Showing posts with label Online Security. Show all posts
Showing posts with label Online Security. Show all posts

Monday, 7 October 2013

Online Security For The Small Business: What's The Score?

Online Security
Any small business will already understand the importance of online security - if not for their employees and themselves, but for the business itself. Imagine being on the receiving end of a hack which results in personal details being released, or a virus that knocks your computer network for six. The problem with some small business owners is they are a little too complacent, with the mind-set of:

"Oh, I'll sort that later, it's an expense I could do without and it won't happen to me anyway."

While it's natural for any business to analyse their spending and cut back on unnecessary investments, online security isn't one of those commodities that can be forgotten about. Even with the economic climate the way it is, there are some things that are worth investing in and protecting your assets is one of them.

Recent research by the internet security giant, Symantec, has found that there has been a significant shift in website threats for small businesses to be a little more concerned than usual. While in previous years, chances of being targeted over larger, more lucrative businesses has been circumstantial but Part 1 of a new Symantec Infographic has shown that this is no longer the case. Nowadays, there have been more and more targeted attacks aimed at small and medium businesses rather than larger enterprises, highlighting the importance of online security, regardless of how many employees you have.

This infographic also mentioned the alarming statistic regarding security breaches - 12% were found to come from within a company's network, implying that you need to protect against third parties from outside and inside your network. The infographic also informed us that there has been a 13% increase in SME attacks in 2012, compared with 2011.

Part 2 of the infographic includes snippets of information about the current phishing trends, including a phenomenal increase in social media phishing. This highlights the importance for online security and diligence within small business setting, especially one which utilises social media networks to their advantage. It's also important to ensure your employees stay at the top of their game and are careful about what they click on when browsing the internet and social media sites during any downtime.

Owners of small businesses shouldn't ignore the importance of online security, investing in anti-virus software and network protection wherever possible. In an age where almost every business has an online presence, we will only see malicious activity rise - don't fall victim to it.


Did you like this article? Please let me know by leaving me your valued comments in the comments section below.

Related articles:
Must-Remember Tips In Securing Your Corporate Social Media Accounts
Spear-Phishing On Twitter: How Not To Become The Catch Of The Day


If you found this or any of my other posts helpful, don't forget to share the posts to your favourite networks using the toolbar below or by using the "+1" and "Share" buttons located at the bottom of each post.

As ever, if you want to stay up to date with the latest blog posts, don't forget to follow via Google Friend Connect (button on sidebar), on NetworkedBlogs, via Email (maximum of one email per day), on Facebook and Google+ or by subscribing to our blog feed at:
http://feeds.feedburner.com/DereksHomeAndBusinessBlog

You can also follow me on Twitter @djones1509, Google+ and on Facebook at:
http://www.facebook.com/djones1509
https://plus.google.com/104849975941505117776

Until my next post on Wednesday on using FAQ pages for content creation, have a great and productive week ahead! See you back here on Wednesday!


Advertise your business here

© 2013. This article is DMCA protected. Republication is prohibited.

Friday, 6 September 2013

Must-Remember Tips In Securing Your Corporate Social Media Accounts

Online Security
More and more businesses are embracing social media as a weapon in not only promoting their products, but also in establishing online visibility. From Twitter to Facebook to Google+ to LinkedIn, companies are using different online platforms to connect with their audience. But just like any activity made on the internet, creating a social media account may be putting sensitive company information at risk.

Accessing your account means total control on what to post and what message to send, ultimately carving how you would appear in the public's eye. The enemy may not always be external, sometimes the risk lies within your company. To avoid unwanted circumstances of hacking and unauthorized use, here are precautions you can take to secure your corporate social media account.


Create a Strong Password

This is a no-brainer. The first thing in securing your corporate social media account - or any account, for that matter - is by creating a strong password for it. Right now, you may not be able to think of anyone who might be interested in hacking your account but hackers don't give a warning of how and when they are going to do this. It may be an old disgruntled employee, a disappointed customer, or a bitter competitor. Come up with a complex password which isn't anything related to your company or product. A combination of letters, numbers, and symbols is always advisable, and changing it on a regular basis will also help.


