: 100%;"><iframe width="485" height="402" frameborder="0" src="//embed.gettyimages.com/embed/172601351?et=KZfD29Y8RKJvP7VO91lAaA&sig=5jtQDiykEpY-twF09avom33gjuUmsY_QCLokXaE98GU=" scrolling="no" style="display: inline-block; position: absolute; top: 0px; left: 0px; width: 100%; height: 100%;"></iframe></div>
<p style="margin: 0px;"></p>
<div style="padding: 0px; margin: 4px 0px 0px 10px; text-align: left;"><a href="http://www.gettyimages.com/detail/172601351" target="_blank" style="color: #a7a7a7; text-decoration: none; font-weight: normal ! important; border: medium none; display: inline-block;">#172601351</a> / <a href="http://www.gettyimages.com" target="_blank" style="color: #a7a7a7; text-decoration: none; font-weight: normal ! important; border: medium none; display: inline-block;">gettyimages.com</a></div>
</div>
<p><em><strong>To read Part 1 of this series, <a target="_blank" href="http://newberrygroup.com/Blog/Default.aspx?id=54">click here</a>.</strong></em></p>
<p>According to the <a target="_blank" href="http://hitconsultant.net/2014/02/26/infographic-state-of-mobile-technologies-in-healthcare-today/">HIMSS Analytics 3rd Annual Mobile Survey</a>, the top benefit to having mobile tech in facilities is increased access to patient information, and the ability to view data from a remote location. But this means there are thousands of devices accessing a provider’s network. In order to select a proper security solution that not only meets HIPAA requirements but offers the protection for medical device end points in use, medical IT Administrators must look at a number of factors:</p>
<ul>
<li>
<strong>What is on my network?</strong> This is the first and most important step in providing a secure IT enterprise. Many IT administrators believe they know what devices are on their network. However, healthcare facilities are littered with transient devices such as personal phones and tablets, patient monitors and diagnostic tools that have unique and often antiquated operating systems. These devices may only show up on IT networks once a week or perhaps once a month. It can be a daunting task to know exactly what is connected to the IT enterprise.</li>
<li><strong>Controlling BYOD.</strong> Practitioners, nurses, and administrative staff often use their own unregulated devices, such as phones and tablets, to record data and communicate with staff and patients. Add to that the fact that many facilities offer open WiFi to their patients and guests. This creates a massive amount of end points that are not monitored and leave the IT enterprise vulnerable to malware, viruses, and advanced persistent threats. Survey findings shows that <a target="_blank" href="http://hitconsultant.net/2013/04/12/infographic-the-state-of-wireless-networking-in-healthcare/http:/hitconsultant.net/2013/04/12/infographic-the-state-of-wireless-networking-in-healthcare/">32% of hospitals</a> are not even using technology to enforce their BYOD policies. </li>
<li><strong>End Point Compliance.</strong> Knowing what is on the network is one thing. Keeping known devices compliant is something else entirely. Security of an IT Enterprise is only possible through awareness. Once the devices are discovered IT administrators must be certain that they remain compliant. Having the ability to confirm applications and disable those that are unauthorized, verify whether or not the devices meets established security policies, knowing if the device is compliant with the latest security patch and antivirus definitions is essential. </li>
<li><strong>Cost vs. Risk.</strong> While the Federal Government provides some mandates that direct medical IT Administrators to protect patient data, the healthcare IT network remains largely susceptible to your average hacker. It is up to each healthcare IT Administrator to protect the physical network to the degree they feel necessary to secure data and network end points. Healthcare budgets, like many vertical industries, are balanced toward production vs. protection. In the HIMSS Analytics survey, <a target="_blank" href="http://hitconsultant.net/2014/02/26/infographic-state-of-mobile-technologies-in-healthcare-today/">lack of funding</a> was the most common barrier to implementing a security solution. An effective solution with low cost of ownership is necessary. And while incentive programs such as EHR Incentive Program may seem to add balance to this in favor of the healthcare facilities, the incentive received is certainly not equivalent to the cost of losing patient data.
</li>
</ul>
<p>Network administrators can’t secure what they can’t see. It is imperative that administrators have access to <a target="_blank" href="http://newberrygroup.com/Technologies/ForeScout.aspx">real-time visibility</a> of everything on their network and be able to control what is on their network at all times. When choosing a solution that meets all of these requirements, look for one that is simple to install on your network, without the need for agents or client software.</p>
<p>If you’d like to talk more about end point security solutions or need help, <a href="http://newberrygroup.com/Contact-Us.aspx">get in touch</a> with us!</p> <br /><i><a href='/Blog/?id=55'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=55Gerald KennedyWed, 23 Jul 2014 16:03:00 GMTCase Study: Optimizing Barracuda Load Balancer to Meet Web Application Demands<h2><img src="/data/images/NewberryBlog/06-2014_NG_Blog_Banner.jpg" style="float: right; margin-bottom: 20px; margin-left: 20px;" alt="Barracuda Load Balancer" />Challenge:</h2>
A regional energy cooperative wanted a way to provide seamless application availability for their customers and scalable performance for future growth demands. Their current Barracuda Load Balancer and Oracle ERP solutions were deployed by a 3rd party using a method that would significantly impact performance and scalability in their virtualized environments. With a deadline on the horizon, they needed a solution that offered both flexibility and availability while minimizing complexity.<br />
<h2>Solution:</h2>
Newberry conducted a network and infrastructure assessment and found that the current Load Balancer and ERP deployment would only meet a fraction of the organization’s web application demands. Newberry’s engineer worked closely with the customer to fine tune their Barracuda Load Balancer and rebuild their Oracle ERP system from the ground up while keeping the principles of scalability and application uptime at the forefront.<br />
<h2>Results:</h2>
<p>Newberry enhanced the organizations ability to manage and scale critical application environments by:</p>
<ul>
<li>Creating custom Load Balancer services and rules to automate application failover, rewrite URL requests for cross-platform compatibility with Oracle, and utilized URL redirection to simplify end user navigation during their initial orientation.</li>
<li>Tuning the Load Balancer’s application layer for session persistence and Layer 7 health monitoring.</li>
<li>Clustering the Load Balancers together using High Availability for seamless failover and web application availability.</li>
<li>Identifying I/O performance bottlenecks in virtual and networking environments.</li>
<li>Redesigning the customers ERP architecture by reducing complexity and adding additional nodes which resulted in doubling the amount of concurrent users and sessions available.</li>
<li>Training and knowledge transfer with System and Network Administrators covering operations, maintenance and advanced troubleshooting.</li>
</ul>
<h2>Why Newberry Group?</h2>
<p>As one of the few Barracuda partners that can support the entire product line beyond what was required by this customer, Barracuda immediately turned to Newberry to make this project a success. <a href="http://www.newberrygroup.com/Technologies/Barracuda-Networks.aspx" title="Newberry's Barracuda Services and Solutions">Newberry’s Barracuda-certified</a> engineers brought their in-depth knowledge, experience and passion for technology that was needed to exceed the demands of this time critical project.</p> <br /><i><a href='/Blog/?id=52'>Click here</a> for more information.</i><br/>IT Serviceshttp://www.newberrygroup.com/Blog/?id=52Nicholas TrifilettiMon, 09 Jun 2014 09:51:00 GMTCase Study: Protecting a Large-Scale Federal Network with Sourcefire NGIPS<h2><img src="/data/images/NewberryBlog/Sourcefire-Logo-1-7-10_300px.png" style="float: right; margin-bottom: 20px; margin-left: 20px;" alt="Sourcefire logo" />Challenge: </h2>
<p>A Federal agency recognized that they needed to improve their threat protection by monitoring all traffic as it passes through their gateways without hampering their network performance. This agency knew that malware was entering into their network enterprise but was not able to detect it. Due to client data sensitivity and the need to ensure the security of the network for their customers, they needed to be able to apply customized protections as quickly as possible. </p>
<h2>Solution: </h2>
<p>Newberry Group partnered with Sourcefire to provide a solution that included multiple Sourcefire Next-Generation IPS Sensors at the four main data centers. The Sourcefire IPS solution provides the agency with real-time contextual awareness and threat protection with the ability to act intelligently and automatically when an internal host is affected by a client side attack. </p>
<h2>Results: </h2>
<p>With Sourcefire’s NGIPS, Newberry Group helped the customer meet performance and customization demands so that the agency has access to:</p>
<ul>
<li>Real-time contextual awareness with the ability to see and correlate extensive amounts of event data related to their IT environment—applications, users, devices, operating systems, vulnerabilities, services, processes, network behaviors, files and threats.</li>
<li>Advanced threat protection to discover, assess and respond to hacking activities, intrusion attempts and vulnerabilities in order to stay ahead of threats.</li>
<li>Intelligent security automation with event impact assessment, IPS policy tuning, policy management, network behavior analysis, and user identification. This significantly lowers the total cost of ownership to the agency and enhances their ability to keep pace with changing environments.</li>
</ul> <br /><i><a href='/Blog/?id=51'>Click here</a> for more information.</i><br/>IT Serviceshttp://www.newberrygroup.com/Blog/?id=51Tony HausmannTue, 20 May 2014 11:53:00 GMTCase Study: Installing a Websense Web Security Filtering Appliance<h2>Challenge: </h2>
<p><img src="/data/images/NewberryBlog/04-2014_Newberry_blog_websense-logo.jpg" style="float: right; margin-bottom: 20px; margin-left: 20px;" alt="Websense logo" />A Federal agency recognized that they needed to improve their current web security solution to allow for better filtering of the Internet traffic coming in and going out of their network. They needed to provide for data loss protection, as well as utilize real-time analysis of malware and recognized advanced threats with the ability to perform forensic activities. They needed the solution to provide protection for local and remote users as well as support multiple campus sites. Additionally, in the end, they wanted to be able to centrally manage the system post-deployment and develop reports for Executive staff and trend analysis. Thus the solution needed to have an easy to use interface that allowed for the monitoring and management of the entire system from a single location.</p>
<h2>Solution: </h2>
<p>Newberry Group partnered with Websense to provide a technical solution that included multiple Websense appliances and the implementation of the Websense Web Security Gateway Anywhere (WSGA) solution installed at a main campus and a satellite location. The final solution included the following:</p>
<ul>
<li>Scalable deployment for up to 12,000 users with high availability and automated failover and load balancing.</li>
<li>
Deployment of Websense’s TruHybrid solution that protected the agency’s branch offices and remote and mobile users.</li>
<li>
Provisioning through a single unified interface.</li>
<li>
Deployment of Websense’s TruDLP to prevent data loss and enable compliance with agency and NIST standards and policies.</li>
<li>
Real-time analysis utilizing Websense’s Advanced Classification Engine (ACE) and threat intelligence from Websense’s ThreatSeeker Intelligence Cloud.</li>
<li>
An advanced threat dashboard providing actionable forensic detail on who was attacked, what data was attacked, where the data almost went, and how the attack was executed.</li>
<li>
File sandboxing to protect the environment from advanced malware.</li>
<li>
Training of Websense Administrators on system operation, maintenance and report generation.</li>
</ul>
<h2>Results: </h2>
<p>Newberry enhanced the agency’s overall environment by optimizing the customers filtering and security monitoring. The agency now has the ability to:</p>
<ul>
<li>Identify and monitor security vulnerabilities while being supported by manufacturer recommendations, industry best practices and compliance requirements.</li>
<li>
Implement security configurations for web filtering policy down to a user level.</li>
<li>
Provide reporting documentation to support security investigations or remediation. </li>
<li>
Direct reach-back to Newberry engineers and Websense Premium Support</li>
</ul>
<h2>Why Newberry Group?</h2>
<p>As a preferred Federal Executive Partner for Websense, Certified Triton Integrator, and Authorized Training Center, Newberry can offer a full scope of products and services to each of our clients. Our in-house certified Websense engineer trainers are able to provide a wide range of professional services that include integration, configuration and installation of Websense technology as well as standard and customized training courses to meet a client’s specific needs. </p> <br /><i><a href='/Blog/?id=50'>Click here</a> for more information.</i><br/>IT Serviceshttp://www.newberrygroup.com/Blog/?id=50Valerie RootMon, 21 Apr 2014 10:51:00 GMTCase Study: Ensuring Network Health with ForeScout CounterACT <h2><a title="Newberry ForeScout Professional Services" href="http://www.newberrygroup.com/Technologies/ForeScout.aspx"><img alt="Newberry Blog | ForeScout Logo and CounterACT" style="float: right; margin-bottom: 20px; margin-left: 20px;" src="/data/images/NewberryBlog/03-2014_NewberryBlog_ForeScout-Logo-Counteract.jpg" /></a>Challenge:</h2>
<p>A large Midwest firm wanted to allow employees and guests to access to their networks and internet regardless of the device being used. They also wanted a way to ensure anti-virus and security vulnerability patches were up-to-date on their own Windows devices. </p>
<p>The company needed a solution that provided visibility of their network and attached devices, provided an agentless capability, and was easy to install and manage. Compatibility with the client’s current switch and MDM vendors was another key factor as well as ensuring it could move forward with a future global deployment.</p>
<h2>Solution: </h2>
<p>Newberry partnered with ForeScout to provide a plan around the CounterACT solution. The client tested the solution for more than a month to ensure that the product worked well with the existing infrastructure, that it was easy to use, and that it would not cause network disruption.</p>
<p>CounterACT also provided the organization with a large amount of instant information they did not have access to previously. Now they can see who’s connected to specific switches, see who was the last person to log into the network on a specific Windows PC or user IP address, then enforce policies against those devices and machines attempting to connect.</p>
<h2>Results:</h2>
<p>Forescout CounterACT enhanced the health of the customer’s network by providing:</p>
<ul>
<li>
A more efficient and effective way to control network access (authority to connect) and ensure endpoint compliance.</li>
<li>
Real-time inspection and easy manageability of guests, contractors and employees using a variety of devices to connect.</li>
<li>
The ability to enforce security policies to only allow devices on the main network that have up-to-date antivirus, OS, and application patches.</li>
<li>
The ability to quarantine any noncompliant devices and devices with viruses and immediately reduce the threat of malware entering the network.</li>
<li>
An agentless solution with unprecedented compatibility with over 16 switch vendors and multiple MDM, antivirus and antispyware vendors.</li>
<li>
Fewer resources required for network access control (NAC) deployment, maintenance and administration</li>
</ul>
<p>With ForeScout CounterACT, Newberry was able to quickly improve the customer’s network health and provide an automated solution for network access control, mobile security and endpoint compliance. Do you have a similar network access situation? Learn more about <a title="Newberry ForeScout Professional Services" href="http://www.newberrygroup.com/Technologies/ForeScout.aspx">how Newberry can help</a>.</p>
<p></p> <br /><i><a href='/Blog/?id=49'>Click here</a> for more information.</i><br/>IT Serviceshttp://www.newberrygroup.com/Blog/?id=49Tony HausmannWed, 12 Mar 2014 23:06:00 GMTCase Study: Optimizing a Barracuda Web Application Firewall cluster<h2><img src="/data/images/NewberryBlog/02-2014_NG_Barracuda_Blog_Banner.jpg" style="float: right; margin-bottom: 20px; margin-left: 20px;" alt="Barracuda Logo and Web Application Firewalls" />Challenge:</h2>
<p>A Federal agency had recently purchased ten <a title="Barracuda.com | Web Application Firewall" target="_parent" href="https://www.barracuda.com/products/webapplicationfirewall">Barracuda Web Application Firewalls</a> (WAF) from another vendor and had installed the devices themselves. However, since the Barracuda WAF solution was new to them and the configurations were transferred from another solution, they were unsure if they had installed the devices in the most optimal setup. </p>
<h2>Solution: </h2>
<p>The agency relied on Newberry for a technical review of the installation of ten Barracuda Web Application Firewalls to validate operational efficiencies, infrastructure design, and to determine if deployed security policies for protected sites were effective in protecting from external threats.</p>
<h2>How We Solved the Problem:</h2>
<p>After determining the intended functionality of the configuration, Newberry’s Barracuda-certified team used current network diagrams to review the logical placement of each WAF in their respective data flows to determine correct placement and deployment method.<br />
A full review of the WAF environment was performed to determine if the services, security policies, advanced security protection features, and administrative access controls were appropriately set up to protect against external threats and comply with NIST standards and agency policies. The configuration of enabled services such as High Availability (HA), Load Balancing, Data Theft Protection and Caching/Compression were also reviewed to ensure optimal performance and adherence to Barracuda’s recommended configuration.<br />
Our team also analyzed firewall logs and reports to identify any security vulnerabilities and made configuration recommendations to enhance performance and offer a greater level of security.</p>
<h2>Results:</h2>
<p>Newberry enhanced the overall performance of the customer’s network and WAF configuration by:</p>
<ul>
<li>
Identifying security vulnerabilities that were supported by manufacturer recommendations, industry best practices, known vulnerabilities, and compliance requirements. </li>
<li>Providing fixes for the identified vulnerabilities </li>
<li>Offering recommendations for enhancing security and performance of the WAF and the overall network</li>
<li>
Lastly, providing a report of the assessment/configuration that included a management summary and the technical findings. </li>
</ul>
<h2>Why Newberry Group? </h2>
<p>As one of the few Barracuda partners that can support the product line to the extent that was required by this customer, Barracuda immediately turned to Newberry to conduct this review. Newberry’s Barracuda-certified engineers brought the in-depth knowledge and experience needed to perform even the most intricate configuration and troubleshooting tasks.
