Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, August 12, 2015

Are Weak Passwords Putting your Business at Risk?

Let’s face it, everybody hates passwords. They are a pain and a nuisance, but in today’s connected world, they are clearly necessary. Passwords are multiplying and are not going away any time soon. Most companies have no real password requirement. Everyone has a password but the clarity on what needs to be done and what is appropriate and/or what’s not appropriate is not distributed to the company.

You need to take this seriously, securing your information is important.

Log-in box on computer screen of admin“But Marge does not have anything really sensitive on her computer so we just leave her alone.” – Anonymous Owner

There is often a feeling that certain people need less security, because their work does not deal with sensitive information. Please understand leaving one person’s password unsecured is like leaving a door unlocked to your palace. You cannot make this assumption without paying high penalties.


All passwords need to be secure and updated. Often breaches start by entering a smaller target to gain access to the real target. We see hacks that use smaller companies who service larger organizations targeted because they tend to be very lacking in basic security.

So what is a secure or strong password?

It may sound cliché, but your password has to be strong or there is no point in it. There are plenty of articles and viewpoints out there about how complex passwords must be, but you should always have a minimum of at least eight characters. It should not be a dictionary word (in English or any other language). It should include both uppercase and lowercase letters and a special character or two. A passphrase is a great approach as well, as long as it is not common. Passwords like 123123, letmein, birthdays, sports, names, even password1 are no good. It is like having a key with no ridges.

NOTE: Stop writing your latest password on sticky notes and “hiding” them under your desk. That is a security 101 no-no. Store it somewhere safe, out of everyone’s hands.

The top passwords for this year:

1. 123456
2. password
3. 12345
4. 12345678
5. qwerty
6. 123456789
7. 1234
8. baseball
9. dragon
10. football
11. 1234567
12. monkey
13. letmein
14. abc123
15. 111111
16.mustang
17. access
18. shadow
19. master
20. michael
21. superman
22. 696969
23. 123123
24. batman
25. trustno1

Apparently lots of people enjoy playing baseball with a dragon and driving a superman mustang. Personally, we prefer the bat mobile.

Put your password to the test at this “How Secure Is My Password” website.



Your password policy: 

Create – Implement – Enforce
Your WRITTEN policy needs to define secure and unsecured passwords, sharing rules, frequency of changing and reiterate the importance of them. All those that complain may not be fully educated on the impact that a breach would have on everyone, not just the company. Please explain to your staff clearly why it is a requirement of being employed. Lastly, your employees need to acknowledge they understand it and are responsible to abide by it. They need to also be accountable.



The skeleton of your policy should include:
  1. Minimum password length
  2. Password composition:
    • Character requirements and allowances as well as capitals, lowercase, numbers, special characters or items such as your name and the company name are not allowed.
  3. Password age limitation:
    • The frequency of change required.
  4. Password storage:
    • Passwords are not to be written down, they must be memorized or kept in a password manager.
  5. Reuse of passwords:
    • Do not use the same password at work that you use in any other account.
  6. Sharing and transferring:
    • Passwords are not allowed to be shared without proper authorization.
    • If it is shared, establish what criteria is needed to share.
  7. Electronic transmission:
    • No transmission over insecure networks or communication.
  8. Requirements for System Administrators:
    • Both their permission level and power to control others as well as a clear understanding of how are they held accountable
  9. Enforcement:
    • Roles, responsibilities, consequences and sanctions
  10. Exemptions:
    • Policy and forms for any exceptions

Now let’s be reasonable, you are not Fort Knox, but perspective still matters. If you have anything of value on those systems that you wouldn’t want distributed to everyone: your employees, competitors, vendors, partners, investors, ex-spouse, etc. then you need to protect it. Like your key to the lock on the front building that’s there for a reason.

But really, who is out to get me? I am just a small business owner.

