Managed IT Services and Security


We are an IT Services and Support company based in Hatfield Hertfordshire. We believe that your staff should be spending their time working with your clients / customers, not spending hours on the telephone to your IT support company.

If you would like to know more, please send an email to TonyH@clearview.co.uk. I will then get back to you to arrange a date when we can meet up to explain how we can reduce the cost of your IT by using our experienced IT staff with the right automated tools to support your business.
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, 21 August 2013

Farewell Microsoft TMG! But What Do You Replace It With?


Microsoft have announced that they are no longer going to be supporting Microsoft Threat Management Gateway (TMG) from April 2015. So what should you do if you have been using Microsoft TMG as a firewall, proxy server or web filter?

In reality, TMG’s technology was starting to look a little “old hat” anyway. Filter lists can only ever know about a small percentage of the web sites on the internet, and it can be a hacked business site that can hurt you! 

 
Web security today needs be a little smarter to protect your networks:

Blocking Known Hacked Web Sites
If you end up with a Trojan or spyware on your PC, you have a 90+% chance that you got it from a malicious or hacked web site. These days, web security solutions refers to a constantly updated database of known hacked or malicious web sites to which access is blocked.

Control of Web Applications
Love them or hate them, web applications such as YouTube and Skype are here to stay. There is some great training / research material on YouTube, and Skype can be incredibly useful, but it gobbles up your internet connection if you aren’t careful. Today’s web protection products allow you to control the amount of your internet bandwidth that can be used by video and audio, so that you have at least some bandwidth reserved for home workers and email.

Facebook security
Facebook is probably an integral part of your marketing strategy, but it is also a great way to waste time playing games and a playground for malicious code that can infect your PC’s. You need a system that can allow you to update your company’s Facebook page but block downloads of malicious code and stop your users playing games. 

Different manufacturers approach web security in different ways. You can secure internet access on your employees’ PC’s, using a web proxy appliance, integrated into your firewall, or as a hosted web security service. 

If you are a UK company and need some help in deciding which approach is right for you, please do get in contact so that we can find out a little more about your IT installation and recommend some sensible options.

Sunday, 16 June 2013

How Would A Server Crash Effect Your Business?


Could your company carry on doing business if your server failed and you were unable to recover your data? If your answer is that “It’s not going to happen!” because you know that you have got that one covered, then great. If on the other hand you have just felt a chill run down your spine at the very thought of your server failing, then don’t put it off any longer. If your data is that important to you, then for heaven’s sake do something about it. 

Uninterruptible Power Supplies
If your server sits in your office, you should protect it using an Uninterruptible Power Supply (UPS). A UPS does 2 jobs. Its primary job is to provide you with time to shut your machines down properly in the event of loss of power. It does this by providing you with power from its batteries. Servers don’t like losing power unexpectedly. It can cause corruption on the hard drive and in extreme cases can make it impossible to read data from it. The second job that a UPS will do for you is to smooth out the power and protect you against temporary power surges which could damage your server as well as momentary loss of power which could cause the system to shut down unnecessarily.

When looking at a UPS, there are two things that you need to know:
  • The amount of power that you want to pass through it.
  • The amount of time that you need protection for. 

For most small businesses, you just need a few minutes as a grace period to allow you to shut your servers down safely. 

When you buy a UPS, don't forget that you will need to replace the batteries every couple of years. 

Online Backup
Most companies take some form of backup of their servers, but I am always surprised by the number of companies that still rely on tape and disk backup backup. It’s not that I dispute whether tape backups work or not. It’s rather that the only truly reliable solution for business continuity is to have offsite backup, and to automate that process rather than relying on the office manager remembering to insert the tape and take it home with them at night. The time when you will need that backup most is in the event that you are unlucky enough to suffer a fire or a flood, and the best way to ensure that you get access to your data after a fire is to use online backup. Admittedly, you need to have a high speed internet connection to use online backup reliably, but they are more widely available now. If you haven’t already made the investment in online backup, now is a good time to do so.

