Showing posts with label WISP Vault. Show all posts
Showing posts with label WISP Vault. Show all posts

Friday, December 9, 2011

HIPAA Dangers Lurk on Facebook; Ongoing Policy Revisions Are Advised | AIS Health

HIPAA Dangers Lurk on Facebook; Ongoing Policy Revisions Are Advised AIS Health

This is a well written article.  It identifies an ongoing issue that all organizations, not just those in healthcare struggle with on a daily basis.  How do we empower our employees, yet maintain control over social media to protect the private information for which we are responsible?



I support the premise of policies for employees as many do not take the time to think beyond the moment to consider the consequences of their actions.  Many postings as the article points out are innocently placed.  Most people do not realize that enterprising people can take these separate pieces of information and place them together.  In the wrong hands that information is sold to the highest bidder.

The article points out: “There are people who have grown up having everything posted on Facebook, and having no privacy,” Drummond says. “They are posting more” with little thought to the potential impact.

The solution is not to single out any specific social media forum, but rather to invest in education for all workers.  Many simply are ignorant of the consequences.  At the organizational level, the education becomes part of a Written Information Security Program (WISP) plan.

Think of a WISP plan as a fire drill for a data breaches.  It is not a static, shelf sitting, and dust collecting binder.  A working WISP plan is reviewed annually or at any change in business or organizational process.  A WISP plan provides the foundation for a secure environment.  There is no one perfect solution.  Any plan that incorporates humans has the potential to break down.  In the event of a breach, there are well documented procedures that will mitigate damages and help create a defensible position for the regulators that are sure to be involved.

Dolvin Consulting works with industry experts Cyber Security Auditors and Administrators (CSA2) to help companies of all sizes manage the risk associated with private information.  Those companies are typically concerned with the threat of lawsuits related to the loss of personal information as well as the loss of their customer base due to the degradation of their reputation.

We cannot promise you that you will never have any problems, but we will do our best to understand your challenges and help you create a working WISP plan that matches your risk quotient.   Contact us today to see how we can help you manage your risk.


Friday, November 18, 2011

HIPPA Audits and Compliance

Alan Heyman, Managing Director of Cyber Security Auditors & Administrators LLC (CSA2) was contacted and quoted recently, because of his expertise in working with companies to help them determine their risk quotient. 

Automating HIPAA Compliance Tracking and Audit Preparation

The article is a quick read, but reading between the lines may take a bit longer.  Alan is of course talking about a Written Information Security Program (WISP) plan and a WISP-Vault which is a highly secured storage facility to keep the plan safe. 




There has never been a perfect mouse trap and the mice keep getting smarter.  You cannot engineer a perfectly secure environment when humans are involved.  A WISP plan is more than a fancy binder filled with out-of-date information sitting on a shelf in someone’s office collecting dust.  It is a process, not an event.  A real WISP plan is a living breathing environment which is kept up to date with the changes in your business.

Think of a WISP plan as a fire drill for data breaches.  You plan, prepare, and practice over and over so that in the case there is a data breach everyone stays calm and you implement the right corrective action in a timely manner.

You cannot keep the auditors away, but you can be prepared.  A working WISP plan creates a defensible position that will protect you and your business.  The preventative medicine might taste a little bitter, but is a lot less painful than cure.  You know the saying Ben Franklin made famous: “An ounce of prevention is worth a pound of cure”.  Ben made this observation long before there were computers or HIPPA concerns.

Every business has its own risk assessment and the solution is based on potential exposure.  You would prepare your home if you knew a storm was coming, so why not do the same with your business.  Start now by contacting us to see how we can help. 

Dolvin Consulting works with organizations that are worried about lawsuits related to the theft of personal information and are concerned about the loss of customers related to a data breach.

Friday, November 11, 2011

HIPPA Enforcement Promotes Compliance

Leon Rodriguez, the new director of the Department of Health and Human Services' Office for Civil Rights, describes his HIPAA enforcement agenda.


"As I've learned as a prosecutor and then as a defense lawyer, enforcement promotes compliance," Rodriguez says in an interview with HealthcareInfoSecurity's Howard Anderson. "The fact that covered entities out there know that they are at risk for penalties is something that, in fact, in many cases will promote compliance."


The full article can be found by clicking here.  Some excerpts are below. 


ANDERSON: In recent months, as you just alluded to, the Office for Civil Rights has significantly ramped up its HIPAA enforcement efforts.  Under your leadership can we expect to see your office announce more resolution agreements in civil monetary penalties and other enforcement actions?
RODRIGUEZ: I think you can expect that; absolutely you can expect that.

