3 Disaster Recovery myths

Disaster Recovery ain’t what it used to be. Long gone are the days where a DR solution cost over a hundred thousand dollars and predominantly relied on tape backups. With the onset of cloud computing, today’s DR landscape has dramatically changed. But, unfortunately, there are still many misconceptions about DR still hanging around. Here are a few of the myths that no longer apply.

Tape Backups are the best DR solution

Like a car, computer or television, tape is a physical object that deteriorates over time. Don’t believe us? Go ahead and listen to your favorite cassette. One day your tape backups will become distorted and no longer work. And hopefully, that day isn’t the same one when your business suffers a disaster. However, there is a good chance all your tape backups will work. So does that mean there’s nothing to worry about? Well, consider where you store your tape backups. Are they on-site or in a location within a few miles of your office? If so, remember that if your business is hit by a natural disaster, chances are those tapes nearby will be hit as well. And if they’re damaged or become inaccessible, say goodbye to your business continuity.

While tape backup is better than nothing, many of today’s DR providers will backup your data to an offsite location that is far away from the neighborhood your office is at. That way, if your business is affected by a disaster, your backup is located hundreds of miles away in a safe place that is likely untouched.

It’s also worth noting that modern day DR solutions also provide another valuable commodity – time. So ask yourself, is the mindless task of backing up tapes really worth the time of your IT staff? Wouldn’t you rather have them working on more valuable tasks that require a skill? Today’s DR service providers eliminate this need, as they take care of nearly everything. You or your staff will never have to bother with it.

The RTO you want will be too expensive

Recovery Time Objective (RTO) is of primary importance to most business owners. And who can blame them. If you’re going to invest in a Disaster Recovery solution, you want to be able to rely on it to recover quickly (on a timetable that won’t damage your business). In the old days before the cloud, a quick recovery time could cost you well into six figures. Today, tools such as the cloud and virtualization have made this much more affordable, and faster than ever. Most DR providers can backup all your critical data in a matter of minutes. And if you ever need to recover it, most services can do so in hours, rather than days. That’s the power of the cloud. And when it comes to DR, it truly has changed everything.

Disaster Recovery is for big business, not SMBs

Well, it once was. Again, the cloud has really leveled the playing field. And it is making a truly valuable service accessible to businesses of all sizes. From dental offices to small retail operations, SMBs can now easily take advantage of the best DR solutions on market, as the barriers of complexity, costs, and insufficient IT resources no longer apply. Modern IT advances and the cloud have eliminated these obstacles.

We hope these three myths will help you see how Disaster Recovery is more affordable and efficient than ever. If you’d like to learn how our DR solutions can safeguard your business, send us a message. We’re happy to fill you in.

Published with permission from TechAdvisory.org. Source.

Infuse life into your old laptop

It can be tough to see your laptop die. While you likely shared many good moments with it, undoubtedly, there will come a time when it’s ready to be retired to the back of the closet or disposed of. If you are lucky enough to still have yours hanging around the house or office, then there’s no better time to dust it off. A new software is available that’s breathing new life into old laptops across the country. Here’s what you need to know.

A New York City based startup known as Neverware has developed a dual-boot system that essentially turns your old laptop into a Chromebook, and even uses the same operating system as a Chromebook: Chrome OS. The software that enables this is called CloudReady and, once installed on your system, you can switch between your old OS and Chrome OS at startup.

How does CloudReady revive your old laptop?

Because the Chrome OS operating system is lightweight, it frees up your laptop from its old, sluggish operating system. With CloudReady installed, your old laptop can boot up more than twice as fast, and you can browse the web twice as fast as well. However, it should be noted that these times vary, and in some cases, you may see no difference in speed.

Does it work for all laptops?

Most, but not all. CloudReady can be installed on many different models of the Macbook Pro and iMac. As for Windows, it will only work on PCs preinstalled with Windows 7 and up, and installed in UEFI mode. While that last bit may sound a bit confusing, if your laptop is ten years old or younger, CloudReady will likely work.

How to install CloudReady

To get started, you’ll need the following two items:

  • A laptop with internet connection
  • A USB drive with at least 8 gigs of storage

Everything else you’ll need to install the software can be found at Neverware’s website. Once you’ve got all your tools handy, here’s how you install it:

  1. Download the OS
  2. Install OS on a USB drive
  3. Insert USB into your old laptop and reboot it to CloudReady drive
  4. Install the OS on your laptop’s internal drive (make sure to backup your files first).