You can of course spend much more on business continuity than simply investing in online backup and provision of a decent UPS system, but this is sufficient for most small businesses. It’s a small price to pay for peace of mind that your business can recover as quickly as possible when bad things happen. 


Sunday, 9 June 2013

Why Good IT Security Is Important For Small Businesses.

Why do small businesses need to worry about IT security? We all understand why banks need to have good security … they’ve got our money, and if they get hacked they are probably out of business. What’s the worst that can happen if you don’t have good security as a small business?

The truth is that the damage caused to a small business by poor security may not be as catastrophic as a bank getting hacked, but the consequences of poor security are still painful .. and costly. 

The first thing you’ve got to realise is that security isn’t just about getting your web site hacked. In fact, a good proportion of what we do in managing IT support for our customers involves managing network security. 

How does IT Security impact small businesses?
The problem for small businesses is internet malware. Malware is “bad” software that is unintentionally downloaded from hacked web sites that seeks out bugs in software that is installed on your PC. Unless your PC is kept updated with the latest security updates, malware can use these bugs to upload malicious software which can turn your PC into a spam sender or steal your internet passwords. The first you are likely to know that you have malware on your PC is when things start to grind to a halt, and this is the point at which bad security starts to cost you money. 

Few things are more frustrating than a PC on a go-slow because of a malware infection. It gets in the way of doing your work and causes frustration. You can try running applications such as Malwarebytes to lean it up, but you then lose your PC for the best part of a day while it runs a full scan of your system. Critically all of this is taking place when you want to be getting on dealing with your clients, costing you money with every minute that goes by … and you haven’t even called your IT support company yet!

How to keep internet malware at bay.
The answer is to make sure that your PC’s and servers are kept updated and maintained on a regular basis. If you’re a small business without a dedicated IT Manager that can be a tall order. In reality you are better off outsourcing to a managed service provide who will use automation software to run manage and update your systems remotely. Using automation cuts the cost of keeping your PC’s properly updated and in good working order. More importantly, it’s not your problem!

So don’t discount security just because you’re a small business. It’s just as important to you as it is to bigger businesses. You just see the benefits a different way. For you, IT security translates into reliability of your PC’s and servers.

Saturday, 27 April 2013

Web Security – How Do You Know If A Site Is Safe?

The Internet can be a dangerous place! We all love to scour the Internet for a bargain, but beware the bad stuff out there that can steal your credit card details, Paypal login, or turn your PC into a “zombie” that can be used by spammers and password thieves. Web sites that have been hacked and are being used to disseminate malicious software don’t advertise the fact .. in fact the web site owner probably won’t even know about it.

How Big A problem Is Web Security?
If you visit a compromised web site and your PC is missing the latest updates, you stand a good chance of ending up with software on your PC that you didn’t ask for. The problem is that it isn’t going to introduce itself and shake your hand! A bit like the neighbour you didn’t invite to your barbecue, it came along uninvited and it’s going to make a nuisance of itself.

How Do I Know If My PC Is Infected?
You are unlikely to recognise that your PC has been infected straight away. Internet malware can sit there silently waiting for you to connect to your online bank account so that it can steal your login details or send out so much traffic that it clogs up your entire network as we saw with one of our customers recently. Eventually though your PC will become unusable as more malware gets downloaded at which point you need to call your IT support company.

Which Are The Most Dangerous Web Sites
It's not just “Sex and Drugs and Rock and Roll”  web sites that are potentially dangerous. According to a Symantec study in 2012, 61% of malicious web sites are regular web sites that have been compromised and infected with malicious code.

The Top 5 Most Exploited Web Site Categories - % Of Total Number Of Infected Websites

1.       Blogs / Web Communications - 19.8%
2.       Hosting / Personal Hosted Sites – 15.6%
3.       Business / Economy – 10%
4.       Shopping – 7.7%
5.       Education / Reference – 6.9%

Whilst these figures are based on 2011 data, the percentages won’t have changed much, and new around 9,500 malicious web sites are being found by Google every day.