ANDERSON: The Office for Civil Rights recently hired KPMG to launch a HIPAA audit program. What would you like to see that program achieve, and is it possible that any of those audits will result in sanctions or penalties?
RODRIGUEZ: This is the first time we're doing it, so the first thing ... is for us to 'go to school' on how best we will run an audit program. In part, this is what you might call a pilot. We're going to look at it and learn: How do we use an audit program? How does an audit program best advance our enforcement goals?

The second purpose, and this is really different than enforcement, is to promote compliance among the covered entities that are subject to the audit.  Our first objective is not to go out there and start banging [organizations] with penalties; it's really to take a good look at them, find out where their opportunities for improvement are and help them improve.  Having said that, I think we know that there are cases where we're going to find some significant vulnerabilities and weaknesses.  And in those cases, we may be pursuing significant corrective action.  And in some of those cases, we may be actually pursuing civil monetary penalties.  But that's really not the primary goal of the audit program.



Rodriguez’s goal is to audit and learn, but even then he acknowledges they will pursue significant corrective action.  You can interpret the interview in several ways and they may all be correct to some extent.  What I suggest you walk away with is that the casual compliance days are over.  If you are found at-fault for a data breach, you will be subject to fines and other penalties.

In a post breach situation, there is no moderator.  Your organization will be held accountable.  Your client base will lose confidence in your operations and unless you are the only one performing that service, your clients will go elsewhere.  The publicity of the lawsuits will ensure a degradation of reputation and client base.

The only real course of action is to address your Risk Quotient in a pre breach environment.  Your organization will have the luxury of being able to take the time to plan and prevent data loss.  Preparation is like a fire drill for data security.  Plan and practice in the hopes you never need to use what you know.  But, if you do, then you will know what to do and when and the result will be a defensible position for the regulators.

Dolvin Consulting works with Cyber Security Auditors & Administrators (CSA2) and your organization to prepare, plan and implement a Written Information Security Program (WISP) plan.  The WISP plan is your key to sleeping well at night.  Contact us today to start a conversation that will help you connect with resources that can help with your compliance challenges.


Wednesday, October 19, 2011

BISD notifies parents of 15,000 students of data breach

BISD notifies parents of 15,000 students of data breach - KFDM-TV Channel Six

No one can really be sure that this information was not retrieved and will not be used for illegal activities.  How well will the parents and children sleep now, knowing that their private information was vulnerable. 



What confidence and creditability has been lost, because someone "thought" only principals could access the information.  Fortunately the student who discovered the breach notified the right people in a timely manner. 

If this was a business, would you want to want to do business with them?  Would you keep doing business with them?  It takes a long time to rebuild the trust lost in a few minutes, because someone thought they had a secure system.

It will be interesting to see if government regulators will now fine the school.  Most businesses will not have much choice.  You have to wonder if they have a Written Information Security Plan (WISP)? 

A WISP plan is more than a set of documents that sit on a shelf and collect dust.  It is a comprehensive plan to ensure data breaches do not happen.  Nothing is perfect and breaches do occur.  The WISP plan defines how to recognize a breach and what to do when one is discovered.  These plans must be updated every year and at any fundamental change in business operations.

If you are wondering what a WISP plan is and if you should have one, then you should and you should contact us as soon as possible.  Typically any organization that keeps private information about employees, suppliers, or customers is required to have a WISP plan.  Private information is a name, social security number, address, credit card number, or any personally identifiable piece of information.  To complicate matters more, each state has its own definition of what needs to be reported and how soon along with how much they are going to fine you.

Dolvin Consulting partners with industry experts Cyber Security Auditors & Administrators (CSA2) to determine your risk quotient and help you plan, develop, implement and secure a working WISP plan.  Contact us today to see how we can help you meet your compliance needs.  We are here to help.

Wednesday, October 12, 2011

Data breach exposes 4.9 million Tricare patients

A data breach affecting 4.9 million Tricare beneficiaries began when a government contractor left backup computer tapes in his car after parking it in downtown San Antonio one day this month. The worker had been given the job of taking the tapes from one federal facility to another when they were stolen.



“How does it happen? ... At one level, the answer's totally carelessness, obviously,” Stahl said.

“Let's take a medical facility. They've got a heart that needs to be transplanted into a patent and they give it to somebody to take from Point A to Point B. Is that person going to stop for eight hours along the way?” he said.

