Showing posts with label consumer. Show all posts
Showing posts with label consumer. Show all posts

Tuesday, February 20, 2018

ID Fraud and Your Taxes - Take Action!

   It's that time of year again.  Brian Krebs just put out two articles on the ongoing issue of tax fraud.  As is so often the case, the advice to protect yourself hasn't changed - and be assured, you must protect yourself because no one else will, certainly not the IRS!

   As noted below and in the Krebs' article, what you need to do now and always is:
  1. file your taxes early
  2. monitor your credit (I covered that topic here... in 2013!)
  3. freeze your credit (two articles from Krebs, also from 2015)
  4. become you before someone else becomes you (I wrote about that subject here and here)
   Here's a re-run of my article on this subject from three years ago.  It's all still true!  As I wrote nearly 5 years ago, the more things change the more they stay the same.

   I did a series of posts last year (2014) on the problem of ID Fraud.  This is an ongoing issue, certainly because organizations struggle to protect information, there are cyber attackers out there, and also individuals don't often take steps to protect their own information.

   The bottom line is that your personal information, primarily your financial information, has tangible dollar value to a cyber attacker.

   We usually think about credit card fraud or maybe bank account fraud as the results of these kinds of data breaches.  But in this post and the next I'd like to talk about two other scenarios that have happened, are happening... and you need to be aware.

   It's that wonderful time of year again in the US.  Crisp weather, snow (most places), the days are starting to get a bit longer... and it's the beginning of tax filing season.

   Imagine you are doing your civic duty, filling out and filing your tax return.  You send it in to the IRS, only to find out that "you" already filed your return and "you' have already received your rather sizable refund - surprise!

   Unfortunately, this has happened.  And, as we've discussed in the past, these attackers are smart.  This is a business.  They need to be able to maximize profits because there is a limited timeframe in which to commit the crime.  So they need to attack a sub-population who:
  1. makes good money;
  2. might have many deductions;
  3. might have complex returns, and;
  4. for whom a large refund might not raise red flags.
   How about... Doctors!

   And, just as I finishing writing this article, we have new news out about tax fraud this year!  Reports say this is connected with Turbo Tax software, but it is more likely that scammers got people's info through other means and filed the fraudulent returns.  Maybe Turbo Tax is just the scammers software of choice! :-)

   As always, we want to talk about what you can do.

   In addition to the steps outlined in these previous blog posts, here is the IRS Guide on Identity Theft.  The IRS guide and my previous tips talk about not only what you should do if you are a victim, but tips to avoid the problem in the first place including:
  • protecting your personal information, primarily your social security number
  • don't click on links sent to you via email or in social media - type the link in yourself or do a search
  • use link rating applications like Web Of Trust (WOT)
  • don't give our your personal information via web, email, phone unless you can positively identify the person on the other end
  • review your bills, credit record and other information that might provide early warning of a problem.
   Have you been the victim of tax-related ID Fraud?  Do you have any additional tips to share?

   Of course, this issue is not just about doctors!  Next time we'll talk about something perhaps even closer to your wallet... payroll fraud and misuse.

Tuesday, February 14, 2017

ID Fraud, Taxes and Doctors Again (Still?)

   It's that time of year again.  Brian Krebs just put out an article on "darkweb" sales of W-2 information.  You can read that article here.  As is so often the case, the advice to protect yourself hasn't changed - and be assured, you must protect yourself because no one else will, certainly not the IRS!

   As noted below and in the Krebs' article, what you need to do now and always is:

  1. file your taxes early
  2. monitor your credit (I covered that topic here... in 2013!)
  3. freeze your credit (two articles from Krebs, also from 2015)
  4. become you before someone else becomes you (I wrote about that subject here)

   Here's a re-run of my article on this subject from two years ago.  It's all still true...

   I did a series of posts last year (2014) on the problem of ID Fraud.  This is an ongoing issue, certainly because organizations struggle to protect information, there are cyber attackers out there, and also individuals don't often take steps to protect their own information.

   The bottom line is that your personal information, primarily your financial information, has tangible dollar value to a cyber attacker.