How To Protect Your Computers Against Internet Malware
Home users need to make sure that their security is kept up-to-date. Make sure that you enable automatic updates for Windows Updates and keep applications such as Java and Adobe Acrobat updated as well. Malware exploits bugs in software that is installed on your PC to upload malicious code to your system, and regular updates are your best defence. There is no  need to shell out large amounts of money for security software though. Microsoft Security Essentials is free and good enough for home use. 

If you are a business, the same principles apply, but you need to take your IT security a little more seriously:
  • Make sure that all Windows / Java / Adobe updates are applied to your computers on a weekly basis.
  • Make sure you run commercial security software.
  • Monitor your PC’s for tell-tale signs of trouble.
  • Use web security software to block access to known infected sites as well as pornographic / illegal / non-business material
A little common sense also goes a long way. If you are asked to click on a link in an email, or a Facebook / Twitter post, engage brain before clicking. Is the person that it came from likely to have sent you a link to ”Some hilarious pics of you”? If in doubt, don’t click! 

Saturday, 6 April 2013

Protecting Your Online Privacy Part 2


Welcome to part two of my personal battle against pesky password thieves. Don't be the one that becomes their next victim! Last week I explained briefly the danger of password hacking of web sites such as Amazon and Paypal. Nobody wants to have to remember multiple passwords, so they reuse their Paypal and Amazon passwords for other web sites such as Twitter and Facebook. The problem is that if your password for one web site is stolen, you could be the next victim of online fraud.

Remember The Golden Rule .. Don’t Re-Use Passwords!!
It is a real pain to have to use a different password for each of your online logins, but once you have been bitten, you realise that it’s worth it. My heart stopped when I saw that someone had transferred £680 out of my Paypal account, so it’s not going to happen again in a hurry. Realistically, you need to keep a spreadsheet of your passwords for your online logins. Not only that, but you need to make them good passwords including upper and lower case letters as well as special characters. 

My Password System
I worked out a system that I am happy to share with you because it works for me. You can adapt it and make it more complex. It all depends on how obsessive you want to be about it!

My recipe for password security has three simple ingredients:
  • A number of 4 or 5 word phrases
  • Some special characters that you alter for each login
  • A string of character that you are going to remember. Make it the first part of your partner’s vehicle registration plate or something equally memorable.

You then create a system using a spreadsheet and a little imagination. Here’s one I cooked up earlier based on the first letters of the words in Beatles songs:


Needless to say you don’t have to use Beatles songs. You could use book titles, proverbs, recipes or just about anything else the will give you a number of phrases of 4-5 words. Just devise your own system, work out where you are going to put your special characters, which letters will be upper case and which will be lower case and generate as many passwords as you need. If you want to be really fastidious you may want to use an application such as 7-Zip to store the spreadsheet in a password protected zip file. Just make sure that you can remember that password … and make it a good one!

Sunday, 31 March 2013

How To Protect Your Online Privacy

If you have read my blog recently, you will know that I had my PayPal account hacked a couple of weeks ago. It’s pretty embarrassing for me to get caught out since I have been involved in IT Security for over 10 years, but it shows that if it can happen to me, it can also happen to most of you who are reading my blog. So here are some helpful tips to ensure that you aren't the next one to end up with egg on your face and a hacker in your PayPal account.

The Online Golden Rule That I Broke!
I’m pretty convinced that my password was compromised because I made the schoolboy error of using the same password for PayPal as I had used for another Internet site. That site was probably hacked specifically to get hold of the web site's password file so that the hacker could try the email addresses and passwords on shopping sites such as Amazon and PayPal. When they tried my email address and password in PayPal, they would have thought that they had struck lucky. Fortunately for me, I saw the email payment confirmation from PayPal on my iPad, so I reported the incident to PayPal and changed the password within 20 minutes. Credit goes to PayPal who acted to return my £680 within 48 hours.

How Easily Can Hackers Get Your Passwords?
It is distressingly easy for Internet criminals to get hold of your PayPal / Amazon passwords. All they need to do is get hold of your password for another Internet site and then simply try it on Amazon, PayPal, or any number of other Internet shopping sites. If you are a Twitter user, have you ever seen any emails like this one?