Maybe you are the kindest person with no secrets willing to give away all your information. Even so, you may not realize largest offenders are most often internal or external IT people [who have the largest amount of access to your network]. They have access to your servers, workstations, applications and firewall. Make sure you have a process to verify their compliance as well. Also, be certain that many times these mistakes are simply that, mistakes. If one person unknowingly provides their password to an outsider who has any malicious intent, your biggest asset, and your information could be swiped from you in minutes. In this case you can be yourself, be trusting on other levels, but don’t be naive with your information.

Avoid Reaction, Take Action.
  1. Create a written password policy. It should be part of your computer usage policy. Make sure all employees are familiar with it and agree to abide by it.
  2. Help them understand why it is important. Listen to the groans, appreciate their issues and then insist they do it.
  3. Help them understand what appropriate and inappropriate passwords are.
    • While you are at it, help them understand that their families and personal information needs to be safeguarded as well. They need to keep their interested protected as well. Make it a service announcement for them. Identity theft is booming. Keeping yourself safe is very important.
  4. Make sure your IT support puts the policy in place that requires policy to be followed. Often they will not like this because they will have to spend more time “resetting passwords”. A small price to pay for security.
  5. Make sure your IT people are following the same procedure. We have seen often they circumvent it, because they have the authority.

For more information you can trust, visit us at bbb.org/boston, like us on Facebook, or follow us on Twitter and LinkedIn. Become an Accredited Business and get the resources you need to give you confidence and help keep your business safe and secure. 


Written by Dan Adams, CEO of BBB Accredited Business, New England Network Solutions (NENS).  

Dan is a serial entrepreneur who ran his first retail operation in high school. He founded NENS in 1993 and over the years, owned and managed several start-up companies. Dan is passionate about sharing his success strategies with fellow entrepreneurs.

Thursday, May 29, 2014

Maine Attorney General Warns Businesses of Phone Scam

Earlier this week, we told you about the homework folder phone scam that was plaguing Vermont business owners. Well, in true scammer fashion, they never rest. BBB has just learned of a new phone scam affecting small business owners in Maine.

The Maine Attorney General issued a warning last week that phone scammers were calling businesses and claiming to be from the Maine Office of Tourism. The callers claimed to be selling advertising space on a publication that was to be produced by the Maine Office of Tourism. The scammers demanded an upfront cash payment to be made over the phone immediately.

Businesses should know that these caller are not affiliated with the Maine Office of Tourism, nor are they subcontractors of the organization. If you receive a call, Attorney General Janet Mills advises you to hang up.

BBB recommends that you never give out personal information, over the phone, to someone you don’t know. If the caller requires you to pay by money order, you should also consider that as a giant red flag.

Tuesday, April 29, 2014

Do you use Internet Explorer?

A vulnerability in Microsoft’s popular Internet Explorer web browser can allow a “remote, unauthorized attack” on users’ computers, the company announced over the weekend via a Service Advisory. Although it is working to fix the problem, the company suggests “workarounds.”

Meanwhile, the U.S. Computer Emergency Readiness Team, a division of the Department of Homeland Security, is urging computer users to employ Microsoft’s Enhanced Mitigation Experience Toolkit (EMET) if possible, or temporarily switch to a different browser until an official update is made available.

The “use-after-free” vulnerability can allow remote attackers to install code on a user’s computer without authorization. Versions 6 through 11 of Internet Explorer (IE) are vulnerable, and users who still have the Windows XP operating system are at greater risk because the company is no longer supporting the product.

Better Business Bureau is joining with security experts in recommending that IE users take the following steps:
  • Download the EMET on your computer for additional protection (although it may not mitigate this particular vulnerability);
  • Temporarily switch to a different web browser, such as Goggle’s Chrome or Mozilla’s Firefox.
  • Disable Adobe Flash, as the attack may not work without it.

Windows XP users should upgrade their operating system or disconnect the computer from the Internet, as the company no longer supports this version of Windows.

Saturday, April 12, 2014

Beware of the "Heartbleed" Bug

The “Heartbleed” bug is a computer security vulnerability that can reveal the contents of a server’s memory and expose private data such as user names, passwords and even credit card information.

