<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyber Security | Computer Systems, Inc.</title>
	<atom:link href="https://csiomaha.com/category/cyber-security/feed/" rel="self" type="application/rss+xml" />
	<link>https://csiomaha.com</link>
	<description>For all your IT needs</description>
	<lastBuildDate>Fri, 02 May 2025 14:35:11 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://csiomaha.com/wp-content/uploads/2019/02/cropped-CS-LOGO-32x32.png</url>
	<title>Cyber Security | Computer Systems, Inc.</title>
	<link>https://csiomaha.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Password Autofill Has its Dangers</title>
		<link>https://csiomaha.com/password-autofill-has-its-dangers/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=password-autofill-has-its-dangers</link>
		
		<dc:creator><![CDATA[Alisa]]></dc:creator>
		<pubDate>Wed, 03 Aug 2022 08:54:13 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<guid isPermaLink="false">https://csiomaha.com/?p=2357</guid>

					<description><![CDATA[Modern web browsers and password managers come with a feature called password autofill. This feature allows users to store and automatically use their account credentials to access websites and other applications. While this seems to make users’ online world easier, there is a way for hackers to track your activities, through the autofill function.  This [&#8230;]]]></description>
										<content:encoded><![CDATA[<p><span data-contrast="auto">Modern web browsers and password managers come with a feature called password autofill. This feature allows users to store and automatically use their account credentials to access websites and other applications. While this seems to make users’ online world easier, there is a way for hackers to track your activities, through the autofill function.  This loophole can give hackers and advertisers access to user accounts and gather sensitive information without the user’s consent.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span><b><span data-contrast="auto">How Does a Password Manager Work?</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">A password manager requires one master password to manage all your accounts. The password unlocks your “Vault” to ensure your data is safe. Thus, you don’t have to keep a tab on many passwords. But, you can also take further security measures like two-step verifications and logging in your data on secure computers.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">Password managers offer both convenience and a high level of security. You use secured and unique passwords across all devices and manage these passwords. But, how do you trust a password manager to handle such sensitive information?</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">The best password manage does “manual autofill”; where the password manager waits for the user to interact with the page.  It allows the user to select from a list of passwords.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><b><span data-contrast="auto">Why password autofill is so dangerous</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">This feature isn’t completely safe. If you enable this feature and hackers gain access to your computer or web browser, it will be easier for them to infiltrate your accounts because the autocomplete feature will fill in all saved credentials.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">Tricking a browser or password manager into providing saved information is incredibly simple. All a threat actor needs to do is place an invisible form on a compromised webpage to collect users’ login information. Once the browser or password manager enters the user’s information, the hacker will gain access to that data.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><b><span data-contrast="auto">Using autofill to track users</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">Shrewd digital marketers can also use password autofill to track user activity. For instance, they can track people based on the usernames in hidden autofill forms they place on websites and sell the information they gather to advertisers. While they don’t intend to steal passwords, there’s always the likelihood of exposure.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">One simple security tip</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">A quick and effective way to improve your account security is to turn off autofill. Here’s how to do it:</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><b><span data-contrast="auto">On Microsoft Edge</span></b><span data-contrast="auto"> – Open the Settings window, click Profiles, and then select Passwords. Disable “Offer to save passwords.”</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><b><span data-contrast="auto">On Google Chrome</span></b><span data-contrast="auto"> – Open the Settings window, click Autofill, and disable “Offer to save passwords.”</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><b><span data-contrast="auto">On Firefox</span></b><span data-contrast="auto"> – Open the Settings window, then click Privacy &amp; Security. Under the Logins and Passwords heading, untick the box next to “Autofill logins and passwords.”</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><b><span data-contrast="auto">On Safari</span></b><span data-contrast="auto"> – Open the Preferences window, select the Auto-fill tab, and turn off all the features related to usernames and passwords.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">The easiest way to protect yourself is to disable autofill in any browser you use. If you use a password management service – which we highly recommend – then they will instruct you on how to disable the browser autofill. It&#8217;s important to complete this step, because password management services will help you to address this serious security flaw by first verifying the authenticity of the website that you are trying to log in to, and then require your input to fill in the credentials before safely logging in.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">Having good password security habits can significantly protect your sensitive data. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">For more information on password manager tools or any other cyber security concern, reach out to us.  402.330.3600 or </span><span data-contrast="none">feedback@csiomaha.com</span><span data-contrast="auto">.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><i><span data-contrast="auto">Some content provided from TechAdvisory.org. </span></i><a href="http://www.techadvisory.org/2022/01/why-password-autofill-is-risky/" target="_blank" rel="noopener"><i><span data-contrast="none">Source.</span></i></a><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Top Cyber Security Terms to Know That Could Protect Your Business</title>
		<link>https://csiomaha.com/cyber-security-keywords/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cyber-security-keywords</link>
		
