Showing posts with label Social Security Number. Show all posts
Showing posts with label Social Security Number. Show all posts

Wednesday, February 6, 2019

Why Googling Yourself Is Not Just for Fun Anymore

Why Googling Yourself Is Not Just for Fun Anymore
Yoav Vilner, Entrepreneur
Google searching our own names isn’t just a game anymore.  This is a common practice for millions of individuals, but there are higher stakes involved now.  20% of people find outdated info about themselves and 12% are unpleasantly surprised about what they find when they do a simple Google search.  This inaccurate or embarrassing information can hinder a job application or your business from growing.  Removing personal content from Google searches can be a complicated process; nevertheless, it is vital to protect ourselves from cyber criminals who can finely tune a personalized scam.

Monday, January 28, 2019

How Much Do Cyber-criminals Make with Your Personal Data?


How Much Do Cyber-criminals Make with Your Personal Data? 
Security Magazine
According to a study from the Kapersky Lab, a global cybersecurity company, criminals can sell an individual’s complete digital life for less than $50.  The market for a single breached account is even lower.  You’ll be surprised to learn the various ways criminals are stealing and selling a person’s complete digital life on the dark web.

Friday, October 28, 2011

Encryption 101


For many people, the word "encryption" invokes images of spies, clandestine operations and World War II code breakers feverishly working to decipher enemy messages. Actually, encryption is a priceless security tool that any business can easily use to keep sensitive information confidential and safe from prying eyes.



This article from IT Security highlights some important information about encryption.  As the article title implies, this is a basic overview of what encryption is and how and why you might want to take advantage of this technology. 

What would be nice is a link to an Encryption 202 article.  The article would cover corporate compliance and policies.  When the information we work on contains private information, information containing names, addresses, email addresses, social security, or credit card information we expose ourselves and our companies to global risk.  When the computer or storage device contains proprietary information that would benefit a competitor, then you have potential losses that mount quickly. 

These loses can encompass government intervention, audits, lawsuits, fines and the degradation of your customer base.  When the mix includes these loses, then the stakes are much higher.  The first thing the regulators will look for is a Written Information Security Plan (WISP).  A WISP plan is security fire drill to prevent data loss and a checklist resource to be used in post breach situations.

A WISP plan ensures that your devices are protected by encryption in addition numerous other attributes, including human resources, legal, and insurance compliance.  We are not trying to make it hard for you to sleep, we just want you to follow the best practices in the industry.  Dolvin Consulting works with industry experts Cyber Security Auditors and Administrators (CSA2) to help you to determine your risk quotient and build and maintain your WISP plan to match your risk.  Contact us today to see how we can help you.

Friday, October 21, 2011

Are Firewalls Really Necessary?

People that have some familiarity with networking know what a Firewall is.  A lot of people really do not know anything about them.  It is not unusual for me to run into people that do not know what a Firewall is or if they are using this technology. 



One of the great things about today’s technology providers is that they make it very easy, even for a novice, to set up networking.  From a professional’s perspective, it gets frustrating.  Most of us would like to see equipment and software fully configured with the maximum security when delivered.  It is a lot easier to start secure and ease restrictions on trusted sources, than to try and remediate problems and make a network or computer secure after the fact. 

One supplier indicated that only about 40% of the people they spoke with had a firewall.  And too many who do have firewalls are not monitoring them.  Which means your network could be under attack or even breached, and you would not even know it.

They symptoms may not be that obvious.  Unprotected networks and computers have a short lifespan of productive use.  It is estimated that an unprotected system connected to the Internet will be compromised (hacked) in about 20 minutes.

There is more to security than just a Firewall.  A Firewall can either be software or hardware.  Many use both.  And just like a chain is only as strong as its weakest link, so is security.  There are many aspects to consider, this biggest vulnerability is people.  We can be our own worst enemy at times. 

A Firewall is still an important part and it must be configured properly, updated and monitored to ensure it is doing the right job.

So what exactly is a Firewall?   As we explain this, think of “Traffic” as information or data that is transmitted back and forth.  An example might be a Google search engine request for the capital city of New Jersey and the response would be “Trenton”.  A firewall is a device that allows some traffic to enter your network while rejecting other traffic not specifically allowed or data traffic in response to your request.   The challenge is to configure the firewall to allow only the traffic that you need for your work, and not to allow bad traffic, like unauthorized users, or traffic that contains programs that will secretly grab your passwords, or worse, grab control of your system or your entire network.
Firewalls need to be updated regularly with updates that help it to
identify new threats and protect against new vulnerabilities.
Firewalls need to be monitored periodically to check for unauthorized access or attacks of your network.

Many Firewalls can be configured to create and/or accept secure connections that are often referred to as Virtual Private Networks (VPN).   When configured properly, these VPN connections allow safe and secure access to your network from a home office or while you are traveling.

So what value is your information to others?  If you use online banking, check your pension or medical information online, or use a username and password for anything, then you absolutely have information that others want. Those usernames and passwords give hackers access not only to information, but can give hackers access to other systems and other networks.

It is important to understand that if your computer is compromised, it can be turned into a system that distributes software, movies, songs, photos, documents or other types of materials that are illegal to distribute.

