Showing posts with label Risk Analysis. Show all posts
Showing posts with label Risk Analysis. Show all posts

Monday, February 18, 2019

Friends Don’t Let Friends Hire Their Friends

Friends Don’t Let Friends Hire Their Friends
Jeff Hyman, Forbes 
Balancing relationships in and outside of the workplace can be a difficult juggling act; however, when a friend is hired in the workplace, that makes the juggling even more difficult.  This new co-worker who is seen as an emotional confidant outside of work, might receive office favoritism and act as a person to confide in.  Northwestern Business School professor Jeff Hyman believes that mixing friendships and work isn’t the best practice, but gives several steps/things to consider if you are going to hire a friend.    

Wednesday, February 6, 2019

Why Googling Yourself Is Not Just for Fun Anymore

Why Googling Yourself Is Not Just for Fun Anymore
Yoav Vilner, Entrepreneur
Google searching our own names isn’t just a game anymore.  This is a common practice for millions of individuals, but there are higher stakes involved now.  20% of people find outdated info about themselves and 12% are unpleasantly surprised about what they find when they do a simple Google search.  This inaccurate or embarrassing information can hinder a job application or your business from growing.  Removing personal content from Google searches can be a complicated process; nevertheless, it is vital to protect ourselves from cyber criminals who can finely tune a personalized scam.

Monday, November 10, 2014

Innovation (ERP)


Over the last few weeks I have had the opportunity to attend several events.  The evens were both Trade shows and Expos.  I define Trade Show somewhat differently than an Expo.  An Expo tends to be cross industry and a Trade show tends to be more vertical in nature. 

Both fill niches. 

An Expo’s value is typically the concentrated focus which is helpful, because you have experts in product delivery and service together to share industry best trends and practices.  You know, stuff to help your grow and expand your business.

A cross industry perspective is the value of an Expo.  Unlike a trade show, you have multiple industries instead of one that support, supply, work with and purchase from.

Both have value.

There was a security conference which talked about risk management and the state of uncertainty.  An Expo which represented a cross section of business and industry in a market area.  A Trade Show in technology service and support.  Then off to another industry Trade Show and finally to a Business Development industry focused event. 



Business Development

The Business development event was by far the bestest.  Okay “bestest” is not really a word, but the event, if you could call it that, was a conglomeration of medical people and up and coming businesses working in an accelerator to create new and innovative solutions to improve, streamline and create efficiencies that save organizations time, money and most of all lives.

At the end of the day, if you can succeed in business by helping others and increase the quality of lives, that is a pretty good achievement.

The Business Development event is somewhat of a cross mix between a Trade Show and Expo. 

It was organized by government sponsored organization whose goal was to take existing businesses, put them together to nurture their growth and then place them in front of the medical community and business leaders to showcase what they developed, kind of like a graduation ceremony, and take feedback to grow further and present an opportunity to present and hopefully sell their solution to their industry.

What made this event great was the mix of people and business and the anticipation.  Most of all was the atmosphere of community.  That we are all working to address a growing challenge that transcends borders and cultures.  Medical issues are foremost in all societies.  Everyone gets older and at some point we want to improve the quality of our lives and those we love.  

So, you might ask, what does this have to do with Enterprise Resource Planning (ERP) solutions?

Everything.

There are needs to have innovation, industry focus, and cross community collaboration.  Any business needs support of others in their same industry to share challenges and find solutions. They need cross industry support to help them with their challenges, supply goods and services, and provide solutions. 

Businesses also need incubator type of organizations to provide a fresh look, a new set of eyes, to develop new and innovative solutions to the challenges they face.  These incubators or accelerators need funding, government support, and industry nurturing to be effective. 

It takes much more than throwing money at a problem to find a solution.  It also takes a leader with vision.

It also takes a community. 

It takes questions, a lot of questions to find the answers to questions not yet asked.  It takes a cross section of industry to observe and think of new ways to solve the challenges of business.  All too often a closed industry of technologists keeps coming up with new ways to solve the same problem, which is not really a problem.  Inventing a better mouse trap when a trap is not what is needed.  Mice are not the issue after all.

I know of an ERP solution provider that takes the time to provide a user forum to educate their users and take their challenges to heart and create updates that address those challenges.  New features are created to address their real-world struggles. 

They are smart enough to know that if they want to be of value they need to provide value.

