IT Security Archives - Page 3 of 3 - DNA IT Solutions

Tag Archives: IT Security

What is malware and ransomware, and how can I protect against it?

Cyber security DNA IT

PCs and mobile devices are all at risk from malware. That is the generic term for any program, OS update, email attachment or rogue website that can cause harm to business PCs and the data stored on them. Ransomware is rapidly becoming the most prevalent form of malware. This type of threat locks away the company’s data, and the owners often are forced to pay a ransom, usually in the electronic Bitcoin currency, to restore their files, unless they make very regular backups.

A complete security solution

To defend against these threats, your company needs more than a consumer-level firewall or antivirus software protecting its systems. Instead, a well-rounded approach is required to ensure that all systems are using the latest operating systems and are automatically updated with the latest patches to prevent an attack.

This is because many new types of malware can access “backdoors” into computers that the U.S. government have been using to spy on their enemies, until information about all these backdoors was leaked. Now any cyber criminal can launch a hacking campaign using these tools, and while most operating systems have been patched to protect against them, if your company’s systems are not up to date, they are not protected.

Sophos Security

On the network side, your business needs to scan all data coming into its computers across the Internet, on memory sticks, or in emails. Virus software needs to be updated daily with the latest list of threats. Sophos is our choice of security vendor and its endpoint solutions are smart and can detect malware before it has even been categorised by other anti-virus software.

Security solutions made for your business

With many businesses growing fast, it is hard for them to spare the resources for an IT security expert, so relying on outside help from a company like DNA IT Solutions is an ideal option. This allows you to concentrate on your business and let us worry about the threats that lurk online. These aren’t targeting your business specifically, but they spread so wide, fast and randomly that it is easy for any company to be caught in their net. With all-round IT security protection, you can be sure that your business is best protected, and your data – which is essential for day-to-day operations – will be safe.

Data security in the cloud

Data Security cloud DNA IT

Many businesses are moving to the cloud and their primary motivation for this move is the cost savings and flexibility it offers.  However, there is another significant benefit to be gained and that is increased security for data.

Protecting Data

When you hold sensitive customer data you have an obligation to keep that information safe.  If this data is compromised it will leave an organisation in a negative situation which may cost more than just a loss of a client.  And with the new GDPR coming into force next year this makes the protection of data a regulatory issue.

While breaches do happen in the cloud, attacks on traditional data centres are more frequent.   The main advantage is that the cloud actively helps increase security so threats are mostly eliminated before they can reach the users account.

New ways to attack the cloud

Hackers have always been around and are not likely to disappear anytime soon.  They have just moved location using their existing tactics to try attack the cloud.  Their methods are becoming much more sophisticated so it is vital that your information is protected to the highest level.  Much can be prevented if the data is encrypted throughout its cloud journey from sending to receiving.

Lost Data

Lost Data can be a disaster for any company in any industry and can impact greatly on the day to day running of the business well into the future.  Certain regulations mean that documents must be kept for a number of years and should these be stored somewhere that is not secure the loss of them can be a legal nightmare.

Even losing records of past work, proposal documents or customer records might seem less important but they can have long reaching negative repercussions.

Increased security

The cloud helps increase security as the appropriate level can be built in from the start.  The right provider will ensure your data is securely managed to a level you are comfortable with.  You will be able to choose from public or private cloud to suit your needs.  There will also be the option of a hybrid cloud where you can mix cloud with your on-premises storage.

Whichever you choose, the safety and security of your data is of paramount importance. Protect it in the cloud.  You can speak to one of our cloud service experts to get advice on any aspect of cloud or security.

Another Ransomware Attack Hits

ransomware DNA IT

Throughout the afternoon we have been monitoring a developing global situation with a new version of the highly publicised WannaCry attack.  This major attack has struck both in the USA and Europe and is the second of such attacks in as many months causing serious disruption at major organisations in many countries.

Ransomware

It appears to be a new variant of an old particularly vicious version of Ransomware with some data stealing tools built in also. This strain is known as Petya and affected system are non recoverable and non backed up data and systems are being lost.

The information is emerging in pieces as would be expected and as each hour passes more information is being gathered and shared.  At this point we believe that recent patching against WannaCry closes the door on this variant however extreme caution is advised for all users.

 

Many are concerned about protecting themselves from Ransomware at this stage.  DNA IT Solutions would advise accordingly:

  • Do not open mails with suspicious attachments or with pdf or other documents that you were not expecting. The usual vector to start these infections is via email and a link asking you for more information and for usernames and passwords.
  • These links usually direct to an official looking site (UPS, Fedex , Netflix , Paypal) and look for user names and passwords.
  • Do not browse any non-work related websites. Infections have been known to come via “malvertising” on pages where a link to an ad is actually opening a backdoor to allow rogue software enter a system.
  • XP PC’s and laptops and Windows 2003 servers are particularly vulnerable so please be extra vigilant if using these Operating Systems
  • If you question whether a mail is genuine then it is a risk so the advice is not to open it.
  • If you observe any suspicious activity, please shut down the system affected contact your managed IT Service provider immediately.

 

DNA IT Solutions work with Sophos to provide the best security for IT infrastructures we can.  Broader information on the Sophos approach and guidelines is available here