Tags: businesses
Self Employed & Home Based Business must take IT Security very seriously
Good day to you,
I would like to take this opportunity to share some very critical information with the self employed and home based business owners about the state of The IT Security Threats Landscape ~TITSTL~ and how it affects you. This is a discussion I have every day as more and more people in these categories are finding out the real effects and impacts of these threats are not excluding them and that they fall very much into the mix of it. As the economy tightens its grip on our lives, those who are being laid off are turning to home based and self employed business thus sparking an increased growth in this area of business. The SMB space has grown tremendously since his recession and to that end has become a serious security issue for us security professionals as we look across the IT Security Threats Landscape horizon.
Therefore, the reality of the issue must be faced thus bringing the question of, what am I to do about it.
I have published numerous articles on these threats, preventative measures and how to deal with the security issues of today and tomorrow on my blogs but I am going to do this as a summary of those here.
First let me say this, if it requires a security patch (let’s just keep it at security for now), it is vulnerable.
What does this mean?
Simple, any operating system, Microsoft, Mac, Linux, Solaris, you name it, that requires a security patch for any reason is vulnerable. The patch is to prevent exploit of the vulnerability right so it is a security risk.
I had to get that out of the way so that we wouldn’t get into the ridiculous argument of which is more secure than the other. The way I see it is simply that, if a door is left open for anyone to come through it, the length of time left open versus the threat that comes through it is just as critical. So, any open door is a threat no matter where. What comes through it may differentiate the severity. They all have their insecurities at some point but how the vendor/developer addresses it lessens the impact and wide scale visibility of the issue. While some may announce these vulnerabilities and findings, other may patch/update them behind the scenes thus limiting the visibility and knowledge of the user.
Second, anti-virus alone is NOT going to protect you from the threats of today. It takes a multi-layered approach and as such, the various layers of protection must be enforced. So telling yourself that you have anti-virus protection on your PC is being as naïve as saying the threats doesn’t affect me and i’m not worried about them. While it is true that most anti-virus vendors are bundling multiple threat protection/prevention layers into their solutions, the proper configuration becomes the caveat to that solution. While many deploy with an out of the box config, there will be tweaks needed to customize it to your environment and needs. So one must understand what is being deployed and if it will provide the layers of protection needed.
So why is IT Security so serious for me as a self employed or home based business?
Well, ask yourself these questions,
What is it that you do and how do you do it?
Do you use email?
Do you send emails to customers/clients/partners/associates/potential clients?
Do you leverage the powers of social networking/media (Twitter, LinkedIn, MySpace, Facebook, Ning and the list goes on) today?
Do you use IM for personal and/or business use?
Do you browse the internet for data/information on whatever you’re working on or researching?
Do you do online banking or shopping?
Do you download multimedia contents from the web (music, movies, flash videos, etc)?
Do you download online presentations (PDF, PowerPoint)?
Did you know that PDF files presented one of the biggest security risks over the past 2 years but is the most widely distributed online document format?
Do you have a printer or some media player connected to you system(s) at home or in the office?
Do you have any applications running on that system aside from the operating system?
Do you know of the Breach Notification Law in your state and what it means for you?
When was the last time you downloaded a keygens or crack file to open full access to that app or game you really wanted but didn’t want to buy/pay for?
Maybe you didn’t crack/keygen it but someone did and opened a backdoor which planed a rootkit or some nefarious threats on your system(s). What happens when you use that for business purposes, what are you spreading to those you collaborate with?
Well by now i’m sure you’ve caught my drift and I don’t have to get technical for you to see how you’re affected. All these questions pose security risks in various ways and are able to be stopped, prevented and protected if the proper education, awareness and measures are put in place. Don’t ask if you’re affected or if I should be taking these things seriously, you must. You are as much a risk to me as I am to you if the proper steps are not implemented to secure your system and the data/information you have sitting on it about me, you and those you collaborate with.
That system is being used for personal and business use and at some point the access to/from or by a threat is heightened because of the lack of separation of the two. A system that is used by everyone in the home should not be the same used for doing your business. When someone in the home decides to crack that app and opens that backdoor, you’ll never know what can come through it and what your risk factor will be or are. Separate the two, business is business and personal is personal. The cost of a system today is much more affordable than a few years ago so it shouldn’t be a problem to get an extra one.
You are not a small business because you have 5 people working for you. You are not a small business because you only have 5 computers in your office or where you decide to conduct your business. To me as a security professional you are not a small business (home based or in an office) when you have records/information and access to 5000 people. A doctor who has an office with 5 employees and 8 systems managing 4000 patients’ info is not a small business in my eyes. If you’re a consultant running your own business and you manage systems or information for your clients you’re now there biggest risk because it’s your responsibility to control that. Every PC must be secured whether it is connected online or not as you never know if/when it will cross the line. This is how I see security.
When you decide to start doing business today you must consider the role you play with those in which you will be doing business and the kinds of interaction you will have with them. When sending an email from an infected system (whether you did or the resident worm) it is still coming from you and the possible effect on the recipient(s) can be adverse which may lead to legal issues.