We are human and as humans we are subject to errors.  Errors in behavior, errors in judgment, errors in concentration.  It was on the way.  I was only going to stop for a few minutes.  What could possibly happen?  Who would even know what to do with these tapes?  No one will know. 

It just is not possible to know at this point where the system broke down, but there is a steady trend of these incidents.  It could also be that we are just hearing about them more now.  Bottom line is that you cannot be too careful or take enough care when handling information of this type. 

A Written Information Security Plan (WISP) establishes the guidelines for handling and securing private information.  A plan is only as good as its implementation.  That is why a WISP plan is not a static document that collects dust on a shelf.  It is monitored, updated, and reviewed every year and at any fundamental change in business operations.   It is not a catch all, but it is a necessity that the government looks for in cases like these.  A good WISP plan creates a defensible position. 

Dolvin Consulting works with industry experts Cyber Security Auditors & Administrators (CSA2) to assess your risk exposure and develop the solutions needed to protect your information and to give you the tools to manage your risk.

When your questions outnumber your answers it is time to contact us.


Friday, October 7, 2011

Attorneys General continue to increase legal standards for data privacy compliance

Many have written about it and several have contemplated it -- whether states will adopt private data security standards, such as the Payment Card Industry Data Security Standards (PCI DSS), and use them as legal standards that owners and holders of personal information (PI) must comply with.



That’s exactly what the Massachusetts Attorney General did when it recently filed suit against Briar Group, LLC and alleged, among several other things, that Briar was not PCI compliant at the time of its data breach in November 2009, affecting 53,000 MasterCard and 72,000 Visa accounts.

PCI DSS are private data security standards created by the Payment Card Industry Security Standards Council that apply to all organizations collecting credit cards. The Complaint alleged that Briar’s failure to implement basic data security measures on its computer system allowed hackers to gain access to Briar’s customers’ credit and debit card information.

Please see full article for more information.

Briar ultimately settled with Massachusetts through a consent judgment with the following penalties, in part:
Briar Group to pay State of Massachusetts $110,000;
Establish a Written Information Security Program;
Maintain PCI compliance and verify same within fourteen days;
Revise password management process; and
Implement various network system changes.


So here is a point that Briar Group or any company that is responsible for private information about their employees, suppliers or customers should consider.  Having a Written Information Security Plan (WISP) in place "Before" a breach happens is a worthwhile investment. 

So much so, that if they were compliant with a working WISP plan, they might not have been breached in the first place.  Fire drills save lives, because people are prepared and can stay calm in an emergency. 

A WISP plan prepares an organization.  The "plan" ensures that a company follows industry best practices.  Nothing is perfect, but the heavy fines and bad publicity are minimized by being prepared.  A WISP plan creates a defensible position.

Dolvin Consulting and Cyber Security Auditors & Administrators (CSA2) work with organizations that are worried about the threat of lawsuits related to the loss of private information and concerned about the loss of their customer base from the erosion of confidence that results from data breaches.

Contact us today to see how we can help you sleep better at night.



Thursday, September 29, 2011

Las Vegas Identity Theft Case Ends After 15 Years - ABC News

Las Vegas Identity Theft Case Ends After 15 Years - ABC News



This article came to my attention on Twitter, and I would have to agree with one readers comment ( ) that "We need stronger protection for consumers and stronger penalties for businesses that allow our data to be stolen."

Worse than the identity theft, is the loss of time and energy spent trying to resolve this case with an unresponsive government that seems utterly clueless.  His case cannot have been unique.  Why did it take so long?

Until sometime in the future when we do not rely on this type of information we are all going to be potential victims.  Now is the time for businesses to batten down the hatches.  Invest in an audit and take the precautionary steps to protect the information your customers entrust with you.

Dolvin Consulting works with Cyber Security Auditors and Administrators (CSA2) to help businesses create and maintain a Written Information Security Plan (WISP).  We help you prepare for the worse, like a fire drill, in the hopes you never need to use what you know.  You cannot be too prepared and if the worse should happen you will have peace knowing that you did everything possible to prevent the breach and you have a solid plan to restore your customer’s faith your business.

Contact Dolvin today to see how we can help you prepare for future data breaches.  We have Forensic experts available if you have already been breached.   

Remember that an ounce of prevention is worth a pound of pain.  We help you sleep better at night.