The Heartbleed bug exploits a flaw in the Secure Sockets Layer (SSL) of popular open source software called OpenSSL. SSL is the standard security technology that establishes an encrypted link between a user’s web browser and the server where a website is hosted. It is used to secure numerous kinds of data transfers, including email, instant messaging, social media, and business transactions. Encryption is essential to Internet security.

The flaw, discovered on April 7 but apparently in existence for two years, means that attackers can copy a server’s digital keys and use them to impersonate servers to decode communications from the past (and, potentially, the future).

BBB recommends that businesses immediately check to see if their website(s) use Open SSL or have been vulnerable. One way to check, recommended by tech/media website CNET, is a tool developed by a cryptography consultant. If vulnerability exists, businesses should work with their IT department or computer professional to install a more secure SSL on their websites.

Tuesday, October 29, 2013

STOP.THINK.CONNECT



Follow these tips from the STOP.THINK.CONNECT campaign to stay safe online in both your business and personal lives.

Thursday, June 6, 2013

Fake Scanner Emails Infect Office Computers

You are at work, and you receive a message from what you think is your office printer/scanner. It appears that someone sent you a copy of a scanned document.  The name doesn't ring a bell, but you open the attachment anyway.

When you click on the file, you find that it isn't a scanned copy of the latest office report. It’s really a link to a third-party website that will download a virus to your computer.  These viruses phish for personal and banking information on your machine. 

The settings in the email header have been faked, so the messages appear to come from an internal email address. However, with so many workplaces failing to set strong passwords, it is possible that your scanner was hacked.

As always, variations of the scam exist. Most recently, scammers have disguised malware as emails from Hewlett-Packer and Xerox scanners. But scammers will hijack any famous manufacturer’s name to lend credibility to their scam.

NOTE: Hewlett-Packard, IBM and Microsoft are BBB Accredited Businesses. Hewlett-Packard is also a BBB National Partner.

How Do I Protect My Work Computer From Viruses: 

While your work computer is not your personal property, downloading a virus is great way to ruin your work day. Here are tips for protecting your office computer:

  • Create strong passwords. Don’t leave the factory presets or use easy to crack passwords. See Microsoft’s tips for creating strong passwords.
  • Don’t believe what you see. Scammers can make emails appear to come from an account at your office. Just because it’s an “@yourbusiness.com” address does not mean it’s safe.
  • Be wary of unexpected emails that contain links or attachments. Do not click on the links or open the files.
  • Beware of pop-ups. Some pop-ups are designed to look like they’ve originated from your computer. If you see a pop-up that looks like an anti-virus software but warns of a problem that needs to be fixed with an extreme level of urgency, it may be a scam.
  • Keep anti-spyware, anti-virus and anti-spam software up to date.  Your office’s IT department probably has your computer programmed to conduct regular scans and updates. Let these run as planned.

Have you received an email like this?

Saturday, June 1, 2013

Important Tips for Businesses Regarding Checks

A BBB-accredited ad agency in San Antonio, TX recently discovered that bogus checks claiming to be from their company were being used in an over payment/money wiring scam. The checks looked very professional, with the company name and actual routing and account numbers.

People who answered work-at-home want ads on Craigslist were caught up in the scheme. One woman was asked to send out fake checks on behalf of the scammers and was paid by Western Union. When she noticed the Western Union payment was in someone else’s name, she called the real ad agency and asked, “Am I working for you?” The answer was “no.”

She had already sent out 200 bogus checks.

According to the ad agency, the scammers somehow intercepted a check that was sent to a client. They knew something was wrong when someone tried to cash it in another state. Scammers “washed” the check and used it as a template for numerous fake checks in the ad agency’s name.

Which brings up some important tips for businesses regarding checks:

  • Monitor your accounts payable. Stop payment on the check and send out another one if too much time goes by and the check appears to be “lost.”
  • Use tamper resistant checks. Checks with security features make it harder for crooks who may intercept them to counterfeit or alter them.
  • Keep track of check orders. Notify your check supplier and bank if you order checks that don’t arrive in a reasonable amount of time.
  • Keep checks secured. Keep reserve supplies of checks, deposit slips and other banking documents locked up and limit the number of people who can access them. 
  • Keep your eye on the ball. Don’t leave checks or other bank records unattended while you serve customers. Someone might take them while you aren’t looking.