</p>
<p>Need help with your Barracuda product installation? Learn more about <a title="Newberry Group | Barracuda Professional Services" target="_self" href="http://newberrygroup.com/Technologies/Barracuda-Networks.aspx">how we can help</a>.</p> <br /><i><a href='/Blog/?id=48'>Click here</a> for more information.</i><br/>IT Serviceshttp://www.newberrygroup.com/Blog/?id=48Steve CarneyThu, 13 Feb 2014 11:43:00 GMTBuilding Effective Teams<p><img style="margin-bottom: 20px; height: 215px; float: left; width: 300px; margin-right: 20px;" alt="Newberry Blog | Building Effective Teams " src="/data/images/NewberryBlog/11-2013_NG_Blog_Banner.jpg" /><strong>Exceptional individual performer, or team player; which is more rewarding and which is more valuable?</strong> Most organizations talk “team” but unfortunately many primarily recognize and incentivize individual performance. Further, some organizations unwittingly go out of their way to attract and promote people who actually resist the idea of linking their performance to someone else or the “greater good.” They seek out the lone wolf with the gaudy numbers for that silver bullet fix and regrettably those gaudy results are often achieved at the expense of others and the long term health of the larger organization. It is a fact in both team sports and business that a seamlessly executing team is the best way to accomplish complex tasks and sustain long term exceptional performance. Effectively integrated teams are also central to cutting across boundaries to get things done - - truly becoming organizationally agile and successful.</p>
<p>So in a short-sighted world that glorifies and rewards the individual in spite of the proven negative consequences to sustained performance, how do you assure the building of effective teams? Fortunately experts like <a href="http://www.lominger.com/about.aspx" target="_blank">Michael Lombardo and Robert Eichinger</a> have some ideas:</p>
<p><span style="font-size: 16px; color: #1f497d;"><strong>Practice #1:</strong></span> <strong>Have a Plan.</strong> A clearly articulated plan energizes, aligns, brings focus, encourages efficiency, and empowers. Involve team members in creating that plan and you will only enhance their energy and commitment to “The Plan”. </p>
<p><span style="font-size: 16px; color: #1f497d;"><strong>Practice #2:</strong></span> <strong>Run Interference.</strong> An effective team leader has made the effort to become a “Maze Bright” organizationally agile person and is therefore an extremely good advocate for their team. As discussed in my July 28, 2013 blog on Organizational Agility, no skill is more respected by your team. When you can go off into the wilderness of the organizational maze and consistently come back with results that benefit your team and make their professional lives easier, their loyalty to you, the team, and “The Plan” is assured. </p>
<p><span style="font-size: 16px; color: #1f497d;"><strong>Practice #3:</strong></span> <strong>Make a Concerted Effort to Communicate and Inspire.</strong> Show an interest in the work of your people, adopt a learning attitude toward mistakes, celebrate successes, have visible measures of success. Invest time in understanding each person uniquely. You don’t have to agree with them, you just have to understand them. Give them the benefit of your thinking, particularly with respect to key objectives.</p>
<p><span style="font-size: 16px; color: #1f497d;"><strong>Practice #4:</strong></span> <strong>Build a sense of joy and fun in the team.</strong> Learn to celebrate wins. Use humor and support it in others; look for opportunities to build group cohesion outside the office.</p>
<p>Building a “Dream Team” is not an easy task. Blending individual talents and ensuring that you are taking advantage of each person’s strengths and avoiding unreasonable exposure to each person’s weaknesses is hard. However, it is very much worth the effort. High performing teams establish an uncommon trust between the team members in which individuals value the team above their own singular objectives. Weaknesses are not considered “bad.” They simply represent opportunities to cover for each other for the good of the team and take part in achieving a shared ultimate objective. When the team is at its best, this exceptionally valuable behavior happens without any ill feeling, it just happens. In the words of John Wooden, the immortal College Basketball Coach, “The main ingredient of stardom is the rest of the team.”</p> <br /><i><a href='/Blog/?id=47'>Click here</a> for more information.</i><br/>Employee Ownerhttp://www.newberrygroup.com/Blog/?id=47Christopher SteinbachWed, 13 Nov 2013 09:50:00 GMTThe Responsibilities of Cleared Personnel<p><img style="margin-bottom: 20px; float: left; margin-right: 20px;" alt="Newberry Blog | image of cyber hand" src="/data/images/NewberryBlog/10-2013_NewberryBlog_Banner_v1.jpg" />With October being <a href="http://newberrygroup.com/News/default.aspx?ID=146" title="National Cyber Security Awareness Month | Newberry News">National Cyber Security Awareness Month</a>, this is a good time to think about the responsibilities that come with having a security clearance. It’s especially timely with the recent high profile security events of <a href="http://articles.washingtonpost.com/2013-08-21/world/41431547_1_bradley-manning-david-coombs-pretrial-confinement">Chelsea Manning</a>, <a href="http://www.politico.com/story/2013/08/edward-snowden-timeline-of-events-95057.html">Eric Snowden</a>, or <a href="http://articles.washingtonpost.com/2013-09-25/local/42380094_1_navy-yard-shotgun-shooting">Aaron Alexis</a>. We may seem surprised by their actions, but if we think back to <a href="http://www.fbi.gov/about-us/history/famous-cases/aldrich-hazen-ames">Aldrich Ames</a> or <a href="http://www.fbi.gov/about-us/history/famous-cases/robert-hanssen">Robert Hanssen</a>, we see that these events are not the first of their kind. </p>
<p>When we obtain security clearances as government employees or contractors, we take on a multifaceted obligation: protect the technology and information that we have access to, ensure that others are doing the same, and ensure that we and our colleagues remain fit to work in a secured environment. </p>
<p>Once we complete the background investigation and possible polygraph process, we are given strict guidelines in how we handle and protect information from both a technological and a philosophical perspective. No matter how obvious it may or may not be, the information we access is directly or indirectly related to the safety and well-being of our warfighters abroad, our allies, our state department representatives, and even civilians. Even if you encounter information or programs that you disagree with from a philosophical, moral, or legal perspective, there are internal government avenues to voice your concern without jeopardizing the information to the general public. Choosing the avenue of public disclosure only serves those who wish to harm our interests or freedoms. That route is very treacherous, possibly traitorous and most likely illegal. </p>
<p>Even though you may be confident and diligent in your efforts to protect information, that doesn’t mean those around you are thinking the same way. It is equally your responsibility to be observant of the actions taken by others working with sensitive information. When suspicions arise, muster the moral courage to approach the appropriate personnel and report your concerns. Quick action could result in stopping a serious security incident.</p>
<p>Lastly, we must be cognizant that we and our colleagues are displaying the mental capacity to operate in a secure environment. Working in a secure setting can easily create a false sense of security and we assume that individuals around us are just as fit to be there as we are. However, secure areas are just as susceptible to criminal activities as an urban street corner, including anything from theft to shootings. There appears to be a growing number of mentally unstable individuals who have somehow slipped through the security screening process or co-workers who are upset by a life event that feel impelled to pursue indiscriminant or directed attacks against co-workers. We must be alert to suspicious signs and have the moral courage to approach or report those who may no longer be fit to work in a cleared environment. </p>
<p>Some view the Mannings and Snowdens of the world as whistleblowers or even heroes. However, the information they released was not theirs to disclose or release and may ultimately seriously affect the freedoms of Americans. Conversely, attacks within a cleared setting, such as the recent Navy Yard shooting attack, raised concerns about the security screening process. These unfortunate recent events can serve to reiterate that protecting information and maintaining a secured environment is an ongoing responsibility for everyone with a security clearance. By following tried and true policies and procedures the right outcome can be achieved.</p> <br /><i><a href='/Blog/?id=46'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=46Steve CadoganWed, 30 Oct 2013 14:30:00 GMTWhat Can Spiderman Teach Us About Teaching?<p>In 2009, a quick-thinking firefighter, <a href="http://www.google.com/hostednews/afp/article/ALeqM5jvsAYI-CbAikaUjcI6x5ULZyySyA?hl=en" target="_blank" title="Thai 'spider-man' rescues autistic boy | AFP">Somchai Yoosabai</a>, disguised himself as the comic book character Spiderman and successfully saved the life of an autistic 8-year boy who was sitting on the edge of a three story tall school house roof. The child was traumatized over his first day of school and would not let anyone come close to him. Overhearing a conversation about the child's love for super-hero's, Mr. Yoosabai quickly returned to his firehouse and put on a full body Spiderman costume which he used to make fire drills at schools more entertaining. Returning to the school, he cautiously approached and connected with the traumatized student. "I told him Spider-Man is here to save you. No monster will hurt you now." The child reacted immediately by walking toward the familiar character and was safely removed from the danger. (<a href="http://www.google.com/hostednews/afp/article/ALeqM5jvsAYI-CbAikaUjcI6x5ULZyySyA?hl=en" target="_blank" title="Thai 'spider-man' rescues autistic boy | AFP">Read full story and see photos here</a>)</p>
<p><img src="/data/images/NewberryBlog/09-2013_NewberryBlog_Teacher_01.jpg" style="float: right; margin-bottom: 20px; margin-left: 20px;" alt="Newberry Group Blog | icon of teacher at blackboard" /><strong>What does this heart-warming story have to do with effective teaching methodologies?</strong> Well, there are some critical similarities between this rescuer's actions and being an effective instructor. Let's review some of key factors of the child's stress.</p>
<h3>Apprehension </h3>
<p>The child was trying to escape from a learning environment because he was anxious about school. He obviously felt alone, afraid, worried that he wouldn’t fit in, that he shouldn't be there and probably many other feelings that some students feel when starting a new class, regardless of their age.</p>
<h3>Unfamiliarity </h3>
<p>Many of the feelings that he was experiencing most likely stem from the fact that he was in an unfamiliar place; he could not find anything in the new environment that he could associate with. This feeling only compounded the problem by contributing to his stress and was a significant factor in why he would not allow anyone near him. </p>
<h3>Isolation</h3>
<p>Because of the factors listed above, the child's "fight or flight" instinct was invoked. He could not fight the fact that the school house was there, nor could he fight the fact that he was there. So he decided to take "flight" away from all of the stress factors associated with the educational process. Unfortunately, the flight option that he chose was a drastic and dangerous one.</p>
<p><strong><img src="/data/images/NewberryBlog/09-2013_NewberryBlog_TrainingClassroom_02.jpg" style="float: right; margin-top: 20px; margin-bottom: 20px; margin-left: 20px;" alt="Newberry Group Blog | Image of training classroom" />The three negative, stress-inducing emotions listed above are experienced by all students at some point, even adults. </strong> Despite the misconception, adults who are sent to training sessions don't view the time away as a work-free "vacation"; they are required to come to the training. Based on comments from my previous students, a two-week training class can be one of the most stressful periods of a student’s life. The critical question is how can instructors help combat and at the very least reduce the feelings of: apprehension, unfamiliarity and isolation. I'd like to offer some suggestions.</p>
<h3>Apprehension </h3>
<p>Surprisingly, it is actually easy for instructors to forget that many of their students are not at all familiar with the class material. Instructors need to address this at the beginning of the class and repeatedly stress that it's OK if they have never used Linux, logged into a router or taken apart a computer. Tell the students to use you as a resource like they would a textbook. I have literally told students that if they don't ask questions, there's no reason for me to be there and I'd be out of a job! I usually see several smiles from students after I've proclaimed this light-hearted statement. Emphasizing that you're there for them and that you're approachable will benefit all of the class members.</p>
<h3>Unfamiliarity </h3>
<p>It makes sense that students will not be familiar with the class material, otherwise there would be little need for them to attend. One of the main jobs of a technical instructor is to take an abstract and technical subject and parallel the material with something that is "real world" and tangible. For example, try using an office building’s directory as a comparison to a storage media's file allocation table. Compare a real-life highway's congestion and slowing issues to a network's congestion and slowing issues. Try comparing a situation where 16 children want your attention to the way a computer interrupts requested work. I've found using children in analogies to be extremely effective because most adults are parents, or at the very least they were all children at some point.</p>
<h3>Isolation</h3>
<p>I previously mentioned that many adult learners are required to attend training sessions in order to learn a new task and that training is not a vacation. They will be expected to use the skills they are learning to complete a new responsibility, or in some cases they must pass the class in order to maintain their current position. Because of this, students experience stressful isolation even before the class begins! The feeling of isolation of which I speak exists between the student and the class material; it's not between the student and the instructor or other class members. Many of my former students willingly admit that they initially felt that their knowledge and experience were worlds apart from the material being taught. I believe that one way to break this isolation is to make use of an acronym - "WITFM" 0r "What's In It For Me"? If students discover a direct connection between what is being taught and how they will use it, they will be more receptive and motivated to learn the material. This discovery can be nurtured by the instructor using phrases such as "When you notice this problem at your work site, you can ..." or "When you are out in the field, you may see ..." Giving the student a practical reason to learn the material can greatly aid them in comprehending and retaining the information.</p>
<p>Using these methodologies, an instructor may significantly help in subduing the considerable and impeding stress that all students feel at some point during the learning process.</p> <br /><i><a href='/Blog/?id=45'>Click here</a> for more information.</i><br/>Traininghttp://www.newberrygroup.com/Blog/?id=45Michael KobettThu, 05 Sep 2013 11:23:00 GMTEmployee Data Protection: Securing Your Most Valuable Asset<p><img src="/data/images/NewberryBlog/08-2013_newberry_employeedata.jpg" style="float: left; margin-right: 20px; margin-bottom: 20px;" alt="Graphic Folder with Lock | Newberry Group Blog" /><strong>Protecting employees’ personal data is a big responsibility that falls on the shoulders of anyone who has access to create, store, handle or view personal information that is contained within Personnel and/or Accounting records.</strong> Federal regulations in the <a href="http://www.hhs.gov/foia/privacy/" target="_blank" title="www.hhs.gov/foia/privacy/">Privacy Act of 1974</a> hold government agencies accountable for the proper management of personal information, which raises the concern for how private employers protect their employees’ personal information. </p>
<p>
Personnel files should always be maintained with utmost care and confidentiality and only shared with others on a need-to-know basis, and with the express written consent of the employee, as required by law. </p>
<p>While there is an endless host of actionable possibilities to protect our employees’ personal data, it is important for employers to adapt some commonsense practices, which may include:</p>
<ul>
<li>
Never respond to outside inquiries, other than job title, dates of employment, and employee status, for employment verification without prior written consent from the employee.</li>
<li>
Develop policies and procedures with your IT department and use up-to-date technologies to protect personal information that is maintained in electronic format. Develop internal controls, such as limiting the number of people who can access personal information, as well as limiting which data each individual can view.</li>
<li>
Safeguard all paper copies of personal information under lock and key with restricted access</li>
<li>
Only collect information from each employee that is required to pursue the company’s business operations and to comply with government reporting and disclosure requirements.</li>
<li>
Always keep the medical history of an employee in a separate file with restricted access</li>
<li>
After employees are terminated, keep their files in your records in accordance with applicable state and federal laws. You can learn more about federal requirements by visiting the <a href="http://www.dol.gov/" title="www.dol.gov">US Department of Labor’s website</a> or by searching individual state Department of Labor sites.</li>
<li>
Have a written code of ethics and a confidentiality policy, and require every employee to sign an acknowledgment of having read the policy. Place the signed acknowledgment in each employee’s personnel file.</li>
<li>
Develop a procedure for the confidential reporting of breaches such as an ethical hotline.</li>
<li>
Communicate to your employees the types of data that are not considered confidential such as partial employee birth dates, (i.e., day and month only, but not year), an employee’s company anniversary or service recognition information, etc.</li>
</ul>
<p>The bottom line is that employers should take every reasonable precaution to protect the personal data of their employees, whether that information is held in a government database or not. Not only is it the right thing to do, it’s just good business. After all, our employees are our most valuable asset, and taking extra precaution to protect our most valuable asset is an investment that contributes directly to the company’s bottom line.