Wednesday, September 21, 2011

Senator to businesses: Protect data or pay

Senator Richard Blumenthal says his data breach legislation will deter data breaches. IT security experts have their doubts



Senator Richard Blumenthal, D-Conn., says his newly introduced legislation, the Personal Data Protection and Breach Accountability Act of 2011 will protect individuals' personally identifiable information from data theft and penalize firms that don't adequately secure their customers' information. Naturally, there are skeptics.

The bill would establish "appropriate minimum security plans" for businesses with 10,000 or more customers to safeguard their customer information and hold those businesses accountable through fines should they fail to meet those standards. The bill also calls for more public/private information sharing.

Click here or the headline above for the full article.



Certainly "larger" companies should already have and maintain a Written Information Security Plan (WISP).  They should already be allocating budget dollars to their security plan.  But what about all of the other companies that operate with information that should be kept private? 

Best practice in the industry suggest that all companies should be addressing their particular risk assessment.  For some smaller companies it is a simple process.  As the company size grows, so do the complexities of risk management.

Dolvin Consulting works with industry experts Cyber Security Auditors and Adminstrators (CSA2) to help companies of all sizes calculate their risk exposure and take the appropriate steps to safe guard their client and employee relationships. 

Think of this as a fire drill for a data breach.  You hope you never need it, but you will be prepared for the worse.  Contact Dolvin today to see how we can help you get a decent nights sleep.

Friday, September 16, 2011

Jail Time for Physician's HIPAA Violation Highlights Need to Redouble

A visiting cardiothoracic surgeon from China, working as a researcher at UCLA School of Medicine, became the first person sentenced to prison for unauthorized access to medical records in violation of HIPAA.



The jailing of the Chinese researcher highlights the fact that providers and employers no longer can be complacent about HIPAA compliance.
 
 
With so much information available to so many people, businesses need an advocate on their side.  Dolvin works with industry experts Cyber Security Auditors & Administrators (CSA2) to help you create a defensible position against the ever increasing tide of regulations, fines and breaches.
 
Contact Dolvin today for your risk analysis and assessment.  We are here to help.
 

Wednesday, September 7, 2011

Former waiter charged with stealing credit card numbers.

Former waiter charged with stealing credit card numbers.


A former waiter at a TGI Fridays restaurant in Laurel was indicted on charges he copied and sold the numbers of 73 credit cards, Prince George’s authorities said.


It really should not be any great surprise that we see these types of reports.  Apparently this guy’s mistake, which led to the discovery and his arrest, was not realizing who he was stealing from.  A couple of Secret Service agents ate at the restaurant and noticed the unauthorized charges.



What may surprise many more is how common this type of theft is and how often it occurs.  Sometimes a credit card is stolen and the offender charges up a storm.  That is relatively easy to spot on your statement or alert from your credit card company. 

What is much more prevalent are small, but numerous charges.  Small, like less than $9.  You read that correct, small charges are unlikely to be seen and even if they are discovered, they are too small to prosecute.  Why bother to steal a small amount?  Credit Card theft is a high volume low margin theft.  Steal lots of card numbers and charge lots of small amounts.  This adds up and ultimately makes everything more expensive.

There are many aspects to crimes like these.  First and foremost, the business management has public relations issue to contend with.  Will customers choose another establishment?  For how long?  How much business will be lost?  After the bad press settles a good many people will forget the incident, unless they were the one of the one’s affected.

In general a significant percentage of breaches are due to human error or negligence.  Until there is a time when having the information is of no value, people without will take from those who have.  Business tries to build a better mouse trap and the mice get smarter.

Dolvin Consulting and Cyber Security Auditors and Administrators (CSA2) work with companies to help them determine their risk exposure and build a Written Information Security Plan (WISP) and store that plan and other critical documents in a secure WISP-Vault.  You may never be able to eliminate all risks, but you can be prepared.  Perhaps as punishment or perhaps as a revenue stream, Government regulations are becoming more stringent and the fines are growing. 

You need someone knowledgeable on your side to help you manage your risk.  We would like to help you before trouble comes a knocking, but we also have experts in post-breach situations.  Do not wait, Contact Dolvin today.

Wednesday, August 31, 2011

HIPAA Auditor Involved in Own Data Breach

Who audits the auditor? 

Check out Identity Finder’s recent post about the HIPPA auditor that was responsible for their own breach.  HIPAA Auditor Involved in Own Data Breach.  What seems to be a recurring song these days is how these organizations tend to minimize the value and impact of the data loss.  The data did not contain this or that or some other statement designed to offset its political impact.