I have also seen screens and field prompts that were clearly written by technical people.  The prompt asks a question in reverse.  Instead of simply asking if a product in their catalog should be available on their Internet web site.  A simple Yes/No question.  They ask if the part should not be excluded.  A reverse answered question.  They should just ask if they want the item to appear.  Instead they ask if the item should be excluded.  So, to get the item listed, they have to answer “No”. 

Effective, but not intuitive. 

Users should not have to figure out logic questions to get their work done.  In the end most businesses just want their systems to work so that their people remain productive.  Customer service needs to be knowledgeable about their products, availability and to serve their customers well.  The other departments of business need to service the customer service department and those who directly face the customers.  All employees, even those who sweep up the shop floor contribute to the ability of your organization to serve your customers.

A good solution is one that looks beyond itself to drive efficiency and collaboration in the Enterprise.  Dolvin Consulting works with your team and industry experts to find solutions to your challenges.  Contact us today to see how we can help.  That is why we do what we do.


Monday, October 21, 2013

Hot, Warm and Cold

Hot, Warm and Cold ERP (Enterprise Resource Planning) responses.

What constitutes the need for an emergency response?  A system failure can range from an inconvenience to a failed business.  Length of down time and the amount of data loss will typically factor heavily in the business impact.

 


In planning for disaster, roles must be defined in conjunction with the recovery procedures.  Who will be in charge, who will determine the impact, which person will be responsible for status updates?  Has the notification chain been created and tested?

 

The Hot zone is where the incident occurred.  In an online, virtual world this may not be your place of business.  Disasters can occur to cloud or hosted providers as well.  Up time and available time are two separate categories of availability.  In cases of natural disaster does the affected operation have a disaster recovery site geographically separated from business operations and the point of failure or disaster?  Have key personnel been identified and do they have access to the alternate site?

 

The Warm zone is a transitional area between Hot and Cold sites.  This may be a physical area or virtual area.  It may be the same location in cases where there is a system down, but no physical damage.  In cases of natural disaster is often a safe place near the disaster where status can be checked, yet far enough away to not be in harm’s way. 

 

The Cold zone is either a neutral area or the remote area where responsible people can delegate recovery tasks and notify users, customers, suppliers when necessary of status updates.  This is where press releases can be issued, personnel and resources coordinated and delegated.

 

Priorities varry depending on the extent of the disaster.  In cases of physical or natural disasters first priorities should be to the health and well being of personnel, then protection and recovery of resources.  In cases consisting of physical or operational equipment failures these steps are typically not necessary.  The next priorities are to assess the problem, determine its impact and to estimate recovery times for partial and full recovery.

 

First thoughts.  What is/was the hazard, disaster or affected resource?  Have the responsible people been notified?  What resources are at risk, what resources are likely to become at risk?  What is being done to contain the risk?  Who is coordinating the emergency response?  Are there others that need to be notified? 

 

Support functions.  What resources can be notified to provide support and recovery? Are emergency response personnel to be notified?  How and which communications methods can be used to notify employees, customers and suppliers?  Who and how are facility and equipment repair and remediation personnel notified?  What other resources can be contacted for immediate or future response?

 

Public relations.  Does the disaster or incident require a public relations media expertise to notify the affected parties and mitigate the loss of reputation?

 

There are many aspects to any critical interruption in service.  There are many ways to prepare.  The point to first consider is if your organization has acknowledged the possibility and has consulted with others to create a recovery and continuity plan. 

 

Businesses come in all shapes and sizes as due risks.

 

1.       What are you doing now to prepare? 

2.       What can you do now to prepare? 

3.       What will you do to prepare? 

 

We would like to hear your thoughts.   Please share your comments in this blog.  We would love to hear your feedback.

 

Friday, July 13, 2012

Complexity in ERP Solutions

John C Maxwell, a well know author and friend to many, recently talked on one of his daily Minute-With-Maxwell video messages about the word Complexity.  In his daily messages he shares his thoughts about a word that someone has sent in.  John does not prepare or plan a response, the responses are candid.






When John talked about Complexity he made the point of how educators tend to make the simple more complex in their efforts to teach about whatever subject was being discussed.  In contrast John feels that people that are communicators make complex topics simpler.


The need for an Enterprise Resource Planning (ERP) solution tends to start out as a simple thought. 


Something along the lines of “Hey, if we shipped the right product on time, the first time we tried, then we would have happier customers” or “It sure would be nice if our purchasing department really knew what was in the warehouse instead of guessing”, “Heck, it might even be nice if what the computer said was on the shelf was actually correct and we could find it”. 