</p> <br /><i><a href='/Blog/?id=44'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=44Brinda BeasleyWed, 14 Aug 2013 11:35:00 GMTCreating Organizational Agility<p><img alt="Graphic for Organizational Agility | Newberry Group blog" style="float: left; margin-right: 20px; margin-bottom: 20px;" src="/data/images/NewberryBlog/07-2013_NG_Blog_Banner.jpg" />Every upwardly mobile professional has a copy of the Organization Chart within arms-reach - - straight lines and boxes mapping accountabilities and authorities depicting the easy and “sanctioned” routes to get things done. But is this really accurate? Organizations are staffed with<em> people</em>. These people all have their own preferences, insecurities, personal desires and goals hidden behind the boxes on that chart. So there is a big difference between how an enterprise is organized and how it functions. There are friends, foes, good Samaritans, gatekeepers, resisters, expediters, naysayers, influencers, etc., etc. The organizational “Chart” is a maze of personalities and ambitions at best. The key to success is to accept this reality, not resist it, and work diligently to become a “maze bright” person in the organization. As discussed last time, this starts by working hard to develop effective peer relationships but as described by <a target="_blank" href="http://www.lominger.com/about.aspx">Lombardo & Eichinger</a> and others, there are additional approaches you should use to become truly agile within your organization:</p>
<p>
</p>
<p><strong><span style="font-size: 16px; color: #1f497d;">Practice #1:</span></strong> <strong>Become more self-aware.</strong> Try and do the most honest self-assessment of your skills “getting it done” in your organization. Identify at least one person within each group you work with and ask them for feedback what you could do better working with that group.</p>
<p><strong><span style="font-size: 16px; color: #1f497d;">Practice #2:</span></strong> <strong> Pay attention to how the “Movers and Shakers” behave.</strong> If things you are doing appear to not be working, try things you generally don’t do that have proven successful for others. You have to look beyond the surface and see what is going on in the background. Who do others rely on to expedite things? Who are the major gatekeepers who control resources and information? Who appear to be the guiders and helpers? These are people you need to know better.</p>
<p><strong><span style="font-size: 16px; color: #1f497d;">Practice #3:</span></strong> <strong>Think equity.</strong> Understand the <em>persona</em>l “balance of trade” within the organization. Don’t just ask for things; find some common ground where you can provide help, not just ask for it. What do people need in the way of problem solving or information? How does what you’re working on impact them? What can you “trade” in return?</p>
<p><strong><span style="font-size: 16px; color: #1f497d;">Practice #4:</span></strong> <strong> Patience.</strong> Some people know the channels to work and the steps to follow to get things done but are too impatient to follow the functional “people-driven” informal process. Developing the ability to maneuver through the organizational maze includes giving things time to run their course; taking deep breaths; and practicing serious self-control. Don’t get frustrated, lose your cool and force the agenda. Focus instead on diagnosing new paths and developing counter-moves if things really are not moving. Be mindful that personal the bridge you burn today, you may desperately need in the future.</p>
<p>Make no mistake, becoming “Maze Bright” and organizationally agile is not easy. That said, once mastered, the dividends are tremendous. You will be seen as a person who get things done where other fail, as someone who is committed to the organization and the good of others as well as yourself. Most importantly, you will find that no skill is more respected by your team. When you can go off into the wilderness of the organizational maze and consistently come back with results that benefit your team and make their professional lives easier, their loyalty is assured. Further, the knowledge gained by developing this skill within yourself will allow you to truly build and prepare your team to perform most effectively in the future. I look forward to discussing this critical skill next time.</p> <br /><i><a href='/Blog/?id=43'>Click here</a> for more information.</i><br/>Employee Ownerhttp://www.newberrygroup.com/Blog/?id=43Christopher SteinbachThu, 18 Jul 2013 10:04:00 GMTSocial Media in the Cyber Security Space<p><img src="/data/images/NewberryBlog/06-2013_NewberryBlog_Banner_v2.jpg" style="float: left; margin-right: 20px; margin-bottom: 10px;" alt="Social Media in the Cyber Security Space | Ryan Steinbach | Newberry Blog" />Last fall, I started as an intern at the Newberry Group with objectives of assessing the impact of growing a social media presence, developing a strategy for social media use and executing on that strategy. After nine months, my team and I accomplished these objectives and learned a great deal about the cyber security digital community in the process. </p>
<p>In my relatively short, but deep dive into social media strategy and development over the last two and a half years, I’ve witnessed how different the digital communities can be. The cyber security digital community is particularly fascinating. My team found that cyber security professionals tend to fall into two buckets when it comes to social media. There are those who embrace social media due to their above average understanding of its utility, and there are those who avoid it at all costs due to their above average understanding of the risks associated with it. </p>
<p>This creates an interesting obstacle when engaging with the cyber security digital community. The space expects a sophisticated level of engagement, yet can also feel fragmented and reserved. It seems most companies have accepted that they need to be present on social media but there are huge disparities in utilization. Some online presences are merely place holders while others are hosting weekly webinars. </p>
<p>My team at Newberry decided the greatest value was between these two extremes. We saw opportunities for talent sourcing, service promotion, and partnership development, but we also needed to be realistic about the amount of capacity we could commit to these efforts. The value is there to be had, but only with the people and buy-in to capture it effectively. </p>
<p><img src="/data/images/NewberryBlog/06-2013_NewberryBlog_EngagingInSocial.jpg" style="float: right; margin-bottom: 10px; margin-left: 20px;" alt="Social Media Engagement | Newberry Blog" />We knew we didn’t have the capacity to be active in every space or create a large amount of unique content so we focused our efforts on building out the spaces we felt had the most value and created a content strategy that balanced quality and thought leadership with consistency and practicality. </p>
<p>Creating a social media policy also became a critical element of our strategy. The greatest enemy of engagement is uncertainty and, in a space as sensitive as the cyber security community, assessing the appropriateness of a 140 character tweet will likely lead to abandonment. We want to be as explicit as possible about our internal expectations for social media because we believe it will remove that uncertainty and foster greater internal engagement.</p>
<p>The development of a social media strategy and policy that balanced value with capacity is the product of what has become my biggest take away from my time at Newberry. I’ve learned that the benefits of social media do not appear over night. Early wins can be few and far between. But, sustainable and consistent execution of social media builds equity in a digital community that eventually translates into real company value. </p>
<p>This kind of sustainability requires a hard look at where a company can be most effective and then tailoring that to the company’s internal capacity. Instead of leaving social media to the intern as many companies do, my team decided early on that there was no point in me doing any of the day-to-day social media work. Instead, I focused on strategy and setting up Newberry’s internal structure – things that once set in place can be utilized with minimal maintenance.</p>
<p>I’m confident that as I leave Newberry my work will be appreciated, not missed. I’ve helped give Newberry the tools to continue to build value in the cyber security digital community on their own. While this was not part of the three original objectives I had going into the internship, I believe it is by far the most valuable and can serve as an example to others in the space.</p> <br /><i><a href='/Blog/?id=42'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=42Ryan SteinbachTue, 11 Jun 2013 10:26:00 GMTDeveloping Effective Peer Relationships<p><img style="margin-bottom: 20px; float: left; margin-right: 20px;" alt="Developing Effective Peer Relationships graphic | Newberry Group Blog" src="/data/images/NewberryBlog/05-2013_NG_Blog_Banner_PeerRelationships.jpg" longdesc="Developing Effective Peer Relationships graphic | Newberry Group Blog" />Being “Action Oriented”, having “Career Ambition”, being excellent at fostering a “Boss Relationship”, maintaining “Customer Focus”, and excelling at “Directing Others” are critical to growing into a management role and being effective in that role. However, these vital competencies can often get in the way as one moves from being an effective <em><strong>manager</strong></em> to becoming an effective <em><strong>leader</strong></em>. Career growth early in one’s profession often is dependent on being effective “up and down”. Building trust and credibility with clients and bosses (up), and effectively directing those junior to you (down) to achieve superior results is of paramount importance. However, as one’s responsibility begin to expand to support scale within an organization it is imperative that individuals begin to work “across” and foster effective peer relationships. Learning to work “across” is in fact the essence of organizational <em><strong>leadership</strong></em>. Leaders are able to achieve positive results for the organization even when they do not have direct power and control over all resources involved in the activity. Leaders are able to work through <em><strong>influence</strong></em>; trading on mutual respect and goals, share credit and rewards, and build and grow trust. This highly valued ability leads to a more efficient use of time and resources by easing the exchange of ideas and talent across the organization. Managers direct their people. Leaders make the whole organization better. Certainly this requires putting one’s ego on the back-burner but the rewards for those that do are huge. You become recognized for being someone that can work and be effective well beyond your direct span of control for the good of the organization. How do you make this transition? Fortunately, Lombardo & Eichinger and others offer some suggestions:</p>
<p><strong><span style="color: #1f497d; font-size: 16px;">Practice #1: </span>Curb your Competitive Nature.</strong> If peers see you as excessively competitive, they will work to cut you out of the loop and sabotage your efforts to work across organizational boundaries. Always offer an explanation for your thinking and invite others to explain their point of view. Resist “staking out a position” and focus on generating a variety of possibilities. Invite, and accept, criticism of your ideas.</p>
<p><span style="color: #1f497d; font-size: 16px;"><strong>Practice #2:</strong></span> <strong>Separate working smoothly with peers from personal relationships.</strong> Remember, you are not forming friendships, you are avoiding “one-upsmanship” and the “not invented here” phenomenon in all your organizational interactions. You are keeping your ego and pride in check for the good of the organization. That is the reputation you seek to build. You don’t have to “Like” everyone.</p>
<p><span style="color: #1f497d; font-size: 16px;"><strong>Practice #3:</strong></span> <strong>Avoid the water cooler banter.</strong> If a peer does not play fair, avoid talking about it with others. Talking about conflicts with others will often backfires on you by undermining the trust you are attempting to build with other peers. Confront the peer directly, privately, and politely and give them a chance to save face. Explain the unfair situation and its impact on you. Even if you don’t totally accept what is said, you have set the stage for an improved relationship going forward. More importantly, you will reinforce your reputation as a person who can be trusted even when there is a conflict.</p>
<p><span style="color: #1f497d; font-size: 16px;"><strong>Practice #4:</strong></span> <strong>Keep a balanced Scorecard. Watch out for “winning” too much</strong>. Look for appropriate opportunities to grant concessions you can live with even if they are not what you wanted ideally. You want to foster a desire in others to work with you again and again. If you are seen as leader who has a strong point of view but is willing to cooperate and compromise with others that favor will be returned when it matters most. You will create an army of influential peers who are all to ready to support your position because you supported theirs in the past even when you did not totally agree.</p>
<p>Make no mistake; learning to achieve results through influence alone is a tough skill to master for ambitious people. However, the fact remains that those who leave positive impressions get more things done more efficiently than those who leave cold impersonal impressions. Learning how to build and sustain peer relationships is the cornerstone for developing organizational agility. I look forward to discussing this this vital skill next time.</p> <br /><i><a href='/Blog/?id=41'>Click here</a> for more information.</i><br/>Employee Ownerhttp://www.newberrygroup.com/Blog/?id=41Christopher SteinbachTue, 14 May 2013 11:20:00 GMTSocial Engineering through Social Networking: Defending Your Organization<p><img style="width: 275px; margin-bottom: 20px; float: left; height: 197px; margin-right: 20px;" alt="Newberry Blog - Defending Your Organization graphic" src="/data/images/NewberryBlog/04-2013_Blog_Banner.jpg" /><strong>Human beings are the weakest link in data protection.</strong> Social networking has made this weakest link, even weaker. Social engineering continues to be one of the most leveraged attack vectors for targeting an organization’s electronic data or IT systems. Historically, a social engineering attempt would consist of an unsolicited phone call or e-mail. Attackers would attempt to obtain reconnaissance-related information from an unsuspecting employee or get them to click a link, or download an e-mail attachment, that would introduce malware to the system, potentially allowing backdoor access to the network. As users have become more educated on information security, they have learned not to open attachments or click links from individuals they do not know or trust. However, with the continued growing popularity of social networking, potential attackers can perform a more targeted social engineering attack that exponentially increases their level of possible success. </p>
<p>One piece of information typically found in social networking profiles is employment information. A quick search on LinkedIn or Facebook can reveal a list of potential social engineering targets for just about any organization. By using the information found in the target’s profile, the attacker can craft an e-mail that looks legitimate and includes an attachment or link containing malicious software. If an attacker determines the target worthy, they may even establish a false profile reflecting similar interests and befriend the employee, allowing them to eventually introduce the malware through an e-mail or link. </p>
<p>Since it is not feasible to control and monitor what employees put on their personal social networking profiles, how can an organization appropriately defend against this type of attack?</p>
<p><strong><span style="font-size: 16px;"><img style="width: 100px; float: left; height: 100px; margin-right: 20px;" alt="Newberry Blog - User Education graphic" src="/data/images/NewberryBlog/04-2013_NG_UserEducation.jpg" />1. User Education:</span></strong> This has been, and always will be, the most effective tool for combating social engineering. In addition to the typical IT security training provided by most organizations today, users should be educated on what company information is appropriate for disclosure on social networking sites and how this information could be used to exploit them. Employees should understand that individuals they make contact with online should not be considered a trusted contact. E-mail attachments or hyperlinks from these online contacts should not be accessed from company-owned computers. </p>
<p><strong><span style="font-size: 16px;"><img style="width: 100px; float: left; height: 100px; margin-right: 20px;" alt="Newberry Blog - Policy and Procedures graphic" src="/data/images/NewberryBlog/04-2013_NG_Policy.jpg" />2. Policy and Procedures:</span></strong> Organizations should prohibit employees from using, or listing, their company e-mail addresses on social networking sites. If the social networking sites are a means for networking or marketing and part of official job duties, then look at establishing a generic e-mail account with increased security restrictions that the employee can utilize. This will allow the employee to identify any contact that is made through the site and treat it as untrusted. </p>
<p><strong><span style="font-size: 16px;"><img style="width: 100px; float: left; height: 100px; margin-right: 20px;" alt="Newberry Blog - Security Infrastructure graphic" src="/data/images/NewberryBlog/04-2013_NG_SecurityInfrastructure.jpg" />3. Security Infrastructure:</span></strong> A reputable web proxy with malware scanning capabilities should be utilized to scan web traffic for potential malware. URL filtering should be enabled and sites that contain known malicious code or malware blocked. Social networking sites should also be restricted for users that do not have a business purpose for visiting them. URL filters typically have groups of sites that are categorized and updated to make this process easy. Finally, a spam filter device or service should be used to scan inbound e-mail for malware and filter unwanted e-mail. Some spam filtering devices also have the capability to scan outbound e-mail for sensitive information such as social security or credit card numbers; this is commonly referred to as Data Loss Prevention (DLP). </p>
<p>With employees advertising more personal information on social networking sites, we can expect to see a continued increase in targeted social engineering attacks. As with any security threat; a layered defense strategy is the best defense against social engineering attacks. </p> <br /><i><a href='/Blog/?id=40'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=40Steven CarneyTue, 16 Apr 2013 12:15:00 GMTMaking Quality Decisions <p><img style="width: 350px; margin-bottom: 20px; float: left; height: 250px; margin-right: 20px;" alt="Making Quality Decisions Graphic" src="/data/images/NewberryBlog/03-2013_NG_Blog_Banner.jpg" /><strong>You have worked hard to become a confident decision maker, </strong><a href="http://thenewberrygroup.com/Blog/Default.aspx?id=38" title="Dealing With Ambiguity | Newberry Blog" target="_parent" shape="rect"><strong>even in the face of ambiguity</strong></a><strong>.</strong> How do you ensure that you hit the target more often than not and, more importantly, get closer and closer to the bull’s-eye over time? You must practice. Making good decisions requires the right amount of patience, humility, and ice cold nerve to step up and make the call. As I discussed last month; no one is right all the time, it’s being more right than wrong over time that matters. You must develop a highly refined sense for the right amount of data, analysis, intuition, wisdom, experience, and judgment required for each decision opportunity. <a href="http://www.lominger.com/about.aspx" title="Lominger Website" target="_parent" shape="rect">Michael Lombardo and Robert Eichinger</a> and others have proposed some ways to refine that “6th Sense” that is so recognizable in people renowned for their decision quality. A few of my favorites include:</p>
<p><strong><span style="color: #1f497d; font-size: 16px;">Practice One: </span>Know your biases</strong>. We all have them; attitudes, beliefs, opinions, prejudices, favorite solutions or ways of doing things. The key is to not let them influence your cold objective point of view. Before you make any significant decision, step away. Examine your motives; look at your past decisions; talk through the consequences of various decisions with a trusted third party. Look for patterns. Do I see every problem as a nail demanding a hammer as a solution? A great decision maker is constantly, humbly, examining the source of his intuition and challenging himself to recognize each problem as new while eliminating his own prejudices and biases. Much of what we learn is relevant to the next problem, but a lot is not. Work to know yourself first, then the problem, and then decide.</p>
<p><span style="color: #1f497d; font-size: 16px;"><strong>Practice Two:</strong></span> <strong>Holster your gun and sleep on it.</strong> Life is a balance between waiting, and doing. Clearly in business a premium is placed on doing over waiting. However, decision quality can often be greatly improved with just a small amount of additional data and/or reflection. Challenge yourself to gather one more piece of data relevant to a meaningful “Why?” question. Let the subconscious brain aid your efforts. Get a good night’s sleep and get back to it in the morning.</p>
<p><strong><span style="color: #1f497d; font-size: 16px;">Practice Three: </span>Understand the difference between “Thinking”, “Understanding”, and “Knowing” when defining a problem</strong>. Do you ever represent (or more accurately, <em>misrepresent</em>) as fact your personal assumptions or the opinions of others using the expression “I know that…”? I personally believe this common tendency of people, to mischaracterize personal thoughts and the conjecture of others as “known” facts, is the leading cause of poor decision making. There is a very simple formula to get out of this trap: When you “think” something (created between your own two ears), seek validation from a credible third party or obtain first-hand knowledge of the critical facts. When you “understand” something from a credible third party, seek first-hand knowledge of the critical facts. Only when you “know” the critical facts through direct first-hand exposure - - act.</p>
<p>So quality decision making is born first of self-knowledge. Being humble enough to examine our motives and tendencies as a starting point and building a framework of the problem through careful consideration and seeking to understand cause and effect; asking “Why?” a lot, as we discussed last month. The final step is to have the patience to seek relevant data and most importantly having the guts to seek first-hand knowledge of the most critical facts. In doing so, you elevate your perspective and attain that “6th Sense” for the right call. You will become recognized as someone who is willing to own their decisions and the basis upon which they are made. And that is the first building block for effective peer relationships and effective team building, which are the essence of leadership. I look forward to discussing those skills next time.</p>
<p> </p>
<p> </p> <br /><i><a href='/Blog/?id=39'>Click here</a> for more information.</i><br/>Employee Ownerhttp://www.newberrygroup.com/Blog/?id=39Christopher SteinbachTue, 12 Mar 2013 09:22:00 GMTDealing with Ambiguity<p><strong><img style="margin-bottom: 20px; float: left; margin-right: 20px;" alt="Graphic of words: Dealing with Ambiguity" src="/data/images/NewberryBlog/02-2013_NG_Blog_Banner.jpg" />How does one survive - - and thrive - - in this modern world?</strong> In my experience, it starts with learning how to effectively deal with ambiguity. This critical skill, which I introduced at the end of <a href="http://www.thenewberrygroup.com/Blog/Default.aspx?id=37" title="Building Culture through a Common Language by Chris Steinbach" target="_parent" shape="rect">my last post</a>, is important because; congressional leaders are unable to make tough budget decisions; good people can sometimes do bad things while bad people can also do amazingly good things (consider Lance Armstrong); Getting great at anything runs straight through being awful at it; The solution for today’s problem may not be the solution for tomorrow’s problem. In fact, for 90% of business it’s not clear what the problem even <em><strong>is</strong></em>, let alone what the solution could be; the only constant is change. We live in a “grey” ambiguous modern world. </p>
Let’s be honest. Most of us would prefer to be 100% sure - - about everything! We prefer to know <em><strong>everything</strong></em> that is going on around us because it makes us feel like we are in control. Most of us get really uncomfortable if we can’t wrap up everything we start into nice neat packages with a bow on top. Unfortunately, the cold truth is that success and rewards go to those who develop the ability to make more good decisions than bad in less time than the other guy, using impartial information and few if any precedents or examples of how similar problems were solved before.