   We usually think about credit card fraud or maybe bank account fraud as the results of these kinds of data breaches.  But in this post and the next I'd like to talk about two other scenarios that have happened, are happening... and you need to be aware.

   It's that wonderful time of year again in the US.  Crisp weather, snow (most places), the days are starting to get a bit longer... and it's the beginning of tax filing season.

   Imagine you are doing your civic duty, filling out and filing your tax return.  You send it in to the IRS, only to find out that "you" already filed your return and "you' have already received your rather sizable refund - surprise!

   Unfortunately, this has happened.  And, as we've discussed in the past, these attackers are smart.  This is a business.  They need to be able to maximize profits because there is a limited timeframe in which to commit the crime.  So they need to attack a sub-population who:
  1. makes good money;
  2. might have many deductions;
  3. might have complex returns, and;
  4. for whom a large refund might not raise red flags.
   How about... Doctors!

   And, just as I finishing writing this article, we have new news out about tax fraud this year!  Reports say this is connected with Turbo Tax software, but it is more likely that scammers got people's info through other means and filed the fraudulent returns.  Maybe Turbo Tax is just the scammers software of choice! :-)

   As always, we want to talk about what you can do.

   In addition to the steps outlined in these previous blog posts, here is the IRS Guide on Identity Theft.  The IRS guide and my previous tips talk about not only what you should do if you are a victim, but tips to avoid the problem in the first place including:
  • protecting your personal information, primarily your social security number
  • don't click on links sent to you via email or in social media - type the link in yourself or do a search
  • use link rating applications like Web Of Trust (WOT)
  • don't give our your personal information via web, email, phone unless you can positively identify the person on the other end
  • review your bills, credit record and other information that might provide early warning of a problem.
   Have you been the victim of tax-related ID Fraud?  Do you have any additional tips to share?

   Of course, this issue is not just about doctors!  Next time we'll talk about something perhaps even closer to your wallet... payroll fraud and misuse.

Tuesday, April 19, 2016

Ad Where?

   The first website debuted on Dec. 20, 1990 at CERN in Switzerland.  And less than four years later, the first banner ad.  The idea was simple... if people are reading information on a website, why not hit them with an ad?  Media has traditionally been either for-pay or ad-supported and the model for the web included that.  Of course, back then people had no idea the extent to which other screens like laptops, tablets and smartphones, and binge-watching would displace traditional TV watching.

   And shortly after website ads arrived, so did the malware. Ad-ware, also called "malvertising", was born.

   There are a few different ways website ads can cause problems:
  • virus code in the ad itself - so clicking on the ad downloads or executes the malware
  • malicious code that executes based on a mouse action - such as clicking on a flash animation or even just moving your mouse over an ad (called a "drive-by download")
  • a link in the ad brings you to a different page that can have malware, asks for personal information or exploits your browser to grab information from another tab (kind of like phishing)
   You may ask... why would someone allow a virus in an ad on their site?  That's a great question.   The issue is that most sites don't have a direct relationship with the people creating the ads.  The way it typically works is that sites sell space on their pages to ad brokers, who resell that space either to someone wanting to place an ad, or even to other ad brokers.  And often the ads rotate.  It becomes pretty easy for crooks to insert malware into these ad spaces without detection.

   This led to the creation of ad blockers.  These are programs that work in your browser to block content from the 3rd party ad brokers.  There was a big controversy about this in 2015.  On one hand, websites that offer free content need to have a way to monetize.  On the other hand, web and banner ads are annoying, collect our information, and can contain malware.  Some businesses block ads on corporate systems as a way to cut down on malware... and it works.

   To fight back, some sites block people who block ads!

   And that's where things get interesting.

    Let's look at Forbes.com for example.  Many websites simply show their ads along with each page.  If the ads are blocked, then those parts of the pages just don't load, or show a broken image icon.  But when you go to the Forbes website, you first see a welcome page that counts down until you can click to the main page.  While that is happening, the page loads hundreds of those 3rd party ad sites.

   And earlier this year, the Forbes site was serving malware through ads!

   So there's the bind... allow sites to display their ads, including those full sites that only display if ads are allowed; or open the enterprise to malware!

