If you don’t where it is, you can’t protect it.
Do you know where ALL your organisation’s data is – not physically, but on which web and cloud services?
Here’s the problem. If you don’t where it is, then you can’t protect it. The secondary problem is finding out, because not everyone in your organisation will be onboard. It is common for people to sign up to web services because they offer something useful that helps them do their job.
They sign up using their email address and creating a password. There is the first headache – how does anyone track what has been signed up to across your organisation, let alone who has access to it? If that person leaves, no one will change the account credentials if they don’t know about it, but your ex-colleague still has access.
Secondly, what data do they upload? Is that data that you have a legal or moral responsibility for?
There’s nothing noble about Nobelium.
This isn’t theory – it’s real. USAID is a pretty important US organisation – promoting democracy and human rights around the world. Turns out, someone there was using a well-known email database tool called Constant Contact. But their account wasn’t well protected. Worse still, their account had a huge mailing set up, and of course, it had all the official USAID templates.
So, these Nobelium people, allegedly a Russian state-sponsored hacker group, compromised the Constant Contact account and sent a bulletin out. The bulletin contained malware that allowed the hackers to take command and control over victims computers. Ironically the fake email alleged interference in the US federal elections.
So, what can you do?
The first step is knowing what SaaS tools your people are using. We call this SHADOW IT and it is inevitable. Rather than stopping it, the job IT has is to identify it and manage it. The second step is to secure those platforms. That’s why our KARE for Security S2 plan contains a useful tool to help you identify what services your people are using.
Refer : What We Know About The Apparent Russian Hack Exploiting USAID : NPR
Making Teams presentations stand out
How to put yourself in the picture and make your online presentations look really professional!We are all looking for ways to stand out, apart from others. Lockdown has taught us that we don't have to be in the same room any more to present to clients, partners and...
Urgent – “Zero Day” exploit 9 Sept 2021
Today's news is full of stories about increased cyber-threats in NZ - Cyber attacks against Kiwibank, ANZ, NZ Post, MetService - experts see lockdown link - NZ Herald We've seen several days of issues caused by these "DDOS" attacks. Overnight, another...
Real world Cyber-Security stories from the battlefront.
Every day we’re seeing more and more hacking attempts against clients. Cyber security attacks are getting more frequent, more threatening, and much more sophisticated. But for all that, and for all the associated risks, we’re astounded by the number of organisations...
Have you tried Microsoft Teams Breakout Rooms yet?
Lockdown has driven our normal meetings and events online. Tools like Zoom and Teams have responded by becoming more and more capable. The challenge is that many of the features being added just appear. There is surprisingly little fanfare about many of them. I...
Have you heard about “typosquatting”?
"Typosquatting" is the name given to criminals pretending to be someone they aren't - taking a domain name that uses a clever combination of legitimate-looking original sender email addresses, with spoofed display sender addresses that contain the target usernames and...
Are Skype’s days numbered?
Is it finally time? For a long time, Skype was the “go-to” video calling app. It was free, and it worked so much better than the alternatives. It used to be the default means to connect with friends and family, to the point that it achieved verb status – we would say...
Advanced Warning – Microsoft 365 Price Changes
New pricing for Microsoft 365 | Microsoft 365 Blog We wanted to give you a heads-up to expect a price increase for Microsoft 365 (Office 365) from May next year 2022. When you consider the additional functionality they’ve included, this is fair enough – the challenge...
Preparing for a sudden Covid19 Delta Lockdown in New Zealand
Every week that we don't go into lockdown seems like a blessing. It can only be a matter of time before NZ is thrown back to a tight, restrictive lockdown. If, as we read yesterday, every Covid case coming in through the New Zealand border right now is infected with...
Cyber-war Seminar
Stories from the Cyber-war The simple reality is that cyber-crime is now a mega-business. The cost and effort to combat it grows all the time. "Is it worth it?" Good question. Every organisation needs to choose a level of security and resulting cost, effort and...
Law firm Tip : Don’t lose Word Documents if you use Infinity Law
Be careful with what you delete. We're proud to be one of NZ's foremost IT support businesses for law firms. That means we run across common legal software all the time, and one of the most common programs we see is InfinityLaw Recently we encountered an hidden issue...