<p>Please note that I did not say “make only good decisions...” I said “make more good decisions than bad...” All successful people today have learned to live <em>comfortably</em> in the “Grey Space” by cultivating a well-developed tolerance for errors and mistakes - - both for ourselves and <em><strong>others</strong></em> - - and absorbing the heat and criticism that might follow. </p>
<p>Make no mistake, this is a tough but extremely valuable skill to learn and develop. In the words of English Statesman George Savile - - “He that leaveth nothing to chance will do few ill things, but will do very few things.” And we all know that “doing very few things” just won’t cut it in today’s world of work - - and especially not in a dynamic, energetic, and empowered culture like we have here at Newberry Group. We must learn to thrive and act effectively in the “Grey Space”. So how do we learn and develop this tough skill and effectively deal with ambiguity? Michael Lombardo and Robert Eichinger propose some of the following in their book “<a href="http://store.lominger.com/store/lominger/en_US/pd/ThemeID.2815600/productID.127293400?resid=URpV9QoBAlcAAAnzCMwAAAB0&rests=1360680437211" title="For Your Improvement | Lominger.com" target="_parent" shape="rect">For Your Improvement</a>”:</p>
<p><strong><span style="color: #1f497d; font-size: 16px;">Practice One:</span></strong> <strong>“Incrementalism”.</strong> Research indicates that we do not grasp the essence of a new problem until the second or third attempt at solving it. Plan on making a series of small decisions, get feedback, correct course, and get a little more data moving forward until you have solved the problem. Start small so you can recover quickly and build confidence that you can “handle the heat” and course correct. You will not build this confidence if you start with “the” problem.</p>
<p><strong><span style="color: #1f497d; font-size: 16px;">Practice Two:</span> Recognize your Perfectionism for what it is - a roadblock to success</strong>. Perfectionism is born of an obsessive need to collect more information than the other guy, thus limiting your personal risk. Try to decrease your need for data and your need to be right a little every week. Pick small decisions and try to act on them with little or no data at all, trusting your gut. As discussed before, the real test in the world of business is who can make a good decision on limited or no data in a reasonable time frame. That takes practice so start with the small stuff - - you will likely be surprised how often you are right. (And if you find that you’re not more right than wrong, you need to read next month’s blog :).)</p>
<p><strong><span style="color: #1f497d; font-size: 16px;">Practice Three:</span> Ask “Why?” a lot.</strong> Evidence from decision-making research makes it clear that the better your problem definition, the better chance you have at finding the solution quickly. Focus on causes, not fixes. <a href="http://www.isixsigma.com/dictionary/5-whys/" shape="rect">http://www.isixsigma.com/dictionary/5-whys/</a></p>
<p><strong><span style="color: #1f497d; font-size: 16px;">Practice Four:</span> Develop a philosophical stance toward failure/criticism.</strong> Learn to crave feedback. The faster and more frequent the feedback on small problems the faster and greater our learning. Teach yourself by letting others “off the hook” when a mistake is made by focusing on what we can learn from the mistake, not the consequence. In doing so, you will bolster your own ability to handle failure and criticism.</p>
<p><strong><span style="color: #1f497d; font-size: 16px;">Practice Five:</span> Become Process focused, not results focused.</strong> To work well in uncertain times means that you must recognize first and foremost that your work is never done. If the only constant is “change” then that constant will demand that you jump from incomplete project to incomplete project. You must alter your internal reward structure so that you feel good about moving things forward incrementally instead of finishing it. In taking this approach, you will not only cease to be easily frustrated, you will also find that the critical few things that need to be finished – in the sea of insignificant many things - will be. Trust that “through the process” the results desired will be derived from completing the critical few, not everything you start.</p>
<p>Working to develop your ability to deal with ambiguity will give you the will to confidently act when information is limited. But like every well-developed competency, its over-use can become a weakness if relied upon too often or worse, exclusively. A complete person or a complete organization fosters complementary competencies that provide balance and assure that strengths don’t become weaknesses. One of the strongest complementary competencies for those that are comfortable with ambiguity is a strong sense for what is, and is not, a quality decision. Developing this critical competency in our culture will be the topic next month!</p> <br /><i><a href='/Blog/?id=38'>Click here</a> for more information.</i><br/>Employee Ownerhttp://www.newberrygroup.com/Blog/?id=38Chris SteinbachTue, 12 Feb 2013 09:04:00 GMTBuilding Culture through a Common Language<img style="margin-bottom: 20px; float: left; margin-right: 20px;" alt="Wordcloud graphic of Lominger Competencies" src="/data/images/NewberryBlog/12-2012_NG_Blog_Banner.jpg" />In today's intensely competitive environment it is critical that organizations establish and sustain a corporate culture that reinforces the behaviors most important to maintaining a distinct competitive advantage. The cornerstone of corporate culture is effective communication but how do you ensure that all are receiving the same message when you are talking about something as "soft" as organizational or individual behaviors? When we say "patience", or "perseverance", or "compassion" what do these words mean in the context of the workplace and how do we ensure that all hear the same meaning? Well, you have to establish a common language for the discussion of these "soft" skills, these competencies. By establishing that common language, all are clear on which "behaviors" individuals are expected to be competent and in turn are valued by the organization for their contribution to organizational effectiveness and competitive advantage. <br />
Fortunately, considerable research has been done over the years with respect to those behaviors most likely to lead organizations and people down the path toward success. This research has produced a number of useful behavioral frameworks, taxonomies, of desired and undesirable behaviors in individuals and organizations. I was fortunate enough to be exposed to one of the more popular and widely used behavioral taxonomies early in my professional career, the Leadership Architect, developed by <a href="http://www.lominger.com/about.aspx" shape="rect">Mike Lombardo and Bob Eichinger</a>. The Leadership Architect defines 67 competencies found in the most successful people and organizations. In fact, I was certified in the use of this tool for facilitating organizational development and culture building, and as a tool to promote individual professional growth and development. However, the art in successfully using such tools is in clearly determining and communicating which of the many "desirable" behaviors are most important to a particular organization at a particular place in time.<br />
In this series I will introduce those competencies most vital to Newberry's success over the next 36 to 60 months. I will endeavor to explain the competency, it's relevance to our business today and offer suggestions on developing or becoming more skilled in the desired competency. It is my desire to contribute to the development of our own cultural framework for success by starting the dialogue about how our behaviors will shape our future success. It is important to remember that as the market evolves so should the competencies of the organization. What is important today may not be important tomorrow. Which leads us to our first competency - - Dealing with Ambiguity; and our first developmental lesson.....chat soon. :-) <br /><i><a href='/Blog/?id=37'>Click here</a> for more information.</i><br/>Employee Ownerhttp://www.newberrygroup.com/Blog/?id=37Christopher J. SteinbachMon, 17 Dec 2012 08:16:00 GMT5 Tips for Building a Cyber Security Career<p><strong><img style="width: 245px; margin-bottom: 10px; float: left; height: 175px; margin-right: 25px;" alt="IT career seeker" src="/data/images/NewberryBlog/11-2012_NG_Blog_Banner.jpg" /><span style="font-size: 16px;">The cyber security field is rapidly expanding to deal with the accelerated risks of changing technology and now is a great time to make the move into a security career.</span></strong> However, not only do you need the qualifications, but also an analytical mindset and good communication skills to effectively convey your expertise to the wide range of customers. Cyber security experts are always chasing an elusive problem and you have to think outside the box quite a bit to find that advanced persistent threat. Here are five tips on how to build your successful career: </p>
<h2><span style="color: #000000;">1. Develop a Solid IT Foundation</span></h2>
<p>In the case of cyber security, it's really beneficial to have a strong background in information technology. A lot of universities have modified curriculum to provide security focused-degrees. Previously you might have been restricted to computer science or information technology, but now there are actual degrees tailored around computer security. These programs are often sponsored by entities that are focused on cyber security and want to help build the workforce. For example, currently the U.S. government has a shortfall of cyber security professionals. So they have started working with universities to establish these programs to help grow the cyber security field and fill the jobs that they know will be out there.</p>
<h2><span style="color: #000000;">2. Get Certifications and Training</span> </h2>
<p><img style="margin-bottom: 20px; float: right; margin-left: 20px;" alt="Certifications" src="/data/images/NewberryBlog/11-2012_NG_Certifications.jpg" />Certifications are necessary because they establish a foundation. They identify the individuals that have put in the time and effort to understand the fundamentals of cyber security. The <a href="https://www.isc2.org/cissp/default.aspx" title="CISSP certification website" target="_blank" shape="rect">CISSP</a> certification is a well-known and internationally recognized security certification and is a great starting point. But with all the different domains of expertise within the security field, you should hone your craft and acquire certifications for your specific area. </p>
<h2><span style="color: #000000;">3. Use Your Past Military Experience</span></h2>
<p>Today, information technology in the military is no different than it is in the corporate world. There are disciplines within the military that focus on IT and cyber security, so veterans have an opportunity to directly transfer their experience from military service into commercial cyber security work. </p>
<h2><span style="color: #000000;">4. Use Your Existing IT Career</span></h2>
<p>If you've been in IT for a long time and you have a strong background, you have most likely been exposed to security issues. In all reality, you probably have a level of experience that would qualify you to easily transition and adjust to cyber security work without having to start from the ground up. Talk to your peers or managers about what security opportunities are available to you. Also take some personal initiative to start working on a certification in your area of interest. </p>
<h2><span style="color: #000000;">5. Build Up Practical Experience</span></h2>
<p><img style="margin-bottom: 20px; float: right; margin-left: 20px;" alt="Icon - Build Practical Experience" src="/data/images/NewberryBlog/11-2012_NG_Experience.jpg" />At the end of the day, just like in any field, you need the qualifications and the practical experience. And you have to work your way up. Unless you have a lot of applicable experience, expect to start at the bottom and prove yourself so that you have the evidence to put in your resume. Certifications are great because they establish a foundation through the training, but practical experience is just as important. If you don't have the experience, be forthcoming about it, but also have the wherewithal to press forward with developing your career. </p>
<h2><span style="color: #000000;">Are there jobs out there?</span></h2>
<p>There is a wide range of cyber-related jobs and almost every industry will have availability whether it's on the commercial side or federal side. In some cases, a cyber opportunity might be there, it just might be coupled with 2 or 3 other roles at the same time; You might be the cyber expert and the IT guru. Newer fields within information technology or security, such as cloud security, mobile security, digital forensics, and malware analysis, are all hot domains so you'll see a lot of opportunities advertised. However, no area in cyber security has lost momentum. Cyber security as a whole is a hot industry to be in, and I predict it to be so for the next couple of decades. It's not slowing down. </p>
<p> </p> <br /><i><a href='/Blog/?id=35'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=35Phillip Justice, Jr.Mon, 19 Nov 2012 09:57:00 GMTOctober is National Cyber Security Awareness Month (#NCSAM)<p><a href="http://www.staysafeonline.org" target="_blank" shape="rect"><img style="margin-bottom: 20px; float: right; margin-left: 20px;" alt="National Cyber Security Awareness Month" src="/data/images/NewberryBlog/banner%20300x250.gif" /></a>We’re one of the official champions of National Cyber Security Awareness Month (NCSAM) and there’s still time to get involved! National Cyber Security Awareness Month is a campaign focusing on the need for improved online safety and security for all Americans. The National Cyber Security Alliance has sponsored National Cyber Security Awareness Month every October since its founding in 2003. </p>
<h2>This year’s theme is “Our Shared Responsibility.” So how can you help?</h2>
<h3>1. Share Tips and Resources with Your Friends and Family</h3>
<p>The <a href="http://www.staysafeonline.org/" target="_blank" shape="rect">National Cyber Security Alliance</a> (NCSA) website is full of tips on how to protect your personal information, teach online safety, and keep your business safe online. Would you know what to do if your <a href="http://www.staysafeonline.org/stay-safe-online/keep-a-clean-machine/hacked-accounts" target="_blank" shape="rect">accounts were hacked</a>? Do you need resources to help <a href="http://www.staysafeonline.org/teach-online-safety/" target="_blank" shape="rect">teach cyber security</a> in your classroom? Does your small business have a <a href="http://www.staysafeonline.org/business-safe-online/implement-a-cybersecurity-plan/" target="_blank" shape="rect">Cyber Security Plan</a>?<br />
<strong>Find resources and tips on</strong> <a href="http://www.staysafeonline.org" shape="rect">www.staysafeonline.org</a>.</p>
<h3>2. Attend An Event and Share It!</h3>
<p>Organizations all across the United States are hosting cyber-related events to help raise awareness. </p>
<ul>
<li>Find an event in your area on the Events page: <a href="http://www.staysafeonline.org/ncsam/events" shape="rect" originalPath="http://www.staysafeonline.org/ncsam/events" originalAttribute="href">www.staysafeonline.org/ncsam/events</a> </li>
<li>Stay at your computer and check out these FREE Webcasts from SANS: <br />
<strong>Securing The Human <br />
Oct 16th</strong> and <strong>Oct 30th<br />
</strong>Register on their website: <a href="http://www.securingthehuman.org/blog/2012/09/06/three-security-awareness-webcasts-for-oct/" shape="rect">http://www.securingthehuman.org/blog/2012/09/06/three-security-awareness-webcasts-for-oct/</a> </li>
</ul>
<p>Newberry Group is proud to be a part of National Cyber Security Awareness Month. Anyone can help raise awareness in their community, let’s continue to help others stay safe online!</p>
<p>To learn more about the National Cyber Security Alliance, visit <a href="http://www.staysafeonline.org" shape="rect">www.staysafeonline.org</a>.</p> <br /><i><a href='/Blog/?id=34'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=34Newberry Marketing TeamMon, 15 Oct 2012 17:55:00 GMTUnderstanding the ‘Why?’ in B2B Social Media<p><img style="width: 300px; margin-bottom: 20px; float: left; height: 215px; margin-right: 20px;" alt="Newberry Group Blog | Social Media Icons" src="/data/images/NewberryBlog/09-2012_Blog_Banner.jpg" />Last January I came across this post by Brad Friedman, <a href="http://socialmediatoday.com/bradfriedman/424216/build-your-social-media-schedule-2012" target="_blank" shape="rect">Build Your Social Media Schedule For 2012</a>. He explains that while more and more business are getting into social media marketing, many get into it for the wrong reasons. I came across this post while skimming through an abyss of opinions on ‘Social media resolutions for 2012.’ What caught my attention was this:</p>
<p><em><strong>Start with the – "Why?"</strong></em></p>
<p>Intrigued, I went back and took the time to reflect on what Brad had to say. Early in the post, he gets right to the source of most ineffective social media marketing. </p>
<p><em><strong>Are you involved with social media to boost your ego?</strong></em></p>
<p><em><strong>…do you just want to promote yourself or your product all the time? </strong></em></p>
<p><em><strong>Did you join…because ‘Everyone I know is on …?’</strong></em> </p>
<p><img style="width: 125px; margin-bottom: 20px; float: right; height: 125px; margin-left: 20px;" alt="Newberry Group Blog | Sharing content" src="/data/images/NewberryBlog/09-2012_sharing_right.jpg" />Brad encourages us to evaluate ‘why’ – our motivations for using social media. Unfortunately, not much has changed in the last 9 months. As more research supports <a href="http://www.mckinsey.com/insights/mgi/research/technology_and_innovation/the_social_economy" target="_blank" shape="rect">the benefits of social media in business</a>, more companies are joining social networks, creating blogs, and hiring social media staff. Although no manager will admit it, their motivations are often as unjustified and misaligned as the questions listed above, and with no consideration of the information security implications. In order to reap the benefits of social media and use it in a way that is safe for the company and its employees, a more comprehensive approach is required. </p>
<p><img style="width: 125px; margin-bottom: 20px; float: left; height: 146px; margin-right: 20px;" alt="Newberry Group Blog | image of puzzle" src="/data/images/NewberryBlog/09-2012_strategy.jpg" />This begins with an evaluation of the business model, value chain, and internal as well as external communication channels. Understanding the information security risks of social media use and, more importantly, <em>how to mitigate these risks</em> is also a critical yet often overlooked step. Once the institutional framework is in place, a company can begin identifying opportunities for social media, developing metrics for evaluating performance, and, finally, implementing social media into business operations. Even if a social media strategy is working for competitors, it doesn’t mean that strategy, or even social media in general, is going to be effective. </p>
<p>The staff at <a href="http://www.newberrygroup.com" target="_blank" shape="rect">Newberry Group</a> understands this and has given me the opportunity to research and prove an opportunity for social media in their business model. As a social media intern, I’ll be developing a business case for social media use at the Newberry Group. I’m excited by this opportunity, not only because I have a deep interest in B2B social media development but also, because I believe my role is a fundamental step that every business should take, even if it is already engaging social media. </p>
<p>I hope to share some of my work and findings in subsequent blog posts over the next few months. If you have any thoughts on, contributions to, or questions about my work, please do not hesitate to email me: <a href="mailto:[email protected]" shape="rect">[email protected]</a> or shoot me a tweet: <a href="http://twitter.com/r_steinbach" target="_blank" shape="rect">@R_Steinbach</a> (note: tweets are my own and in no way reflect the views or opinions of Newberry Group)</p> <br /><i><a href='/Blog/?id=33'>Click here</a> for more information.</i><br/>Information Technologyhttp://www.newberrygroup.com/Blog/?id=33Ryan SteinbachThu, 20 Sep 2012 12:40:00 GMT5 Tips to Get Your Data and Computer Storm-Ready<span style="font-family: helvetica;">
<p><img style="margin-bottom: 20px;" alt="Newberry Group Blog - storm image" src="/data/images/NewberryBlog/08-2012_Blog_Banner.jpg" /><br />
Hurricane season is upon the southern United States and now is a good time to make sure your data and computer is prepared for an emergency too. Here are some tips to get you started:</p>
<ol>
<li>
<p><strong><span style="color: #0070c0;">Backup your data with an online backup service</span></strong> - There are many online backup services to choose from. This <a href="http://www.pcmag.com/article2/0,2817,2395766,00.asp" target="_blank" shape="rect">article</a> by <a href="http://www.pcmag.com/article2/0,2817,2395766,00.asp" target="_blank" shape="rect">PC magazine</a> does a great job of outlining the different options available. </p>
</li>
