Blog

May 15th, 2013

Security_May15_AHackers and other cyber criminals are an ever present danger on the Internet. This is a fact that we simply can't escape, and what's more, you can be pretty sure that we will see an increase in the number of attacks against sites as the internet continues to expand and be used by more and more people. One of the latest major sites to be hacked is LivingSocial, so if you have an account with this website, you may want to keep reading.

LivingSocial is a daily deals website that focuses on bringing bargains and original deals to users based on their geographical location. In late April, news broke that the website had suffered a massive cyber attack with 50 million accounts being compromised.

From the reports we have seen, the attack targeted accounts world-wide with only account holders in Thailand, Indonesia, South Korea and the Philippines being unaffected. An email sent out by Tim O'Shaughnessy, LivingSocial's CEO shortly after the incident said, "We recently experienced a cyber-attack on our computer systems that resulted in unauthorized access to some customer data from our servers. We are actively working with law enforcement to investigate this issue."

The company assured users that their credit card data had not been compromised, as they are kept in another database. Account passwords were also encrypted, which means they are harder to crack but not impossible.

What should you do? If you have a LivingSocial account, we recommend that you go and change your password immediately. This can be done by:

  1. Going to LivingSocial's forgot your password page.
  2. Entering the email address you used to sign up for the account with.
  3. Pressing Reset Password.
  4. Checking your email for an email from LivingSocial and following the instructions in the email.

It is advisable to pick a new password, one that is as different as possible from your old password and, as always, the longer, the better.

Is there anything I can to do protect my company? If you are a business owner who has websites that encourage customers to sign up for updates, accounts, etc. you may be wondering how you can keep your user's information secure from cyber attack. In truth, you can't keep your important information 100% secure, if a hacker is committed enough, they will be able to get the information they need or wreak the havoc they want to. But what you can do is to make it as hard as possible for cybercriminals to get your information. This could be as simple as using multiple databases to store different bits of information, or as complex as using the latest encryption methods and systems.

Each business is unique, and the best way to ensure your valuable data is secure is to work with an IT partner who takes the time to get to know your security needs and develop a solution that is as near to 100% secure as possible.

If you are worried about the security of your systems, contact us today. We may have the perfect solution that will meet your needs and budget.

Published with permission from TechAdvisory.org. Source.

March 23rd, 2013

BCP_March20_ADisasters come in all shapes and sizes, from losing a day's worth of data to floods or fires that can harm whole cities. Because they are so unpredictable in nature, it can often be hard to prepare your business for the inevitable. However, businesses aren't at a total loss if they have Business Continuity Plans that can help them through any disaster.

Some companies are hesitant to adopt a Business Continuity Plan (BCP) because of the perceived costs and complexity involved. We won't deny that plans are usually on the complex side, but there are good reasons as to why your company should adopt one. Here's five.

1. Your business will be seen as more valuable Banks, venture capitalists and other investors tend to air on the side of caution, and as such will usually look to businesses that appear to be stable as more viable investment vehicles. Companies with a BCP are often seen to be more valuable, as they can address diverse situations better than those without. As a result, they will make the investor more money over time.

2. Compliance Big companies in a number of industries have had continuity plans for years and many have started to look for suppliers/vendors with continuity plans. Beyond that, some industries and government bodies have made BCP a requirement. If you are a vendor, supplier or even in specific industries, it is a good idea to have one in order for business to run smoothly.

3. Potentially lower insurance premiums Operating a business is filled with risks, and business managers are often looking for ways to minimize it. One way includes the purchase of insurance - many industries and situations require you to carry it. Generally, insurance providers will give more favorable rates to companies that take steps to minimize risk. A solid BCP will go a long way in showcasing how risk-averse your company is, which could lead to lower rates or at the very least, stable rates.

4. More efficient communication Developing a BCP involves constant, company-wide communication in order for it to be successful. For many businesses, this involves collaboration between team members who don't normally work together on a regular basis.

A BCP also fosters communication plans during disasters, both within the organization - most employees have a role, and will need to work together to pull through - and outside - customers, suppliers and other stakeholders will be contacting you. If your employees know how to communicate what needs to be done, effects of the disaster will be minimized.

5. Survival Recent natural disasters around the globe have highlighted that businesses without a plan will most likely be forced out of business. Having a BCP will minimize the chances of this, while preparing your business for survival.

If you are looking to implement a business continuity plan, or improve on an already existing one, please contact us today. We may have a solution for you.