Saturday, May 18, 2013

Spring Cleaning? What to Keep and What to Shred


The Federal Deposit Insurance Corporation (FDIC) says it can’t tell you when it is safe to throw away financial documents, but they do say to keep the information as long as the IRS can assess you additional taxes. Right now, that is approximately seven years. Laws change. Always check with your CPA for the latest laws.

Here are some guidelines:

Credit card statements:
Credit card statements with no tax or other long-term significance can be discarded after one year; remaining statements should be kept for up to seven years. If a consumer receives a detailed annual statement, they should keep it and shred the corresponding monthly statements.

Bank account statements:
Check with your financial institution to determine how far back they keep statements available to you.

Canceled checks:
If purchases are tax related, keep canceled checks seven years. If they are related to your house purchase, renovations, or big items that you purchased, keep them indefinitely. Canceled checks that support tax returns, such as charitable contributions or tax payments, should be held for at least seven years. By the way, banks are required to keep copies of checks for seven years.

Deposit, ATM, credit card, and debit card receipts:
Consumers should save credit, debit, and ATM receipts until the transaction appears on their statement and they have verified that the information is accurate. If it is for a big item and it has a warranty, save the receipt at least until the warranty is up. You might want to save it longer for insurance and/or IRS reasons, if there is a disaster.

Credit card contracts and other loan agreements:
Credit card contracts and loan agreements should be kept for as long as the account is active in case the consumer has a dispute with their lender over the terms of the contract.

Documentation of a purchase or sale of stocks, bonds, and other investments:
Investors should retain documentation of a purchase or sale for as long as they own the investment and then seven years beyond that time. Monthly retirement and monthly investment account statements can be shredded annually after being reconciled with the year-end statement.

Paycheck stubs:
Paycheck stubs can be shredded yearly after the income has been reconciled with a W-2 or other tax forms.

Utility or monthly bills:
Monthly bills should be shredded the year after being received by the consumer. This way, if it’s a power bill, for example, consumers can compare this month’s bill to last year’s bill for any major changes before shredding it.

Electronic Records:
Make sure you back up your data. Technology is always changing. Make sure you are using a method that allows the information to be retrieved.

Saturday, April 6, 2013

Choosing a Domain Name Service

Domain names are used in URL's to identify Web pages. For example, in this URL  http://www.bbb.org/boston/Accredited-Business-Guide/, the domain name is bbb.org.  

It's important to choose a domain name that will be easy to find and navigate. These factors depend upon the registrar where the domain name is purchased. The domain name is reflected in its registrar; when the registrar provides direct and fast service, so will the purchased domain name.

Tips for Finding a Domain Name Service: 

Look at Different Registrars.  Searching domain name registrations online will provide many links to buy a domain name. Make a list of a few of the registrars and investigate them at bbb.org.

Check for ICANN Accreditation.  ICANN, the Internet Corporation for Assigned Names and Numbers, gives accreditation to registrars after their applications are accepted and they sign an agreement. These registrars pay an annual fee. ICANN accreditation assures consumers that when they purchase a domain name from the accredited registrar, the domain name will officially be part of the Internet. Only purchase domain names through registrars that are ICANN accredited.

Carefully Review the Contract.  Each registrar policy is different. When registering, make sure you will be the owner of the domain name. The domain should list you as the administrative and technical contact. This allows customers to have full control over the domain name.

Check Out the Prices.  Compare costs of buying a domain name at different registrars and look at the time period the domain name is owned. Look for a registrar that is known for good customer service and is easy navigate; not just one that has the cheapest price. On occasion, a .org or .net name could be less expensive than buying the .com version. Be careful when purchasing the domain name for longer than one year. If the registrar does not provide good service or goes out of business, you do not want to be restricted or left with an unhosted domain name.  

Pay Online.  Paying with a credit card or through PayPal is the best method. Customers cannot use the domain name until payment has been received and cleared. Paying online allows customers faster access to the domain name that has been purchased.