<li>
<p><strong><span style="color: #0070c0;">Copy your User folder (the folder named "Username") to an external hard drive</span></strong> – This will ensure that all of your documents, photos, videos, music, desktop, and application data such as email archives and application preferences are saved. For the ultimate backup, consider making a "snapshot" of your entire computer with a program such as <a href="http://www.acronis.com/" target="_blank" shape="rect">Acronis True Image</a> (PC) or <a href="http://www.bombich.com/" target="_blank" shape="rect">Carbon Copy Cloner </a>(Mac). The "snapshot" will allow you to boot from that hard drive if you had to completely restore your files.</p>
</li>
<li>
<p><span style="color: #0070c0;"><strong>Use a battery backup + surge protector</strong></span> – If you use a desktop computer, a battery backup will provide some buffer time for you to save your files when there is a power outage. Most battery backups also give you the benefit of a surge protector.</p>
</li>
<li>
<p><strong><span style="color: #0070c0;">Plug your cable modem’s coaxial cable into a surge protector</span></strong> – If you use a cable modem and your computer is directly connected to it via an ethernet cord, be sure to plug the coaxial cable into the battery backup. This will help prevent power surges being transferred from the cable, through the ethernet cord, and on into your computer.</p>
</li>
<li>
<p><span style="color: #0070c0;"><strong>Unplug your computer when not in use during a storm</strong></span> – The most certain way to avoid power surge damage is to simply unplug your computer from its power cord.</p>
</li>
</ol>
</span> <br /><i><a href='/Blog/?id=32'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=32Breanna Cooke & Nicholas Trifiletti, contributorFri, 31 Aug 2012 12:19:00 GMTWhy do Nigerian scammers say they are from Nigeria?<span style="font-family: helvetica;">
<h1 style="text-align: left;"><img style="margin-bottom: 20px;" alt="Image of binary code and password" src="/data/images/NewberryBlog/07-2012_Blog_Banner.jpg" /></h1>
<p>Far-fetched tales of West African riches strike most as comical. So why do Nigerian scammers say that they are from Nigeria? Why so little imagination? Why don’t Nigerian scammers claim to be from Turkey, or Portugal, or Switzerland? Stupidity is an unsatisfactory answer: The scam requires skill in manipulation, considerable inventiveness and mastery of a language that is non-native for a majority of Nigerians. </p>
<p>We’ve all seen some form of this "too good to be true" chopped up English type of technique designed to part us from a significant amount of money. However, the <em>initial reaction</em> of a scam-savvy person is just what the attackers are looking for. This scam method relies on a vast numbers game and is examined in <a href="http://research.microsoft.com/pubs/167719/WhyFromNigeria.pdf" title="Cormac Herley's whitepaper: Why Do Nigerian Scammers Say They Are From Nigeria?" target="_blank">Cormac Herley’s whitepaper</a>, <em><a href="http://research.microsoft.com/pubs/167719/WhyFromNigeria.pdf" title="Why Do Nigerian Scammaers Say They Are From Nigeria?" target="_blank"><em>Why Do Nigerian Scammers Say They Are From Nigeria?</em></a>.</em> A researcher at Microsoft, Herley’s analysis delves into the numbers that make these scams work and the gullibility of the victims. Make no mistake, these scammers are smart and they know what they’re doing.</p>
<h2attacks />
<p><img style="margin-bottom: 20px; float: right; margin-left: 20px;" alt="Image of target and money" src="/data/images/NewberryBlog/07-2012_money.jpg" /></p>
<h2><span style="color: #a01c33;">Attacks are seldom free.</span></h2>
<p>Malicious software can accomplish many things but few programs output cash. At the interface between the digital and physical worlds, effort must be spent. Turning digital contraband into goods and cash is not always easily automated. For example, credentials may be stolen by the millions, but emptying bank accounts requires recruiting and managing mules. The end game of many attacks require per-target effort. Thus when cost is non-zero each potential target represents an investment decision to the attacker. He invests effort in the hopes of a payoff. Therefore, he must "qualify" his victims prior to expending significant amounts of resources (time and money) to attain the prize.</p>
<h2><span style="color: #a01c33;">Who is a target and how are they chosen?</span></h2>
<pto />
<p><img style="margin-bottom: 20px; float: right; margin-left: 20px;" alt="Image of target with holes" src="/data/images/NewberryBlog/07-2012_target.jpg" />There are several models of human behavior that illustrate the theory that when large numbers of communications are cast to random recipients, there is a direct relationship to the number of viable targets harvested. The attacker is looking for people gullible enough to respond to the communication. These people make the "short list" and the attacker continues to nurture these targets until all false positives have been eliminated and there are only true positives left. True positives represent a tiny subset of the initial list of random recipients. In addition to a high gullibility trait, true positives must also have money and an absence of any factors that would prevent them from following through all the way to sending the money. </p>
<p>Since gullibility is unobservable, the best strategy is to get those who possess this quality to self-identify. These are the communication recipients who respond. An email with tales of fabulous amounts of money and West African corruption will strike all but the most gullible as bizarre. It will be recognized and ignored by anyone who has been using the Internet long enough to have seen it several times. Therefore, shrewd recipients are in a sense, helping the scammers by inadvertently classifying themselves as non-viable targets merely by the absence of their response.</p>
<p>So how does this approach answer the question in <a href="http://research.microsoft.com/pubs/167719/WhyFromNigeria.pdf" title="Why Do Nigerian Scammers Say They Are From Nigeria">Herley’s title</a>? His answer: By sending an email that repels all but the most gullible, the scammer gets the most promising marks to self-select and tilt the odds in his favor.</p>
<h2><span style="color: #a01c33;">So what…?</span></h2>
<p>You say, "I don’t fall for these Nigerian scams so this won’t affect me." That’s great… AND keep in mind all that was discussed in this article was only one type of scam. There are millions more scams relying on the same gullibility factors of human behavior with the same end game. <strong>We are the weakest link.<br />
<br />
</strong></p>
<span style="color: #000000;">Read the full whitepaper by Cormac Herley here: <br />
</span><span style="font-family: helvetica;"><a href="http://research.microsoft.com/pubs/167719/WhyFromNigeria.pdf">http://research.microsoft.com/pubs/167719/WhyFromNigeria.pdf</a><br />
</span></span> <br /><i><a href='/Blog/?id=31'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=31Diane McClainWed, 11 Jul 2012 09:49:00 GMTJune is National Internet Safety Month<p style="text-align: left;"><img style="margin-bottom: 20px;" alt="Image of padlocks" src="/data/images/NewberryBlog/06-2012_Blog_Banner.jpg" /></p>
<p>Like wearing a bike helmet, staying safe on the Internet is all about taking the right precautions. In celebration of National Internet Safety month, we’re directing you to some resources from the National Cyber Security Alliance’s (NCSA) website. The National Cyber Security Alliance is a non-profit organization that collaborates with the government, corporate, non-profit and academic sectors to empower citizens to use the Internet securely and safely. Visit their site, <a href="http://www.staysafeonline.org" target="_parent">www.staysafeonline.org</a>, for more information and resources.</p>
<h3>Tip Sheets from the NCSA</h3>
<p>The NCSA has put together some tip sheets that are great reminders and can help facilitate Internet safety discussions with your family. Some of the sheets include:</p>
<pncsa />
<ul>
<li><a href="http://www.staysafeonline.org/sites/default/files/resource_documents/Gaming%20Tips%20for%20Parents%20STC.pdf" target="_parent">Online Gaming Safety – Tips for Parents:</a><strong> </strong>Most video games are connected to the Internet whether they are played through an Internet browser or a computer or gaming console. NCSA gives steps on how you can help keep your child’s information safe and be an informed parent. </li>
<li><a href="http://www.staysafeonline.org/sites/default/files/resource_documents/Mobile%20Devices%20Safety%20Tips%20STC.pdf" target="_parent">Mobile Device Safety Tip Sheet:</a><strong> </strong>With apps that access your location, public wi-fi hotspots, and text messages with suspicious links, mobile safety is just as important as on the home computer. These tips serve as a good reminder about how to safely manage your mobile devices. </li>
<li><a href="http://www.staysafeonline.org/sites/default/files/resource_documents/Social%20Networking%20Safety%20Tips%20STC.pdf" target="_parent">Safe Social Networking Tip Sheet:</a><strong> </strong>Taking time to set your privacy settings and being conscious of the personal information you share is what helps keeps social media enjoyable. Go over these tips with your family so that everyone is on the same page about what information should be shared and how to keep accounts secure. </li>
<li><b>For <a href="http://www.staysafeonline.org/tools-resources/tip-sheets" target="_parent">more tip sheets</a>, visit </b><a href="http://www.staysafeonline.org/tools-resources/tip-sheets" target="_parent">www.staysafeonline.org/tools-resources/tip-sheets</a> </li>
</ul>
<h3>Free Security Checkups</h3>
<p>NCSA has provided a list of security vendors who offer <a href="http://www.staysafeonline.org/tools-resources/free-security-check-ups" target="_parent">free online security checkups</a>. Most of these will search for viruses and spyware and will help you keep a clean machine. Check out the list of vendors here: <a href="http://www.staysafeonline.org/tools-resources/free-security-check-ups" target="_parent">www.staysafeonline.org/tools-resources/free-security-check-ups</a></p>
<p>Also, check out the <a href="https://survey2.securestudies.com/wix/p122560761.aspx" target="_parent">Microsoft Computer Safety Index survey</a>. The survey will ask you some questions about your online habits, then will walk you through some steps to check the settings on your computer. (For PC only)</p> <br /><i><a href='/Blog/?id=30'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=30Breanna CookeFri, 22 Jun 2012 10:38:00 GMTYour Digital Footprint: What can you control?<p><img alt="" style="margin-bottom: 10px;" src="/data/images/NewberryBlog/05-2012_Blog_Banner.jpg" /></p>
<h4>Do you know how much of your private information is available to strangers?</h4>
<p>We may be in a digital world but that doesn’t mean that we shouldn’t take precautions with our information. Many of us do not realize how much of our personal information is available to outsiders and how it contributes to our digital footprint.</p>
<h4>What is a Digital Footprint?</h4>
<p>Your Digital Footprint is the information about you or from you (activities, comments, public records) that can be accessed via a digital environment.*</p>
<h4>The 3 Main Sources of Information</h4>
<p>Our personal information is available from a variety of sources and much is out of our control: we don’t have any say in who can access our information.</p>
<h3><span style="color: #c00000;"><strong>1. Public Records</strong></span></h3>
<p><img style="margin-bottom: 15px; float: right; margin-left: 15px;" alt="Newberry Group | Digital Footprint: Image of columns" src="/data/images/NewberryBlog/05-2012_public.jpg" />The Freedom of Information Act was first enacted in 1966 by President Lyndon B. Johnson and supplemented by President Bill Clinton with the Electronic Freedom of Information Act Amendments in 1996.** Some of the information available to anyone as a public record includes: </p>
<ul>
<li>Census records </li>
<li>Consumer protection information </li>
<li>Court dockets </li>
<li>Criminal records </li>
<li>Government spending reports </li>
<li>Legislation minutes </li>
<li>Professional and business licenses </li>
<li>Real estate appraisal records </li>
<li>Sex offender registration files </li>
<li>Voter registration </li>
</ul>
<h3><span style="color: #c00000;"><strong>2. Web Searches</strong></span></h3>
<p><img style="margin-bottom: 15px; float: right; margin-left: 15px;" alt="Newberry Group | Digital Footprint: Image of search bar" src="/data/images/NewberryBlog/05-2012_search.jpg" />Have you ever Googled yourself? Almost anyone can be found online. Someone can find information about you through:</p>
<ul>
<li><strong>Simple search</strong> by name, e-mail or phone number (it gives thousands of results!) </li>
<li><strong>Companies that help you look up anyone</strong> if you can provide some basic information. Many of the results will come back as free searches and then they offer more in-depth information for a fee. </li>
<li><strong>Companies who maintain massive databases</strong> that troll public and government websites for information and sell it to anyone willing to pay. </li>
</ul>
<h3><span style="color: #c00000;"><strong>3. Social Websites</strong></span></h3>
<p><img style="margin-bottom: 15px; float: right; margin-left: 15px;" alt="Newberry Group | Digital Footprint: Social Media" src="/data/images/NewberryBlog/05-2012_social.jpg" />Do you have a Facebook, Google+ or LinkedIn account? Even with extensive privacy settings, there is no guarantee that the information you share won’t get into the wrong hands. A simple status update about being away from home can be an open invitation for a thief. Some of the information you may have shared includes:</p>
<ul>
<li>Home <strong>address</strong> and <strong>phone</strong> number </li>
<li><strong>Dates</strong> for vacation and travel </li>
<li>Photos or “check-ins” of <strong>where you are</strong> </li>
<li><strong>Names</strong> of your family members </li>
</ul>
<h4>What do you want your Digital Footprint to be?</h4>
<p>Take steps to protect yourself and the information that you can actually control. Privacy controls are an important component when interacting with online resources. Regularly reviewing and setting your privacy controls helps limit what is available to the general public. Not everyone will look at the pictures, posts, blogs, likes/dislikes or comments without evil intent. Being aware of what you are putting online and who might see it is the best step in protecting yourself.</p>
<p>* <a href="http://en.wikipedia.org/wiki/Digital_footprint">http://en.wikipedia.org/wiki/Digital_footprint</a><br />
** <a href="http://en.wikipedia.org/wiki/Public_records">http://en.wikipedia.org/wiki/Public_records</a></p> <br /><i><a href='/Blog/?id=29'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=29Valerie RootWed, 09 May 2012 09:59:00 GMTIdentifying and Reporting Suspicious E-mail<p><img alt="" style="margin-bottom: 20px;" src="/data/images/NewberryBlog/04-2012_Blog_Banner_700px.png" /><br />
<span style="font-size: 13px;"><strong>If you are like me, you receive the occasional e-mail that just doesn’t look quite right.</strong></span> It may be from an anxious individual looking for your help to move their recent monetary windfall out of their impoverished country. Or it’s from someone who has a “can’t miss” investment opportunity that just needs some additional capital. Or it’s from someone who is simply looking for a sales quote for a business that just doesn’t look right. While I am sure that none of us have taken that bait, we shouldn’t ignore these suspicious e-mails. We should be reporting them to the Defense Security Service (DSS) and the Federal Bureau of Investigation (FBI). </p>
<h4>How do I know if it’s suspicious?</h4>
<p><img alt="" style="width: 125px; margin-bottom: 15px; float: left; height: 125px; margin-right: 15px;" src="/data/images/NewberryBlog/04-2012_Blog_Virus.png" />Most of us understand that phishing is the act of someone trying to elicit personal information from you so they can exploit you or IT systems/accounts that you have access to. However, what if these e-mails do not ask for anything other than your simple response? Many of the examples above only ask you to respond and, if you do, they will “send you further information.” Once you respond and essentially confirm your e-mail address is active, these devious folks commonly do a number of things. They do as they promise and send a response back that is typically malware or spyware that infects your computer or network. They also typically sell your e-mail address to hackers or spammers who inflict their own damage to your systems.</p>
<br />
<h4>What does DSS and the FBI do?</h4>
<p><img alt="" style="width: 125px; margin-bottom: 15px; float: left; height: 125px; margin-right: 15px;" src="/data/images/NewberryBlog/04-2012_Blog_DSS.png" />The DSS and FBI depend heavily on leads and information from the general public. It is rare for Federal investigation cases to be initiated by the DSS or the FBI. The sources of many of their investigations stem from reports from the general public. To aid in their data collections, we can forward suspected e-mails to them. DSS and the FBI then track these to the source, compile it with other data on file, and determine if an investigation is required.</p>
<br />
<h4>Should I report everything?</h4>
<p><img alt="" style="width: 125px; margin-bottom: 15px; float: left; height: 125px; margin-right: 15px;" src="/data/images/NewberryBlog/04-2012_Blog_Reporting.png" />It is important to keep in mind that not all unsolicited e-mail is malicious. Legitimate companies often send mass e-mails hoping to gather customers. And those lengthy “Terms and Conditions” that we all ignore when signing up for an online service or purchasing software often gives the recipient authority to use your e-mail address as they see fit. Always remember that you should never open any attachments that come from unknown or unexpected recipients.</p>
<br />
<h4>How do I report suspicious e-mails?</h4>
<ol>
<li>Seek the advice of your company’s <strong>Security Officer or IT Department</strong> on how to handle and report malicious e-mails. <br />
<strong><span style="color: #c00000;">OR</span></strong> </li>
<li>Visit the <strong>FBI</strong> website for instructions: <a href="http://www.fbi.gov/scams-safety/e-scams">http://www.fbi.gov/scams-safety/e-scams</a> </li>
</ol> <br /><i><a href='/Blog/?id=28'>Click here</a> for more information.</i><br/>Cyber Securityhttp://www.newberrygroup.com/Blog/?id=28Jerry KennedyWed, 18 Apr 2012 15:45:00 GMTSANS Presentation Webcast PostedEoghan Casey delivered the presentation “Expert Briefing: Mobile Device Forensics Essentials” on behalf of cmdLabs at the SANS WhatWorks in Forensics and Incident Response Summit on July 8. SANS has made this presentation available via webcast at the following URL:<br />
<br />
<a href="https://www.sans.org/webcasts/show.php?webcastid=92648" target="_blank">https://www.sans.org/webcasts/show.php?webcastid=92648</a><br />
<br />
If you have any comments or suggestions regarding the presentation or anything else, please shoot us an e-mail at <a href="mailto:[email protected]">[email protected]</a>. <br /><i><a href='/Blog/?id=26'>Click here</a> for more information.</i><br/>Mobile Device Forensicshttp://www.newberrygroup.com/Blog/?id=26cmdLabs StaffSat, 17 Dec 2011 23:01:00 GMTSalvaging Digital Video Fragments<p>Digital video is becoming a more common form of digital evidence with the increasing prevalence of video in computers, mobile devices and cameras. Digital cameras can create high quality videos, most smart phones can create videos, and the iPad2 has two cameras that can create videos. The videos created by such digital devices can be stored on removable storage media and on the devices themselves. Frequent creation and deletion of videos on these kinds of devices can result in fragments of deleted video clips that most file carving tools cannot salvage. In addition, when dealing with Flash memory dumps acquired from mobile devices, data at the physical level is often fragmented. Specialized methods and tools are needed to salvage deleted video fragments as demonstrated in this article using the contents of Flash memory acquired from a Motorola V3 (RAZR) mobile device.</p>
<h3>File Carving Limitations</h3>
<p>Most file carving tools require a known file header in order to salvage deleted data. For instance, to recover a deleted 3gp file, most carving tools look for the file headers such as the following.</p>
<p><img alt="" src="/data/images/cmdLabsImages/image001.png" /><br />
<em>Hex view of 3gp header in the Motorola V3 Flash memory dump</em></p>
<p>If the file is fragmented or the header is missing, the file carving approach will not salvage the deleted video successfully. In this example, a file carving tool that searched the Motorola V3 memory dump for several 3gp header signatures found two files in as shown in the audit log: </p>
<ul>
<pre>05/24/2011, 11:26:35
QuickTime 3GP (3gp), header: ftypisom
QuickTime 3GP (3gp), header: ftyp3gp
QuickTime 3GP (3gp), header: ftypmmp4
Default file size: 1024 KB
Maximum file size: 100 times (individual file type definition defaults sizes respected)
E:\Physical GSM Motorola V3 RAZR\Flex Partition 1140000-1fe0000.bin
Scope: 000000 - E9FFFF
Extensive byte-level search
9D0E80 - AD0E7F: 00001.3gp
B888F0 - C888EF: 00002.3gp
05/24/2011, 11:26:35
2 file headers were found. 2 files were retrieved.