Depending on how tech savvy you are, the installation process can take anywhere between 45 minutes, to well over an hour.

So is it worth trying? Well, besides maybe an hour or two of your time, you don’t really have much to lose by giving it a shot. If you’d like more ideas on how to improve the life of your hardware or are interested in buying some new tech gear this Spring, get in touch with our experts today.

Published with permission from TechAdvisory.org. Source.

Monitoring employees online. Is it right?

Whether or not to monitor your employees’ computers can be a tricky decision. While part of you may think it’s unethical, you also may question if your staff are spending too much time on non-work related activities, and taking advantage of you in the process. So, should you monitor? Here are some pros and cons of monitoring, and some tips to effectively do it if you decide it’s right for your business.

The case for monitoring

There are a number of reasons why monitoring your employees is a good idea. Doing so can help you:

  • Protect your organization from data theft or harm – because some disgruntled employees may try to steal from you or corrupt your data.
  • Ensure you have a harassment free workplace – because cyber harassment (sexual or otherwise) happens among employees.
  • Ensure staff are complying with policies – not downloading illegal programs or spending time on websites with illegal or hostile content.
  • Provide evidence in case of a lawsuit – heaven forbid this happens, but if an employee participates in illegal activities on your business’s computers, monitoring can provide evidence of it.

The sad fact of the matter is that many businesses who monitor end up discovering that employees are doing things they’re not happy about. Research by Nancy Flynn, the executive director of the ePolicy Institute in Columbus, Ohio, revealed that two thirds of companies monitor their employees, and half of them have fired employees due to their behavior on email and the web.

Cons

Of course there are some potential downsides to monitoring that you should be aware of as well. These include:

  • Productivity loss – monitoring can kill employee morale, and therefore you may see a hit in their productivity if they feel you distrust them.
  • TMI and lawsuits – you’ll likely learn about the personal lives of your employees that you would’ve never known about had you not monitored. You may discover their political or religious views, sexual orientation or medical problems. This could potentially open up your business to privacy or discrimination issues if you or your management team act negatively on this information.

Monitoring guidelines to follow

If you decide to monitor your employees, here are a few tips you should follow.

1. Create written policies

When you decide to monitor, ask yourself, are you doing it for security purposes? Is it to ensure your employees are not wasting large amounts of time on Social media? Whatever the reasons, it’s smart to balance your policies with the expectations of your employees. If you’re too strict with your monitoring, you could create that atmosphere of distrust we mentioned above. So set guidelines for acceptable use of email, social media, web surfing, instant messaging, and downloading software and apps. Also, in your policy, include how monitoring will be carried out and how data will be secured or destroyed.

2. Tell your employees

It’s important to inform your employees about your monitoring. If they find out you’re doing it without their knowledge, you could create resentment among them or even face legal issues. And just by letting staff know, you may actually see a boost in productivity as it could deter them from wasting time on the web.

When you tell your employees, explain why you’re doing it and the risks your business faces from misuse of digital assets. Reassure them you’re not doing it to spy on their personal life, but only attempting to create a compliant and law abiding workplace. Because their activities will now be less private, encourage your staff to keep their personal communication to their smartphones. Also, provide a copy of your written policy to employees to read over and sign.

3. Get the right technology tools

While there are many technology tools to monitor your employees, bear in mind, you don’t need to follow their every move. In fact, you shouldn’t as it will not only waste your time, but also cause you to find out more information than necessary. So look for technology that will alert you to potential problems, so you can focus on more important things. Lastly, you may also want to consider technology that can block certain content, like porn or hate websites, as employee access to this content could create larger problems.

Whether or not to monitor your employees can be a tricky decision but, if implemented correctly, could benefit your business in making it more secure and even more productive. For more information about security and other IT support tools, get in touch. We’ll make our best effort to help however we can.

Published with permission from TechAdvisory.org. Source.

Get ahead in social media with these 10 tools

As a small business owner, you only have so many hours in the day, and managing your social media accounts is likely at the bottom of your to-do list. But while it can be easy to simply put off those social media updates, you know in the back of your mind your business can surely benefit from them. They can help you gain new customers and increase profits in the process. So how can you find the time to get it done? These 10 tools can help you better utilize your social media marketing time, and help produce more results.