   But shouldn't the responsibility for this malware be with the website that displays the ads?  Shouldn't they test to make sure there isn't executable code in those ads?  I think so.

   I also understand that sites display content that is worth something and they deserve to be compensated.

   There are some compromises.  Some sites ask you to register to see additional content.  You are "paying" by providing information about yourself that they can sell.  Some sites charge nominal subscription fees (some sites charge high subscription fees!).

   There is perhaps some middle ground with Google Contributor.  With this consumer service you pay a nominal monthly fee.  Then google distributes that to sites based upon your usage patterns.

   What are your thoughts?  Is there a middle ground?  Should consumers have to pay for content?  Do we need to be bombarded with ads?  And who should be responsible when sites serve up malware or malicious links?

Tuesday, August 18, 2015

Crypto Where?

   It's that scary moment...  You're getting some work done on your computer when you see a dreaded pop-up message:

   CryptoLocker, CryptoWall and other crypto-/ransom-ware has been in the news again (or still?).  This kind of malware attack was first identified in 2013.  Rather than trying to steal information, the malware encrypts your files.  But you don't have the key to decrypt.  The attacker offers, through a pop-up message, to "sell" you the "service" to unlock your files.  To make things worse, the attacker threatens to delete the keys after a set amount of time, typically 72 hours, which could prevent you from recovering the files.

   These ransom-ware viruses are usually sent to your computer as an email attachment.  The attachment can be an office file, pdf, zip file or other file.  The malware can also come from an infected web link.

   When your computer is infected, the virus operates quietly in the background, encrypting files.  You usually won't know there's a problem until the files are encrypted, and then you're in trouble.

   So if you are infected and encrypted... then what?  Well, there's bad news, good news, more bad news and some more potentially good news!

Tuesday, February 10, 2015

ID Fraud, Taxes and Doctors, Oh My!

   I did a series of posts last year on the problem of ID Fraud.  This is an ongoing issue, certainly because organizations struggle to protect information, there are cyber attackers out there, and also individuals don't often take steps to protect their own information.

   The bottom line is that your personal information, primarily your financial information, has tangible dollar value to a cyber attacker.

   We usually think about credit card fraud or maybe bank account fraud as the results of these kinds of data breaches.  But in this post and the next I'd like to talk about two other scenarios that have happened, are happening... and you need to be aware.

   It's that wonderful time of year again in the US.  Crisp weather, snow (most places), the days are starting to get a bit longer... and it's the beginning of tax filing season.

   Imagine you are doing your civic duty, filling out and filing your tax return.  You send it in to the IRS, only to find out that "you" already filed your return and "you' have already received your rather sizable refund - surprise!

   Unfortunately, this has happened.  And, as we've discussed in the past, these attackers are smart.  This is a business.  They need to be able to maximize profits because there is a limited timeframe in which to commit the crime.  So they need to attack a sub-population who:
  1. makes good money;
  2. might have many deductions;
  3. might have complex returns, and;
  4. for whom a large refund might not raise red flags.
   How about... Doctors!


   And, just as I finishing writing this article, we have new news out about tax fraud this year!  Reports say this is connected with Turbo Tax software, but it is more likely that scammers got people's info through other means and filed the fraudulent returns.  Maybe Turbo Tax is just the scammers software of choice! :-)

   As always, we want to talk about what you can do.

   In addition to the steps outlined in these previous blog posts, here is the IRS Guide on Identity Theft.  The IRS guide and my previous tips talk about not only what you should do if you are a victim, but tips to avoid the problem in the first place including:
  • protecting your personal information, primarily your social security number
  • don't click on links sent to you via email or in social media - type the link in yourself or do a search
  • use link rating applications like Web Of Trust (WOT)
  • don't give our your personal information via web, email, phone unless you can positively identify the person on the other end
  • review your bills, credit record and other information that might provide early warning of a problem.
   Have you been the victim of tax-related ID Fraud?  Do you have any additional tips to share?

   Of course, this issue is not just about doctors!  Next time we'll talk about something perhaps even closer to your wallet... payroll fraud and misuse.