If you have, and you clicked on the link, you probably also gave the bad guys your Twitter password, and if you use your Twitter password for PayPal, Amazon etc. please stop reading this blog post and go and change those passwords now!

The Golden Rule … DON’T RE-USE PASSWORDS!!
You may be careful not to click on “dodgy” links, but that won’t stop the bad guys from hacking one of the web sites that you belong to and getting your password, and don’t think that adding a “!” or a “£” to the start and end of your pet stick insect’s name is sufficient protection either. Password cracking software is pretty sophisticated now and will probably crack it in a few seconds (unless your stick insect is called Sy900$r5%)!

So How Can You Stay Secure Online?
The simple answer is that you need a system to provide you with strong, unique passwords for your online web site logins, and next week I will be happy to share mine with you. Don’t forget to come back next week!

Saturday, 16 March 2013

Dude - A virus ate my customer's internet connection!

Did you think that viruses were a thing of the past that you don't have to worry about any more? Well here is a story from one of our customers that shows that the Internet really can be a dangerous place even for the most security conscious companies. Understandably, businesses focus on making money rather than IT security. The problem is that when you get a malware infection (which many of you will understand better as viruses), you may not know about it, but that doesn’t mean that they can’t cause problems for your company.

Recently, one of our largest customers was having problems with a web security system that they had bought about a year ago. They have around 2,000 IT users and a sizable internet connection, but something was bringing their system to a grinding halt, and quite a lot of the web connections had very little to do with their line of business!

Since they have a support contract with us we held our hands up to do some investigation as to what was causing the problem, and it soon became obvious that 75% of their network traffic was coming from a single PC which had obviously been infected with malware and was generating huge amounts of network traffic which was clogging up their Internet connection.

The graphs below show you what happened as soon as the infected PC was removed from the network. It’s amazing what one infected PC can do!:

Web connections per hour dropped from 20,000 to 5000.


Blocked connections per hour dropped from 14,000 to 0.



Connections per hour to “malicious” sites dropped from 20,000 to 0.


We will never know how the malware ended up on our client’s PC. They were probably just unlucky and visited a hacked web site that took advantage of a missing security update to infect the PC. What it does demonstrate though is the importance of making sure that your PC’s are kept updated to minimise the likelihood of picking up a malware infection. 

Just imagine the devastating effect that a similar incident could have on your company if you rely on cloud services for your line of business applications. It just goes to show that as you grow more and more reliant on the Internet to run our businesses, you will need to make sure that your security is up to scratch. 

Sunday, 10 March 2013

Had Your Paypal Account Hacked? Join The Club!

Last Thursday night I was sitting at home watching the TV when my iPad on the arm of the chair went “Bing”! The email notification said something about a Paypal transaction which (being a cautious sort of chap) I thought was worth checking. I'm used to seeing phishing emails, and Google Apps has a very good spam filter,  so this particular email was worth a second look.

When I opened the email a shiver ran down my spine. It was a notification from Paypal that £689 had been paid from my Paypal account to someone whose email address meant nothing to me. What was worse, this email looked genuine. I immediately fired up my laptop, logged on to Paypal and there it was staring me in the face. £680 had been paid out of my account using the card that I had hooked up to it.




The crafty beggars had timed the transaction to go through just after 10 pm when the Paypal phonelines closed, so I reported the unauthorised transaction through the Resolution Centre. Paypal sent through an email to confirm that my dispute had been registered and I sat back and crossed my fingers.

To their credit, within 2 days I received confirmation from Paypal that my £689 would be credited back, so with a big sigh of relief I was able to think of the lessons I had learnt from the experience.


How was my account hacked?
I’ll never know for sure, but the only two possibilities that make any sense are that:
  • I had a password stealing trojan on my PC or
  • Another site where I used the same password had been hacked and they tried out all of the usernames and passwords on Paypal.
If you ever have the misfortune of suffering a Paypal hack, you will need to cover both of these options. The only way to make sure that any trojan on your PC is no longer there is to back up your data and re-load your PC from the Windows CD. Is there anyone reading this who doesn’t have the Windows CD for their PC? If so, please go back to wherever you got the PC from and find out how you get one. It’s your ultimate “Get out of jail” card.