Published with permission from TechAdvisory.org. Source.

February 21st, 2013

BCP_Feb20_AFebruary was an interesting month in terms of disasters. First there was the incident at the Super Bowl where half the stadium's lights abruptly went out leaving the game suspended and millions of viewers wondering what was going on. Then there was another Super Storm that hit the Eastern US, not to mention all the dramas going on around the world. These events continuously highlight the need for all businesses to have a Business Continuity Plan.

While a Business Continuity Plan (BCP) can be complicated, and comprised of many different objectives, the main reason companies include this in their business strategy is to build up resilience. Disasters of many kinds can result in either lost data, sales or even business. While a BCP won't prevent large-scale disasters, it will help your business recover quicker.

When looking at how resilient your business is, there are three main aspects to consider.

RTO RTO stands for Recovery Time Objective and is the time period from the beginning of the disaster to recovery of operations. This number, or time period, will be different for every company. For example, companies that operate online stores will likely have a short RTO, as they rely on 24/7 uptime to conduct business and sales.

In general the RTO is an objective, one that employees and stakeholders should strive for. Having one can help planners identify potential problem areas along with critical functions that must be recovered and any preparations that will be necessary. If a business does not address, or identify a set time to recovery they could see an unnecessary increase in recovery times, or worse lost profits.

RPO RPO stands for Recovery Point Objective and represents the amount of data a business is willing, or can afford, to lose. The easiest way to figure this out is to look at your systems and think about how much data or information you personally can lose before being unable to do your job. From there, you can work out the frequency with which you should back up your systems.

For example: If you figure that you can lose a day's worth of data, then your backup should be done on a daily basis. If you currently back up your data or systems once a week, and figure you can only miss a day, then RPO helps you realize this is not enough and that you need a system or plan that better meets your needs.

The difference between RTO and RPO is that RTO is a broad process that covers the whole Business Continuity timeline, while RPO is focused on data and backup.

ROI When looking at different Business Continuity systems, it is always a good idea to calculate the ROI, or Return on Investment. You can calculate the cost of the integrating any plan, time to implement and recovery, expected value it can bring your business and avoided losses. This will give you a pretty good picture on whether current systems are strong enough, and if new alternatives are better.

By figuring out the time you expect to recover, how often you should back up and the total ROI of proposed, or existing, systems you can gain a clearer picture of how resilient your company is.

If you're looking to make your company a little more resilient, why not get in touch with us? We are happy to sit down and discuss your options with you.

Published with permission from TechAdvisory.org. Source.

January 24th, 2013

If the scale of natural disasters in 2012 is any indicator of what 2013 is to bring, we could see an increase in the severity of the weather. For businesses, this often means disruption of key services. We don't have to tell you that any disruption in service could have a drastic negative impact on profits. To mitigate potential losses, many companies are turning to Business Continuity (BC). Those just starting to develop their own plans are often at a loss due to the scale of the project. We're here to help make it a bit less daunting.

Here's four questions you should answer when looking into adopting a Business Continuity plan.

1. What systems need to be recovered first? A good idea is to request each department/role list their essential systems and rank them in the order they need them back online in order to do their jobs. From here, you can compare answers and rank them in priority. For example, If all roles say they need Internet connection back online first, you know that the Internet is the first system that needs to be recovered.

2. What do we need to assure customers of stability? For the majority of businesses, the customer is the lifeblood. However, most customers will only stick around for a limited amount of time before going to a competitor if your business can't meet their needs. To keep customers loyal during a time of disaster, you need to prove you are either stable, or working to get there. Some examples of this could be a backup site with basic functionality that can take the place of your main website if it goes down.

3. What do business partners require? Your business partners are just as important as your customers and are often the link between the two. With partners, you often have set requirements that you need to meet in order to continue order fulfillment and shipment. You need to be aware of what these are and the related systems. After all, how are you going to get your product to your customers?

4. Are there any contractual requirements with vendors? Businesses that work with suppliers or vendors often have contractual obligations such as payment due on a certain date, or a set product order volume to fulfill the contract. As with business partners, you need to be clear on what these obligations are, and how you meet them. For example, if you pay a supplier on the 10th of every month, most will expect payment on the 10th, regardless of if you are operational or not.

Once you have the answers you needed you can take a step back and try to come up with a timeline of how long continuity actions should take and what your priorities are. From here, you can draft an actual plan, or look for vendors that can work with your systems and provide a continuity plan or service that meets your needs.