Problems often occur when those thoughts get translated to other people.  Are we trying to educate others or communicate a simple thought?  When and where does the meaning get lost?  “There is a hole in that canteen, plug it to stop the leak or replace it with something new”.  Our ERP system or lack of one is having a negative impact on our bottom line.  Let us fix it or replace it.


Internally there ought to be a team approach to collect all those “gee-wiz” thoughts in one place.  Are there enough issues that warrant looking for a new solution?  What is the financial impact of these issues? 


This is where a trusted advisor can help. 


While you are concentrating on your business and your challenges, there are others that can look at what you are doing, recognize the obvious and not so obvious areas for improvement. 


Ever notice how doctors look at x-rays?  They toss them up on the light board (they study that move in medical school by the way), mumble to themselves and flip through them quickly.  You sit there thinking about all the time you invested to get the images taken and to get them and yourself to the doctor and what they may tell the doctor, and he does not seem all that impressed.  It is the doctor’s experience and focus about what he/she is looking for that allows that quick analysis.  He does not have to look at the whole image, he can narrow it down to where the pain is located.  He is a professional and does this all the time.  The doctor knows what to look for.  So does your trusted advisor.


There are several other key steps that we will talk about in more detail in future posts, but for now here are a few key steps many organizations take in evaluating new solutions:

1.       Hire a trusted advisor.

2.       Company self discovery mode.

3.       Assemble requirements.

4.       RFQ process to select five candidates.

5.       First pass selection to narrow the field to four candidates.

6.       Executive overviews from four candidates.

7.       Second pass selection to narrow the field to three candidates.

8.       Discovery process with three candidates

9.       Second look demonstrations with three candidates.

10.   Self analysis of solution fit and company culture.

11.   Selection of final solution provider with contracts.

12.   Implementation project plan including installation, conversion, training and testing, etc.


There are a lot of details to fill out your plan.  Not everyone's plan will look the same.  Some companies may need other steps.  The list above is not meant to be everything for everybody.  The point is that having a road map and a tour guide can make the process a little less stressful. 


Dolvin Consulting is a trusted advisor that works with their industry resources to identify and bring solutions to your challenges.   We care, so Contact us Today to see how we can help your business. 


Friday, March 9, 2012

Detecting Fraud in your ERP Solution

Fraud and theft are difficult topics to address.  There are so many resources available, so many places to review in your organization.  How often do we just make the assumption that our Enterprise Resource Planning (ERP) solution has all the needed checks and balances? 

ERP systems can help by organizing operations and allowing auditors to spot trends in the data.



This sounds important.  Where do I start?  First of all, this is not meant to be a technical report, nor a complete one.  I only hope to highlight the importance of security and how your system can enable or prevent fraud from occurring.



Does your ERP solution run on a secure platform?  This is the physical stuff, the box, the server, the equipment.  This question must be asked and answered regardless if the solution is in-house or hosted in the Cloud.  Who has physical access to the system?  Who has wired and/or wireless, VPN, or virtual connectivity to the system?



The next step after the physical equipment would be to look at the operating system running on the system.  Many servers have choices in operating systems, some servers have proprietary operating system.  Regardless all operating systems have security settings.  These settings should be based on the user, resource accessed, the device being used, and where the person is located.



The next layer is the ERP software solution itself.  How are controls enabled?  Does each user have a unique login credentials?  How are the modules and the options secured?  Does the software audit and track changes by user, date and time. 



Above this are functional roles.  For example there should be a check and balance (more than one person) processing the billing and the receipts.  More than one person counting inventory and auditing the counts.  There are many such role checks that should be implemented in your organization.  The specifics should be discussed with your audit team.



Where do the threats come from?  Ultimately people are involved.  Are they solo efforts or are they conspiracies?  Do you perform background checks on your personnel?  Do they have gambling problems or prior criminal records?  Men and women of all ages commit fraud. 



Some industries have higher rates of embezzlement than others, but few, if any are exempt from the risk.  It does not matter if it is nonprofit or for-profit.  The incidents often happen over a long period of time.  Small amounts taken regularly versus an armed robbery all-at-once.



Today there are many financial and operational standards, particularly for publicly held companies.  Again, I am not here to tell you which ones or how they should be implemented.  I am suggesting that the ERP solution you have should meet those standards.   The security solution like the software modules should be integrated in the system, not a separate bolt on effort.



