Showing posts with label Firewalls. Show all posts
Showing posts with label Firewalls. Show all posts

Thursday, September 1, 2011

How to Protect Your Business In the Age of Technology

by Matthew Frank - Inside Sales Rep at MAC Source Communications

If you have ever watched the movie "Catch Me If You Can" you know that it was fairly easy for Leonardo DiCaprio's character to become someone else and steal millions of dollars from companies.  He was able to print his own paychecks, make new ID's, and then when all is said and done, he was able to disappear.  This all took place in the 1960s, before personal computers, before cell phones, before social media.  And the guy was less than 19 years old.  Oh, the movie was based on true events.

Now, its 2011, and we have things like personal computers, iPads, Cellphones, and Social Media.  In fact, we have so much technology, that people are constantly exposed.  What does this mean?  It means that people are just as exposed, if not more exposed than in the 1960's.

To combat this, you have a few options.  You can lock down all your electronics.  Password protect and encrypt every device you have and even then that doesn't give you 100% protection.  You can never go on the Internet again (although, lets be realistic, I would be crying after about 2 hours), or you can be smart about your technology.

The first thing to do is to look at your business and say "Am I properly protected?"  Do you have all your security features in place?  Is the wifi at your company secure?  Is your firewall setup properly?  Do you monitor everything your employees do online to make sure there is no malicious software coming through and people are being productive?  What about guest access to your wireless network?  Do guests have the ability to go on your network without having the ability to get into the private information on there?  Think about these questions for 2 minutes.  Good, now here are two solutions.


Next Generation Firewall:

Most companies have firewalls that block everything coming through a specific port.  The problem with this, is that it blocks things that are both good and bad.  Who wants to block the good?  Facebook for instance, is a great tool to use for marketing, but most companies can only turn it on or off.  They can't choose what features they want on, or what they want blocked.

With the Next Generation Firewall from Palo Alto Networks, you can control what applications and content come through on your network.  That means, that you can allow Facebook, but limit it.  Block games, but give employees the ability to read their messages.  Stop them from posting pictures (especially if you have sensitive information in your company that cannot be leaked) but allow them to post status updates or update the company page.  What about monitoring what sites employees are on?  Don't have time right?  Well, this firewall is a great device, in that it can generate reports for you in a nice and clean format so that you can see what is coming through your firewall.  You can see who is viewing something, what they are viewing, and how long they are viewing it for.  It also gives you graphs and tables, because lets face it, to many words can turn anyone away.

Social Media:

The second way to protect your company is by understanding how people get information.  Facebook is a staple in most people's lives.  The problem is that most people keep it open for anyone to see, and lets be honest here, will friend anyone.  To understand how people get information off Facebook and use it for bad intentions, you need to understand how to do it yourself.  On Tuesday September 13th, 2011, join MAC Source Communications and Information Security Expert and Penetration Tester, Steve Stasiukonis, to learn "How to Rob a Bank With Facebook."  Steve will explain how white collar criminals leverage the use of common people, processes and technologies to infiltrate the internal workings of your network. He will share his real world experiences on how he and his company used these techniques to breach the networks of numerous banks and other financial institutions.  This is a Webinar, so you don't even need to leave your office.

For more information on both ways to protect your business visit www.macsourceinc.com

Also, you can contact me at 585-368-2101 or Elizabeth Rizzo at 518-694-3904 for more information.

Friday, August 12, 2011

Next Generation Firewalls

Many companies today don't realize how important security is for their company.  For instance, many companies think that if they don't do credit card transactions, don't allow guests on their network when people come to their company, and block sites like Facebook, that they are secure and nobody can get through their gate.  Unfortunately this is not true.

In today's connected digital world, many companies are allowing their employees to use mobile devices such as laptops, smartphones, and tablets on their network.  With everything being connected, the merging of innovation and ideas come together.  This is great for companies that want to move forward and look towards the future (because everything is going mobile).  But what happens when these devices that are used outside of the business come into it?  It's ok, you have a firewall right?

Just because websites like Facebook are blocked internally and guests cannot access the web at a company, does not mean that company is safe.  Because employees use mobile devices and are using them other places besides work, they are still prone to malicious software.  They could easily go to a coffee shop and play Mafia Wars or Farmville on Facebook, and never know that someone had gotten into their laptop or embedded some malicious software or tracking software on their device through those apps.  Then, when that employee brings the laptop to work, it is on your network.  It found it's way around that great firewall that you have.

So what do you do about this situation?  Lock employee's hardware down so they can't do anything at all no matter where they go?  Wrong.  You get a Next Generation Firewall or NGFW.

A Next Generation Firewall or NGFW allows you to control applications, users, and content, not just ports.  This gives you significantly more protection for your network and allows you to identify threats that you never thought could get it.

Visit our website to learn more.

Thursday, August 4, 2011

Black Hat shows hacker exploits getting more sophisticated


By Byron Acohido, USA TODAY

LAS VEGAS — Fresh evidence that the Internet has become saturated with hacking groups relentlessly striving to crack into company networks grabbed attention as the Black Hat cybersecurity conference got underway here Wednesday.
  • By Sam Ward, USA TODAY

By Sam Ward, USA TODAY
Anti-virus giant McAfee revealed how a single hacking group, dubbed Shady Rat, has infiltrated at least 72 companies and governments over the past five years, including some 49 victim organizations in the U.S.
And Dell SecureWorks senior researcher Joe Stewartpresented results of his analysis of nearly 1,000 corrupted servers. Stewart isolated 18 servers actively being used to relay information to and from infiltrated PCs inside company networks to command servers in two regions of China.
Security analysts and researchers at the conference say that's the tip of the iceberg. Nation-state spies and cybergangs "are trying to get at sensitive intellectual property and government information every hour and every minute of the day," says Andy Grolnick, chief executive of tech systems-monitoring company LogRythm.
The majority of hacks fail, but "sophistication is increasing, and some are getting through," says Grolnick. "There's value in the data they're trying to get at."
McAfee has been aware of Shady Rat's activities since 2009. Then, last March, Dmitri Alperovitch, McAfee's vice president of threat research, located a server storing a list of successfully infiltrated organizations.
Some 49 of the 72 hacked companies were in the United States, four in Canada and the rest sprinkled through Europe and Asia.
The hackers most likely targeted a specific employee to receive an e-mail carrying an infected Web link or attachment, then tricked the employee into activating the infected link or file, McAfee says.
McAfee declined to name any of the 72 organizations that were infiltrated. The shortest time the hackers remained inside a company's network was less than a month; the longest, 28 months.
Stewart's research zoomed in on two hacking groups going after intellectual property.
"The final destination for all the activity we're seeing is a couple of hubs in China," says Stewart. "It tells us that somebody has invested specific resources to control this operation."

Link to original post on USAToday.com