If you are looking for a business continuity system for your business please give us a call, we may have a solution that fits with your business.

Published with permission from TechAdvisory.org. Source.

November 28th, 2012

Fact: all it takes is one security breach to destroy a company. But few - especially small businesses - seem to realize it, according to a recent survey released by StaySafeOnline.org. Results show that few small businesses see themselves as a target of online thieves or hackers, resulting in many having only token security policies in place.

StaySafeOnline.org, a website of the National Cyber Security Alliance, has recently released a study that chronicles the cyber security practices and attitudes of small businesses. Conducted in partnership with Visa, the study shows some interesting, if not disturbing, results.

It turns out that many small businesses (about 65% of the respondents) are highly dependent on their computer / IT / data systems, where they store important information, from sensitive company financial records to personal client information such as credit card info, addresses and phone numbers, and more. However, as many as 85% believe that they will not be targeted by hackers and online thieves, and less than half have data security systems in which they are confident. In general, small businesses have, at best, a mediocre security system.

Few realize, though, that it only takes one breach to compromise a company's finances and relationships with clients. And if you have less than stellar security, stealing from you is easier. You might not have as many online assets as big businesses, but hackers can make a hefty profit by victimizing several easy marks as opposed to bigger and riskier efforts with more secure systems of larger firms.

Don't take a risk with important data, and don't compromise the relationships and reputation you've built with your clients over the years. Good security is always worth it. If you're interested in knowing more about beefing up your security through company policies, software, and user education, please don't hesitate to contact us. We'd be happy to sit down with you and discuss a security blueprint that's cost effective and custom built to meet your specific needs.

Reference: National Small Business Study

Published with permission from TechAdvisory.org. Source.

October 25th, 2012

There are many reasons as to why you would spend time developing a Disaster Recovery Plan (DR) that fits your company. The biggest reason is because it will help during times of disaster, and could be the difference between your business failing or succeeding. Often when we develop such a plan, we only look at the immediate surroundings, which could make the strategy too narrow. When developing a plan of action, it might help to look outside your region and country to what other regions are doing in relation to DR.

A report published by the EMC corporation in the summer highlights the current state of Disaster Recovery in Asia. The report takes an in-depth look at IT spending and the views of IT decision makers on Disaster Recovery in the Asia Pacific Region - South East Asia, Australia, China, Japan, South Korea and India.

The findings of the report are interesting considering current socioeconomic and natural conditions in the region. Asia, to date, has been largely unaffected by the negative economic conditions in both Europe and North America. According to the Q2 2012 Asia Job Index report released by Robert Walters, the number of IT positions advertised in major regions has grown across all sub-regions in Asia.

The most impressive countries were: Japan which saw IT postings achieve a quarter-on-quarter growth of 8%, compared to a country-wide quarter-on-quarter average decrease of postings across all industries of -4.6%. Malaysia is the other IT star, seeing IT positions grow 24.2% quarter-on-quarter, compared to a nation wide average growth of postings across all industries of 13.4%. On comparison, the whole Business Services Industry, including IT, in the US, achieved a growth of approximately 11%.

These figures for Asia show that companies in the region are investing in IT services and positions. The EMC’s findings parallel this, noting that many companies are investing more on DR possibly due to the relatively high number of disasters, natural or otherwise, affecting the region in the past year. On average, companies invested 11% of their IT budget on DR plans. Companies in North America spend between 2% and 4% of their annual IT budget on DR plans. This is a big difference, but is it paying off?

Looking deeper into the survey it can be noted that in the past year, 47% of respondents saw some form of data loss. The average amount of data lost was 484GB. Malaysia and India were hardest hit with an average loss of 1,099GB and 713GB lost, respectively. The top three reasons for loss were reported as being due to: data corruption (58%), hardware failure (50%) and loss of power (35%).

Despite the larger spending, the information reveals that many companies in Asia may not be spending their DR budgets wisely. Almost half of companies have experienced negative effects from some kind of emergency they likely could have prepared for.

In this region, and in all regions, the amount of data available to, and stored by companies is growing exponentially. If this trend of inadequate spending continues, companies will stand to see loss of data compounded.

We highly recommend that you take this information into account when developing your DR plans, and ensure that your budgets are properly allocated. For help with adopting the right DR strategy please contact us, we may have an effective plan that meets your needs.

Published with permission from TechAdvisory.org. Source.