The long term solution is to engage with your Certified Public Accountant (CPA) and find a Certified Fraud Examiner (CFE) to take a close look at your organization.  Accountant relationships are one of the select few where you do not like to make changes unless something goes terribly wrong.  No one wants to bear their sole over again with someone new.  However, if the relationship is professional, an independent audit will not offend your finance person and may only need to be done every few years.  This will assure ownership that the proper controls are in place and allow you to keep your advisor.



Dolvin Consulting is available to help you find and implement sound ERP solutions that meet your challenges and budget.  Contact us today to see how we can help.


Friday, January 20, 2012

Zappos customer data accessed in security breach

Zappos is apparently one of the latest data breach victims.  Or, perhaps their customers are the latest victims.  Zappos feels that that the information was limited in scope, because the entire credit card number was not exposed (that is what they believe).  Many data thieves compile information from many sources to build complete profiles on people.  It just takes some patience and time to put together information that can be sold to the highest bidder.  It is a volume business and the 24 million customers are just bigger targets now.



You may read the CNET article by clicking this link:


There is no perfect solution, the mice get smarter and the traps more complex, but in time unless there is a proactive approach, “they” will get in and the damage will be done.

Here is the big message in the article and it applies to everyone, not just Zappos:

"We've spent over 12 years building our reputation, brand, and trust with our customers. It's painful to see us take so many steps back due to a single incident" Hsieh wrote in the letter.

An organization builds their reputation one satisfied customer at a time.  It takes years of effort to ensure your customers are happy.  It is evidenced by the referrals you get.  Then, in an instant your well earned reputation is gone. 

The data breach notification is the tip of the ice berg.  The piracy may have actually been going on for a time and the breach turns on the lights.  Other times it may be a single event.  As far as your customer cares, it puts them in jeopardy.  The only thing slightly in your favor is that people not directly affected are becoming numb to these news stories.  Never thinking it would happen to them, until it does and your company gets the blame and loss of business.

The bad publicity comes. The regulators come.  The forensic people come.  The remediation comes.  Then you try to rebuild your business. 

What comes after an event like this is what should have been in place in the first place.  A Written Information Security Program (WISP) plan.  You may think of a WISP plan in these simple terms.  It is a fire drill for a data breach.  You plan, practice, and protect hoping that you will never use what you have learned, but in the case when it is needed, it saves your life. 

A WISP plan is not a static document that sits on a shelf collecting dust.  That is what makes it different and what satisfies and creates a defensible position with the regulators.  A WISP plan involves a risk analysis of your organization and appropriate, best practice, measures are implemented.  It is different and scales for each organization.  Every company has some exposure, some more than others.

No one can promise you anything, not even us, but you should contact Dolvin Consulting to determine your Risk Quotient.  You cannot hide your head in the sand.  It is your responsibility to find out what you can to protect yourself and your customers, supplier, and employees.  Contact us today to see how we can help you mitigate the risks associated with the private information you are responsible for.



Friday, December 16, 2011

Study: Hackers and IT pros share personal information online

A recent study found that tech-savvy people disclose sensitive information to strangers they meet online, even though they should know better and found that Hackers apparently can be just as careless as their victims.




This study focuses on the phenomenon of disclosing private information to online friends who appear to be sharing your interests.  The sample consisted of 100 persons, half of them working in the IT security industry (chosen from a professional network), while the other half dwelt on 'the other side of the fence' - the hacker’s clique (selected from specialized forums for 'bad guys').

Two experimental profiles were created, using the same information (age, sex, interests), but different jobs - corresponding to those of the respondents. After being contacted, the participants were interviewed in order to determine what kind of information they would be willing to disclose to a person working in the same industry, but still unknown to them.

The results suggest that, no matter what side of the fence they are on, people will behave the same: as though the virtual environment creates a second life, entirely different from the real one - they are willing not only to accept unknown persons inside their group just based on a nice profile, but also to reveal sensitive information (about their company, themselves and other persons) after a short online conversation.  This applies to both categories of respondents even though they are aware of the risks such information disclosure would pose in real life.


Well I guess you just cannot trust anyone anymore.  Perhaps with all the social media forums available today we are trying to connect more in an impersonal world.  We should be connected more, we should have a greater sense of community.  What seems to be happening is that we are becoming more and more disconnected, like islands.