Many nefarious people take the time to collect information from separate sources and combine the data to build a complete profile of someone’s identity.  This information is available to the highest bidder.  Just name your price.

Corporate identity theft is now a lot like what we technology people tell people about disk drives and other hardware.  It is not about if it will fail, it is about when it will fail.

No one is exempt.  Of course some organizations are bigger targets, but everyone needs to start addressing the potential for data loss.  Fire drills save lives.  Written Information Security Plans (WISP) save companies that would otherwise have no alternative than bankruptcy.


With so much information available online and the mounting number of data breaches there has to be a better solution.   Dolvin works with industry experts Cyber Security Auditors & Administrators (CSA2) to assess and manage your security risk.  Contact us today to see how we are different.

Wednesday, August 24, 2011

Data Breach Response Best Practices

Data Breach Response Best Practices

Cyber Security Auditors & Administrators (CSA2) web page addresses data breaches and the best practices to address your risk exposure.



With so many breaches occurring each year, what happens if your company experiences a breach?  Most large companies are taking the necessary measures to prevent security breach incidents.  Breaches have almost become business as usual.  It is a “numbness” of sorts.  We hear so much about data loss, that is seems ordinary.

Ordinary of course until it happens to your organization.  No organization is immune.  Breaches can be accidental or intentional.  Regardless of how they occur, preventative measures, no matter how advanced the security technology is or extensive the resources are, offer no guarantees.

Breaches can also be costly events when you factor in losses such as lost business, fines and litigation costs, lost shareholder value and reputation damage.  The single largest cost component is the loss of business from a tarnished reputation. 

What distinguishes one breach from another is the post-breach response.  Like a fire drill, preparedness makes the difference.  Open communication with those affected is critical.  No one likes to be left in the dark.  If breaches are common today, the response and respect to those affected make the difference of survival. 

CSA2 works with organizations to help them prepare and maintain a Written Information Security Plan (WISP) and offer solutions to protect that plan from its own breach with their proprietary WISP-Vault.

Dolvin Consulting in partnership with CSA2 offers comprehensive risk analysis and management solutions.  Contact us to see how we can help.

Wednesday, August 10, 2011

Five Years of Cyberattacks Against 14 Countries: Operation Shady RAT - HotHardware

Five Years of Cyberattacks Against 14 Countries: Operation Shady RAT - HotHardware

This is an interesting read in security related issues.  Most people know now that many organizations from everywhere it seems have been collecting information on you.  Now just imagine some one or group took those separate pieces of information and put them together. 



Think about it.  There is no undo button.  More than likely someone had or could put together all the information they needed to target you or steal from you. 

In their research (click on article link above), McAfee gained access to one specific Command & Control server used by the hackers, and examined logs from the system. It determined that the hackers infected computers by first sending targeted emails to individuals in the companies or organizations. Once again, the weak link in security were human beings.


You do not have to be a security expert to understand that we ourselves (human beings) are the root of our own problems.  Cyber Security Auditors & Administrators (CSA2) have strategic partnerships with industry experts to help organizations of all sizes create Written Information Security Plans (WISP).  These plans are not only required, but they give you a defensible position to help with the government regulators.

Plan ahead, be prepared.  Contact Dolvin today to find your solution.

Wednesday, July 27, 2011

Did your customer just make you non-compliant with PCI guidelines?

Did your customer just make you non-compliant with PCI guidelines?

The convenience and ease at which technology has connected us may open the door to inadvertently exposing your organization to violations and PCI audits.  If, for an example, a customer sends their credit card information to you in an email or other social medium format, which sends (or should send) red flag warnings.  You absolutely cannot process the transaction.



According to Walter Conway, “If you do, then your company’s email servers, cell phones, web browser caches, Twitter, and Facebook accounts are all subject to a PCI-DSS audit.”

Refusing the transaction is not good for business, but accepting it means that everything in the communications channel is now handling cardholder data and must be compliant.

Worse yet, because much of these communications are not encrypted, what happens if that card information is compromised?  You now have a post-breach situation which notification requirements and regulators looking for your Written Information Security Plan (WISP).  Fines are sure to follow, but what about the loss of that customer and others that now look at your company as liability.


Better to refuse the transaction and explain the gory details to the customer rather than risk the alternatives.  Dolvin Consulting works with Cyber Security Auditors and Administrators (CSA2) to help you prepare.  Contact us to discuss how we can help protect your reputation and bank balance.

Thursday, July 21, 2011

Data Archiving: If it is worth saving, it is worth protecting.