Headlines

Let’s face it, most small business owners are not experts at writing compelling headlines. Thankfully, there are several social media tools that can help you get it right. Here are two of them.

  • Headline Analyzer – When it comes to spurring people to action, appealing to emotions can be very effective. This free tool analyzes and scores the emotional aspect of your headline and then informs you of which emotions are being communicated the loudest.
  • Optimizely – It’s one thing to hear a so called expert claim that a specific type of headline will work, and it’s another to see it for yourself. This tool enables you to A/B test your headlines, images or variations of them to see which are most effective.

Content Generation

When you’re generating new blogs, marketing messages and other content on a regular basis, sometimes the creative juices run dry. This is where these three tools can come in handy.

  • Portent – Whether it’s blogs, memes, videos or other social content, Portent provides easy idea generation. Simply enter a subject you want to create content for, and Portent will give you some ideas.
  • Hubspot Blog Topic Generator – Similar to Portent, but for blogs only. Enter three topics into this tool, and it will instantly give you a week’s worth of blog titles to write about.
  • Banner Ads Creator – Creating an effective ad can be a real pain in the rump. But this easy-to-use tool enables users to generate ads almost effortlessly in a matter of minutes. Use it to create ads for Facebook, Twitter, YouTube, your website and more.

Management

Perhaps the most difficult part of social media marketing is the management aspect of it. These tools will help you be more efficient with your time and create maximum impact.

  • Social Rank – Curious to know which of your followers are most engaged? Well, now you can with Social Rank. This nifty tool enables you to identify, manage and organize your followers on Instagram and Twitter.
  • Riffle – Mingling with influencers can have a huge impact on the number of your followers. While doing that may sound easier said than done, this tool enables you to do just that. Riffle will help you find and connect with social influencers on Twitter, and engage with them when they’re active on the platform.
  • Hootsuite – How would you like to manage all your social media accounts from one location? That would probably save a lot of time, right? Hootsuite offers just that, and enables you to grow your brand by allowing you to schedule updates and engage with your audience from a single platform.

Video and Images

What many consider the bane of social media marketing, finding affordable images and videos on a weekly basis can be both frustrating and costly. These two tools will hopefully make your efforts a bit easier.

  • Unsplash – This tool gives you free access to thousands of high resolution photos that you can use however you please. And to ensure there is an influx of fresh new images to choose from, the service adds 10 new photos every day.
  • Mazwai – To go along with your free images, how about some free video? That’s exactly what Mazwai does, offering you the ability to download videos under the free creative common license. All you need to do is credit the video producer, and then you are allowed to use the footage.

We understand that for the small business owner, social media marketing can seem like a monumental chore, and we hope these tools will help make it a smoother process. If you need any advice or assistance with your own social media marketing, give us a call today.

Published with permission from TechAdvisory.org. Source.

How to switch securely to Office 365

It’s easy to see why Office 365 is an attractive solution for small and medium-sized businesses already familiar with the Office interface. More and more companies are making the move to the cloud, but many have yet to complete their transition and still rely at least in part on on-site SharePoint systems. When you’re ready to migrate, the move from SharePoint to Office 365 presents numerous security challenges to prepare for – not least because breaches are far more likely to be caused by localized issues than insufficient protection on Microsoft’s part. Here’s what you need to do to ensure you’ve got security covered when you make the leap to migrating from SharePoint to Office 365.

Identify your company’s sensitive data…

It’s so easy to create sites within SharePoint that businesses often have far more than they realize, covering just about every aspect of their operations. And it’s natural, of course, for at least some of the files housed within those sites to contain sensitive commercial or personal data. The key is ensuring that sensitive information is adequately identified and protected. Do this by conducting a security audit before you undertake your migration.

Your audit should identify the types of data stored in the various parts of your SharePoint network, including which specific information needs extra safeguarding. Be sure to consider everything from trade secrets and contract details to the personal information of your clients.

…and then restrict access to it

Once you’ve worked out where your most precious data lies, you can check who currently has access to it and whether their access is appropriate. After all, it’s not necessary for everyone to be able to get at all the data your company owns; it’s far better to operate on a need-to-know basis, with a reasonable level of flexibility.

Ensure that each of your employees has access only to the data that’s necessary for them to perform their duties. When you make the switch to Office 365, you’ll find that it allows you to conveniently set these different levels of permissions, including for external partners with whom you collaborate.