It might not be that obvious that you system has been compromised.  Has your Internet connection slowed to a crawl?  Have you noticed unusual charges on your bank statement?

If you do not already have a Firewall, or are not sure, or have not checked its status or have no idea about what I am talking about, then you should contact a professional to help you determine what will work for your needs and fit your budget.  If you do have and know what a Firewall is, then make sure its settings are still correct for your needs, it has been updated recently, and turn on and monitor logging to check the log files for suspicious activity. 

There are also services available for no-charge that will test your security.  Just make sure that you select these carefully and they are from a reputable source.  And above all else, do not give out any passwords or personal information to an unknown source.

Contact Dolvin Consulting today to see how we can help with your security issues.


Wednesday, October 19, 2011

BISD notifies parents of 15,000 students of data breach

BISD notifies parents of 15,000 students of data breach - KFDM-TV Channel Six

No one can really be sure that this information was not retrieved and will not be used for illegal activities.  How well will the parents and children sleep now, knowing that their private information was vulnerable. 



What confidence and creditability has been lost, because someone "thought" only principals could access the information.  Fortunately the student who discovered the breach notified the right people in a timely manner. 

If this was a business, would you want to want to do business with them?  Would you keep doing business with them?  It takes a long time to rebuild the trust lost in a few minutes, because someone thought they had a secure system.

It will be interesting to see if government regulators will now fine the school.  Most businesses will not have much choice.  You have to wonder if they have a Written Information Security Plan (WISP)? 

A WISP plan is more than a set of documents that sit on a shelf and collect dust.  It is a comprehensive plan to ensure data breaches do not happen.  Nothing is perfect and breaches do occur.  The WISP plan defines how to recognize a breach and what to do when one is discovered.  These plans must be updated every year and at any fundamental change in business operations.

If you are wondering what a WISP plan is and if you should have one, then you should and you should contact us as soon as possible.  Typically any organization that keeps private information about employees, suppliers, or customers is required to have a WISP plan.  Private information is a name, social security number, address, credit card number, or any personally identifiable piece of information.  To complicate matters more, each state has its own definition of what needs to be reported and how soon along with how much they are going to fine you.

Dolvin Consulting partners with industry experts Cyber Security Auditors & Administrators (CSA2) to determine your risk quotient and help you plan, develop, implement and secure a working WISP plan.  Contact us today to see how we can help you meet your compliance needs.  We are here to help.

Wednesday, October 12, 2011

Data breach exposes 4.9 million Tricare patients

A data breach affecting 4.9 million Tricare beneficiaries began when a government contractor left backup computer tapes in his car after parking it in downtown San Antonio one day this month. The worker had been given the job of taking the tapes from one federal facility to another when they were stolen.



“How does it happen? ... At one level, the answer's totally carelessness, obviously,” Stahl said.

“Let's take a medical facility. They've got a heart that needs to be transplanted into a patent and they give it to somebody to take from Point A to Point B. Is that person going to stop for eight hours along the way?” he said.

We are human and as humans we are subject to errors.  Errors in behavior, errors in judgment, errors in concentration.  It was on the way.  I was only going to stop for a few minutes.  What could possibly happen?  Who would even know what to do with these tapes?  No one will know. 

It just is not possible to know at this point where the system broke down, but there is a steady trend of these incidents.  It could also be that we are just hearing about them more now.  Bottom line is that you cannot be too careful or take enough care when handling information of this type. 

A Written Information Security Plan (WISP) establishes the guidelines for handling and securing private information.  A plan is only as good as its implementation.  That is why a WISP plan is not a static document that collects dust on a shelf.  It is monitored, updated, and reviewed every year and at any fundamental change in business operations.   It is not a catch all, but it is a necessity that the government looks for in cases like these.  A good WISP plan creates a defensible position. 

Dolvin Consulting works with industry experts Cyber Security Auditors & Administrators (CSA2) to assess your risk exposure and develop the solutions needed to protect your information and to give you the tools to manage your risk.

When your questions outnumber your answers it is time to contact us.


Thursday, September 29, 2011

Las Vegas Identity Theft Case Ends After 15 Years - ABC News

Las Vegas Identity Theft Case Ends After 15 Years - ABC News



This article came to my attention on Twitter, and I would have to agree with one readers comment ( ) that "We need stronger protection for consumers and stronger penalties for businesses that allow our data to be stolen."

Worse than the identity theft, is the loss of time and energy spent trying to resolve this case with an unresponsive government that seems utterly clueless.  His case cannot have been unique.  Why did it take so long?

Until sometime in the future when we do not rely on this type of information we are all going to be potential victims.  Now is the time for businesses to batten down the hatches.  Invest in an audit and take the precautionary steps to protect the information your customers entrust with you.

Dolvin Consulting works with Cyber Security Auditors and Administrators (CSA2) to help businesses create and maintain a Written Information Security Plan (WISP).  We help you prepare for the worse, like a fire drill, in the hopes you never need to use what you know.  You cannot be too prepared and if the worse should happen you will have peace knowing that you did everything possible to prevent the breach and you have a solid plan to restore your customer’s faith your business.

Contact Dolvin today to see how we can help you prepare for future data breaches.  We have Forensic experts available if you have already been breached.   

Remember that an ounce of prevention is worth a pound of pain.  We help you sleep better at night.