November 2020 Newsletter
Black Friday vs. Cyber Monday:
How to navigate cyber threats as lines blur between the two biggest shopping days of the year
As a very unique holiday season approaches, many are making big changes to their annual plans. This year the usual Black Friday madness is joining Cyber Monday with many stores shifting their doorbusters online to meet new restrictions. In 2019 Cyber Monday had already topped Black Friday, with retail sales in 2019 soaring to a record-high of $9.4 billion online. And while Cyber Week normally draws a crowd of roughly 165 million shoppers in search of the best deals, this year foot traffic is scarce and online shopping has become the chosen mode of gift-givers and bargain shoppers everywhere.
This year, many stores will remain closed on Thanksgiving. Others say they’ll re-envision the idea of Black Friday only being a single day — and offer their best deals throughout November and December, since there’s little to no Thanksgiving Day in-store shopping (See the list of who is closed and open on Thanksgiving here.)
With the opportunity to score incredible deals and receive super-secret shopping codes from Santa via email, comes an even bigger opportunity for cybercriminals to prey on the unsuspecting shopper. The Cybersecurity and Infrastructure Security Agency (CISA) encourages users to be aware of potential holiday scams and malicious cyber campaigns, particularly when browsing or shopping online. Cyber actors may send emails and ecards containing malicious links or attachments infected with malware or may send spoofed emails requesting support for fraudulent charities or causes. Below we’ve added some tips from CISA and the Stop.Think.Connect.™ Campaign to shop a little safer this season.
How can you protect yourself?
- Do business with reputable vendors – Before providing any personal or financial information, make sure that you are interacting with a reputable, established vendor. Some attackers may try to trick you by creating malicious websites that appear to be legitimate, so you should verify the legitimacy before supplying any information. (See Avoiding Social Engineering and Phishing Attacks and Understanding Web Site Certificates for more information.) Attackers may obtain a site certificate for a malicious website to appear more authentic, so review the certificate information, particularly the “issued to” information. Locate and note phone numbers and physical addresses of vendors in case there is a problem with your transaction or your bill.
- Make sure your information is being encrypted – Many sites use secure sockets layer to encrypt information. Indications that your information will be encrypted include a Uniform Resource Locator (URL) that begins with “https:” instead of “http:” and a padlock icon. If the padlock is closed, the information is encrypted. The location of the icon varies by browser; for example, it may be to the right of the address bar or at the bottom of the window. Some attackers try to trick users by adding a fake padlock icon, so make sure that the icon is in the appropriate location for your browser.
- Be wary of emails requesting information – Attackers may attempt to gather information by sending emails requesting that you confirm purchase or account information. (See Avoiding Social Engineering and Phishing Attacks.) Legitimate businesses will not solicit this type of information through email. Do not provide sensitive information through email. If you receive an unsolicited email from a business, instead of clicking on the provided link, directly log on to the authentic website by typing the address yourself.
- Use a credit card – There are laws to limit your liability for fraudulent credit card charges, but you may not have the same level of protection for your debit cards. Additionally, debit cards draw money directly from bank accounts, unauthorized charges could leave you with insufficient funds to pay other bills. You can minimize potential damage by using a single, low-limit credit card to make all of your online purchases. Also, use a credit card when using a payment gateway such as PayPal, Google Wallet, or Apple Pay.
- Check your shopping app settings – Look for apps that tell you what they do with your data and how they keep it secure. Keep in mind that there is no legal limit on your liability with money stored in a shopping app (or on a gift card). Unless otherwise stated under the terms of service, you are responsible for all charges made through your shopping app.
- Check your statements – Keep a record of your purchases and copies of confirmation pages, and compare them to your bank statements. If there is a discrepancy, report it immediately. (See Preventing and Responding to Identity Theft.)
- Check privacy policies – Before providing personal or financial information, check the website’s privacy policy. Make sure you understand how your information will be stored and used. (See Protecting Your Privacy.)