IBM Smart Archive Strategy utilizes tiers of security.  One of the more important features of the information archive is the three levels of information protection, which coincide with the collections architecture. 


As reported in IBM System’s Magazine (July 2011), One of the benefits of this collection architecture is you can assign the protection level for each collection according to your information protection requirements.

Basic protection level:
·         Documents can be deleted before the expire.
·         Retention periods can be increased and decreased.
·         Documents with an extended retention period due to a retention hold can be deleted.
·         IT administrators can change the document protection level at any time.

Intermediate protection level:
·         Documents with an extended retention period due to a retention hold can’t be deleted.
·         Administrators can change the document protection option to maximum at any time, but can’t lower it to basic.
·         After the retention period expires, elements within the collection can be deleted, but the collection itself is permanent so new documents adhering to the same requirements can be added.

Maximum protection level:
·         Documents can’t be deleted until the end of their retention period.
·         Documents with an extended retention period due to a retention hold can’t be deleted.
·         Document retention periods can be lengthened but not shortened.
·         After enabling maximum protection, administrators can’t modify the document protection option to another level.
·         The collection can never be deleted.

IBM information archive also offers and enhanced tamper protection feature, which is important for customers with very strict retention requirements.  With this technology the administrator can remove root access so nobody, with malicious or non-malicious intent, can affect archived information.  This optional feature can be enabled at the customer’s discretion, but once enabled, it remains for the duration of the system’s life.


Why is all this important?  Because, if it is worth saving, it is worth protecting.  Dolvin works with enterprises to help them define and implement the right solution for their challenges.  Contact us today for an evaluation.

Friday, July 1, 2011

The Regulators Are Coming


The link above points to a recent article published by Alan Heyman Managing Director of Cyber Security Auditors & Administrators (CSA2) concerning the growing maze of regulations regarding data privacy and security. 

Alan highlights how the Massachusetts law reaches beyond their border to include any company outside of Massachusetts regardless of them being public, private, professional or not-for-profit that maintains personal information of a Massachusetts resident.

The direction all companies should be taking as a first step is to create a Written Information Security Plan (WISP).  A WISP plan must include administrative, technical and physical safeguards that are designed to meet the objectives of the regulators.

I invite you to read Alan’s full article, then contact Dolvin Consulting to see how we can help you connect with the resources you need to safeguard your information and sleep better.

Friday, June 17, 2011

WISP Vault - A Smart Solution for Protecting Your WISP Data

WISP Vault - A Smart Solution for Protecting Your WISP Data

Whether you are a company large or small, data breaches to Privacy Information are always possible as long as the human element is involved.

With data breaches becoming an almost every day occurrence, businesses of all sizes need a surefire alternative to keeping their Written Information Security Plans, files and information protected while following state and federal requirements. From state-to-state, a Written Information Security Policy (WISP) is required of organizations and establishments that must include how the WISP Plan will prevent such compromises (pre-breach) and what to do after a breach happens (post-breach). Failure to comply will result in hefty fines. Congress is cracking down on such offenses and businesses are the ones who have to pay, meanwhile, precious information which has been stolen can cost you more than just money. How will you tell your customers and clients that their personal information has been hijacked?


Now there is a smarter way to work with key-company critical data. Dolvin Consulting in partnership with Cyber Security Auditors & Administrators (CSA2), along with BMC Group, proudly introduces the WISPvault.

What separates this data security concept from any other is the highest protection for your WISP Plan, files and materials at efficient cost-conscious pricing, which puts you in control. A complete set up is easy and requires little time.  There are numerous customizable layouts and the feature-rich intuitive Windows-based interface offers dragand-drop capability, as well as other simple to operate features.

The WISPvault is effortless to update and only takes minutes. There is the option of managing it yourself or having a knowledgeable team assist you. A special team is assigned to you for the life of your site. Support is available 24/7 to answer any questions and aid in solving problems to keep your vault running smooth. The WISPvault offers the highest caliber of security with sophisticated encryption software, multiple firewalls, and powerful virus detectors and geographically dispersed secure servers.

Encompassing all aspects of cyber security, the WISPvault is the easiest method for executives; advisors and decision-makers to quickly access secure data. This essential solution allows businesses to stay a step ahead of the hackers and avoid breaches that are low cost and simple to navigate. You are at risk of being breached?  Can you afford not to have your data protected?

Written by Alan Heyman, CSA2 Managing Director


For further information, please contact: Dolvin Consulting