Thursday, 30 June 2016

VIII. Thou shalt never reveal thine password for any account to anyone.

This is the eight instalment in the series, which I have outlined here.

Summary:

This is one that should be an absolute no-brainer. Your password is your key to your data and applications. It should be absolutely sacrosanct and known only to yourself and NOBODY else. Nobody else has a need for it, except the evil doers and you wouldn’t give it to them willingly, would you? It couldn’t be simpler than this.

Wednesday, 29 June 2016

Microsoft Office 365 users hit by massive Ransomware phishing campaign.

It is estimated that 57% of customers using Microsoft's Office 365 platform received at least one copy of the Cerber Ransomware. They will have received a word document attachment which, if it were opened, would appear as follows:


Note the big banner with red text asking for the "Enable Content" button to be clicked. No reputable document would contain such a request.

So if you have not adhered to Commandment V and have opened a document from a stranger - don't click Enable Content or any other button other than the X in the top-right-corner of the Word Window and delete the e-mail that contained the document.

Full details from the company that detected the attack is here.

Tuesday, 28 June 2016

VII. Thou shalt use two factor authentication on any account that provides the facility.

This is the next instalment in the series, which I have outlined here.

Summary:

What is two factor authentication? Put simply it is a way of gaining access to an application by using two means of verifying the identity of the person requesting access. Typically the means of verification are (a) something you know – e.g.- a Password (b) something you have – e.g.- a Mobile phone (c) something you are – e.g.- a Fingerprint.

It is probably one of the best ways of protecting an on-line account from evil doers, who scour the web, stealing passwords by the millions from the likes of LinkedIn and MySpace.

Thursday, 23 June 2016

VI. Thou shalt encrypt all data stored on thine mobile devices.

This is the sixth instalment in the series, which I have outlined here.

Summary:

Your data is valuable to you. Even something as simple as the phone numbers in your phone’s contact app. It’s also valuable to the evil doers. They would dearly love access to your phone with all of the valuable e-mail, SMS, call logs, WhatsApp messages. Everything on your phone will be of some use to these criminals, because it is real data, with valid names, e-mail addresses, phone numbers, etc. and they can sell this online to anybody who wants it, such as your competitors. Wouldn’t they like to know that you’ve been making lots of calls to one of their customers recently.

Tuesday, 21 June 2016

V. Thou shalt cast aside messages from strangers and not open attachments/click links they may send you.

We are half way through this series, which I have outlined here.

Summary:

I’m going to start this summary with some scary figures. 93% of phishing e-mails in Quarter 1 2016 have carried a Ransomware payload (source - PhishMe Q1 2016 Malware review). 30% of people that receive phishing e-mails open them and 12% of those that do, then open attachments or click on links (source - Verizon 2016 Data Breach Investigations Report).

Putting this into real figures – if you have 50 staff and they each receive phishing e-mail, 46 of them will have received Ransomware, 14 of them will look at the ransomware e-mail and 2 of them will open an attachment or click the link which will bring Ransomware into your business and cause mayhem. Even if you have followed Commandment IV to the letter.

Friday, 17 June 2016

IV. Thou shalt always back up thy data and regularly check its integrity.

This is the next instalment in the series, which I have outlined here.

Summary:

In conjunction with the first, second and third commandments … are you seeing a pattern here? By following each of these simple commandments, you are providing additional layers of defence against the evil doers. This is what security experts refer to as Defence-in-Depth. The more precautions you take, the more difficult it makes life for the bad guys, so they move on to easier targets than you.

Friday, 10 June 2016

III. Thou shalt have a firewall in place on thine Desktop/Laptop as well as thine internet connection.

This is the third instalment in the series, which I have outlined here.

Summary:

In conjunction with the first and second commandments, having a Firewall in place on your desktop or laptop improves your security posture as it adds another layer of protection in the fight against the evil doers. It is by no means a perfect solution on its own, as a poorly configured firewall would offer as much protection as a string vest in -30c/-22f weather conditions.

Tuesday, 7 June 2016

II - Thou shalt have Anti-virus software installed, updated and active.

This is the next instalment in the series, which I have outlined here.

Summary:

In conjunction with the first commandment, having Anti-Virus software installed, updated and active on your desktop, laptop or mobile device dramatically improves your security posture. This adds another layer of protection in the fight against the bad guys. 

Saturday, 4 June 2016

A slew of fake connection requests.

For somebody who normally receives a connection request about once a week, yesterday I suddenly received 6! Wow, am I popular or what???

Well in this case I am popular ... for the scammers. Each one was a fake profile.

Firstly none of them had a connection in common with any of my contacts. This always makes me question why are they trying to connect with me.

I then Googled the names and companies.

Thursday, 2 June 2016

I - Thou shalt keep all of thy software and apps up-to-date with automatic updates.


This is the first in the series, which I have outlined here.


Summary

This is the first commandment for a reason. It is probably the number 1 step to reducing your risk of being compromised by hackers or malware. The reason for this is because hackers discover vulnerabilities in applications that are widely used (web browsers, e-mail clients, office productivity suites, etc.) and exploit these vulnerabilities to compromise your system (desktop, laptop, servers or mobile devices).