Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Saturday, July 30, 2016

How MSPs Fail Their Clients

Do Your Employees Recognize Phishing Emails?

We recently conducted an email phishing test for one of our clients, a midsize retailer. Employees received an email disguised as coming from their human resources department. It accused them of accessing prohibited sites on the job and threatened them with termination. Employees were instructed to click a link in the email to see a list of prohibited sites they had allegedly accessed.

We were astonished when 48.5 percent of employees clicked on the link, despite the fact that origination address in the email was from an unknown source and the link clearly led to a destination outside the firewall. This may be an extreme example of the susceptibility of companies to the dangers of phishing, but it is by no means unusual. In our experience, between 20% and 45% of employees fall prey to spurious come-ons. And a single click to a malicious site can infect a user’s computer with malware that compromises the entire corporate network.

Many experts believe that breaches are now so common that the issue is no longer whether organizations will be attacked but when. Some data points:
  • The Ponemon Institute found that nearly 90 percent of healthcare organizations were hit by a breach in the past two years. Last year’s 80 million-record theft at healthcare insurance provider Anthem reportedly went undetected for nine months.
  • Intel’s McAfee Security division reported a nearly eight-fold increase in ransomware attacks over the past year. Ransomware a growing problem; one of our clients was down for four days while they scrambled to pay off an attacker that was holding its servers hostage.
  • An analysis of 11 million stolen passwords for cloud services conducted Skyhigh Networks found that just 20 passwords constitute 10.3% of all passwords in use. They include “123456,” which was used by 4.1% of compromised accounts.
  • The U.S. Bureau of Labor has estimated that 93% of businesses that suffer data loss from a security breach or disaster within five years.
  • Ponemon recently reported that the average consolidated total cost of a data breach is now $4 million.
UCG Adds Cyber Security Training to Cloud Backup

We’ve learned a lot about internal vulnerabilities this year. In January we partnered with KnowBe4, a Clearwater, FL-based security awareness company. The agreement enables us to provide all of our backup and disaster recovery clients with email phishing and exposure tests coupled with online cyber security training for a base number of their employees at no cost. We did this not because it’s profitable be because it’s the right thing to do.

With so many attacks dominating the headlines, we expected that nearly all our clients would jump at the offer of free protection. Surprisingly, only about 20 percent did. We discovered that siloed organizational structures prevented many companies from taking a coordinated approach to security awareness. The people who were in charge of backup and disaster recovery had no responsibility for security. When we were able to tunnel through the organization to find the people who were, they were most receptive to anything that helped increase employee awareness. Unfortunately, finding those people was often like searching for a needle in a haystack.

Technology is Only Part of the Solution

We’ve been in the backup/DR business for nine years, and we compete with many fine companies that provide the best technology: encryption, multisite backup, remote hardware disaster recovery and round-the-clock technical support. But technology is only half the problem. As cartoonist John Klossner pointed out in Computerworld, the finest firewalls, encryption, antivirus software and the like can’t compete against Dave, the accounting clerk whose password is “password.”




Security Training Helps Prevent Phishing Attacks

The good news is that security awareness works. In our experience with KnowBe4, the percentage of employees who are susceptible to phishing emails dropped from 16 percent to 1.3 percent within 12 months after awareness training began. Experts have long agreed that the most serious vulnerability companies’ face is the lack of knowledge of their own people. Security training isn’t difficult or time-consuming. It’s just that many organizations believe its someone else’s responsibility.

Few MSPs are prepared to address this deficit. They have great technology, but they see the security problem as ending at their doorstep. They are failing their customers.

Smart MSPs know that doing business in the cloud is all about partnerships. It’s about taking shared responsibility for customer success and protecting the customer at all levels.

Make Sure You Get the Full Solution

When MSPs come knocking at your door, be prepared to put them through the paces of explaining how their technology protects you. Then ask them what they do about the human side. If you get a blank stare, then proceed with caution. You may be getting only half a solution.


Sunday, September 27, 2015

UCG Partners with Leading Cyber Security Firm KnowBe4, LLC

Managed Service cyber security training now included with UCG’s VAULT400 BaaS and DR program


United Computer Group, Inc. (UCG), a global information technology services firm, is pleased to announce a partnership with KnowBe4 LLC (KB4) Tampa Bay, FL, the world’s most popular integrated Security Training and Simulated Phishing platform.

KB4’s solution suite provides both pre- and post-phishing security tests that show the percentage of end-users that are phish-prone. Scheduled security tests keep employees on their toes with security top of mind, and can provide remedial online training in case an employee falls for a simulated phishing attack. The solution suite is based on Kevin Mitnick’s 30+ year unique first-hand hacking experience, and provides tools to better manage IT security problems of social engineering, spear-phishing and ransomware attacks.  

KnowBe4’s CEO, Stu Sjouwerman stated, “We are very pleased to be partnering with UCG and are looking forward to helping manage the problem created by cybercriminals.”

James A. Kandrac, Founder & President of UCG said, “We continuously listen to client needs and cyber security has been on the forefront for quite some time. UCG’s VAULT400 BaaS will now include a turnkey managed solution version of KB4’s cyber security solution suite via remote implementation in less than 90 minutes.”

Scheduled simulated phishing attacks and monthly reports will provide executives the insight they need to maximize training ROI and track security compliance. As an added value, a base number of KB4 users will be included at no additional charge to current and new VAULT400 subscribers. UCG is very selective when adding a new partner. What impressed UCG the most was the experience, focus, continual product updates and unbridled passion for cyber security that KB4 brings to the table. 

Kandrac added, “We have done our due diligence and are pleased to bring this exciting solution suite into the UCG fold. We look forward to a long term partnership with KnowBe4, Stu Sjouwerman and his valued team.”

About KnowBe4
knowbe4.com
The KnowBe4 team has built, deployed, and supported market leading e-learning applications and has deep roots in IT Security. KnowBe4 was founded by Stu Sjouwerman (pronounced “shower-man”), formerly co-founder of Sunbelt Software, developer of VIPRE Antivirus, which in 2010 was acquired by GFI Software, a portfolio company of the Insight Venture Partners Venture Capital Fund in New York and Boston.

Listen to webinar replay: 2015 State of IBM POWER8 Backup, Disaster Recovery & Cyber Security Webinar, from UCG and IBM Systems Magazine

Download PDF: Why Security Awareness Training? Ransomware. That's Why.


Download PDF: Which email addresses are exposed on the internet and are a target for phishing attacks?

Download PDF: Find Out What Percentage of Your Employees is Phish-prone

Download PDF: Social Engineering Red Flags.