You then absolutely must change all of your critical passwords (eBay, Paypal, Amazon etc). It may be a pain, but if you have already been hacked, you have no choice. Paypal force you to change your password as part of their “disputed transaction” process anyway.

One of our engineers quite rightly gave me a hard time about my passwords, and I spent an amount of time this weekend working out a new system. Your Amazon / Paypal etc passwords really should be unique, and you need to avoid standard words and phrases that can be cracked pretty easily anyway. Use something such as the first letters in song lyrics that you can remember together with special characters. Having been stung once, I damned if I’m going to give anyone another chance of nicking my hard earned cash and neither should you. You can see the system that I have now chosen to use here. I hope it helps.

Tuesday, 1 January 2013

How To Cut The Cost Of Running Your IT

Have you ever wondered why you still get viruses / malware on your company’s PC’s even though you have purchased security software from a reputable vendor? It’s a good question and one that you need to understand if you want to minimise the operational cost of running your business. After all, every time you need to call an engineer it costs you money, and not just in terms of cheques that you write to your IT support company. In addition, there is the cost of lost employee productivity caused by degraded performance as your system becomes unusable, as well as the time lost while your employee waits for their system to be rebuilt. So what should you do to ensure that you don't waste money on engineer call-outs and lost productivity?

IT Security Is A Process

You have to recognise that IT Security doesn’t just involve installing software. You have to make sure that you perform necessary housekeeping on a regular basis. Specifically, it is essential to keep your systems updated with the latest updates and patches for Microsoft Windows and common applications such as Adobe and Java to protect you against the latest security issues that are discovered.

The reason that regular maintenance is so critical is that newly discovered software bugs (also known as vulnerabilities) are used by hackers and fraudsters to plant malicious software on your PC’s. These are the cracks in your defences that allow your security to be breached even with security software installed.

It is likely if not inevitable that you will suffer malware infections at some point if you allow your employees to access the internet. Hackers and security companies are locked in a constant battle that is played out on your IT systems on a daily basis. When a new bug is found, hackers move quickly to write and distribute code that allows them to exploit it before the security companies react with countermeasures to identify and foil their attempts. Each time a new bug is found, a number of PC’s are infected before the new updates are installed.

To give you some idea of the scale of the problem, in 2012, Secunia (the industry reference point on IT security) issued 124 “Security Advisories” for Windows 7 covering 237 vulnerabilities, of which 5% remain unresolved at the time of writing this article. Internet Explorer 9 was the subject of 14 security advisories covering 70 vulnerabilities of which 7% are not yet resolved. These are just two of the most common items of software installed on your PC’s, yet we are already talking about a new security threat being discovered almost every day.

How To Keep Your Systems Up-To-Date

Your PC’s should prompt you to update Microsoft Windows, as well as applications such as Adobe and Java on a regular basis. If you ever see a message that an update has failed to install, you need to do something about it. The reason that the update has failed is very often that you have unwittingly downloaded some malware from a “hacked” or malicious website. If this is the case, malware can be silently gathering your login credentials and feeding them back to a hacker without you realising it. Very often your PC will start to run more slowly as the malware starts to take up resources. To make things worse, once malware finds a victim it will often send out for its friends, which themselves take up more resources until your PC becomes unusable and needs to be rebuilt.


Do It Yourself Or Call In The Experts?
It is understandable that many small business owners still take a reactive approach to IT security. Taking time to make sure that the latest Windows updates and patches have been successfully applied, or making sure that antivirus software on your workstations hasn’t been disabled by malware takes time and takes you away from running your business. The problem is that unless you do spend time making these checks, you are far more likely to suffer a malware attack.