Was the appeal of the “Tests” were really people wanting to be connected?  Offer what people seem to want and need and you can get just about anything you want.  Kind of reminds me of some stereotypical sales people that care more for the bottom line than the consumer.

Have we learned anything (yet)?  Well yes, if it is the fact that your private information, yours or someone you are responsible for, is a valuable commodity for the industry that deals with stolen identities and funds.  Yes, that we can all be fooled.  Yes, that we need to be more aware.  Yes, that we need to recognize there is no perfect solution that will protect us from ourselves.

What can we do?  First, think.  Second, before you reply to an invitation or anything online or even in person, think.  Third, hire experts to help you think, because it is a big bad world out there and we all need help. 

Sometimes it is hard to think outside of the box when you are in the box.  That is where Dolvin Consulting and Cyber Security Auditors & Administrators (CSA2) work best.  We work with your team to analyze your risk quotient and build a working Written Information Security Program (WISP) plan that addresses the volatile nature of information security.  Contact us today to see how we can help you sleep better at night.


Friday, November 18, 2011

HIPPA Audits and Compliance

Alan Heyman, Managing Director of Cyber Security Auditors & Administrators LLC (CSA2) was contacted and quoted recently, because of his expertise in working with companies to help them determine their risk quotient. 

Automating HIPAA Compliance Tracking and Audit Preparation

The article is a quick read, but reading between the lines may take a bit longer.  Alan is of course talking about a Written Information Security Program (WISP) plan and a WISP-Vault which is a highly secured storage facility to keep the plan safe. 




There has never been a perfect mouse trap and the mice keep getting smarter.  You cannot engineer a perfectly secure environment when humans are involved.  A WISP plan is more than a fancy binder filled with out-of-date information sitting on a shelf in someone’s office collecting dust.  It is a process, not an event.  A real WISP plan is a living breathing environment which is kept up to date with the changes in your business.

Think of a WISP plan as a fire drill for data breaches.  You plan, prepare, and practice over and over so that in the case there is a data breach everyone stays calm and you implement the right corrective action in a timely manner.

You cannot keep the auditors away, but you can be prepared.  A working WISP plan creates a defensible position that will protect you and your business.  The preventative medicine might taste a little bitter, but is a lot less painful than cure.  You know the saying Ben Franklin made famous: “An ounce of prevention is worth a pound of cure”.  Ben made this observation long before there were computers or HIPPA concerns.

Every business has its own risk assessment and the solution is based on potential exposure.  You would prepare your home if you knew a storm was coming, so why not do the same with your business.  Start now by contacting us to see how we can help. 

Dolvin Consulting works with organizations that are worried about lawsuits related to the theft of personal information and are concerned about the loss of customers related to a data breach.

Friday, November 4, 2011

Wells Fargo mixes up customer statements

Wells Fargo mixes up customer statements The Post and Courier, Charleston SC - News, Sports, Entertainment

There was a time that this would have been laughable.  As a bank customer you could understand that some machine was out of sync and documents where mismatched with envelopes.  In fact, in the “old” days when you actually received your canceled checks back with your monthly statement I remember receiving someone else’s canceled checks.  I contacted the bank and they were able to straighten out the mix-up.  It was not something we worried much about, back-then.



Today’s world is much different.  Data breaches are linked to identity theft.  Identity thefts create so many challenges for the victims.  Bad credit scores, denied loans, governmental actions and of course, lots of aggravation for the victim and what seems like little penalty for the culprit, if they are ever captured. 

The only party the government seems to be able to touch effectively is the original holder of the information, in this case the bank.  The regulators have their calculators lined up, charging fees and fines.  In a post breach situation, the offending organization is at the mercy of the regulators and courts.  In some cases there really is some negligence and the penalties are justified.  Sometimes these organizations become scapegoats for the industry.



Whenever an organization finds itself in a post breach situation it is like a roller coaster ride.  You just have to ride it out and pay whatever you have to make the problem go away and identify and remediate the vulnerability.

What a difference it makes in a pre breach situation.  You have the time to do audit and analysis, testing and documentation.  Parts in a well organized Written Information Security Program (WISP) plan.  Of course, there is more to a WISP plan than a technology audit.  WISP plans ensure that all aspects of information technology infrastructure, human resources, legal, and insurance issues are addressed.  The depth and expense of a WISP plan is tied to the complexity of the operation it is designed to protect. 