September 27th, 2012

Disaster Recovery (DR), the act of ensuring that your systems and departments are ready for a disaster and that your IT systems can recover from it, is an important issue for all companies. While large companies with operations in more than one country can often bounce back quickly, small to medium businesses in the disaster area might have a tougher time, Ensuring a DR plan is reliable is necessary for small to medium sized businesses.

Here are four ways to ensure your DR plan is sufficient and company is disaster-ready.

Are your systems compliant? Many DR systems are licensed, and it’s important to ensure that these licences are both up-to-date and supported by all necessary backup systems. If you’ve added or changed components like a server or software, but not upgraded the relevant licenses, chances are your systems won’t be covered when disaster strikes. If this is the case, when you go to retrieve the backup, you’ll just get a license error; your data can’t be retrieved.

Another issue with DR software is that it’s often not used, lying dormant for years. You should regularly check and ensure the software meets modern compliance standards, is up-to-date and licenses have not expired. You should also be aware of how the software you use integrates and interacts with the DR software. For example, an upgrade to a new email server, may not communicate well with your DR software.

What’s the status of your backup server? As most DR plans usually involve a separate server from day-to-day servers, it’s important to ensure that they are functioning properly, usually by having the vendor test them. It’s also equally important to communicate with the vendors or manufacturers of the servers to ensure that the correct software/hardware licenses are in place and cover the function. If they aren’t, you could risk legal action or being fined.

Test regularly Regular tests are an integral part of a properly functioning DR plan. You need to conduct tests on at least a yearly basis to ensure all systems involved in the DR plan function well. From these tests, observe any function that performed poorly, or not at all, and take steps to fix or replace it.

Work with a knowledgeable partner DR plans and systems can be a complicated, almost messy aspect of business. While this may be, DR is crucial to the survival of a business after a disaster, and shouldn’t be treated lightly. To get it right liaise with DR experts to create and maintain a plan that meets your needs.

If you would like help with either implementing or improving your DR plan, please contact us, we may have a solution for you.

Published with permission from TechAdvisory.org. Source.

August 31st, 2012

The Internet is the lifeblood of many, if not all companies. We rely on it to communicate, research and relax, and in the modern world, we hardly disconnect from it. As we increasingly rely on it, any disruption in service will normally cause employees to be less productive and your company to lose money. Any slowing down with your Internet can be just as bad, if not worse.

Have you noticed that from time to time the Internet is a lot slower than it should be? If so, this could be because something is hogging all the bandwidth, which is the rate at which data is transferred in and out of one connection. Here are six of the most common bandwidth hogs.

  1. YouTube. If you allow employees to watch YouTube or connect to other streaming services, and they are using it frequently, you’ll notice a significant decrease in overall Internet speed. Some companies have noted that 40 staff using YouTube will account for over half of the total bandwidth usage.
  2. FTP sites. Some companies run FTP sites that host essential files that employees can download. When more employees are downloading/uploading files to the FTP site there’s less bandwidth available for other operations, so the Internet will be slower.
  3. P2P. P2P covers a large number of aspects including video conferencing and sharing of files via programs such as BitTorrent. All P2P services use an incredibly large amount of bandwidth when in operation, slowing the Internet to a point where speeds from 10 years ago were faster.
  4. Online backup. Backing up essential files will capitalize bandwidth leaving very little for other operations. It’s a good idea to conduct backups after office hours to minimize interruptions.
  5. Encryption. In certain industries regulatory bodies require a certain level of encryption, or for companies to take certain steps to secure data. Any extra encryption or security features will slow sites down, however this usually cannot be avoided.
  6. Spam/Virus/Malware. As many scams aim at stealing information the main way this is done is by sending the information over an Internet connection, that is your Internet connection. If you have viruses or other security threats you can guarantee that your Internet will be slower.
If you notice your Internet is slowing down at certain times, it’s a good idea to check and see if any of these six bandwidth hogs are in action. You can:
  • conduct a virus scan to look for malware;
  • ensure your computers aren’t backing up and if they are schedule the backup for later;
  • turn off or block any and all sharing services, and schedule video conferencing for times when bandwidth isn’t needed by other functions; and,
  • limit the bandwidth assigned to YouTube and other streaming services.
Before you tinker with any network connections though, it’s best to contact an expert . We may not just be able to help, but potentially provide an even better solution for you, speeding up your connection and your business success.
Published with permission from TechAdvisory.org. Source.