Trust nobody and suspect everybody

We say that lightheartedly, of course – it would be counterproductive to become so security-paranoid as to suspect everyone is attempting foul play with your company’s data. Nonetheless, it’s wise to consider everyone in your organization when it comes to auditing data access permissions – and that includes system administrators who might be assumed to have master access to every element of your network infrastructure.

A rogue administrator is the stuff of nightmares, since their elevated position gives them much greater leeway to siphon off valuable data without being noticed – or even to allow others to conduct questionable business and bypass the usual built-in security precautions. Overcoming the danger of an all-too-powerful administrator admittedly becomes easier if you have more than one on staff, but even in smaller businesses you can mediate some of the risk by regularly checking on your administrator’s usage and ensuring that their top-level system permissions remain justifiable.

Use machine learning to foresee security breaches

Every action performed by your staff within Office 365 is automatically logged, and with relative ease you can pull reports that allow you to analyze these. But the sheer number of events taking place within Office 365 in the course of your business’s normal operations means that even attempting to identify questionable behavior will be akin to the proverbial needle and haystack. That’s not to say it’s unwise to be on the lookout for anomalies in normal usage – the export of unexplainably large volumes of data, for instance, could suggest that a member of your team is leaking intelligence to a competitor, or that they’re about to jump ship and take your trade secrets with them.

Thankfully, it’s possible to leverage the developing power of machine learning to identify potential breaches before they happen – without the need to wade through unmanageable swathes of perfectly normal data. Graph API is incorporated into Office 365, and allows for the integration of machine learning tools into your security environment to achieve just that. The same tools can also help you avoid being caught out by hackers, by identifying system login attempts from locations that are out of the ordinary; you should bolster this protection by religiously removing inactive accounts and those of departing employees.

By covering these essential security considerations when it comes to your migration, you’ll be one step closer to ensuring you strike the right balance between the powerful collaborative features of Office 365 and the robust safeguards your business’s integrity demands. To find out more about how we can help your Office 365 migration run smoothly, or what other business benefits you can derive from cloud-powered technologies, just give us a call.

Published with permission from TechAdvisory.org. Source.

BI is for small businesses too

Business Intelligence (BI) has conventionally been the preserve of big business, given the need for specialist knowledge meant hiring pricey experts was often the only way to leverage its value. But the rise of self-service BI tools has leveled the playing field, allowing small- and medium-sized businesses to get in on the game too. And with small businesses now producing far greater volumes of data than in the past, there’s never been a better time to put BI to use in your organization. Make your first steps towards smarter business planning by dispelling some popular beliefs about BI – here’s what you need to know.

You’ve already got the data you need

It’s easy to underestimate the amount of data your small- or medium-sized business already has at its disposal. In every area of your business from finance and sales to customer relations and website management, the software packages you use to simplify your everyday operations are packed with reams of information that most of us don’t even think twice about. By talking to key stakeholders in your organization’s various departments, you can get an idea for the kind of data you already have, how it’s generated, and where it’s stored. You’re then in a good place to begin thinking about using BI tools to transform that information into meaningful business insights that inform key decision-making – all while reducing the resources you need to invest in time-consuming data generation from scratch.

Self-service BI tools are plentiful – and affordable

The real beauty of the emergence of self-service BI is that it puts useful business analytics within reach of smaller business owners who lack the fancy-pants budgets of larger corporations. In fact, there are numerous self-service BI tools that you can use to get started in this area without even spending a dime. Microsoft Power BI is a powerful application that’s pleasingly user-friendly, and most businesses will find the functions they need in the free version. Zoho Reports has a low entry-level cost, too, and the slightly pricier yet still affordable Tableau is another option that’s worth exploring.

It’s easy to get started

BI is an intimidating term, and just the thought of delving into it can send a shiver down the spine of the average business owner. But by taking small steps, it’s easy to get started – and before you know it you’ll have the benefit of real-intelligence-based business insights that enable you to make better decisions for your organization’s long-term success. Most self-service BI tools come with built-in suggestions for reports that businesses commonly run and find useful. Other worthwhile statistics to explore include the percentage of your clients who cancel within a set period; website landing pages that generate the longest visits; your most profitable individual products or services; the days or months in which you generate your highest revenues; and which of your clients brings in the most revenue and profit.

