Wednesday, June 18, 2014

Security Training is Lacking

Humans are the weakest link in the enterprise security chain. But a survey finds that more than half aren’t getting any security awareness training at all. The good news is that there is plenty of advice on how to do it, and do it better

But, it is apparently not common enough throughout the enterprise sector. A recent  report by Enterprise Management Associates (EMA) found that 56% of workers may not receive any security awareness training (SAT) at all.

The report, titled “Security Awareness Training: It’s Not Just for Compliance,” is based on a survey of 600 people working for companies ranging from fewer than 100 employees to more than 10,000.


Any doubts about the need for SAT should have been dispelled by last year’s Verizon Data Breach Investigations  Report (DBIR), which found that four out of five breaches were caused by stolen credentials – usually the result of social engineering attacks or weak passwords. And there is abundant evidence that social engineering attacks have become much more sophisticated, and therefore successful.

Friday, May 30, 2014

Effective security awareness includes everyone

I’m often asked which employees are most likely to be targeted by phishing emails. It’s interesting to think about, but the truth is that adversaries will target whichever employees can offer access to the enterprise’s network—and that could potentially be anyone in your organization. Recent research from ProofPoint confirmed this, finding that staff-level employees were targeted by phishing attacks more often than middle and executive management.

The takeaway here is that for security awareness to be effective, it needs to include everyone in your organization. Aside from the obvious security necessity, including the entire organization in your security awareness initiatives enhances your program in a number of ways.

First and foremost, inclusion of everyone in security awareness training reduces the security gaps across organization. While training will never be 100% effective, the more people who receive training, the more potential security risks will be reduced.

Including executives and senior managers in training exercises creates solidarity within the workforce, as staff will be more likely to embrace the exercise knowing their bosses are participating. Training staff-level employees truly makes security awareness part of your organization’s culture, and helps each employee understand that everyone—not just the IT department—has a responsibility for IT security. If you’re collecting metrics with your campaigns, you should be, including everyone will provide a broader baseline of your user population’s susceptibility and pinpoint strengths and weaknesses in your security posture.

Thursday, April 24, 2014

Immersive Security Awareness Training

Ultimately, immersing your employees in an experience will improve their behavior. With that said, here are ways to make your immersive security awareness engaging.

Start simple: For the average user, security concepts are difficult to grasp, so start simple! Sending a beginner down a black diamond trail is a good way to turn them off of skiing forever (or worse, get them injured). It's the same with security. Don't trip up your users by starting them off with complicated concepts – get them on the beginner slope.

Be Specific: Hollow platitudes will undoubtedly get your users to tune out. Avoid vague messages like “keep company resources safe”, instead give users specific, actionable information that will help them change behavior.

Mix it up: How many of you pay attention to the airline safety demonstration prior to take-off? That demonstration never changes so ultimately people lose interest. Don't make the same mistake with security awareness. Vary both the content and delivery method of your security awareness to continually engage recipients.

Keep it going: Why is it so easy to forget what you learned in a boring class? After the final exam, you don't need the information, so there's no need to retain it. We do know that security is a constant and changing threat; therefore, security awareness needs to be continuously reinforced. By continuously training users at different times throughout the year, safe security behavior becomes a habit, and not something forgotten as soon as training is over.

Be Positive: It might be tempting to expose the users who are security risks, but in our experience the negative backlash this generates will quickly undermine your security awareness program. Keep things positive by measuring the results of your program and recognizing people and departments who have done well. Educate and support those that need additional help.

Thursday, February 13, 2014

Tax ID Theft

What is tax identity theft?
It’s a fast-growing crime that costs taxpayers billions of dollars a year, and shows no signs of abating. Someone uses a taxpayer’s personal information to commit fraud on tax returns to claim refunds or for other crimes, including:
  • Filing a fraudulent tax return using another person’s Social Security number
  • Claiming someone else’s children as dependents
  • Claiming a tax refund using a deceased taxpayer’s information
  • Earning wages under another person’s Social Security number
How does it work?
Crooks look for discarded tax returns, bank records, credit card receipts, Medicare cards and more, often relying on email or telephone phishing, dumpster diving or stealing from your mailbox. They use that info to file for a tax refund before you do. When you file your return later, IRS records will show the first filing and refund, and you’ll get a notice or letter from the IRS.