July 25th, 2012

Business continuity - the act of ensuring that business activities are available at all times, including during disasters - is a practice all businesses, regardless of their size, should be implementing in their organization. While many businesses backup their data and think that they’re protected, they will find that during times of disaster they aren’t.

Here are five things you should be doing, aside from backing up your data, to ensure you're ready for anything.

  • Where to work. One of the first things you should consider is where you're going to work if your office is inaccessible. Hotels, convention centers or other office buildings are viable locations. Whichever location you pick, you should pick at least two different places, as far apart as possible. You should also be sure to inform your staff and include maps of the routes to the locations you’ve chosen.
  • Replacement equipment. It’s incredibly important that you know exactly what equipment you use and how integral it is to operations. For mission critical equipment (equipment your company absolutely can’t work without) you need to have a plan in place as to how you can quickly replace lost equipment, the cost of it and replacement time. For less important equipment, you should have a couple of vendors in mind.
  • Communication systems. During adverse business conditions it’s vitally important that you and your employees are able to communicate both with one another and with your clients. You should look into a communication system that’s flexible, can be established wherever you are and allows you to keep your numbers. VoIP is a great system, telecommuting is another option as well.
  • Coordinate staff. You’re staff drive your business, without them, your business likely won’t be able to run. With the continuity plan you develop, it’s important that you have hard and soft copies of the plan that are accessible to all staff, and staff know their role in the plan. When your plan is enacted you need to contact your staff and ensure that there aren’t any problems.
  • Access to critical documents. If you have a good backup location, can set up equipment quickly and staff know their roles you may think your plan is perfect. You’re missing one key element: access to documents, employees won’t be able to work without them. It’s important to ensure that you can access your data backups, which means you should probably keep copies offsite and in the cloud if possible.
A continuity plan is important, hopefully you’ll never have to enact it. Nevertheless, you should plan for the worse. If you’re unsure of where to start, or feel your current plan is inadequate, please contact us.
Published with permission from TechAdvisory.org. Source.

June 27th, 2012

Most elevators/lifts in North America, Australia and the UK have a sign saying something along the lines of, “If there is a fire, don’t use the elevator/lift.” In Hong Kong, all elevators have signs that say, “When there is a fire, don’t use the lift.” The changing of one word, “if” to “when” presents a large difference of outlooks. In Hong Kong, people and businesses expect a disaster to happen. This is a viewpoint small business owners should adopt as well.

When a disaster strikes, 25% or more of small businesses affected will fail. Why do they fail? It’s not because of defects in the physical location, it’s mainly because they didn’t take the necessary steps to ensure that their business’s technology and related data is protected.

Because the modern business relies so heavily on technology, it’s essential that businesses have a business continuity plan (BCP) to minimize the loss of vital data, or in many cases, not lose any data at all. This is an important asset that will, one day, minimize losses felt due to any type of disaster. Small business owners know this, but many don’t know where to start. If you’re one of these owners, here are six tips on how you can prepare.

  1. Establish a backup regime. Data backup is one of the most important things you can do, be sure to regularly backup your corporate files, servers and user data files. A truly prepared company will have backups in a number of locations that can be easily accessed.
  2. Ensure solid communication platforms. One of the first things people do in a disaster is try to communicate with each other to ensure everything is ok. You can guarantee that some customers and employees will be calling to check in, so you need to have communication lines that work.
  3. Train employees. A BCP plan is useless if your employees don’t know their role in the implementation of the plan. It’s important that you train your employees on their roles, and that you communicate with them your expectations.
  4. Contingency plans. Like storing your data backups, you should set up contingency plans with the involved parties in your business. You should know where to go to do your banking, what your vendors’ or suppliers’ plans are and how they affect you, and most importantly: you should have a few locations where you can set up your business if the physical property is damaged.
  5. Review and practice all plans. Everything changes at one time or another, maybe an employee leaves or you adopt a new computer system. This makes it important to periodically practice your plans, review what worked and what didn’t, and update accordingly.
  6. Work with an expert. Planning for disaster is a tough thing to do well, considering all the elements to focus on and work with. To ensure a viable plan for your business, working with a recovery expert can help ensure that you get a plan that works for you while taking the stress off.
If you’re worried about your business’s disaster preparedness, please contact us. We can work with you to develop a solution, or provide you with the information and contacts to set you on the right path.
Published with permission from TechAdvisory.org. Source.