Truly harnessing data is the future of the business world – it’s how companies like yours can make smarter decisions that increase efficiency and profitability. And self-service tools mean smaller organizations no longer need a crazy budget to be able to afford the benefits of BI in the first place. To find out more about putting in place the tools that can help make your business more intelligent, just give us a call.

Published with permission from TechAdvisory.org. Source.

Cloud myths debunked

From hosting websites, email, applications and online file storage, the cloud has become a popular alternative to traditional IT services among businesses. In fact, it is almost impossible to find a company’s data center that does not employ cloud-based services of some kind. However, reported incidents of cloud hacks and server failures can lead some small business owners to be wary of a service that still has much confusion surrounding it. So what are these common misconceptions about implementing cloud computing into a business? Here are a few myths people believe about the cloud.

Cloud infrastructures are unsecure

Security is a necessity for online users. And the most prevalent misconception about the cloud is the idea that cloud services lack appropriate security measures to keep data safe from intruders. Most users also think that the data stored in the cloud can be easily accessed by anyone, anywhere and at anytime.

But the truth is it’s actually a good idea for small businesses to use cloud services. Small companies usually can’t afford to hire an IT department let alone train them to deal with online security threats. Cloud providers, on the other hand, offer services such as layered security and antivirus protection that not only specialize in keeping infrastructures safe from hackers but are available at a price that is much lower than you would pay for in-house IT staff.

Additionally, large cloud-based services such as Google Apps for Work and Office 365 are supported by an infrastructure that constantly installs, updates and patches, which helps manage security breaches. This significantly frees you from the burden of having to install the updates yourself and managing the overall security of your system.

Users should understand that no company is completely safe from security threats regardless of their IT infrastructure. But data is likely to be more secure in the hands of cloud providers as they are the most prepared and qualified to protect your digital property.

Encryption

There is a misunderstanding about the role of encryption or rather how it is implemented to keep your data safe. Encryption is usually used for data in transition, where data is protected from anyone seeing it as it travels from one location to another on the Internet. But encryption can also be applied to data at rest, where data is encrypted on a storage drive.

While cloud service providers already keep their physical storage drive well protected, some keep the decryption key held in software, potentially leaving the key vulnerable to intruders. If hackers were to successfully obtain the decryption key, they can simply access your encrypted data. That’s why some cloud storage services are much better than others in terms of keeping your data protected.

With this in mind, you should understand that while every cloud service highlights their data security by demonstrating their encryption abilities, it does not necessarily mean that a cloud-based service that markets itself as such is right for you. When it comes to choosing the right cloud service, it is best to inform yourself about the security measures that a cloud infrastructure implements and look at how it can protect your company’s digital property.

With the cloud you are no longer responsible for data security

While cloud security is important, the responsibility for protecting data ultimately rests on the user. Misplacing mobile devices can leave your data vulnerable and make the cloud infrastructure insecure. It is also recommended to have verification mechanisms in place for devices that are used to access the cloud.

Losing USBs or external hard drives obviously leads to direct data loss and can be easily remedied by backing up your files. This applies to files stored in the cloud as well. So be smart, and backup your files because it’s better to be safe than sorry.

The cloud is never faulty

Like many online services, cloud-based services are not immune to technical difficulties. For example, some cloud businesses have suffered outages and server failures which corrupted files and may have lost data in the process.

Hacking is another reason why some cloud services fail. Using a less than optimal cloud service that is vulnerable to attacks can lead to stolen or deleted data, which would be near impossible to recover if you did not have any offline backups.

Regardless of these flaws, however, it is vital to note that using the cloud as your only source of data storage and processing can lead to problems in the future. Keeping backups of your files is always a good idea.

Security is truly one of the biggest barriers to the adoption of cloud computing in a small business. But as cloud services expand and encryption technologies advance, cloud adoption is increasingly becoming the most cost-effective solution to meet the small business owner’s IT demands. Contact us today to learn how your business can take advantage of all the cloud has to offer.

Published with permission from TechAdvisory.org. Source.

The meaning of confusing computer words

If you’re not an IT professional or have an in-depth knowledge of technology, computer terminology can seem like a foreign language. While you certainly don’t need to be fluent in geek speak, having a basic understanding of it can help in a number of ways. For example, it can help you purchase the right equipment when searching for new hardware or more clearly explain a technical issue you’re having to your IT provider. Here are a few computer terms that can help you along.

