|
This is the home of the Dolvin Consulting Blog. Dolvin Consulting is an Information Technology firm providing computer & technology services as well as finance software & ERP systems to companies in the retail, distribution, manufacturing, and related industries in New Jersey and Eastern Pennsylvania.
Showing posts with label PCI. Show all posts
Showing posts with label PCI. Show all posts
Monday, January 28, 2019
How Much Do Cyber-criminals Make with Your Personal Data?
Labels:
Business impact,
Communications,
Complex,
Contacts,
Cyber security,
Decisions,
Help,
PCI,
Risk,
Risk Management,
Social Security Number,
Trusted Advisor
Friday, March 9, 2012
Detecting Fraud in your ERP Solution
Fraud and theft are difficult topics to address. There are so many resources available, so many places to review in your organization. How often do we just make the assumption that our Enterprise Resource Planning (ERP) solution has all the needed checks and balances?
ERP systems can help by organizing operations and allowing auditors to spot trends in the data.
This sounds important. Where do I start? First of all, this is not meant to be a technical report, nor a complete one. I only hope to highlight the importance of security and how your system can enable or prevent fraud from occurring.
Does your ERP solution run on a secure platform? This is the physical stuff, the box, the server, the equipment. This question must be asked and answered regardless if the solution is in-house or hosted in the Cloud. Who has physical access to the system? Who has wired and/or wireless, VPN, or virtual connectivity to the system?
The next step after the physical equipment would be to look at the operating system running on the system. Many servers have choices in operating systems, some servers have proprietary operating system. Regardless all operating systems have security settings. These settings should be based on the user, resource accessed, the device being used, and where the person is located.
The next layer is the ERP software solution itself. How are controls enabled? Does each user have a unique login credentials? How are the modules and the options secured? Does the software audit and track changes by user, date and time.
Above this are functional roles. For example there should be a check and balance (more than one person) processing the billing and the receipts. More than one person counting inventory and auditing the counts. There are many such role checks that should be implemented in your organization. The specifics should be discussed with your audit team.
Where do the threats come from? Ultimately people are involved. Are they solo efforts or are they conspiracies? Do you perform background checks on your personnel? Do they have gambling problems or prior criminal records? Men and women of all ages commit fraud.
Some industries have higher rates of embezzlement than others, but few, if any are exempt from the risk. It does not matter if it is nonprofit or for-profit. The incidents often happen over a long period of time. Small amounts taken regularly versus an armed robbery all-at-once.
Today there are many financial and operational standards, particularly for publicly held companies. Again, I am not here to tell you which ones or how they should be implemented. I am suggesting that the ERP solution you have should meet those standards. The security solution like the software modules should be integrated in the system, not a separate bolt on effort.
The long term solution is to engage with your Certified Public Accountant (CPA) and find a Certified Fraud Examiner (CFE) to take a close look at your organization. Accountant relationships are one of the select few where you do not like to make changes unless something goes terribly wrong. No one wants to bear their sole over again with someone new. However, if the relationship is professional, an independent audit will not offend your finance person and may only need to be done every few years. This will assure ownership that the proper controls are in place and allow you to keep your advisor.
Dolvin Consulting is available to help you find and implement sound ERP solutions that meet your challenges and budget. Contact us today to see how we can help.
Labels:
Dolvin Consulting,
ERP Software,
failure,
HIPAA,
HiTech,
Inventory Control,
Michael DeCamillis,
PCI,
Red Flag,
Risk,
Risk Analysis,
Security,
Trusted Advisor
Friday, December 23, 2011
Santa Claus’ Workshop, Naughty/Nice List Databases Hacked
Proprietary Data and PII of Billions Exposed. The Grinch, Disgruntled Elves, Anonymous Lead List of Suspects in Data Theft.
Well... just imagine it was your company that was breached. Santa probably has a healthy bank account and can weather the storm of bad publicity. After all if his organization fails, there is always mom and dad to do the shopping and delivery. It is not like there is a lot of competition. Where else are kids going to write at holiday time?
Maybe you do not consider your information all that valuable. Perhaps your company has no proprietary information. Is there employee information? What about customer credit information?
What happens to your business’ reputation?
It is hard enough finding a business, partner or supplier that you trust in the first place. As a business, how hard is it to keep your customer’s happy? What effect would a data breach have on your existing relationships?
It is very difficult to calculate the costs of a data breach on a business. At least one that survives and does file for bankruptcy to protect itself. The finance team can add up the fines, the cost of auditors and regulators, the pots of coffee consumed during the investigation, but what about the loss of reputation?