If you are happy to maintain your own systems, you can buy PC Audit software which will identify systems that aren’t updating properly, or that show other signs that they have been infected by malware. Otherwise, you may be better off outsourcing the process of regular auditing and updating your IT systems to a Managed IT Service Provider who will be able to use automation software to manage the process more efficiently and cost effectively than you are able to do yourself. They will also be able to undertake a number of other essential housekeeping tasks at the same time such as clearing out temporary files and making sure that PC Hard disks are defragmented on a regular basis, which will also boost your system performance.

If you would like to know more about the IT Support or Managed IT Services that we provide, please download our Managed IT Services White Paper, visit our web site, or contact us by telephone on 01707 255060 or via email at info@clearview.co.uk

Thursday, 15 November 2012

Data Protection Law For Business Owners

Data Protection is a serious issue. In the UK, the Information Commissioner can fine organisations up to £500,000 for repeated breaches of data security caused through broken business practices. Yet data security guidelines are far from prescriptive about what should be done to provide adequate protection for your organisation's confidential data, so what should small business owners do to ensure that they stay on the right side of data protection legislation and protect their own interests?

The UK Data Protection Act
If you hold personal information about individuals, you have a number of legal obligations to protect that data under the Data Protection Act of 1998. For full information on the 1998 Data Protection act, you should visit the web site of the Information commissioner http://www.ico.gov.uk, but the eight principles for data protection can be summarised as follows:


  • You must have legitimate grounds for collecting the data.
  • You must only process the data in a way that is in the person’s best interests.
  • Tell people what you will do with their data when you collect it.
  • Only process the data in a way that the person would expect.
  • Don’t process the data illegally.
  • Only collect the information that is necessary.
  • Make sure that the information is accurate and kept up to date.
  • Don’t keep the information for any longer than you need to.
  • Take appropriate technical and commercial measures to protect the information.
  • Do not transfer personal information outside the EEC unless it is to a country that ensures that sufficient protection is undertaken to ensure the rights and freedoms of the person concerned
It’s Not Just About Credit Card Numbers
Whilst protection of personal data is of paramount importance, it is not the only consideration. Your should always consider the “Three R’s” when considering data security, backup and Business Continuity Planning.


  • Riches - What is the data that will make you rich? The most valuable information for many small businesses is their intellectual property. How should you protect your company’s “crown jewels” against a data breach or “catastrophic” IT failure.
  • Ruin - What is the information that could cost you your business? If you are a law firm and expose data relevant to an ongoing court case by dropping a USB device on public transport, the loss of reputation could cost your firm dearly. The same principle applies to numerous other professions and professional services organisation where the cost of implementing appropriate data security measures is a tiny fraction of the cost of a breach to your business.
  • Regulation - What information are you obliged to protect by industry regulation (such as credit card information), and what measures are stipulated for its protection.
For many large organisations, the biggest problem that they have is finding out where all of their valuable data is. For small companies however, there is a greater imperative to ensure that staff are made aware of their duties with respect to confidential information including what they can and can’t do. Technical measures should also be taken to protect confidential information by restricting access to your network, and ensuring that appropriate measures are put in place for data backup and encryption where necessary.

Data Security Best Practices
There is no “magic bullet” when it comes to protecting your company’s data since no two companies are exactly alike. From an IT perspective however, the most important considerations are to:
  • Recognise which information is important to you, and find out where it is.
  • Ensure that your important data is backed up properly, and these days that probably means using some form of off-site backup
  • Protect confidential data on laptops using whole disk encryption software, and on USD / CD etc using file encryption. If a USB drive / laptop is lost or stolen, it is difficult to prove that no personal data has been exposed unless it has been encrypted, so why run the risk? Data Leakage Prevention (DLP) software can also be used to monitor and optionally prevent confidential information being sent outside the organisation using unmanaged communication channels such as Webmail or Dropbox.
The ultimate responsibility still lies with you to educate your employees to handle your company data responsibly so that you can eliminate the unintentional human errors that are the cause of the majority of data security incidents.


If you would like to know more about data backup, data encryption and IT security products and services available from Clearview Data Systems, or about our IT support services, please visit our web site, call us on 01707 255060, or email us at info@clearview.co.uk.