By Kevin McDonald Investigations into the conduct of the IT staff of the House of Representatives raised alarms. Kevin McDonald explains what we can learn from the case of Imran Awan. Those who operate with high-level system access, [...]
Last year I read a blog, Star Wars: I Find Your Lack of Segmentation Disturbing and I found it to be utterly entertaining, but also spot on. As we approach the release of a new Star Wars movie in December, [...]
Irvine, CA - Overseeing IT and security is a daunting task, even if you are an IT professional. If you are an executive to whom IT reports, then the task becomes near impossible. The list of following questions is designed to empower you to have a meaningful discussion with your IT team so you can be an informed and responsible manager pursuing your due diligence role in protecting the assets of your firm. If you are an IT professional, these are questions you should be prepared to answer.
A. Make sure your IT team is periodically assessing the risks to your IT systems. They should be recommending upgrades and new solutions for you from time-to-time, and you should be listening. They need to be able to express the threat in operational and economic terms in order to justify the expenditure. If your team can’t give you a clear and coherent answer on when and how they last did this, send them off with a task and a deadline.
2. Q. When did we last do a Vulnerability Scan? What were the results of that scan? I would like to see the report. Who did the remediation? When is our next scan planned?...
Navigating Fear in the Security and Compliance World
In advancing technology it is fear of having a project go sideways, over budget or fail to accomplish the stated objective that has many frozen. What if that technology we recommend doesn’t work as we hope? What if it is something required by law (such as encryption in healthcare) that we fear an unknown outcome so much that we won’t act? What if we miss a key component of a project or underestimate the effort required and the entire project goes over our budget?
This is one time you may want to make a quick call to your accountant, then order up some of those infrastructure items you are putting off. A bill known as “tax extenders” if signed by the president will reinstate Section 179 tax [...]
...this then puts all the burden and stigma on Alvaka, our engineer and our NetPlan program. That fuels some of the debate we have with some clients. I remember two separate debates with a controller at a 20 year long client. He said he “should not have to pay for us to check our own work.” I have two answers for that objection:
1. He has two of his own guys that work on his IT system, along with other vendors. His employees can do things unintentionally, etc. This is not about checking on our Alvaka engineer. It is all about checking the overall integrity and operational state of his IT system, which has changing needs over time and changes due to different people touching it. It is simply a matter of doing a periodic review to make sure nothing is getting missed or looking for things that need to be done a different way. Changing and updating tape/disk backup jobs to accommodate new servers and software is a classic example. Without review these jobs don’t often get updated and that leads to tragic results down the road. I have seen it way too many times in 30 years. It is preventable.
2. Even if a client does not have their own IT staff, it is prudent to periodically check IT systems to make sure everything is working right, that the current needs are being met and that important requirements/practices are not getting overlooked or wrongly....
So what should you do at your company?
1. Identify your most valuable IT systems within your company. What is the most important data that resides there? Determine your obligations to protect that data and how important is it that those systems are up-and-running.
2. Do you have a current network/information security policy in place? Once you determine which systems and data are most important to protect, developing your policy becomes much easier.
3. Discover where you are most at risk. A quick and easy solution is to have someone perform a vulnerability assessment on your system. Alvaka Networks can help you with this. Vulnerability assessments are our most common security service we provide. It makes your work easy. We will help you match the protection needs of your most important IT assets with the vulnerabilities identified in the vulnerability assessment. From there you can easily create a roadmap for what you should do to protect you, your company and your IT assets from cyber-attack.
If you have just gotten CryptoWall, CryptoLocker or some other variant, here are a few questions you should be prepared to answer on your road to recovery
1. What date did you get infected?
You might only have a few days to pay the ransom until it goes from $500 to $1000. After 30 days you might not be able to decrypt the files at all.
2. What type of files got infected and what do they mean to your business?
If the files are not worth $500 then don’t pay the ransom. If the files are worth $5 million then you better be very careful and thoughtful about what you do. The decryption process might not even work and if so....
Here is a controversial article written recently by Kevin McDonald for TechTarget.-------------------------------------------------------------------------------------------------------------------------------------Under federal law, the Health Information Portability and Accountability Act (HIPAA) Privacy Rule extends to a class of business entities (i.e., health plans, health care clearinghouses and health care [...]
Tomorrow I speak at the Technolink conference in Los Angeles. I was asked to talk on the subject of computer security, Ransomware, the Obama executive orders on national infrastructure security and other recent topics affecting businesses that use information technology [...]