A WISP plan is not an event, it is a process.  A process too complex to be navigated alone.  That is why Dolvin Consulting has teamed up with industry experts Cyber Security Auditors and Administrators (CSA2) to work with your team to design, plan, and implement a working WISP plan so that you can sleep at night.  Contact us today.  We are here to help!

Friday, October 28, 2011

Encryption 101


For many people, the word "encryption" invokes images of spies, clandestine operations and World War II code breakers feverishly working to decipher enemy messages. Actually, encryption is a priceless security tool that any business can easily use to keep sensitive information confidential and safe from prying eyes.



This article from IT Security highlights some important information about encryption.  As the article title implies, this is a basic overview of what encryption is and how and why you might want to take advantage of this technology. 

What would be nice is a link to an Encryption 202 article.  The article would cover corporate compliance and policies.  When the information we work on contains private information, information containing names, addresses, email addresses, social security, or credit card information we expose ourselves and our companies to global risk.  When the computer or storage device contains proprietary information that would benefit a competitor, then you have potential losses that mount quickly. 

These loses can encompass government intervention, audits, lawsuits, fines and the degradation of your customer base.  When the mix includes these loses, then the stakes are much higher.  The first thing the regulators will look for is a Written Information Security Plan (WISP).  A WISP plan is security fire drill to prevent data loss and a checklist resource to be used in post breach situations.

A WISP plan ensures that your devices are protected by encryption in addition numerous other attributes, including human resources, legal, and insurance compliance.  We are not trying to make it hard for you to sleep, we just want you to follow the best practices in the industry.  Dolvin Consulting works with industry experts Cyber Security Auditors and Administrators (CSA2) to help you to determine your risk quotient and build and maintain your WISP plan to match your risk.  Contact us today to see how we can help you.

Friday, October 21, 2011

Are Firewalls Really Necessary?

People that have some familiarity with networking know what a Firewall is.  A lot of people really do not know anything about them.  It is not unusual for me to run into people that do not know what a Firewall is or if they are using this technology. 



One of the great things about today’s technology providers is that they make it very easy, even for a novice, to set up networking.  From a professional’s perspective, it gets frustrating.  Most of us would like to see equipment and software fully configured with the maximum security when delivered.  It is a lot easier to start secure and ease restrictions on trusted sources, than to try and remediate problems and make a network or computer secure after the fact. 

One supplier indicated that only about 40% of the people they spoke with had a firewall.  And too many who do have firewalls are not monitoring them.  Which means your network could be under attack or even breached, and you would not even know it.

They symptoms may not be that obvious.  Unprotected networks and computers have a short lifespan of productive use.  It is estimated that an unprotected system connected to the Internet will be compromised (hacked) in about 20 minutes.

There is more to security than just a Firewall.  A Firewall can either be software or hardware.  Many use both.  And just like a chain is only as strong as its weakest link, so is security.  There are many aspects to consider, this biggest vulnerability is people.  We can be our own worst enemy at times. 

A Firewall is still an important part and it must be configured properly, updated and monitored to ensure it is doing the right job.

So what exactly is a Firewall?   As we explain this, think of “Traffic” as information or data that is transmitted back and forth.  An example might be a Google search engine request for the capital city of New Jersey and the response would be “Trenton”.  A firewall is a device that allows some traffic to enter your network while rejecting other traffic not specifically allowed or data traffic in response to your request.   The challenge is to configure the firewall to allow only the traffic that you need for your work, and not to allow bad traffic, like unauthorized users, or traffic that contains programs that will secretly grab your passwords, or worse, grab control of your system or your entire network.
Firewalls need to be updated regularly with updates that help it to
identify new threats and protect against new vulnerabilities.
Firewalls need to be monitored periodically to check for unauthorized access or attacks of your network.

Many Firewalls can be configured to create and/or accept secure connections that are often referred to as Virtual Private Networks (VPN).   When configured properly, these VPN connections allow safe and secure access to your network from a home office or while you are traveling.

So what value is your information to others?  If you use online banking, check your pension or medical information online, or use a username and password for anything, then you absolutely have information that others want. Those usernames and passwords give hackers access not only to information, but can give hackers access to other systems and other networks.

It is important to understand that if your computer is compromised, it can be turned into a system that distributes software, movies, songs, photos, documents or other types of materials that are illegal to distribute.

It might not be that obvious that you system has been compromised.  Has your Internet connection slowed to a crawl?  Have you noticed unusual charges on your bank statement?