There is no perfect solution. The criminals keep getting smarter and the mouse traps more sophisticated. What you can do is prepare. That is the role of a Written Information Security Program (WISP) plan. It creates a defensible position with regulators. It is like a fire drill for data breaches.
Many companies provide technology solutions, but few provide a solution that will be approved by regulators. Dolvin Consulting and Cyber Security Auditors and Administrators (CSA2) work with your team to prepare, create and maintain a working WISP plan. A plan that is reviewed, tested, and updated each year. A plan that will help mitigate the risks and let you sleep at night.
The ball is in your court. Contact us today to see how we can help become compliant. Do not let what happened to Santa happen to you.
Labels:
Breach,
CSA2,
Dolvin Consulting,
failure,
HIPAA,
HiTech,
PCI,
Red Flag,
Risk,
Risk Management,
Security,
WISP,
WISP Plan
Friday, December 16, 2011
Study: Hackers and IT pros share personal information online
A recent study found that tech-savvy people disclose sensitive information to strangers they meet online, even though they should know better and found that Hackers apparently can be just as careless as their victims.
This study focuses on the phenomenon of disclosing private information to online friends who appear to be sharing your interests. The sample consisted of 100 persons, half of them working in the IT security industry (chosen from a professional network), while the other half dwelt on 'the other side of the fence' - the hacker’s clique (selected from specialized forums for 'bad guys').
Two experimental profiles were created, using the same information (age, sex, interests), but different jobs - corresponding to those of the respondents. After being contacted, the participants were interviewed in order to determine what kind of information they would be willing to disclose to a person working in the same industry, but still unknown to them.
The results suggest that, no matter what side of the fence they are on, people will behave the same: as though the virtual environment creates a second life, entirely different from the real one - they are willing not only to accept unknown persons inside their group just based on a nice profile, but also to reveal sensitive information (about their company, themselves and other persons) after a short online conversation. This applies to both categories of respondents even though they are aware of the risks such information disclosure would pose in real life.
Well I guess you just cannot trust anyone anymore. Perhaps with all the social media forums available today we are trying to connect more in an impersonal world. We should be connected more, we should have a greater sense of community. What seems to be happening is that we are becoming more and more disconnected, like islands.
Was the appeal of the “Tests” were really people wanting to be connected? Offer what people seem to want and need and you can get just about anything you want. Kind of reminds me of some stereotypical sales people that care more for the bottom line than the consumer.
Have we learned anything (yet)? Well yes, if it is the fact that your private information, yours or someone you are responsible for, is a valuable commodity for the industry that deals with stolen identities and funds. Yes, that we can all be fooled. Yes, that we need to be more aware. Yes, that we need to recognize there is no perfect solution that will protect us from ourselves.
What can we do? First, think. Second, before you reply to an invitation or anything online or even in person, think. Third, hire experts to help you think, because it is a big bad world out there and we all need help.
Sometimes it is hard to think outside of the box when you are in the box. That is where Dolvin Consulting and Cyber Security Auditors & Administrators (CSA2) work best. We work with your team to analyze your risk quotient and build a working Written Information Security Program (WISP) plan that addresses the volatile nature of information security. Contact us today to see how we can help you sleep better at night.
Labels:
Breach,
CSA2,
Dolvin Consulting,
failure,
HIPAA,
HiTech,
PCI,
Red Flag,
Risk,
Risk Analysis,
Risk Quotient,
Security,
Trusted Advisor,
WISP,
WISP Plan
Friday, October 14, 2011
ERP Pitfall- Modifications.
A sure recipe for obsolescence and trouble is making too many modifications to your Enterprise Resource Planning (ERP) system.
Minimize modifications.
Why did you select new software in the first place? Many times it was to take advantage of a fully integrated system with new features needed to stay competitive. Then why risk making changes? Was the selection the correct one in the first place? How well do you trust your advisor now?
Did you select a new system because you lost confidence in your existing system (that was heavily modified)? Do you need a new system, because of all the modifications needed to integrate your separate systems? “It works, but just barely and we cross our fingers every time we run the system or have to make an update”.
What prevents you from taking advantage of your software supplier’s updates? Too many modifications which locked you to a specific release/level, a specific support person/group/company? Too much time to replicate the changes in the new release? Does the new release have the features you already paid someone else to make?
Small changes can result in a domino effect of repercussions. Who will document the new procedures? Have you just sacrificed your compliance with modifications? What security exposures were created by the changes you just made?
It is hard to say what constitutes a valid modification. Certainly, you want to be able to service your customers, accept payments, ship orders, and replenish stock. It varies based on the situation. For one organization it is a necessity to function, in another it creates an unmanageable monster.