Limit the Admins

If your marketing team is in charge of updating your social media posts, you don't necessarily have to provide the whole team with the password. Grant access only to those employees who really need it. It's as simple as this: the more people that can access your corporate account, the more chances of it getting compromised. It would mean more people could voluntarily or be tricked into leaking the password to another person, or more number of heads could accidentally be doing personal transactions through the corporate account.


Assign Designated Devices

Along with keeping the admins at a minimum, also require them to access your corporate accounts through specific devices. This is an extra measure that you can take as corporate-managed workstations are easier to monitor. It is also a way of preventing the account being logged in, even after using it, on an unauthorized device. This means that you might also need to skip on accessing the account through mobile. Strictly implement this rule and let your employees understand the need to do so.


Have a Higher Admin

Aside from your assigned admins, opt to have somebody with a higher power: your IT department. Give them more control when it comes to managing the activities of your social media accounts. According to Nate Ulery, who leads the IT infrastructure and operations practice at West Monroe Partners, you can consider "utilizing password reset email addresses that are not accessible by the social media team without IT involvement." Another way to do this is by not giving out actual login credential to employees. You can instead use a social media manager like Hootsuite. This software allows your employees to post without them having to know the actual password.


Educate the Employees

Just like everything else, it is necessary for your employees to understand the need of having security and privacy the way you understand it. Instigate them to observe proper measures by educating them more about hacking and phishing and the making them aware of the different risks.


Constantly be Updated With Privacy and Security Settings

Sites regularly update their privacy settings so it is essential that you do too. Constantly review it and make sure that your own setting and internal guidelines are based on it. This is also a good way to check if you are still comfortable with the kind of privacy and security a specific site can provide.


About The Author: Amanda Smith is a blogger based in San Diego, California. She loves writing about technology and gadgets, health and wellness, fashion and interior design, and just about anything that tickles her fancy. You can catch more of her works at wordbaristas.com.

Did you find this article helpful? Please let Amanda and myself know by leaving us your valued comments in the comments section below.

Would you like to guest post on the blog? Please use the Contact tab above to get in touch if you write business-related articles or articles on the topics of Internet Marketing, Affiliate Marketing, Social Media Marketing/Optimisation (SMO), Blogging, Search Engine Optimisation (SEO) or Search Engine Marketing (SEM).

Related articles:
Spear-Phishing On Twitter: How Not To Become The Catch Of The Day


If you found this or any of my other posts helpful, don't forget to share the posts to your favourite networks using the toolbar below or by using the "+1" and "Share" buttons located at the bottom of each post.

As ever, if you want to stay up to date with the latest blog posts, don't forget to follow via Google Friend Connect (button on sidebar), on NetworkedBlogs, via Email (maximum of one email per day), on Facebook and Google+ or by subscribing to our blog feed at:
http://feeds.feedburner.com/DereksHomeAndBusinessBlog

You can also follow me on Twitter @djones1509, Google+ and on Facebook at:
http://www.facebook.com/djones1509
https://plus.google.com/104849975941505117776

Until my next post on Monday with SEO marketing ideas for your business, have a fabulous weekend! See you back here on Monday!



© 2013. This article is DMCA protected. Republication is prohibited.

Friday, 5 July 2013

Spear-Phishing On Twitter: How Not To Become The Catch Of The Day

Spear Phishing
Regular phishers send out random phishing e-mails in an attempt to hook as many people as possible into giving away sensitive information. Spear-phishing is a more targeted and insidious pursuit. It targets specific people and entices them to reveal information to cyber criminals. Cyber security professionals are constantly updating their tactics to compete with and stay ahead of these cyber criminals.

Cyber-criminal-turned-security-consultant Kevin Mitnick says that cyber criminals can easily find targets for spear-phishing through social networks. "I can go into LinkedIn and search for network engineers and come up with a list of great spear-phishing targets," Mitnick explains. "Then I go onto Twitter or Facebook and trick them into doing something, and I have privileged access."

Twitter, in particular, has become a frequent spear-phishing target. Knowing how these attacks work and how to avoid them can prevent the loss of important data.