What can you to do protect yourself?
Reduce tax time stress. File as early in the season as possible, and mail tax returns directly from the post office. If filing electronically, use a secure network and encrypt.

Stay safe online. Do not respond to emails that appear to be from the IRS, and never click on links! The IRS does not send unsolicited, tax-account related emails and never asks for personal and financial information.

Protect your personal information. Never store important account numbers or data in purses or wallets, or on smartphones. Use a shredder for paper documents, and install a locking mailbox.

Monitor your accounts and review financial statements regularly. Sign up for your free annual credit report at www.annualcreditreport.com.

Think you’re a victim of tax ID theft?
Take these four steps right away:
  • File a report with the local police.
  • Contact your bank and credit card companies. Inform credit bureaus and consider freezing your accounts (a credit freeze restricts access to credit reports, making it unlikely that thieves can open new accounts in your name).
  • Contact the IRS Identity Protection Specialized Unit at 800-908-4490 and complete Form 14039.
  • Get an IP (Identity Protection) PIN from the IRS so they can verify your identity as they work with you on the theft going forward.


Thursday, January 30, 2014

Fraudsters Target Those Signing Up for Health Insurance

Open enrollment has begun for Obamacare as well as for health insurance plans offered by many employers. And that means its prime time for fraudsters to target consumers with phishing scams, disguised as official-looking open enrollment messages, in an attempt to steal personal information.

Privacy and security experts stress the need to remind those participating in open enrollment about the dangers of phishing, including avoiding clicking on links in suspicious e-mails that bring individuals to fake websites designed to gather information.
The open enrollment scams typically involve e-mails that purport to be official communications about health insurance but link the user to a fake employee or government web portal designed to collect personal information that can be used to commit fraud. In some cases, simply clicking to open the e-mail or a link it contains can lead to an immediate malware infection, Kennedy says.

"People freak out when they receive e-mails about their health benefits or new regulations, and the possibility of losing [coverage] if they don't act," Kennedy says. That's why so many consumers fall for the ploys.


In addition to spear-phishing e-mails targeting employees at specific companies during open enrollment season, scammers are also targeting consumers who are interested in shopping for insurance on new state health insurance exchanges and seniors looking for supplemental Medicare plans.

Saturday, November 30, 2013

If you're not sure you've seen an incident - report it anyway

Most security folks (and IT folks, for that matter) would rather hear about a problem from you than to figure it out afterwards while troubleshooting a system failure. If a phone call from User Support doesn't sound quite right, if a common email announcement is just a little off, or if a caller on the phone is too stressed to remember his or her password — don't be pressured and don't be rushed. Rush and pressure are among the "social engineering" hacker's best tools. Ask for help! Call your supervisor, call your IT group, and call your InfoSec group on the spot for assistance. You are as responsible (or more) to the whole company as you are to the one person on the phone! Don't let one person's stress jeopardize the organization's information security.

Saturday, September 21, 2013

October is National Cyber Security Awareness Month

October is National Cyber Security Awareness Month and it is an opportunity to engage public and private sector stakeholders – especially the general public – to create a safe, secure, and resilient cyber environment. Everyone has to play a role in cybersecurity. Constantly evolving cyber threats require the engagement of the entire nation — from government and law enforcement to the private sector and most importantly, the public. Cyberspace is woven into the fabric of our daily lives and the world is more interconnected today than ever before. We enjoy the benefits and convenience that cyberspace provides as we shop from home online, bank using our smart phones, and interact with friends from around the world through social networks. This year marks the tenth anniversary of National Cyber Security Awareness Month sponsored by the Department of Homeland Security in cooperation with the National Cyber Security Alliance and the Multi-State Information Sharing and Analysis Center. Through a series of events and initiatives across the country, National Cyber Security Awareness Month engages public and private sector partners to raise awareness and educate Americans about cybersecurity, and increase the resiliency of the Nation and its cyber infrastructure.