App – These days when someone hears the word “app”, they usually think of a program for their tablet or smartphone; however, the word “app” actually has a much more broader meaning. Apps, which is short for applications, have been around since the birth of computers, and the word really refers to any type of computer program. Some examples of common apps used today include Microsoft Word, Adobe Photoshop, and Symantec Antivirus.

Browser – Your window to the Internet, a browser enables you to access all the information there is online. In fact, the Internet is virtually inaccessible without the use of a browser, and you’re likely reading this article on a browser right now. Google Chrome, FireFox, and Microsoft Edge are a few examples of common browsers.

Search Engine – Not to be confused with a browser, a Search Engine is a page you visit within your browser that allows you to search and find what you’re looking for on the web. You type keywords or phrases into a Search Engine, press enter, and then the web pages and files that contain those phrases and keywords are presented to you. Google, Bing and Yahoo! are a few of the Search Engines available.

Hard drive – A hard drive is essentially a storage unit for everything on your computer. Everything from your operating system to applications, such as Excel and PowerPoint, are stored on your hard drive, and it allows your computer to access these files and programs for your use. The more hard drive space you have, the more applications, videos, documents and various files can be stored on your computer.

Motherboard – If your computer had a heart, the motherboard would be it. The motherboard is a circuit board that powers your RAM, CPU and hardware, enabling it all to communicate with each other. If the motherboard is taken out of the equation, your computer will be unable to operate.

CPU/Processor – If the motherboard is the heart of the computer, then the CPU, or Central Processing Unit, is the brains. A CPU carries out the instructions it receives from the different hardware and software operating on the computer. At one point or another, everything on your computer goes through the CPU. And the more powerful it is, the faster it will be able to operate and the more advanced applications you’ll be able to run.

RAM – Random Access Memory stores all the temporary programs and data that your computer is currently using so they can quickly be accessed by your computer’s CPU. For example, if you are running Microsoft Word, Google Chrome, Adobe Reader, and Skype all at the same time, RAM enables you to access them fast – without having to reopen them every time. The more RAM you have the quicker these programs will run. Once your computer shuts down, it will no longer store these programs in the RAM, but instead in the hard drive.

These are just a handful of terms a layperson may come across when asking for technology service or talking about computers. If you’d like to learn more about the tech talk that is native to us IT professionals, or have any concerns with your current IT, don’t hesitate to get in touch.

Published with permission from TechAdvisory.org. Source.

Cyber threats and the finance sector

The financial services industry has long been a heavily targeted sector by cyber criminals. The number of attacks that involved extortion, social-engineering and credential-stealing malware surged in 2015. This means that these institutions should strive to familiarize themselves with the threats and the agents behind them. Here are 7 new threats and tactics, techniques and procedures (TTP’s) that security professionals should know about.

Extortion

The cyber criminal Armada Collective gained notoriety for being the first to utilize distributed denial-of-service (DDoS) attacks. This occurs when multiple systems flood a targeted system to temporarily or completely disrupt service. They evolved the idea further and started to extort Bitcoins from victims who were initially notified of their vulnerability. If they didn’t comply with the ransom demands of the criminals, they would flood their systems until the victim’s network would shut down completely.

Social media attacks

This involved criminals using fake profiles to gather information for social engineering purposes. Fortunately, both Facebook and Twitter began to proactively monitoring for suspicious activity and started notifying users if they had been targeted by the end of 2015. However, you should still have your guard up when someone you don’t know, or even a friend or colleague, starts asking you suspicious questions.

Spear phishing

Phishers thrive off familiarity. They send out emails that seem to come from a business or someone that you know asking for credit card/bank account numbers. In 2015, phishers went to the next level and began whaling. This normally involved spoofing executives’ emails (often CEO’s) to dupe the finance departments to transfer large sums of money to fraudulent accounts.

Point-of-sale malware

POS malware is written to steal customer payment (especially credit card) data from retail checkout systems. They are a type of memory scraper that operates by instantly detecting unencrypted type 2 credit card data and is then sent to the attacker’s computer to be sold on underground sites.

ATM malware

GreenDispenser is an ATM-specific malware that infects ATM’s and allows criminals to extract large sums of money while avoiding detection. Recently reverse ATM attacks have also emerged, this is when compromised POS terminals and money mules to reverse transactions after money being withdrawn or sent to another bank account.