Tuesday, December 2, 2014

The 4 R's of ID Fraud (part 2)

   As promised, in this post we'll wrap up the series about ID Fraud.  Check here if you'd like to see the first 3 parts of this series, and the first half of this post.

   So far we've focused on what ID Fraud is, and in the third installment, the steps you should take now if you are a victim.  As we've discussed, having the information for one of your credit cards grabbed in an attack such as we saw on Target or Home Depot doesn't automatically mean you will have other ID Fraud related problems.

   But we should all take steps to reduce our exposure and the odds that our ID and financial information will be fraudulently used... or at least increase the odds that we'll notice any problems quickly.

   We'll continue with the 4 R's: Review, Reduce, Record, Report. (unlike the 5 D's of dodge ball! :-)

Reduce - the amount of information you give out online.
  • Use care when emailing personal information.  Don't unless you need to.  Provide a minimum amount of information. Use encrypted email if it's available.
  • Choose passwords and hints that are not based on personal information.
  • Don't "click here to unsubscribe" from a spam or unwanted message - it just let's them know you exist.
  • Shop online with reputable or known vendors.
  • Delete doesn't really delete.
  • Use malware protection on your home computers and devices.
  • And a bonus tip for online - watch out for Phishing messages.  That's a big topic that I've covered in the past, and probably will revisit as scammer techniques evolve.

Tuesday, November 18, 2014

The 4 R's of ID Fraud (part 1)

   As part of our celebration of US Cyber Security Awareness Month, we've been talking about ID Fraud.  Check here if you'd like to see the first 3 parts of this series.

   So far we've focused on what ID Fraud is, and in the third installment, the steps you should take now if you are a victim.  As we've discussed, having the information for one of your credit cards grabbed in an attack such as we saw on Target or Home Depot doesn't automatically mean you will have other ID Fraud related problems.

   But we should all take steps to reduce our exposure and the odds that our ID and financial information will be fraudulently used... or at least increase the odds that we'll notice any problems quickly.

   Our theme for today is the 4 R's: Review, Reduce, Record, Report (just like you learned when you were a kid! :-)

[as I was writing this, the post became really long so I've broken it up into 2 parts]

Review - your credit report.  You are entitled to 1 free report from each of the big 3 credit reporting agencies each year.  So, spread it out and get 1 every 4 months.  The US FTC endorsed site to get these reports is www.annualcreditreport.com.  You can also put a fraud alert on your account as we discussed last time.
   You're also entitled to a free copy of your credit report if you:

Tuesday, November 4, 2014

Got ID Fraud? - Stop, Drop and Roll

   OK, maybe not stop, drop and roll (I'll always remember that fire safety phrase from my childhood), but take action!

   Cyber Security Awareness Month is now over, and I haven't finished covering the ID Fraud topic I started at the beginning of Oct.  I did get distracted on some other issues.  Besides, we can't confine our celebrating to only one month!

   I covered the basics of ID Fraud in these posts.  But if you have been a victim, and particularly if you recently discovered you are victim, you need to take action... and time matters.

   Here are the four key things you need to do, right now, if you have recently been the victim of ID Fraud in the US:
  1. Contact one of the three major Credit Bureaus (we'll leave a discussion of the "4th credit bureau" for another time).
  2. Close the suspect accounts.
  3. File a police report.
  4. File a report with the FTC by phone and in writing.
   I'll provide more detail and add a few more steps below.

   One additional thing you must do throughout this process is to keep a record of everything you do.  This includes: noting date/time of phone calls; copies of letters; printout any web forms, and; keep a chronological log of your overall progress.

   The FTC website has the specifics here.