A lot of companies change the stock forms to meet their needs. Perhaps to include some additional information, branding and logos, and electronic distribution. These are somewhat common and do not typically create too much risk.
Other changes may include more risk, for example, altering the storage and usage of credit card information. You want to make it easy for your customers to click and order, but did you just invalidate your PCI compliance? Maybe you just wanted to your customers to be able to perform more self service. Did you just open your system up to hackers and data breaches? The media is full of reports about breaches. How many records were exposed and what is your reporting responsibility?
No one is suggesting that you make no changes, but we do suggest that you take the time to review and test the results. Compare the proposed benefits and review them with your trusted advisor and software supplier. Ensure that you have not prevented your organization from taking advantage of new features and functions.
Dolvin Consulting works with small to midsize businesses to help them understand and manage the risks and complexities of today’s ERP solutions. Contact us today to see how we can help you find and manage your solution.
Friday, October 7, 2011
Attorneys General continue to increase legal standards for data privacy compliance
Many have written about it and several have contemplated it -- whether states will adopt private data security standards, such as the Payment Card Industry Data Security Standards (PCI DSS), and use them as legal standards that owners and holders of personal information (PI) must comply with.
That’s exactly what the Massachusetts Attorney General did when it recently filed suit against Briar Group, LLC and alleged, among several other things, that Briar was not PCI compliant at the time of its data breach in November 2009, affecting 53,000 MasterCard and 72,000 Visa accounts.
PCI DSS are private data security standards created by the Payment Card Industry Security Standards Council that apply to all organizations collecting credit cards. The Complaint alleged that Briar’s failure to implement basic data security measures on its computer system allowed hackers to gain access to Briar’s customers’ credit and debit card information.
Please see full article for more information.
Briar ultimately settled with Massachusetts through a consent judgment with the following penalties, in part:
• Briar Group to pay State of Massachusetts $110,000;
• Establish a Written Information Security Program;
• Maintain PCI compliance and verify same within fourteen days;
• Revise password management process; and
• Implement various network system changes.
So here is a point that Briar Group or any company that is responsible for private information about their employees, suppliers or customers should consider. Having a Written Information Security Plan (WISP) in place "Before" a breach happens is a worthwhile investment.
So much so, that if they were compliant with a working WISP plan, they might not have been breached in the first place. Fire drills save lives, because people are prepared and can stay calm in an emergency.
A WISP plan prepares an organization. The "plan" ensures that a company follows industry best practices. Nothing is perfect, but the heavy fines and bad publicity are minimized by being prepared. A WISP plan creates a defensible position.
Dolvin Consulting and Cyber Security Auditors & Administrators (CSA2) work with organizations that are worried about the threat of lawsuits related to the loss of private information and concerned about the loss of their customer base from the erosion of confidence that results from data breaches.
Contact us today to see how we can help you sleep better at night.
Labels:
Breach,
CSA2,
Dolvin Consulting,
failure,
HIPAA,
PCI,
PCI-DSS,
Red Flag,
Risk,
Risk Analysis,
Risk Management,
Security,
WISP,
WISP Plan,
WISP Vault
Wednesday, July 27, 2011
Did your customer just make you non-compliant with PCI guidelines?
Did your customer just make you non-compliant with PCI guidelines?
The convenience and ease at which technology has connected us may open the door to inadvertently exposing your organization to violations and PCI audits. If, for an example, a customer sends their credit card information to you in an email or other social medium format, which sends (or should send) red flag warnings. You absolutely cannot process the transaction.
According to Walter Conway, “If you do, then your company’s email servers, cell phones, web browser caches, Twitter, and Facebook accounts are all subject to a PCI-DSS audit.”
Refusing the transaction is not good for business, but accepting it means that everything in the communications channel is now handling cardholder data and must be compliant.
Worse yet, because much of these communications are not encrypted, what happens if that card information is compromised? You now have a post-breach situation which notification requirements and regulators looking for your Written Information Security Plan (WISP). Fines are sure to follow, but what about the loss of that customer and others that now look at your company as liability.
Better to refuse the transaction and explain the gory details to the customer rather than risk the alternatives. Dolvin Consulting works with Cyber Security Auditors and Administrators (CSA2) to help you prepare. Contact us to discuss how we can help protect your reputation and bank balance.
Labels:
Breach,
CSA2,
Dolvin Consulting,
failure,
Michael DeCamillis,
PCI,
PCI-DSS,
Security,
WISP,
WISP Plan,
WISP Vault
Subscribe to:
Posts (Atom)