</pre>
</ul>
<p>However, the salvaged files were invalid because the original files were fragmented. Furthermore, the names and directory paths of these files were not obtained using this method, demonstrating a further limitation of file carving. <br />
<br />
</p>
<h3>Salvaging Video Fragments</h3>
<p>When video files are fragmented, it is necessary to consider the video file format in more detail. Fortunately, many digital video formats have a structure that can be used to find and salvage individual frames. A frame is a discrete section of the video that can have a timecode or sequence number and other characteristics that can be useful for salvaging digital video clips.</p>
<p>The <a target="_blank" href="http://defraser.sourceforge.net/">defraser tool</a> can be used to identify frames for several video formats in a forensic duplicate of any piece of storage media, including a removable storage card, computer hard drive and Flash dump from a mobile device. The following screenshot shows defraser used to detect video related data in the Motorola V3 memory dump.</p>
<p><img alt="" src="/data/images/cmdLabsImages/img_3.png" /><br />
<em>Defraser showing video related data in the Motorola V3 memory dump</em></p>
<p>Although the defraser tool does not automatically piece together the frames into a video that can be played, it does make the frames available for manual reconstruction. With some effort, defraser may be used to combine fragmented frames into a valid video file that can be played.</p>
<p>As with file carving methods that rely on header signatures, the carving methods employed by defraser do not provide the filenames and directory path of salvaged video data in the context of the original file system. </p>
<h3>File System Reconstruction</h3>
<p>Ultimately, the most effective approach to extracting digital video files from acquired digital evidence such as a Flash memory dump from mobile device is to reconstruct the logical arrangement of data. On mobile devices, this logical structure involves the flash abstraction layer and file system. Using mobile device forensic tools such as <a href="http://www.cellebrite.com" target="_blank">Cellebrite Physical</a> and <a href="http://www.msab.com" target="_blank">XRY</a>, it is possible to reconstruct and review logical file structure of a Flash memory dump as shown below with a 3gp video stored in an MMS related file in the Motorola V3 memory dump. Note that different tools may interpret the logical structure differently and show more files and folders, clearly demonstrating the importance of validating the results of forensic examination tools.</p>
<p><img alt="" src="/data/images/cmdLabsImages/img_5.png" /><br />
<em>XRY/XACT showing the logical file system in the Motorola V3 memory dump</em></p>
<p><img alt="" src="/data/images/cmdLabsImages/img_7.png" /><br />
<em>Cellebrite Physical showing the logical file system in the Motorola V3 memory dump</em></p>
<p>Extracting the MMS file using such a mobile device forensic tool and extracting the video content as discussed in the “<a href="http://www.cmdlabs.com/Blog/Default.aspx?id=24" target="_self">Delving into Mobile Device File Systems</a>” blog post results in a 3gp file that can be played using VLC media player.</p>
<p><img alt="" src="/data/images/cmdLabsImages/image009.png" /><br />
<em>Playing salvaged digital video using VLC Player</em></p>
<h3>Examination of Salvaged Video</h3>
<p>After salvaging digital video files it is important to review the resulting data closely for potential anomalies. For instance, using MediaInfo [http://mediainfo.sourceforge.net/en] to extract metadata from video files shows details related to its creation and format. The following screenshot shows metadata from a 3gp video extracted from the Motorola V3 memory dump, revealing that the embedded date-time stamp was set to an incorrect date. </p>
<p><img alt="" src="/data/images/cmdLabsImages/image011.png" /><br />
<em>Metadata within a 3gp video displayed using MediaInfo</em></p>
<p>In addition, reviewing individual frames within a salvaged video file can reveal anomalies such as portions of two unrelated videos being combined into one salvage file. The following screenshot shows frames extracted from a 3gp file using DCCI Video Validator [http://video-validator.sourceforge.net/] revealing footage from two unrelated video files.</p>
<p><img alt="" src="/data/images/cmdLabsImages/videovalidator3.png" /><br />
<em>Frames extracted from digital video using DCCI Video Validator</em></p>
<h3>Conclusions</h3>
<p>When a video file is fragmented or the header of a video file is overwritten, carving methods that rely on header signatures and contiguous files will not salvage video files successfully and may even incorrectly combine unrelated video fragments into a single file or fail to detect the presence of video content altogether. However, using specialized tools such as defraser, a digital investigator may be able to salvage fragments of video files and piece them together into a valid video file. This process of reconstructing video fragments is time consuming and error prone, particularly when dealing with numerous video files on a single piece of storage media or mobile device. Therefore, whenever feasible, it is preferable to reconstruct the logical arrangement of data to extract the complete content of video files. Whichever method is most effective for salvaging digital video, it is important to examine the results closely to ensure the accuracy and completeness of the resulting videos. Such a review includes inspecting embedded metadata for anomalies and reviewing keyframes for possible fragments of unrelated video footage.</p> <br /><i><a href='/Blog/?id=18'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=18Eoghan CaseySat, 17 Dec 2011 15:11:00 GMTNewberry Group Website Launch<p>It is with great pleasure and pride that I announce the redesigned Newberry Group website, a project more than a year in the making. Our new website will showcase <a href="http://www.newberrygroup.com/Solutions.aspx">our portfolio</a> as it continues to grow and diversify, and highlight the exceptional contribution our fellow employee-owners make to our Nation, our clients, our communities, and our company. As you know, being a Newberry Employee Owner (NEO) isn’t like being an <em>average</em> employee at an <em>average</em> company. At Newberry we have the unique opportunity to create long term wealth for ourselves and our colleagues, as owners, through the Newberry Group ESOP.<br />
<br />
We tried to encompass the spirit of Newberry, the <em>Signature Experience</em>, in this website, our public face to the world. People often ask me, “What is the <em>Signature Experience</em>?” The answer is that it’s different for everyone. For our clients it means an excellent and consistent delivery they can trust. In the marketplace, it means finding an excellent and trusted partner, as well as an extremely focused and tough competitor. For our employee-owners, it means an inspiring workplace where personal and professional development are valued and encouraged. The <em>Signature Experience</em> seeks to enhance and enrich the lives of our employee-owners, our clients, and our communities. <br />
<br />
Newberry is an agile and evolutionary company that is far <a href="http://www.newberrygroup.com/About.aspx">different</a> today than it was a year ago, and will continue to mature into a far different company a year from now than it is today. Our employee-owners strive for more, refusing to remain static, embracing the kind of change that creates a unique and rewarding <em>Signature Experience</em> for all who come to know us and our company. I believe our new website embodies that spirit and tells that story. </p>
<p> </p> <br /><i><a href='/Blog/?id=14'>Click here</a> for more information.</i><br/>Employee Ownerhttp://www.newberrygroup.com/Blog/?id=14Chris SteinbachFri, 25 Nov 2011 16:41:00 GMTWinner of DFRWS2011 Forensics Challenge Announced<p>This year Eoghan Casey worked with Tim Vidas at Carnegie Mellon University and Matthew Geiger at CERT to create the DFRWS Forensics Challenge in an effort to advance forensic analysis of Android mobile devices. The winners of the challenge were Ivo Pooters, Steffen Moorrees and Pascal Arends from Fox-IT. Their submission provides a suite of utilities written in Python for extracting information from data acquired from Flash memory on Android devices. Complete results are posted on the DFRWS Web site.</p>
<p>The scenarios for the DFRWS 2011 Forensics Challenge were two seemingly unrelated crimes that turned out to be tightly linked with each other. The first scenario was a suspicious death and the goal of the investigation was to determine whether the victim killed himself or was murdered. The second scenario was an intellectual property theft case and the goal of the investigation was to document any evidence that intellectual property was stolen and to support termination of the suspected insider.</p>
<p>An interesting outcome of the challenge was that using dd to acquire data from the Android device in Scenario 1 did not copy the important information in out-of-band (OOB) areas of the YAFFS2 file system. As a result, it was not possible to reconstruct the file system. However, contestants were still able to carve out usable content from this data.</p>
<p>The winning submission provides a technical analysis of data structures found in memory dump from Android mobile devices and provides an Android analysis toolkit that extracts specific items and formats them in a report. Using this toolkit to perform a forensic examination of a full NAND dump of a YAFFS2 file system (such as in Scenario 2 of the DFRWS 2011 Forensics Challenge) first requires the file system to be mounted under Linux as an emulated Flash device (using nandsim).</p>
<p>A sample of the information extracted by the winners from the SQLite database located on the Android device in Scenario 2 (mtd8\data\com.android.providers.telephony\databases\mmssms.db) is provided here:</p>
<table border="1" cellspacing="3" cellpadding="3">
<tbody>
<tr>
<th>Address</th>
<th>date/time (UTC)</th>
<th>read</th>
<th>type</th>
<th>body</th>
</tr>
<tr>
<td>[email protected]</td>
<td>05/06/2011 01:34:55 AM</td>
<td>True</td>
<td>in</td>
<td>(Nearby! Coming for my beer) Hey Yob, I am closing in on Fat Heads. See ya soon.</td>
</tr>
<tr>
<td>[email protected]</td>
<td>05/06/2011 05:53:30 PM</td>
<td>True</td>
<td>in</td>
<td>Reminder, planned IT outage this weekend. This maintenance window will start at 3 PM today and continue for approx 48 hours.</td>
</tr>
<tr>
<td>[email protected]</td>
<td>05/06/2011 05:55:16 PM</td>
<td>True</td>
<td>in</td>
<td>This effects external services such as website, email, webmail, and the ftp server. Use the secondary email access and helpdesk # for emergencies</td>
</tr>
<tr>
<td>[email protected]</td>
<td>05/07/2011 11:39:16 PM</td>
<td>True</td>
<td>in</td>
<td>(Save me!) If Luke asks, I’m going out with you to dinner, OK?<br />
I just can’t face Mr. Smooth tonight.<br />
Shandra</td>
</tr>
<tr>
<td>6245</td>
<td>05/07/2011 11:44:27 PM</td>
<td>True</td>
<td>out</td>
<td>Sure thing. Do you know where the wine loft is?</td>
</tr>
<tr>
<td>6245</td>
<td>05/07/2011 11:54:37 PM</td>
<td>True</td>
<td>out</td>
<td>I ran into some friends at the double wide, meetup at 8:30 or so?</td>
</tr>
<tr>
<td>6245</td>
<td>05/07/2011 11:56:53 PM</td>
<td>True</td>
<td>out</td>
<td>Or you can walk down Carson and join us</td>
</tr>
</tbody>
</table>
<p>Much more information was extracted from both Android devices as detailed in the reports, which include an <a href="http://sandbox.dfrws.org/2011/fox-it/DFRWS2011_results/Report/DFRWS%202011%20-%20timeline.png" target="_blank">impressive graphical reconstruction of events</a>. </p> <br /><i><a href='/Blog/?id=15'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=15Eoghan CaseyWed, 09 Nov 2011 13:13:00 GMTSQLite for Digital Forensic Practitioners<p>An increasing number of programs are employing SQLite to store data that can be of relevance in an investigation. Forensic practitioners who become familiar with SQLite and learn how to interpret these files will be in a better position to obtain the most usable information from available digital evidence. We cover this and other useful forensic techniques in our Mobile Device Forensics course (<a href="http://www.sans.org/security-training/mobile-device-forensics-1297-mid" target="_blank">SANS SEC563</a>).</p>
<p>Backup files from an iPhone or iPod Touch provide an excellent example of SQLite databases that digital forensic examiners can exploit with relative ease, provided they are not encrypted. Data backed up from an iPhone using iTunes such as call logs, contacts, multimedia, and other files are, by default, stored in SQLite database files under “~/Library/Application/Support/MobileSync/Backup” Mac. On Windows XP these backup files are stored in the user’s profile under “C:\Documents and Settings\[userprofile]\Application Data\Apple Computer\MobileSync\Backup” and Windows Vista has a “Roaming” subfolder in this path.</p>
<p>SQLite databases can be examined using a command line tool like <a href="http://www.sqlite.org/" target="_blank">sqlite3.exe</a> or with a GUI tool like <a href="http://sqlitebrowser.sourceforge.net/" target="_blank">SQLite Database Browser</a> shown here with the call log backed up from an iPhone.</p>
<p><img alt="" src="/data/images/cmdLabsImages/sql-1.png" /></p>
<p>The dates are in Unix string format and can be converted using Perl as shown here:</p>
<ul>
<pre>$ perl -e "print scalar(gmtime(1247848584))"
Fri Jul 17 16:36:24 2009</pre>
</ul>
<p>The use of SQLite databases gives forensic practitioners the ability to query the available data directly using the SQL database language. Although a full treatment of SQL is beyond the scope of this discussion, simple examples are provided here to get you started.</p>
<ul>
<pre>C:\>sqlite3.exe E:\iPhoneBackup\call_history.db
SQLite version 3.6.16
Enter ".help" for instructions
Enter SQL statements terminated with a ";"
sqlite> .tables
_SqliteDatabaseProperties call
sqlite> select * from call WHERE address like '%868%';
2|+186835xxxxx|1247848584|60|4|-1
3|+186835xxxxx|1247853361|0|5|-1
4|+186835xxxxx|1247854453|0|5|-1
9|+186831xxxxx|1247895923|60|4|-1
10|+186835xxxxx|1247936960|60|5|-1
11|+186835xxxxx|1247941792|0|4|-1
12|+186835xxxxx|1247941827|0|4|-1
13|+186835xxxxx|1247941920|0|4|-1
14|+186835xxxxx|1247942844|0|4|-1
16|+186835xxxxx|1248015352|60|4|-1
17|+186835xxxxx|1248015674|0|4|-1
18|+186835xxxxx|1248016092|0|5|-1
26|+186835xxxxx|1248177103|0|5|3</pre>
</ul>
<p>The Symbian operating system for mobile devices also makes use of SQLite databases, and other computer applications store investigatively useful information in SQLite databases, including Firefox 3 and Skype. For instance, the moz_places table in the places.sqlite file from Firefox 3 is shown below.</p>
<p><img alt="" src="/data/images/cmdLabsImages/sql-2.png" /></p>
<p>This file can also be queried using SQL, as shown here being queried for all URLs containing the cmdLabs web site.</p>
<ul>
<pre>C:\tools>sqlite3 E:\firefox\places.sqlite
SQLite version 3.6.16
Enter ".help" for instructions
Enter SQL statements terminated with a ";"
sqlite> .tables
moz_anno_attributes moz_favicons moz_keywords
moz_annos moz_historyvisits moz_places
moz_bookmarks moz_inputhistory
moz_bookmarks_roots moz_items_annos
sqlite> select * from moz_places WHERE url like '%cmdlabs%';
621|<a href="http://www.cmdlabs.com/">http://www.cmdlabs.com/</a>|Home|moc.sbaldmc.www.|1|0|1||2000
622|<a href="http://www.cmdlabs.com/page11/page11.html">http://www.cmdlabs.com/page11/page11.html</a>|Blog|moc.sbaldmc.www.|1|0|0||100
623|<a href="http://www.cmdlabs.com/services/services.html">http://www.cmdlabs.com/services/services.html</a>|Services|moc.sbaldmc.www.|1|0|0||100
624|<a href="http://www.cmdlabs.com/services/services/services-4.html">http://www.cmdlabs.com/services/services/services-4.html</a>|Training and Education|moc.sbaldmc.www.|1|0|0||100</pre>
</ul>