When using social network can enhance your presence and what you do significantly, it is also an area of heightened risk both personally and professionally. Know the need and use it accordingly. Social networks are the future of collaboration but one must decide why the need and create the separation. If it’s for personal use one should always remember the impact on themselves as they are now putting themselves out there to the world. If for business, one should decide on how they want to be seen and what they would like the world to know about them and what they do. Social networking is a great thing to have and use, it’s the management and control of that presence that matters. The threats people face on social networks are the same they would face outside of it but just through a different medium. Educate yourself on these things and you will be ok.
As for the Breach Notification Law, most people didn’t even know of such laws about digital contents and its security. I strongly suggest you take a look at the law of your state and understand the legal and financial issues it presents for you. Learn it, know it, and understand it. If in doubt, reach out.
The active Conficker worm should be enough of an eye opener for you and if you don’t know what it is then you may have bigger problems that I thought. Security is not just about you, it’s about your way of life today both on and offline. I am not here to scare you but it is better to know before than after as the damage control, legal and financial issues after the fact is much worse and a very daunting issue.
As for the online scams, phishing and SPAM, it is only going to get worse and until you educate and make yourself more aware of and about them, you may fall victim to them as they are craftier than ever.
Ok so I have chatted enough and now you’re saying this is too much so I will leave a few articles of reference. Feel free to contact me if you’d like to discuss further and in more details.
The Conficker Worm – my review
A grim day for browser security at hacker contest
State Security Breach Notification Laws as of December 16, 2008 and the Conficker worm
IT Security Education and Awareness 04-09 #1 - IT Security is a people problem, not an industry one
Apple Mac users warned of web-based malware threats RSPlug-F Mac Trojan horse distributed via HDTV website
TITSSN leverages the Twitter network for critical alerting, notification and network happenings (meetings and events) as of April 1st 2009
Security/Privacy Awareness 03-09 #1 - Do you understand the breach notification law is in your country/state, do you know what it means, all are affected.
Thank you and have a great day,
~Brett A. Scudder~
The IT Security Attaché
TITSSN’s ENGAGED ~ENabling Greater Awareness, Growth and Educational Development~
Link: http://titssn.net
TITSSN has always been a network of, for and about the community and we have always tried to find ways of working within it to make it the most valuable and successful experience ever for our members. In working with our communities in and outside of IT, we have found similar issues that reflected upon the need for creating a more resourceful and aggregated system that would put people, processes and things together, making it a more seamless integration for all. Our education and awareness training and development initiatives built on these findings so that we would address the issues on a more personal level as a team. The extensive experience and qualifications of the network members in their areas of business provides invaluable impact on what we see, hear, say and how we react to them.
It is for this reason that we are enacting a new initiative to aggregate all these issues, programs and initiatives under one umbrella that I believe will fix these problems, ENGAGED. ENGAGED, ENabling Greater Awareness, Growth and Educational Development, is an initiative that will take our education, awareness, training and development initiatives to a whole new level. Through ENGAGED, we are working with businesses, schools, libraries, churches and other institutions to deliver the needed resources for addressing the IT Security Threats Landscape of today for tomorrow.
As a network of technical professionals, consultants, specialists, VARs and business executives, the ENGAGED initiative will add the much needed collaboration between the organization members and those we serve. One such enhancement will be a bi-weekly Live Meetings via Microsoft’s Live Meeting service to help with the adoption, training and development of its members on new and existing products and solutions in the security space. This will add the needed value of increased training on specialized products and services provided by the network. Our integration of working with the vendors directly will allow the additional benefit of having their high level technical people in the session to help with the understanding of the products and any problems and support we may need. TITSSN believes that it is through the proper training, understanding and knowledge of these products that we will be successful in supporting, deploying and managing them, and so we are adding more value through the use of live meetings.
On Monday April 20th, TITSSN will enhance the ENGAGED initiative by starting an IT Security Training and Development course for the youths in our local schools through their local office in Arverne NY. This course will be geared towards working with the youths of today who are growing up to be our professionals of tomorrow to give them a better look and feel of the space and what to expect from it. We are working with the local schools in the community to select a number of students who will participate in this course and get the needed exposure to today’s IT Security Threats Landscape ~ITSTL~ and how they can be valuable resources in making it better for tomorrow. This training course will not be the end all, be all for them as we plan on helping them throughout their professional development as mentors in the space. The initiative does not want them learning and forgetting and so future involvement on different levels will follow after the course is completed. Certifications will be awarded to each student that completes the course and passes a final hands-on test.
The training and development course will introduce them to the world of IT Security and all the factors that are in and around it. They will have hands-on access to the latest and greatest security hardware and software products ranging from Biometrics, IDS/IPS, UTM “Unified Threat Management” devices, anti-virus, anti-malware, firewalls and general IT products that are available today across the various operating system environments. This is an extension of our Secure Minds Initiative where we are trying to get the integration of IT Security into the school’s curriculum to enhance the preparedness of this needed area of specialty for the future. We need the realization of IT Security as a people problem to be one that resonates across all borders and cultures. We are on the brink of a global network catastrophe if this realization is not understood.