Credential theft

Dridex, a well known credential-stealing software, is a multifunctional malware package that leverages obfuscated macros in Microsoft Office and extensible markup language files to infect systems. The goal is to infect computers, steal credentials, and obtain money from victims’ bank accounts. It operates primarily as a banking Trojan where it is generally distributed through phishing email messages.

Other sophisticated threats

Various TTP’s can be combined to extracted data on a bigger scale. Targeting multiple geographies and sectors at once, this method normally involves an organized crime syndicate or someone with a highly sophisticated setup. For example, the group Carbanak primarily targeted financial institutions by infiltrating internal networks and installing software that would drain ATM’s of cash.

The creation of defensive measures requires extensive knowledge of the lurking threats and our team of experts is up-to-date on the latest security information. If you have any questions, feel free to contact us to find out more about TTP’s and other weapons in the hacker’s toolbox.

Published with permission from TechAdvisory.org. Source.

How to boost your WordPress website’s speed

When it comes to websites, speed matters. Internet surfers everywhere are becoming more and more impatient. When once five, or even ten seconds, was a completely acceptable time to wait for a page to load, those days are long gone. Now most users expect a page to load in at least three seconds, some even demand two. And if yours don’t? Bounce rate here we come. So how can you maximize the speed of your WordPress website to ensure users don’t click away while waiting for a page to load? Here are several ideas to help you quicken your site.

Keep WordPress and plugins up-to-date

The Internet is constantly evolving. And if you want to keep up with it, you need to keep your site and plugins up-to-date. While you may already know that updating WordPress and plugins will keep your website secure, you may not know that doing this also increases your site’s speed. So if you want a fast site, install those updates as soon as they become available.

Choose a host wisely

Your host can make or break your website. A key reason for this is that website speed and uptime varies widely between them. So before you select your host, do some research on the various options out there.

Also, while your first impulse may be to choose shared hosting because of its low cost, be aware that it’s also going to be your slowest option in terms of speed because many websites are all relying on the same server for bandwidth. For many SMBs, however, using a dedicated server is simply not an option because it’s expensive. An alternative in the middle price and performance range is a Virtual Private Server (VPS). This acts like a dedicated server in terms of functionality, but still technically uses a shared server. Regardless, using a VPS will give you a boost in speed over typical shared hosting.

Keep your site lean

The leaner your site is, the faster its speed will be. So to create a lean site, be mindful of these four aspects:

  1. Theme – it can be tempting to choose a theme that has a seemingly limitless amount of design options. While the promise of a versatile theme can spark the imagination, actually implementing one can come back to haunt you in terms of speed. When a theme has a ton of features on offer, the amount of code to produce those features can bog down your site. So to ensure you avoid this scenario, test the theme demos to see how long it takes for them to load. If it’s more than a few seconds, it’s probably best to avoid it.
  2. Design – similar to theme, design elements also have the ability to dramatically slow down the speed of your site. Simple sites are faster, so think carefully about what ads, images and extras to use.
  3. Plugins – not all plugins are created equal; some run fast and others slow. So how can you tell one from the other? While it may sound like a bit of an oxymoron, there’s actually a plugin for that. The P3 Plugin Profiler will show the impact a plugin has on your site’s load time. Another plugin rule to follow is that less plugins equals more speed. So think twice before your next plugin installation spree.
  4. Images – bulky images can also slow down your site. And while many raw images are around 3,000 to 4,000 pixels wide, most featured images are 600-800 pixels wide. So to reduce image weight and gain a faster site, resize them to the exact size they’ll appear on your screen.

Mind your plugins

Yes, we just mentioned that you should get rid of plugins to speed up your site, but some specific plugins can actually have the opposite effect. A cache plugin, like W3 Total Cache and WP Super Cache are two that can provide more speed. Another plugin that can help is Lazy Load. It speeds up your site by loading the elements at the top of the website first, where viewers are looking when they first visit your site. Before installing the Lazy Load plugin, check your Theme Options to see if you already have it.

Create redirects sparingly

If a page on your site needs to be redirected to another page, it can really slow down your site. So use 301 redirects as little as possible. And to ensure you aren’t using any without knowing it, use Redirect mapper or other tools that can help you find redirects you don’t need.

Implement some or all of the speed tips above and you’re sure to see a noticeable difference in the speed of your site. If you’d like more tips to optimize your website or need help with any of your web or IT needs, we are just a phone call away.

Published with permission from TechAdvisory.org. Source.