<p>Programs like Firefox that maintain usage records in these databases may leave remnants of deleted items that may be recoverable from unallocated disk space as detailed in Murilo Tito Pereira’s article “Forensic analysis of the Firefox 3 internet history and recovery of deleted SQLite records” (<a href="http://www.digitalinvestigation.net">www.digitalinvestigation.net</a>).</p> <br /><i><a href='/Blog/?id=25'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=25cmdLabs StaffTue, 08 Nov 2011 16:37:00 GMTDelving into Mobile Device File Systems<p>Mobile device forensics tools have come a long way in the past year, giving us access to more data on a wider range of devices. Even when a full copy of physical memory is not possible, for many devices the complete logical file system can be acquired. Although this generally does not include deleted items, it can still provide access to substantial digital evidence including MMS messages, IM fragments, and Web browsing history.</p>
<p>However, even when a tool can acquire the entire file system from a mobile device, it may not be able to display items of interest like MMS messages. In such situations, the forensic examiner must locate the desired information within the file system and interpret it themselves.</p>
<p>This is one of the main reasons why it is important for practitioners to have an understanding of the underlying technology, and not be overly reliant on automated tools.</p>
<h3>Locating MMS Data</h3>
<p>A good example of when a tool can acquire but not display evidence of interest came up in a recent case involving MMS messages on a Verizon LG phone. Although the commonly used tool called Cellebrite could acquire data from the mobile device, including a copy of the file system, it did not present MMS messages in the output report. As a result, the investigating agency was only able to view the incriminating evidence through the device itself by performing a manual “scroll” examination.</p>
<p><em>Until cmdLabs came along to help…</em></p>
<p>By examining the file system acquire using Cellebrite, we found MMS messages in the “mms” folder on the LG device. For the sake of illustration, this file system location is shown using BitPim.</p>
<p><img alt="" src="/data/images/cmdLabsImages/mms-bitpim.png" /></p>
<p>The MMSMsg.db file contains metadata associated with the messages, and the PDU files contain the original file name as well as the actual data of the pictures and videos in the message. The header of one PDU file is shown here, revealing some Synchronized Multimedia Integration Language (SMIL) tags and the original file name on the device (0920091201a.3g2).</p>
<p><img alt="" src="/data/images/cmdLabsImages/xways-pdu.png" /></p>
<p>Even after the original video file is deleted from the device, a copy remains in the MMS message.</p>
<h3>Extracting MMS Data</h3>
<p>The media portion of the PDU message file can be extracted using simple file carving techniques. Although you could remove the file header manually using a hex editor, it is more effective to use a file carving tool like Foremost. By automating the file carving process, your process is repeatable. In addition, Foremost generates an audit log that can be useful for forensic documentation purposes.</p>
<p>The file header (a.k.a. signature) of the 3gp videos from an LG VX series device is “ftyp3g2a” preceded by 4 bytes. The configuration entry for the Foremost file carving tool is shown here:</p>
<ul>
<pre>3gp y 4000000 ????\x66\x74\x79\x70\x33\x67\x32\x61</pre>
</ul>
<p>Using a configuration file that contains the above signature, the command ‘foremost -c foremost.conf MMS*‘ will extract the 3gp video content from PDU files acquired from an LG device. The resulting videos will be saved in the default Foremost output directory and can be played using Quicktime as shown here.</p>
<p><img alt="" src="/data/images/cmdLabsImages/quicktime.png" /></p>
<p>For those forensic practitioners who are interested in learning more about mobile device forensics and related data recovery techniques, cmdLabs is teaching the SANS Mobile Device Forensic course (SEC 563) in New Orleans from January 11–15, 2010 and again in San Antonio from January 25–29, 2010.</p> <br /><i><a href='/Blog/?id=24'>Click here</a> for more information.</i><br/>Mobile Device Forensicshttp://www.newberrygroup.com/Blog/?id=24Christopher DaywaltTue, 08 Nov 2011 16:02:00 GMTHandbook of Digital Forensics and Investigation Released<p>At long last and with the help of many talented experts, I have put together a new Handbook. This book provides an advanced reference for conducting digital investigations and performing forensic examinations. The first part of the book provides comprehensive methodologies and practical tips from experienced practitioners in the areas of forensic analysis, electronic discovery and intrusion investigation. The second part of the book delves into technical aspects of digital evidence on computers, networks, and embedded systems. The technologies covered include Windows, UNIX, and Macintosh computers, cellular telephones and other mobile devices, networks and mobile telecommunications technology.</p>
<p>The Network Investigations chapter written by cmdLabs personnel is <a href="/contact.aspx">available in PDF form upon request.</a><br />
<br />
<img alt="" style="float: left; margin-right: 10px;" src="/data/images/cmdLabsImages/handbook2.png" /><br />
F-Response is giving a copy of the Handbook with purchase of their tool:<br />
<br />
Buy F-Response, Get a copy of <a href="http://www.f-response.com/index.php?option=com_content&view=article&id=216%3%20Abuy-f-response-get-a-copy-of-the-handbook-of-digital-forensics-and-investig%20ation&catid=34%3Ablog-posts&Itemid=58" target="_blank">The Handbook of Digital Forensics and Investigation</a></p>
<p> </p>
<p><em><br />
<br />
<br />
My deepest thanks to the contributors: Cory Altheide (Mandiant) – Christopher Daywalt (cmdLabs) – Andrea de Donno (Lepta) – Dario Forte (DFLabs) – James Holley (Ernst & Young) – Andy Johnson (University of Maryland, Baltimore County) – Ronald van der Knijff (Netherlands Forensic Institute) – Anthony Kokocinski (CSC) – Paul Luehr (Stroz Friedberg) – Terrance Maguire (cmdLabs) – Ryan Pittman (US Army) – Curtis Rose (Curtis W. Rose & Associates) – Joseph Schwerha (TraceEvidence) – Dave Shaver (US Army) – Jessica Reust Smith (Stroz Friedberg).<br />
</em></p> <br /><i><a href='/Blog/?id=23'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=23Eoghan CaseyTue, 08 Nov 2011 15:56:00 GMTThe Pitfalls of File Initialization for Forensic Analysts<p>File initialization is a normal Windows file system behavior that can create problems for forensic analysts. We have encountered file initialization behaviors in a number of cases and find that it creates significant confusion if the underlying cause is not understood. In several cases, incomplete file initialization was misinterpret as backdating, and in another matter it hampered data salvaging efforts.</p>
<h3>File Initialization</h3>
<p>File initialization is a process that Microsoft Windows uses when creating a new file system entry. Basically, when a new file is being created, an appropriate amount of unallocated space is reserved for the data that will be stored in the new file. Under certain circumstances, the storage space reserved for the new file may not be used in its entirety, or at all.</p>
<p>When only a portion of the disk space that was reserved for a new file is used to store data associated with that file, this leaves a discrepancy between the logical file size and the actual amount of data stored in the file. As a result, you can have a file that appears to have a logical size larger than the actual amount of data stored for that file. The space between the end of valid data and the end of file is called uninitialized space.</p>
<p>“In NTFS, there are two important concepts of file length: the End of File (EOF) marker and the Valid Data Length (VDL). The EOF indicates the actual length of the file. The VDL identifies the length of valid data on disk. Any reads between VDL and EOF automatically return 0 in order to preserve the C2 object reuse requirement.” (<a href="http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/fsutil_file.mspx?mfr=true" target="_blank">Microsoft fsutil documentation</a>)<br />
<br />
Uninitialized space is similar in concept to file slack except that it is contained within the logical file size. Unlike file slack which is no longer associated with a file, data in uninitialized space is in a kind of limbo, trapped at the end of an allocated file but not actually part of that file. </p>
<p><img alt="" src="/data/images/cmdLabsImages/uninitializedDiagram.png" /><br />
<em>Figure: Diagram of file with a logical size that is larger than its valid data length, leaving uninitialized space</em></p>
<p>The effect of file initialization behaviors are most easily demonstrated on Windows XP with fsutil as shown here. First, we create a new file that can contain 1024 bytes:?</p>
<ul><code>C:\Test>fsutil file createnew cmdLabs-setvaliddata 1024<br />
File C:\Test\cmdLabs-setvaliddata is created</code></ul>
<p>Then we set the valid data length of the new file to 1000 bytes, which leaves 24 bytes unused at the end of the file.</p>
<code>C:\Test>fsutil file setvaliddata cmdLabs-setvaliddata 1000?<br />
Valid data length is changed</code>
<ul></ul>
<p>NTFS captures the difference between logical file size and valid data length in two MFT fields as shown here:</p>
<p><img alt="" src="/data/images/cmdLabsImages/uninitializedMFT.png" /><br />
<em>Figure:MFT entry with logical size and valid data length viewed using X-Ways Forensics</em></p>
<h3>Salvaging Data from File System Limbo</h3>
<p>The significance of this from a forensic analysis standpoint is that a file with a valid data length smaller than the logical file size can contain data associated with two files: data associated with the new file (VDL bytes), and data from the old file in uninitialized space (logical file size – VDL bytes).</p>
<p>From a forensic analysis perspective, this uninitialized space can be beneficial. While various disk cleaning utilities can be configured to wipe file slack, they generally do not touch data in uninitialized space. As a result, deleted data can remain in uninitialized space indefinitely, even despite data destruction efforts, and can be salvaged by forensic analysts.</p>
<p>However, this arrangement of data can create complications for forensic analysts, particularly when dealing with larger files that have substantial amounts of uninitialized space. For instance, when carving for certain file types, it is common to export unallocated space. However, any data in uninitialized space will not be included in unallocated space. Similarly, when performing keyword searches, a forensic analyst could incorrectly attribute a hit in the uninitialized space with the new file.</p>
<p>In one case, several approaches were employed in an effort to salvage video fragments:</p>
<ul>
<li>examined deleted video files still referenced by file system </li>
<li>performed file carving on unallocated space only </li>
<li>processed file slack only for fragments of video files </li>
</ul>
<p>None of these approaches recovered videos from a time period of interest. It was not until we conducted a forensic analysis of uninitialized space that additional video fragment were found.</p>
<h3>Misinterpreting Normal File System Behavior as Backdating?</h3>
<p>Another complication from a forensic analysis standpoint arises when the file creation process is interrupted before the contents of the file is written to disk, because the new file system entry will point to a cluster that still contains data associated with an older file. When this occurs and a date can be associated with the older file, forensic analysts might think that a newer file was overwritten by an older one. This phenomenon can be misinterpreted as evidence of backdating.</p>
<p>As an example, consider a newly created file that has not been initialized and has not had any associated data saved to disk as shown here using fsutil:</p>
<ul><code>C:\Test>fsutil file createnew cmdLabs-creatnew 1024<br />
File C:\Test\cmdLabs-creatnew is created<br />
</code></ul>
<p>When a file is initialized but the associated contents was not written to disk, the initialized file system entry may point to a cluster that contains old data as shown below using EnCase. By default, EnCase shows uninitialized space in blue text. The cluster that was allocated to the new file “cmdLabs-createnew” contains older data (folder entries of files from earlier in January).</p>
<p><img alt="" src="/data/images/cmdLabsImages/fsutlis.png" /><br />
<em>Figure: EnCase showing folder entries from early January in the cluster allocated to the new initialized file system entry</em></p>
<p>This situation can be misinterpreted as backdating if the forensic analyst assumes that the clock had to be set back to the old date when the file contents was saved to disk.</p> <br /><i><a href='/Blog/?id=21'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=21Eoghan CaseyTue, 08 Nov 2011 15:48:00 GMTAdvances in Windows Mobile Forensics<p>Recent research into important file formats on Windows Mobile devices has led to a breakthrough in mobile device forensics. Our improved understanding of the proprietary Microsoft embedded database format enables us to recover all available data from files such as cemail.vol, including deleted items.</p>
<p>The papers and associated tools detailing these advances in Windows Mobile forensic analysis are published in the Journal of Digital Investigation [http://www.journals.elsevier.com/digital-investigation/#description]. The most recent special issue on forensic analysis of embedded systems contains two papers: Introduction to Windows Mobile Forensics and Windows Mobile Advanced Forensics.</p>
<p>Introduction to Windows Mobile Forensics by Eoghan Casey, Michael Bann and John Doyle covers the fundamentals of Windows Mobile systems, embedded database formats and tools for acquiring and examining these systems in a forensic context. A table from this paper is provided here, listing potentially useful sources of evidence on Windows Mobile devices.</p>
<p><img alt="" src="/data/images/cmdLabsImages/table2.png" /></p>
<p>Windows Mobile Advanced Forensics by Coert Klaver from the Netherlands Forensic Institute provides in-depth technical details about embedded database formats and tools for acquiring and examining this information. The author developed tools for interpreting data in embedded databases acquired from Windows Mobile devices, including deleted items.</p>
<p>An upcoming issues of the Journal of Digital Investigation contains the paper Windows Mobile Advanced Forensics: An Alternative to Existing Tools by Cpt. Frédérick Rehault from the French National Gendarmerie. The author developed custom boot loaders and file parsing tools to extract the maximum amount of information available from Windows Mobile devices. A small sample of the very detailed output from one customized tool is provided below, showing interpreted fields extracted from a text message in cemail.vol along with the location of associated content in the file system.</p>
<ul><code>[ MESSAGE ] <<<< VISIBLE >>>><br />
Message Class : : IPM.SMStext<br />
Message Flag (1:Read; 0:Unread) : 0x00000028<br />
Subject : Love you too. Cant wait to see you tomorrow!<br />
Msg Status : 0x00040000 : SMS<br />
Delivery Time 2009-05-15 04:53:54<br />
Sender Email Address : 14435551212<br />
Sender Name : 14435551212<br />
Last Modification Date 2009-05-15 04:53:55<br />
Recipient Info: address & name : t£ lT SMS14105551212Steven…
<p> </p>
<p>-- Message Content Location --<br />
NORMALLY Stored in "\Windows\Messaging\ 453a000a xxxxxxxx.mpb "</p>
</code></ul>
<p>The tool also extracts the raw database record as shown here with all of the internal database fields:</p>
<ul><code>*************************************************************<br />
[ DEBUG ]: Found RECORD HEADER at Offset 0x000b7e9c</code>
<p> </p>
<p><code>[ DEBUG ]: hRecord = 0x00000a47<br />
[ DEBUG ]: hDBHandle = 0x00000060<br />
[ DEBUG ]: DataRecordSize = 0x00b8<br />
[ DEBUG ]: CompDataRecordSize = 0x009e<br />
[ DEBUG ]: Nb Props found = 12<br />
[ DEBUG ]: Flag = 0x4000 : Data might be compressed
<p>00000000 45 0a 00 3a a0 00 00 00 0f 00 00 31 28 00 00 00 |E..:.......1(...|<br />
00000010 00 00 b0 25 58 00 4c 00 6f 00 76 00 65 00 20 00 |...%X.L.o.v.e. .|<br />
00000020 79 00 6f 00 75 00 20 00 74 00 6f 00 6f 00 2e 00 |y.o.u. .t.o.o...|<br />
00000030 20 00 43 00 61 00 6e 00 74 00 20 00 77 00 61 00 | .C.a.n.t. .w.a.|<br />
00000040 69 00 74 00 20 00 74 00 6f 00 20 00 73 00 65 00 |i.t. .t.o. .s.e.|<br />
00000050 65 00 20 00 79 00 6f 00 75 00 20 00 74 00 6f 00 |e. .y.o.u. .t.o.|<br />
00000060 6d 00 6f 00 72 00 72 00 6f 00 77 00 21 00 34 00 |m.o.r.r.o.w.!.4.|<br />
00000070 00 00 04 00 00 9d b0 25 19 d5 c9 01 16 00 31 00 |.......%......1.|<br />