Spear Phishing Through Direct Messages

When people receive direct messages on Twitter that look like they're from legitimate connections, they may be tempted to click on malicious links. A recent example of a direct message spear-phishing attempt involved a Twitter direct message that said something like, "Funny picture of you, check it out, LOL" followed by a shortened URL. When the user clicked the link, a fake Twitter login screen appeared. The user entered credentials and gave the criminals control of the account.

Take the following precautions to avoid getting caught by direct message spear phishing:

  • Never open a link that you receive in a Twitter direct message. You can always confirm whether or not the person actually sent the message by calling or e-mailing to verify its authenticity.

  • Check the URL. In this case, before logging in, check to see that the domain name is "twitter.com." Some criminals may use a URL like "iwltter.com" that looks legitimate when the user only glances at it.

  • Think about the context. Never click a direct message that seems suspicious in any way.


Suspicious Apps Asking You to "Login With Twitter"

In April, an app called "socialme.me" circulated around Twitter. The app claimed to use information like a Twitter user's age and number of followers to calculate how much time the user had spent on Twitter. Users simply clicked a button on the app's home page that said, "Login With Twitter." This app was another way of obtaining Twitter login credentials.

Socialme.me has changed names a few times since people started to complain that the app had a broken dashboard, bombarded them with ads and sent tweets from their accounts without permission. For instance, it has used the names "socialtracker.me" and "Twalue." To stay out of danger from apps like this, take these steps:

  • Avoid "Login With (Social Network)" buttons. If you want to post to social media through an app, then do it manually instead of allowing the app to have automatic access to your account.

  • Use different passwords for everything, and change them regularly. For example, don't use your Twitter password as your bank account password.


Twitter Account Hijacking

Some Twitter links can inject a "man-in-the-middle" attack into your Web browser. For example, a recent Twitter spear-phishing attack from the Netherlands involved targets receiving a tweet from a trusted connection that said, "Beyoncé falls during the Super Bowl concert, very funny!!!!" When users clicked the link, malware took over their Web browsers and looked for vulnerabilities to exploit. When the unknowing users logged in to other sites, such as their financial institutions, criminals automatically had their banking login credentials.

Avoid hijacking by keeping these points in mind:

  • Keep your antivirus software up to date. Download updates immediately, or set your program for automatic update.

  • Always install patches and operating system updates. Of course, software updates and patches pop up for installation when you're in the middle of a project, and you probably don't have time to download them and restart your computer. Think of it this way: You don't have time for a malware infection or identity theft, either. Just stop, drop what you're doing and download the update.

  • Respond quickly if someone reports unusual tweets from your account. If a friend tells you that your account is sending out strange or spammy tweets, then go to Twitter's login page immediately and change your password. If you've used that password on other accounts, like your online banking service, then change the password in those places as well.


About The Author: James Hallowell provides social media consulting services for a number of SMBs and enterprises throughout North America.

Did you find this article helpful? Have you been the target of spear-phishing on ‎Twitter? Please let James and myself know by leaving us your valued comments.

Would you like to guest post on the blog? Please use the Contact tab above to get in touch if you write business-related articles or articles on the topics of Internet Marketing, Affiliate Marketing, Social Media Marketing/Optimisation (SMO), Blogging, Search Engine Optimisation (SEO) or Search Engine Marketing (SEM).


If you found this or any of my other posts helpful, don't forget to share the posts to your favourite networks using the toolbar below or by using the "+1" and "Share" buttons located at the bottom of each post.

As ever, if you want to stay up to date with the latest blog posts, don't forget to follow via Google Friend Connect (button on sidebar), on NetworkedBlogs, via Email (maximum of one email per day), on Facebook and Google+ or by subscribing to our blog feed at:
http://feeds.feedburner.com/DereksHomeAndBusinessBlog

You can also follow me on Twitter @djones1509, Google+ and on Facebook at:
http://www.facebook.com/djones1509
https://plus.google.com/104849975941505117776

Until my next post on Monday with ten tips for small businesses using LinkedIn, be safe online and have a wonderful and relaxing weekend!



© 2013. This article is DMCA protected. Republication is prohibited.