Through ENGAGED, we have negotiated special vendor pricing and offers to help get the needed security products and solutions out to the general public. As this have been a major issue for many, we are always working on ways in which to bring the networks power to use in negotiating special programs, offerings and incentives from the vendors for our initiatives. A part of our Secure Minds Initiative is to provide security products and solutions to the schools and this will help to make that more readily available through special programs we are hosting there. We are reaching out to our local government resources to funds this initiative through grants and other financial resources in an effort to minimize the costs and offer the products freely when and where we can.
To the business community, ENGAGED provides the needed sales, support and training and development to better prepare you, your company and employees to deal with the issues of the IT Security Threats Landscape. Leveraging our network and resources will be beneficial for you as we provide in-house training and development workshops to further build on this. As your local technology/security professionals, you can reach out to the network to find a resource in your area that can and will work with you. We have customized solutions that will work for you and your company no matter the size or location, if we’re needed we’ll make it there.
With so many resources now being forced online even from the government levels, using the internet and its resource is now a mandatory issues as local offices and resources are being cut as this new online presence becomes more useful. That being said, the use of the internet and its resources has increased significantly over the past year as social networking and other social media have played a key role in this new age of collaboration and networking. The future belongs to networkers and if you’re not a part of the new trend one tends to feel left out when asked if they are on a popular network like Facebook, Twitter or LinkedIn.
The present economic crisis adds a dire need for this engagement as more people are using the internet resources for job hunting and finding new homes to live. This is just the start of a change that will never go back to what it used to be, the internet is here to stay and is more than what it used to be 2 years ago.
TITSSN activates the ENGAGED initiative on April 1st 2009 with a series of kick off events for the month. On April 9th at TITSSN’s monthly meeting at the Microsoft Briefing Center in NYC, president/chairman/security attaché Mr. Brett A. Scudder will officially present the initiative to the organization and outlining a few additional aspects of it and how it will be executed. He will also cover the members ENGAGED aspects as well. Registration is open and available here http://www.clicktoattend.com/?id=137146
On Monday April 13th from 3-5pm, TITSSN will host a local reception at our office at 331 Beach 70th St, Arverne, NY, 11692 to highlight some of the technologies that will be a part of the initiative. This is a RSVP/registration event. Interested persons are asked to register here http://www.clicktoattend.com/?id=137140.
The first ENGAGED members Live Meeting session will be on Wednesday April 22nd from 7-9pm and the info will be sent to active members.
As food and refreshments will be provided at our local meetings and events and we need to ensure that we have enough to cover our guests so registration for these events is a must.
Thank you very much and have a great day.
TITSSN ~The IT Security Suite Network~
We are Security - your Security - our Security - IT Security. Our Security is Safe and Secure.
TITSSN’s March 22nd online security webcast – Security is not an option, it's a must. Five overlooked ways of securing your systems effectively
Link: http://theitsecurityattache.com/blogs
TITSSN’s March online security webcast – Security is not an option, it’s a must. Five overlooked ways of securing your systems effectively.
Sunday March 22nd at 7pm
TITSSN continues its monthly online security webcasts/presentation/forum and invites everyone to join us.
As technology continues to grow and the increase in new products and solutions become inundating, we’re seeing more avenues of risk associated with this growth across the board. On Sunday March 22nd at 7pm we will be taking a look at five critical ways in which we sometimes overlook securing our systems and end up becoming compromised.
Whether this is a home or business system, security is not an option as you never know if or when this system may be used to cross the line. This webcast will give a detailed look at these five issues that have pervasively increased the risks of the threats landscape with little or no interaction from the end user(s). The threats are the same across the board so all are affected.
This will be a live meeting session that offers the needed interactivity (voice and video) for getting the message across effectively.
All are invited as we continue delivering our education and awareness initiatives on/about IT Security and it being a people problem, not an industry one.
—————————————————
When: Sunday, Mar 22, 2009 7:00 PM (EDT)
Duration: 1:00
TITSSN continues its monthly online security webcasts/presentation/forum and invites everyone to join us.
Brett Scudder has invited you to attend an online meeting using Microsoft Office Live Meeting.
https://www.livemeeting.com/cc/usergroups/join?id=7S86HQ&role=attend&pw=8%3Ehg%28ZR%2Fz
Meeting time: Mar 22, 2009 7:00 PM (EDT)
Add to my Outlook Calendar:
https://www.livemeeting.com/cc/usergroups/meetingICS?id=7S86HQ&role=attend&pw=8%3Ehg%28ZR%2Fz&i=i.ics
——————————————————
Thank you very much and have a great day. We apprecilove your business and support and look forward to serving you more.
~Brett A. Scudder~
The IT Security Attaché | http://theitsecurityattache.com | Blogs http://theitsecurityattache.com/blogs
President/CEO/Chairman/Founder/Security Architect
~TITSSN ~The IT Security Suite Network~ | http://titssn.net | TITSSN’s Blogs http://titssn.net/blogs
My LinkedIn profile - http://www.linkedin.com/in/titssn | TITSSN’s IT Security Forum Board http://titssn.net/forum
Follow me on Twitter http://twitter.com/TITSSN