5 things you need to know to future-proof your data security today
Thursday, December 03, 2020 at 1:00 PM EST (2020-12-03 18:00:00 UTC)
Jeff Melnick, John Pescatore
Overview
What cyber threats will your organization face in the coming years? How can you protect your sensitive and business-critical data from malicious insiders, ransomware and targeted attacks, as well as human error? Discover 5 things that can help you orchestrate IT security with your data at its core, and get one step ahead of threats. In this presentation, you will learn the steps to build an intelligent roadmap for protecting your business and reduce the risk of data breaches by gaining better control over your IT environment.
Speaker Bios
Jeff Melnick
Jeff has extensive experience in the design, deployment and management of Active Directory infrastructure, including domain migrations and upgrades, as well as experience with VMware and Citrix systems. Whether an organization needs help ensuring compliance with SOX, HIPAA, ISO or other regulations, or wants to be able to better monitor internal systems like Active Directory, file servers, Windows Server and SQL Server, Jeff is ready and eager to help.
John Pescatore
John Pescatore joined SANS as director of emerging security trends in January 2013 after more than 13 years as lead security analyst for Gartner, running consulting groups at Trusted Information Systems and Entrust, 11 years with GTE, and service with both the National Security Agency, where he designed secure voice systems, and the U.S. Secret Service, where he developed secure communications and surveillance systems and “the occasional ballistic armor installation.” John has testified before Congress about cybersecurity, was named one of the 15 most-influential people in security in 2008 and is an NSA-certified cryptologic engineer.
Don't Forget to Complete the Service Desk Survey!
The Newberry Service Desk is dedicated to providing all customers the Newberry Gold Star Experience. Your feedback provides real-time insight highlighting areas where we meet your expectations or area where we need to improve.
How do you complete a customer survey? Upon resolution of your service request, you receive a survey to provide us feedback. The survey takes about 5 seconds to complete and will allow you to provide a comment regarding your experience.
Client Corner: Spotlight on YOU
The Newberry newsletter will spotlight a new client each month. This is a completely voluntary feature, and it’s all about you: the client. The newsletter is sent to our clients and prospects throughout the National Capital Region and the St Louis MO, Metro area. This is a wonderful opportunity to gain exposure for your business and let everyone know what you do and who you serve! If you would like to be featured in our Client Corner, please sign up below or email [email protected].
Newberry + Marine Toys for Tots
This #GivingTuesday Newberry is raising money for Marine Toys For Tots Foundation. The mission of the U.S. Marine Corps Reserve Toys for Tots Program is to collect new, unwrapped toys during October, November, and December each year, and distribute those toys as Christmas gifts to less fortunate children in the community in which the campaign is conducted. On Giving Tuesday, December 1st at 8 AM, Facebook will begin matching donations:
- $100,000 USD total donations matched per nonprofit
- $20,000 USD in qualifying donations per donor
Learn more about Toys for Tots: https://www.toysfortots.org/
Newberry's Client Referral Program: Cash in on this!
Newberry has just rolled out a Client Referral Rewards Program!
Existing clients, that refer companies to Newberry that result in the execution of a Monthly Managed Services Agreement with the referred client, shall have their recurring monthly managed services fee waived for one (1) billing period. The waived fee will be credited to your invoice after the referred client has met its one (1) month anniversary with Newberry.
To qualify:
- Referring Client has to be registered ahead of time with [email protected]
- New referred prospect must be signing up for one of our Managed Monthly reoccurring services, including but not limited to Mission Control, Managed +, SIEMaaS, Cybersecurity as a Service, etc.
The Newberry Grill:
Bea Brown's Easy Vegetable Soup
- 3 large potatoes - diced
- 1 large onion - diced
- 1 cup of cabbage - diced
- 1 celery stalk or 1 tsp celery or parsley flakes
- 1 can of corn
- 1 can of carrots - diced
- 1 can of roast beef or 8 ounces of pre-cooked roast beef (or ham)
- 1 family size can of Campbells Vegetable Soup
- 1 bottle V8 Vegetable Juice (46 oz)
- 1 1/2 quarts of water
- 1/4 cup of sugar (add slowly to taste
Instructions
- Combine all ingredients
- Bring to a boil then return to a simmer
- Simmer for about 1 1/2 hours
