Showing posts with label Defence in Depth. Show all posts
Showing posts with label Defence in Depth. Show all posts

Monday, 12 September 2016

Protect your on-line accounts, but not with text messages.

As I outlined here, if you are using an on-line account for e-mail, social media, etc. then one of the strongest means of protecting yourself from the evil doers is to use, what is called, two factor authentication. If you are not doing this now, you really should be as it improves your protection massively.

This is where you can set your on-line account to not only request your user ID and password (something you know) but also using your phone (something you have) by way of an app or sending you a text message with a code that you enter on the site to confirm you are you

If you have this set-up to authenticate by a SMS Text message, then a bad guy who has access to your LinkedIn details from the 2012 hack should not be able to access your e-mail account using the password that they have recovered from there, because as soon as they try to access your e-mail account, you will be sent a text message. So you're safe ... right?

Thursday, 7 July 2016

The Ten Commandments of Cyber Security


Click on the links for a summary and detail of each commandment.
  1. Thou shalt keep all of thy software and apps up-to-date with automatic updates.
  2. Thou shalt have Anti-virus software installed, updated and active.
  3. Thou shalt have a firewall in place on thine Desktop/Laptop as well as thine internet connection.
  4. Thou shalt always back up thy data and regularly check its integrity.
  5. Thou shalt cast aside messages from strangers and not open attachments/click links they may send you. (Corollary: Thou shalt never open an unexpected file/link from thine family, friends or colleagues)
  6. Thou shalt encrypt all data stored on thine mobile devices.
  7. Thou shalt use two factor authentication on any account that provides the facility.
  8. Thou shalt never reveal thine password for any account to anyone.
  9. Thou shalt never insert nor allow to be inserted, a USB memory stick that thy has never had complete control of since it was removed from its packaging.
  10. Thou shalt only use the official stores for apps.

X. Thou shalt only use the official stores for apps.

This is the final instalment in this series, which I have outlined here.

Summary:

This commandment is more targeted at the mobile device side of technology, but app stores are spreading into the desktop/laptop areas by way of Windows Store for Windows 8.1 and Windows 10.

From a mobile device perspective, you should only use the official app store for that platform. Most smartphones come with a setting that tells them to only allow apps to be downloaded and installed from the official sources (or not to be installed from untrusted sources).

Tuesday, 5 July 2016

IX. Thou shalt never insert nor allow to be inserted, a USB memory stick that thy hath never had complete control of since it was removed from its packaging.

This is the penultimate instalment in the series, which I have outlined here.

Summary:

This is an easy commandment to follow, but there might be temptation to breach it for convenience. 

If you find a USB memory stick on the street or in a car park, bring it to a waste electrical goods recycling centre and dispose of it there. I was going to say place it in a bin, but that would not be good for the environment.

If anybody comes to you and wants you to plug in a USB memory stick into your desktop or laptop, just don’t! No matter what promises they make as to the security and cleanliness of their systems, you simply cannot trust the device.

Thursday, 30 June 2016

VIII. Thou shalt never reveal thine password for any account to anyone.

This is the eight instalment in the series, which I have outlined here.

Summary:

This is one that should be an absolute no-brainer. Your password is your key to your data and applications. It should be absolutely sacrosanct and known only to yourself and NOBODY else. Nobody else has a need for it, except the evil doers and you wouldn’t give it to them willingly, would you? It couldn’t be simpler than this.

Tuesday, 28 June 2016

VII. Thou shalt use two factor authentication on any account that provides the facility.

This is the next instalment in the series, which I have outlined here.

Summary:

What is two factor authentication? Put simply it is a way of gaining access to an application by using two means of verifying the identity of the person requesting access. Typically the means of verification are (a) something you know – e.g.- a Password (b) something you have – e.g.- a Mobile phone (c) something you are – e.g.- a Fingerprint.

It is probably one of the best ways of protecting an on-line account from evil doers, who scour the web, stealing passwords by the millions from the likes of LinkedIn and MySpace.

Thursday, 23 June 2016

VI. Thou shalt encrypt all data stored on thine mobile devices.

This is the sixth instalment in the series, which I have outlined here.