If you do not already have a Firewall, or are not sure, or have not checked its status or have no idea about what I am talking about, then you should contact a professional to help you determine what will work for your needs and fit your budget.  If you do have and know what a Firewall is, then make sure its settings are still correct for your needs, it has been updated recently, and turn on and monitor logging to check the log files for suspicious activity. 

There are also services available for no-charge that will test your security.  Just make sure that you select these carefully and they are from a reputable source.  And above all else, do not give out any passwords or personal information to an unknown source.

Contact Dolvin Consulting today to see how we can help with your security issues.


Wednesday, October 19, 2011

BISD notifies parents of 15,000 students of data breach

BISD notifies parents of 15,000 students of data breach - KFDM-TV Channel Six

No one can really be sure that this information was not retrieved and will not be used for illegal activities.  How well will the parents and children sleep now, knowing that their private information was vulnerable. 



What confidence and creditability has been lost, because someone "thought" only principals could access the information.  Fortunately the student who discovered the breach notified the right people in a timely manner. 

If this was a business, would you want to want to do business with them?  Would you keep doing business with them?  It takes a long time to rebuild the trust lost in a few minutes, because someone thought they had a secure system.

It will be interesting to see if government regulators will now fine the school.  Most businesses will not have much choice.  You have to wonder if they have a Written Information Security Plan (WISP)? 

A WISP plan is more than a set of documents that sit on a shelf and collect dust.  It is a comprehensive plan to ensure data breaches do not happen.  Nothing is perfect and breaches do occur.  The WISP plan defines how to recognize a breach and what to do when one is discovered.  These plans must be updated every year and at any fundamental change in business operations.

If you are wondering what a WISP plan is and if you should have one, then you should and you should contact us as soon as possible.  Typically any organization that keeps private information about employees, suppliers, or customers is required to have a WISP plan.  Private information is a name, social security number, address, credit card number, or any personally identifiable piece of information.  To complicate matters more, each state has its own definition of what needs to be reported and how soon along with how much they are going to fine you.

Dolvin Consulting partners with industry experts Cyber Security Auditors & Administrators (CSA2) to determine your risk quotient and help you plan, develop, implement and secure a working WISP plan.  Contact us today to see how we can help you meet your compliance needs.  We are here to help.

Friday, October 14, 2011

ERP Pitfall- Modifications.

A sure recipe for obsolescence and trouble is making too many modifications to your Enterprise Resource Planning (ERP) system.



Minimize modifications. 

Why did you select new software in the first place?  Many times it was to take advantage of a fully integrated system with new features needed to stay competitive.  Then why risk making changes?  Was the selection the correct one in the first place?  How well do you trust your advisor now?

Did you select a new system because you lost confidence in your existing system (that was heavily modified)?  Do you need a new system, because of all the modifications needed to integrate your separate systems?  “It works, but just barely and we cross our fingers every time we run the system or have to make an update”.

What prevents you from taking advantage of your software supplier’s updates?  Too many modifications which locked you to a specific release/level, a specific support person/group/company?  Too much time to replicate the changes in the new release?  Does the new release have the features you already paid someone else to make?

Small changes can result in a domino effect of repercussions.  Who will document the new procedures?  Have you just sacrificed your compliance with modifications?  What security exposures were created by the changes you just made?

It is hard to say what constitutes a valid modification.  Certainly, you want to be able to service your customers, accept payments, ship orders, and replenish stock.  It varies based on the situation.  For one organization it is a necessity to function, in another it creates an unmanageable monster. 

A lot of companies change the stock forms to meet their needs.  Perhaps to include some additional information, branding and logos, and electronic distribution.  These are somewhat common and do not typically create too much risk. 

Other changes may include more risk, for example, altering the storage and usage of credit card information.  You want to make it easy for your customers to click and order, but did you just invalidate your PCI compliance?  Maybe you just wanted to your customers to be able to perform more self service.  Did you just open your system up to hackers and data breaches?  The media is full of reports about breaches.  How many records were exposed and what is your reporting responsibility?  

No one is suggesting that you make no changes, but we do suggest that you take the time to review and test the results.  Compare the proposed benefits and review them with your trusted advisor and software supplier.  Ensure that you have not prevented your organization from taking advantage of new features and functions.

Dolvin Consulting works with small to midsize businesses to help them understand and manage the risks and complexities of today’s ERP solutions.  Contact us today to see how we can help you find and manage your solution.