Contact one of the Credit Bureaus and put a fraud alert on your account.
   This is the first thing to do.  You can put what is called an initial fraud alert on your credit record.  This initial alert will last 90 days.  It should not cost anything to place this alert.  The bureau you call should contact the other two credit bureaus, but it doesn't hurt to verify this with them.
   The fraud alert basically requires extra effort to authenticate any requests for new credit.  This typically means that the credit issuer needs to contact you before issuing credit.  This should make it tougher for a fraudster to open credit in your name.  That's good!  The downside is that it also might make it more difficult for you to open new credit.
   After the initial 90 day period, you can renew the alert each 90 days.  This may cost a nominal fee depending upon what state you live in (US).
   (we'll talk about other measures like credit monitoring services in a future post)

Close the affected accounts.
   Contact the credit issuer and close any accounts you know were affected.  If your purse or wallet was stolen, then close all the accounts for the cards you were carrying.
   If you're not sure if a particular account was affected, you're probably best off closing it as well.

File a police report.
   Contact your local police and file a report.  Except in rare cases where there was additional theft (for example, if your identifying documents and credit cards were stolen as part of a home break-in), the police will not actually take any action.  You're not contacting the police so they will investigate the problem.  You are establishing documentation and proof of the event.  In the future, you may need to prove that you took action and when you took action.  The police report accomplishes this.  Get a copy of that report.

File a complaint with the FTC (US Federal Trade Commission).
   Again, this is part of establishing your documentation trail.  The FTC has a great website for information that I'll link below.  The specific instructions for filing the FTC complaint is here.  Note that they suggest filing with the FTC before filing the police report.  That is not critical, and you need to do both.  You can complete the FTC form online so that might be easier and it's available 24x7.

   Those are the first steps to take.  But there are more.  Here are a few more steps to take:

Who else to notify?
   You may want to notify your other banks and creditors both to find out if there has been any unusual activity (banks and card issuers are usually pretty good at finding anomalous activity before you do) and so they can flag your accounts.  Consider notifying anyone who bills you monthly for services including utilities and insurance providers.

   If you think your US social security number has been compromised, you should contact the Social Security Administration.

   You can notify your state driver and vehicle services department in case someone tries to get a driver's license in your name.

Online defense.
   If this problem started online, perhaps through an information breach, you should change your passwords and consider using multi-factor authentication as I've covered in the past.

   There are more complete details on these steps on the FTC website here.

   Even under the best of circumstances, the process of reporting, documenting and repairing ID Fraud is a major pain.  In our next installment I'll talk about things you can do to help prevent you from becoming a victim, or in those circumstances where this is out of your control, how to increase the odds of early detection and minimize the impact.

   Have you had experience with any of the steps I list above?  Do you have any advice on additional steps to take?

Tuesday, September 23, 2014

"Who Am I?" (or, Who Was I?)

   I like the story of Les Mis.  I definitely like the musical.  I was not wild about the movies.  The book is definitely a good, and very long, read (or listen!).

   At it's core, Les Mis is a story about Identity Fraud!  It's the story of a man, seemingly wrongly convicted, who operates under a false identity in order to be able to live his life.  It's a common literary theme, used in stories like Martin Guirre, The Count of Monte Cristo and Matchstick Men.  In "olden times", Identity Fraud penalties were very serious. Today... not as much.  Last time we started a discussion of Identity Fraud - we'll continue our discussion of this topic.


   Breaches of online merchant websites and databases get a lot of media attention.  But there are many ways ID fraud is committed including:
  • Shoulder Surfing - this means someone looking over your shoulder, for example when you enter your PIN at an ATM
  • Dumpster Diving - it's amazing what people throw away
  • Mailbox theft - checks, financial statements and other sensitive documents get stolen from mailboxes
  • Stolen purse, wallet, laptop, tablet, phone - these all contain plenty of personal information
  • Social Engineering - be careful about what information you give out about yourself
  • Phishing - email or phone - con artists will call or email pretending to be your bank, law enforcement or other authority and ask you for information.
  • Social media - do you really know who your "friends" are?... there are all kinds of requests and information gathering schemes
  • Copy-cat websites - it's pretty easy for scam artists to create a fake site that looks just like your bank's website, perhaps with a misspelled URL like nationa1bank.com (that's a one instead of an L), and then collect the info you enter.
  • By known or unknown thieves! - some ID thieves know their victims.

   So many choices!

Tuesday, September 9, 2014

(SuperValu) Wrote Me A Letter

   I'm hearing the Joe Cocker version of Box Tops song! (though I always picture John Belushi doing this!)