00000080 34 00 34 00 33 00 35 00 35 00 35 00 31 00 32 00 |4.4.3.5.5.5.1.2.|<br />
00000090 31 00 32 00 16 00 31 00 34 00 34 00 33 00 35 00 |1.2…1.4.4.3.5.|<br />
000000a0 35 00 35 00 31 00 32 00 31 00 32 00 80 33 49 26 |5.5.1.2.1.2..3I&|<br />
000000b0 19 d5 c9 01 47 0a 00 3b |....G..;|</p>
<p>+ List of properties in record:<br />
-- PropID[ 0 ] = 0x80050013 UI4 : 0x3a000a45<br />
-- PropID[ 1 ] = 0x80110013 UI4 : 0x000000a0<br />
-- PropID[ 2 ] = 0x001a0013 UI4 : 0x3100000f<br />
-- PropID[ 3 ] = 0x0e070013 UI4 : 0x00000028<br />
-- PropID[ 4 ] = 0x003d001f LPWSTR :<br />
-- PropID[ 5 ] = 0x0037001f LPWSTR : Love you too. Cant wait to see you tomorrow!<br />
-- PropID[ 6 ] = 0x0e170013 UI4 : 0x00040000<br />
-- PropID[ 7 ] = 0x0e060040 FILETIME 0x1c9d51925b09d00<br />
-- PropID[ 8 ] = 0x0c1f001f LPWSTR : 14435551212<br />
-- PropID[ 9 ] = 0x0c1a001f LPWSTR : 14435551212<br />
-- PropID[ 10 ] = 0x30080040 FILETIME 0x1c9d51926493380<br />
-- PropID[ 11 ] = 0x80010013 UI4 : 0x3b000a47</p>
<p> </p>
</code></p>
<p> </p>
<p> </p>
</ul>
<p>cmdLabs covers forensic analysis of Windows Mobile and other mobile devices in the course we develop and teach for SANS (FOR563 – Mobile Device Forensics [http://www.sans.org/security-training/mobile-device-forensics-4896-tid]).</p> <br /><i><a href='/Blog/?id=20'>Click here</a> for more information.</i><br/>Mobile Device Forensicshttp://www.newberrygroup.com/Blog/?id=20Eoghan CaseyTue, 08 Nov 2011 15:30:00 GMTWinner of the DFRWS2010 Forensic Challenge Announced<p>This year Eoghan Casey collaborated with the <a href="http://www.forensicinstitute.nl/" target="_blank">Netherlands Forensic Institute</a> to create the DFRWS Forensic Challenge in an effort to advance forensic analysis of Flash memory in mobile devices. The winner of the challenge was Solal Jacob who used the open source <a href="http://www.digital-forensic.org/" target="_blank">Digital Forensic Framework</a>, and provides some new modules specifically for parsing memory dumps of Sony Ericsson K800i devices. Complete results are posted on the <a href="http://www.dfrws.org/2010/challenge/results.shtml" target="_blank">DFRWS Web site</a>.</p>
<p>The scenario for the DFRWS2010 Forensic Challenge involves an arms dealer named Monsieur Victor (a.k.a. “The General”) who was apprehended in the Netherlands and threw Sony Ericsson K800i in a nearby canal. The Netherlands Forensic Institute acquired data from NAND and NOR chips in the water damaged mobile device using Memory toolkit. The goal of the challenge is to recover leads relating to front companies, bank accounts and cohorts.</p>
<p>The winning submission provides a technical analysis of data structures found in memory dump from a Sony Ericsson K800i mobile device and provides DFF plug-ins that recover wear-leveling tables, enabling a forensic analyst to reconstruct the flash abstraction layer as shown here.</p>
<p><img alt="" src="/data/images/cmdLabsImages/ftl-reconstruction.png" /></p>
<p>Once the desired state of memory has been reconstructed, the DFF tool can be used to interpret the partition table and file systems on the mobile device as shown here.</p>
<p><img alt="" src="/data/images/cmdLabsImages/parse-filesystem.png" /></p>
<p>The resulting logical view show metadata associated with files and folders, including deleted items.</p>
<p><img alt="" src="/data/images/cmdLabsImages/file-system-deleted.png" /></p>
<p>In addition, digital photographs recovered from mobile device memory can be previewed using the DFF as shown here.</p>
<p><img alt="" src="/data/images/cmdLabsImages/photos-thumbs.png" /></p>
<p>An interesting outcome of the challenge was that several contestants were able to extract substantial amounts of information from the physical memory dumps without understanding the logical arrangement of blocks or the file system. The implication is that, once full physical dumps of NAND and/or NOR memory are obtained from a mobile device, simple text extraction and file carving techniques can provide significant amounts of useful information, including deleted data.</p>
<p>A logical acquisition created using Microsystemation’s XRY mobile device forensic tool is now available to facilitate further development such as interpretation of foreign characters. As an example, the logical view of SMS messages on the device used in the DFRWS2010 Forensic Challenge is shown here.</p>
<p><img alt="" src="/data/images/cmdLabsImages/xry-logical.png" /></p> <br /><i><a href='/Blog/?id=19'>Click here</a> for more information.</i><br/>Mobile Device Forensicshttp://www.newberrygroup.com/Blog/?id=19Eoghan CaseyTue, 08 Nov 2011 15:11:00 GMTDigital Evidence & Computer Crime, 3rd Edition Released<p>After six years of work, the expanded and updated third edition of <a href="http://www.amazon.com/gp/product/0123742684?ie=UTF8&tag=wwwcmdlabscom-20&linkCode=as2&camp=1789&creative=9325&creativeASIN=0121631044" target="_blank">Digital Evidence and Computer Crime: Forensic Science, Computers and the Internet</a> is now complete. The 800 printed pages and one online chapter cover the methods and tools relevant to incident responders, forensic analysts, police and lawyers.</p>
<p><img alt="" style="float: left; margin-right: 10px;" src="/data/images/cmdLabsImages/casey_1.png" />This book is divided into five parts, beginning with the fundamental concepts and legal issues relating to digital evidence and computer crime in Part 1 (Digital Forensics: Chapters 1 – 5). Part 2 of this text (Digital Investigations: Chapters 6 – 9) covers investigative aspects of digital evidence and computer crime. Part 3 of this text (Apprehending Offenders: Chapters 10 – 14) deals with specific types of investigations with a focus on apprehending offenders, including Violent Crime in Chapter 10, Sex Offenders on the Internet in Chapter 12 and Investigating Computer Intrusions in Chapter 13. Part 4 of this book (Computer Forensics: Chapters 15 – 20) begins by introducing basic Forensic Science concepts in the context of a single computer, and goes on to apply these concepts in updated chapters dedicated to networked Windows, Unix, and Macintosh computers and mobile devices. Part 5 (Network Forensics: Chapters 21 – 25) covers computer networks from an investigative perspective, focusing specifically on the Internet and performing forensic analysis on network logs and traffic.</p>
<p>This material provides the foundation for the more advanced companion text, the <a href="http://www.amazon.com/Handbook-Digital-Forensics-Investigation-Eoghan/dp/0123742676/ref=sr_1_1?ie=UTF8&qid=1320729067&sr=8-1" target="_blank">Handbook of Digital Forensics and Investigation</a>.</p>
Many thanks to <a href="http://www.udayton.edu/law/faculty_and_staff/brenner_susan.php" target="_blank">Susan Brenner</a>, <a href="http://www.cmdlabs.com/Christopher_Daywalt.aspx" target="_blank">Christopher Daywalt</a>, <a href="http://www.techforensicexperts.com/53/index.html" target="_blank">Monique Mattei Ferraro</a>, <a href="http://www.tilburguniversity.edu/webwijs/show/?uid=e.j.koops" target="_blank">Bert-Jaap Koops</a>, <a href="http://www.cmdlabs.com/Terrance_Maguire.aspx" target="_blank">Terrance Maguire</a>, Mike McGrath, Tessa Robinson, <a href="http://www.schatzforensic.com.au/" target="_blank">Bradley Schatz</a>, Ben Turnbull and <a href="http://www.corpus-delicti.com/brent/brent_cv.html" target="_blank">Brent Turvey</a> for their excellent contributions to this textbook. <br /><i><a href='/Blog/?id=17'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=17Eoghan CaseyTue, 08 Nov 2011 14:47:00 GMTGeolocational Log Analysis: Think Globally, Act Locally (with code)<p>In many network environments the administrators and security engineers have an understanding of the full geographical scope and reach of their network. While some corporations have a global audience and expect traffic from the far reaches of the world, others are more localized and target a specific small region.</p>
<p>A health care provider for Alaska would monitor its network connections to ensure that network connections are limited to its main source of users, i.e. those in Alaska. An insurance company in St. Louis will see mostly traffic from IP addresses in Missouri, but Illinois as well, due to the city being on the state line. Occasionally, administrators may notice connections being made from Hawaii, Bermuda, or Italy, signifying users who are on vacation but are still wired in to their work. However, a long-term series of connections from a Eircom subscriber, Ireland’s largest ISP, should spark interest to the network administrator of a Seattle tax firm.</p>
<p>While anonymous web connections from global addresses are common, specific attention should be paid to such addresses being used to access password-protected areas of a corporation. This could include remote file access, VPN and web-based corporate email.</p>
<p>In such cases the logs from these applications, usually supplied in plain text or W3C format, contain details about transactions to include the remote IP address and the account name being authorized. In reviewing logs from various incident responses cmdLabs has found details to show that a short log review made on a daily basis could help smaller corporations determine quickly if a user account was compromised and accessed from a remote location.</p>
<p>For example, the log sample below from a Cisco ASA tracks VPN connections. The user “cmdLabs\bbaskin” was accessed via the IP address of 159.134.100.100 on 2 April, 2011, an IP that was traced back to Ireland. A few hours later the same account was accessed from an IP address in Austria.</p>
<ul><code>Apr 2 21:53:37 192.168.1.1 Apr 02 2011 21: 53:08: %ASA-6-302013: Built outbound TCP connection 7823 for inside:10.10.10.50/389 (10.10.10.50/389) to NP Identity Ifc:192.168.1.1/1047 (192.168.1.1/1047)<br />
Apr 2 21:53:37 192.168.1.1 Apr 02 2011 21: 53:08: %ASA-6-1<br />
04: AAA user authentication Successful : server = 10.10.10.50 : user = cmdLabs\bbaskin<br />
Apr 2 21:53:37 192.168.1.1 Apr 02 2011 21: 53:08: %ASA-6-113009: AAA retrieved default group policy (DfltGrpPolicy) for user = cmdLabs\bbaskin<br />
Apr 2 21:53:37 192.168.1.1 Apr 02 2011 21: 53:08: %ASA-6-113008: AAA transaction status ACCEPT : user = cmdLabs\bbaskin<br />
Apr 2 21:53:37 192.168.1.1 Apr 02 2011 21: 53:08: %ASA-6-734001: DAP: User cmdLabs\bbaskin, Addr 159.134.100.100, Connection Clientless: The following DAP records were selected for this connection: DfltAccessPolicy</code></ul>
<p>For this small set of data it is trivial to query each IP address to determine its country of origin, netblock owner, and other details that would highlight unauthorized access. The problem arises when you have hundreds of thousands of such transactions in your daily log files. One service that cmdLabs uses regularly is the IP to <a href="http://www.team-cymru.org/Services/ip-to-asn.html" target="_blank">ASN WHOIS server</a> run by Team Cymru. This server provides quick and easy access to country codes for a given IP address. However, it has two limitations: it requires Internet-access which is not readily available from a forensic workstation and to process a large bulk of IPs you have to use their Netcat process which only returns ASNs and not country codes. To overcome these limitations I’ve developed a simple solution that could process hundreds of thousands of IP addresses to determine country codes. This solution is a small Python script called IP2CC that takes an IP address as input and outputs the originating country code for that IP. This solution requires three components:</p>
<ol>
<li>The free country code database located at <a href="http://www.maxmind.com/app/geolitecountry" target="_blank">http://www.maxmind.com/app/geolitecountry</a> (updated monthly) </li>
<li>Python API module to access this database located at <a href="http://code.google.com/p/pygeoip/" target="_blank">http://code.google.com/p/pygeoip/</a> </li>
<li>The IP2CC.py script. Downloadable at the end of this blog post. </li>
</ol>
The script allows for input to be given via the command line, stdin, or an input file. In normal use it will simply output the country code. With the –c or -t option the output will contain both the IP and country code in either a comma-separated version (CSV) or tab-separated (TSV) output, respectively.<br />
<br />
<ul><code>Python ip2cc.py –i <ip> -f <input file> [-c] [-t]
<p>> python ip2cc.py -i 11.11.11.11<br />
US</p>
<p>> python ip2cc.py -i 22.22.22.22 -c<br />
22.22.22.22,US</p>
<p>> echo 33.33.33.33 | python ip2cc.py<br />
US</p>
</code>
<p><code>> python ip2cc.py -f IP.txt -c<br />
14.48.7.101,AU<br />
12.51.21.19,US<br />
10.61.14.9,Internal<br />
</code></p>
</ul>
<br />
In one use, we’ll eliminate known intranet/extranet IP addresses and run the resulting list through IP2CC to produce a master list of foreign accesses. This script will run in Linux and OSX in conjunction with the native OS command line tools. For a Windows environment you will find additional capabilities by installing the necessary <a href="http://gnuwin32.sourceforge.net/" target="_blank">GnuWin32</a> components. For example, when reviewing a <a href="http://technet.microsoft.com/en-us/library/cc737651(WS.10).aspx" target="_blank">NCSA-formatted log </a>with the IP address in the first field:
<ul><code>D:\> type in051611.log | egrep –v “^192” | gawk “{print $1}” | python ip2cc.py -t | egrep –v “US|Internal” | gawk -F\t "{print $1}" | sort | uniq > DailyForeignIPs.txt<br />
D:\> for /F %i in (DailyForeignIPs.txt) do grep “%i” in051611.log >> DailyForeignConnections.txt</code></ul>
<p>The first command above will save a simple text listing of all unique foreign IP addresses into a file for processing. The second line takes each IP address from that resulting file and compares it back against the logs to extract all lines that include its presence. The resulting DailyForeignConnections.txt can then be quickly reviewed to determine if any accounts were accessed from a foreign IP address.<br />
<br />
Dealing with the VPN logs shown earlier, we’ll change our command line a bit. Using the standard <a href="http://www.cisco.com/en/US/docs/security/asa/asa72/system/message/logmsgs.html" target="_blank">Cisco log file index</a> as a source we can see that the <a href="http://www.cisco.com/en/US/docs/security/asa/asa72/system/message/logmsgs.html#wp4887754" target="_blank">log id of 734001</a> will show us the remote IP address of a user login. We’ll search the log for that id and then parse out the IP address in the 15th field. An additional hindrance is that the IP address is appended with a comma, which we’ll remove with the ‘tr’ command.</p>
<ul><code>D:\> type asavpn-051611.log | findstr "734001" | gawk “$15 !~ /^192/ {print $15}” | tr -d "," | python ip2cc.py –t | egrep –v “US|Internal” | sort | uniq > DailyVPNForeignIPs.txt</code></ul>
<p>This is ultimately just a very simple Python script. In-house, we use it as a mere function within larger processes, but its simplicity allows for it to be used in a variety of result-tuning processes. Customization is easy. At times I’ll make an offshoot of the script to process input from `uniq` command with the `-c` count option occasionally. The `uniq –c` adds a new column that specifies the total number of instances of that IP address which is useful when evaluating the persistence of a single IP amongst thousands. A few small changes to the Python will allow you to read this count and add it to the CSV output for easy integration into a spreadsheet.</p>
<p>Usage of a tool like IP2CC is a first step to opening an administrators eyes to traffic beyond their network. A good administrator or security engineer should monitor not only the traffic that flows across their network but also the perceived traffic that flows from a network’s outer nodes to the Internet. Monitoring for your company’s existence in spam black-lists, a malware rating on services like <a href="http://MyWOT.com" target="_blank">Web of Trust</a>, and other indicators can give clues that an infection or intrusion may be underway within your network. We’ll discuss these points, and others, in a future blog post.</p>
<p><strong>Downloads:</strong></p>
<p>IP2CC Python Source Code v1.0 [ip2cc.zip] </p> <br /><i><a href='/Blog/?id=16'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=16Brian BaskinTue, 08 Nov 2011 14:45:00 GMTDeeply Embedded Metadata <br/><i><a href='/Blog/?id=27'>Click here</a> for more information.</i><br/><hr />Archivedhttp://www.newberrygroup.com/Blog/?id=27Mon, 01 Jan 0001 00:00:00 GMT