Summary:

Your data is valuable to you. Even something as simple as the phone numbers in your phone’s contact app. It’s also valuable to the evil doers. They would dearly love access to your phone with all of the valuable e-mail, SMS, call logs, WhatsApp messages. Everything on your phone will be of some use to these criminals, because it is real data, with valid names, e-mail addresses, phone numbers, etc. and they can sell this online to anybody who wants it, such as your competitors. Wouldn’t they like to know that you’ve been making lots of calls to one of their customers recently.

Tuesday, 21 June 2016

V. Thou shalt cast aside messages from strangers and not open attachments/click links they may send you.

We are half way through this series, which I have outlined here.

Summary:

I’m going to start this summary with some scary figures. 93% of phishing e-mails in Quarter 1 2016 have carried a Ransomware payload (source - PhishMe Q1 2016 Malware review). 30% of people that receive phishing e-mails open them and 12% of those that do, then open attachments or click on links (source - Verizon 2016 Data Breach Investigations Report).

Putting this into real figures – if you have 50 staff and they each receive phishing e-mail, 46 of them will have received Ransomware, 14 of them will look at the ransomware e-mail and 2 of them will open an attachment or click the link which will bring Ransomware into your business and cause mayhem. Even if you have followed Commandment IV to the letter.

Friday, 17 June 2016

IV. Thou shalt always back up thy data and regularly check its integrity.

This is the next instalment in the series, which I have outlined here.

Summary:

In conjunction with the first, second and third commandments … are you seeing a pattern here? By following each of these simple commandments, you are providing additional layers of defence against the evil doers. This is what security experts refer to as Defence-in-Depth. The more precautions you take, the more difficult it makes life for the bad guys, so they move on to easier targets than you.

Friday, 10 June 2016

III. Thou shalt have a firewall in place on thine Desktop/Laptop as well as thine internet connection.

This is the third instalment in the series, which I have outlined here.

Summary:

In conjunction with the first and second commandments, having a Firewall in place on your desktop or laptop improves your security posture as it adds another layer of protection in the fight against the evil doers. It is by no means a perfect solution on its own, as a poorly configured firewall would offer as much protection as a string vest in -30c/-22f weather conditions.

Tuesday, 7 June 2016

II - Thou shalt have Anti-virus software installed, updated and active.

This is the next instalment in the series, which I have outlined here.

Summary:

In conjunction with the first commandment, having Anti-Virus software installed, updated and active on your desktop, laptop or mobile device dramatically improves your security posture. This adds another layer of protection in the fight against the bad guys. 

Thursday, 2 June 2016

I - Thou shalt keep all of thy software and apps up-to-date with automatic updates.


This is the first in the series, which I have outlined here.


Summary

This is the first commandment for a reason. It is probably the number 1 step to reducing your risk of being compromised by hackers or malware. The reason for this is because hackers discover vulnerabilities in applications that are widely used (web browsers, e-mail clients, office productivity suites, etc.) and exploit these vulnerabilities to compromise your system (desktop, laptop, servers or mobile devices). 

Tuesday, 31 May 2016

Ten Commandments of Cyber Security.

Over the coming weeks, I will post a series of short articles in support of each of what I am calling the Ten Commandments of Cyber Security. These are simple steps for improving your cyber security posture, which should reduce your risk of being compromised.

These commandments are listed below, but I would like your opinions on this subject too. Do you have a commandment to add or any thoughts on any of those listed? Please let me know and I will do a follow up after I have completed my run through.

 Ten Commandments of Cyber Security.



  1. Thou shalt keep all of thy software and apps up-to-date with automatic updates.
  2. Thou shalt have Anti-virus software installed, updated and active.
  3. Thou shalt have a firewall in place on thine Desktop/Laptop as well as thine internet connection.
  4. Thou shalt always back up thy data and regularly check its integrity.
  5. Thou shalt cast aside messages from strangers and not open attachments/click links they may send you. (Corollary: Thou shalt never open an unexpected file/link from thine family, friends or colleagues)
  6. Thou shalt encrypt all data stored on thine mobile devices.
  7. Thou shalt use two factor authentication on any account that provides the facility.
  8. Thou shalt never reveal thine password for any account to anyone.
  9. Thou shalt never insert nor allow to be inserted, a USB memory stick that thy has never had complete control of since it was removed from its packaging.
  10. Thou shalt only use the official stores for apps.