   I don't want my summer to end, but October is coming soon and, in the US, October is National Cyber Security Month.  This will be the first post of a series on Identity Theft that will carry us into October.

   First of all, the term Identity Theft is a misnomer.  According to Findlaw:
 Theft is often defined as the unauthorized taking of property from another with the intent to permanently deprive them of it. Within this definition lie two key elements:
1) a taking of someone else's property; and
2) the requisite intent to deprive the victim of the property permanently.
The taking element in a theft typically requires seizing possession of property that belongs to another, and may also involve removing or attempting to remove the property. However, it is the element of intent where most of the complex legal challenges typically arise in theft-related cases.
   But, with Identity Theft, your identity is not actually stolen, because you still have use of it.  A more accurate term is Identity Fraud.  Someone is using your identity, without permission, to execute fraudulent transactions or commit other crimes.  And, in many cases it's just aspects of identifying or financial information that is being used fraudulently, like your credit card.

Tuesday, February 11, 2014

Bad Policies = Bad Passwords

   It seems that passwords are in the news again.  In the past I've discussed a number of aspects of the password dilemma.  Among the key issues are:
  • good passwords are hard to remember, and;
  • passwords you can remember are easy for attackers to guess.
   Adding to this mess is that many organizations do a poor job of protecting their storage of your password.  And now we have some new information...
Many organizations allow you to pick poor passwords on their websites by enforcing few or weak password construction requirements.
   We call these password policies, and these specify things like: how long the password can be; the minimum length it must be; what kinds of characters can or must be used; if the password needs to change, and; if there are some passwords that can't be chosen.

Tuesday, December 24, 2013

Are You a "Target"?

   By now, most of you have probably heard about the Target credit card information breach.  This is very big here in Minneapolis, home of Target.  All the details aren't out yet but it appears that credit card information for brick-and-mortar stores between Friday Nov. 27 ("Black Friday") and Sunday Dec. 15.  Here are some articles covering the story.  Here's Target's response and an FAQ.

   I'd like to talk a bit about next steps.  If you've been the victim of a data breach... what next?

   First... for consumers.  Target is a retail company and the direct victims of the breach are those of us who shopped at a Target store during the dates in question.  Consumers have two concerns here: credit card fraud and identity fraud. (I don't like the term "identity theft" even though it is commonly used.  No one can steal your identity... you still have it.  They can improperly discover, and misuse, the details... a.k.a. fraud.)

Tuesday, November 26, 2013

Internet Safety... The Song Remains the Same

   As seems to often be the case in the fall, I'm doing a number of Internet Safety talks lately.  Maybe it's the tie-in with October US Cybersecurity month, and I did some posts celebrating that.  Maybe it's that fall makes us think about back to school (though maybe safety should be a "hotter" topic in the summer when kids have more free time!).

   I've been presenting to groups about Internet Safety and related topics for over 12 years.  I've got a few events coming up at work, so I'm updating my material.  I've got a number of talks on these "consumer" issues.  You can see my slides on my slideshare page.  I regularly update my material.  But what's really amazing to me is that the core, key messages have substantially remained the same.


   For example, I recently did a presentation and blog post on bullying.  The biggest change in online bullying in the past few years has been the news media attention.  But what happens, how it happens and options for victims, unfortunately, hasn't changed much.

   As I talk with people about these issues, and research and update my presentation material, I think there are 3 main areas in which things have substantially changed.
  1. The rise and expansion of social media.  In the early 2000's, we were talking about things like email, Chat like AOL Instant Messenger (AIM) and web surfing.  Xanga.com was around, but MySpace and Facebook weren't even invented until around 2003!  And, needless to say, there's been an explosion of social media sites with the latest trends favoring pictures and video.  While kids had the ability to share too much information since the beginning, social media sites really drove the norms.
  2. Technology.  In particular... mobile technology.  I used to recommend that families keep their computer (singular) in a common place like the family room or kitchen so kids' use could be seen.  While that is still good advice, most families have more than one computer.  And most teens, and many younger kids, carry a powerful computer with them wherever they go... their smartphone.  While we still have options available for monitoring, and good communication is key, portable devices are really a game-changer.
  3. Kids get it.  During my Internet Safety talks of the mid-2000's, we used to play a little game.  It was a live demo in which I would bring up a social media site, typically MySpace.  The game was to see how few clicks it would take us to get to some inappropriate content (like kids/teens sharing too much personal information or posting pictures parents would wish they didn't).  When I first started doing this demo it would only take a few clicks.  Then, by around 2008, it took more.  Then I would just save a few URLs of TMI pages.  Then I gave up the game altogether!  It's not that we can't still find inappropriate content, or examples of kids sharing far more than parents might want.  But kids are doing a much better job of protecting their information online.  Of course, kids, teens and young adults - actually digital natives in general - do have different ideas, definition and expectations of privacy compared to their parents!
    One final thought... another thing that has changed is that the oldest digital natives - people who do not know of a time without pervasive digital media and technology - are now having their own kids and showing up at Internet Safety talks!  But some things don't change and their kids still know more about technology!


   What surprises you about changes in our online world over the past decade?  What do you think has changed, or has not changed?

Tuesday, August 27, 2013

People and Process First!

   I've been reading, and hearing, lately about the ideas of client-centric or human-centric IT.  Here's a cool article and interactive infographic from GovLoop.com.  It describes a roadmap approach to get to a people-centric approach while showing examples of what some US federal agencies are doing to advance the cause.

   I like infographics!  They are fun, impactful, and this is a good one.  But, sometimes they are so busy that the simplest parts of the message gets obscured.

   It's not just infographics that obscure simple ideas.  Security and IT are experts at over-complicating things.  We get so caught up in the cool tools that we sometimes miss the main point.

   In the Security and IT world, we should always look at any project or program through the lenses of:
  1. People
  2. Process
  3. Technology
   And definitely in that order!

Tuesday, July 9, 2013

The More Things Change...

   As the saying goes... the more they stay the same.  In our ever-changing world of technology and security, it always amazes me how things often don't change!

   Let me clarify... there's always a totally new technology, programming language or social network to learn. Of course, computing power has changed drastically.  Many of the techniques used by attackers to gain improper access to our information have changed.

   Though many have not.  And the advice we give to consumers and business users to protect themselves has not changed!   Consider...

Tuesday, July 2, 2013

Want someone's password? Just ask!

   SC Magazine recently put out an article entitled: More users than ever experiencing phishing attack attempts.  According to the article, phishing attacks are on the rise.

   Phishing is simply any kind of communication intending to extract (typically) personal information from someone.  The scam usually tries to either get the victim to visit a malicious website or directly provide their information, via a reply to the attacker or in an online form.

   Years ago, phishing emails were easy to spot.  They typically used obvious From: addresses, poor grammar and spelling, clearly misleading url's, and overall poor imitation of a legitimate organization's communication.

   But, as is often the case, the phishers have gotten better.  The emails look legit, the grammar and use of language is good, and the links often go to realistic-looking, but malicious, sites.  And email isn't the only delivery method.

   So, how do we avoid, and help others avoid, these attacks?

Tuesday, May 21, 2013

The Business (not Blind) Side

   A Doctor, Lawyer, Salesperson and Systems Adminstrator walk into a bar...

   As I mentioned last week, the Secure360 conference was in town.  And as always, it was a great show.  I was pretty busy and had 3 different talks.  The first was a 4 hour pre-conference session on BYOD. (slides here)

   After talking about the history of portable devices and framing the issues with which organizations struggle, we did something a bit different.

Tuesday, April 16, 2013

Bring It On Home

   There have been a number of discussions about the value of Security Awareness training floating around the net.  Some say that even with training, people will still fall for phishing attacks and social engineering, and that networks and servers will still get hacked.  I wrote about this a while back.

   I think there is great value to awareness training.  To me, the content and delivery are key considerations.  If the security messages are the same old, rehashed information then it will be hard to get people to pay attention, care and retain information.  No one wants to see yet another dry review of an organization's security policies.

    But there is a better way...