		<dc:creator><![CDATA[Alisa]]></dc:creator>
		<pubDate>Fri, 22 Jul 2022 18:11:58 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<guid isPermaLink="false">https://csiomaha.com/?p=2354</guid>

					<description><![CDATA[Scary stories of cyberattacks against large corporations, small businesses and individuals regularly appear in our daily news cycle. Even if you don&#8217;t know a whole lot about computers and the internet, chances are you&#8217;ve heard a lot of cyber security terminology and jargon. While some of these terms and acronyms may seem intimidating at first, they&#8217;re [&#8230;]]]></description>
										<content:encoded><![CDATA[<p><span data-contrast="auto">Scary stories of cyberattacks against large corporations, small businesses and individuals regularly appear in our daily news cycle. Even if you don&#8217;t know a whole lot about computers and the internet, chances are you&#8217;ve heard a lot of cyber security terminology and jargon. While some of these terms and acronyms may seem intimidating at first, they&#8217;re easy to understand with a little help.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">Here&#8217;s a cyber security keywords list to help you out if you&#8217;re just getting started with cyber security:</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="auto">Cyber-attack: </span></b><span data-contrast="auto">A cyber-attack is any attack carried out by an individual or organization against the computer and information systems of another individual or organization. Common examples of cyber-attacks include computer viruses and email spoofing.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><b><span data-contrast="auto">Malware: </span></b><span data-contrast="auto">A broad term referring to malicious software that, once installed on your device, could enable hackers to gain access to it. Once that happens, cybercriminals may be able to control your device, steal your identity and commit fraud.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="auto">Spyware</span></b><span data-contrast="auto">: Spyware allows cybercriminals to track and record all your online activities, as well as capture sensitive information, such as passwords. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><b><span data-contrast="auto">DDoS:</span></b><span data-contrast="auto"> A distributed denial-of-service (DDoS) attack is a malicious attempt to disrupt the normal traffic of a targeted server, service or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"><b><span data-contrast="auto">Vulnerability: </span></b><span data-contrast="auto">Vulnerabilities are potential weaknesses in your company&#8217;s cyber security, which could be a superuser or admin account, third-party software, and more.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="auto">Exploit:</span></b><span data-contrast="auto"> An exploit is a term in cybersecurity meaning a code to reap the benefits of a software weakness or flaw in the security of any application or system. Cybercriminals use exploits to remotely access a network and deeper into the network. It is known as a piece of software or a sequence of commands that cause unintended behavior. There is a zero-day exploit as an advanced cyberattack defined. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><b><span data-contrast="auto">Ransomware: </span></b><span data-contrast="auto">Ransomware is a type of attack where information or services are held for ransom by the attackers. Once the victim of the attack has paid the ransom, they can continue using their computer or gain access to their accounts again.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"><a href="https://www.morganstanley.com/what-we-do/wealth-management/online-security/social-engineering" target="_blank" rel="noopener"><b><span data-contrast="auto">Social Engineering</span></b></a><b><span data-contrast="auto">: </span></b><span data-contrast="auto">This is a deceptive tactic that uses social interactions—and often psychological manipulation—to obtain your personal information or gain access to your accounts. The fraudster behind a social engineering scam may pretend to be a representative of a legitimate organization.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"><b><span data-contrast="auto">Email Phishing: </span></b><span data-contrast="auto">Email Phishing refers to the practice of masking your email with a fake email address. Using phishing, an attacker can send a malicious message via email that looks like it came from a legitimate email address.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="5" data-aria-level="1"><b><span data-contrast="auto">Spoofing:</span></b><span data-contrast="auto"> With a spoofed phone call, the incoming number on your caller ID may falsely display the number of a well-known company or government agency.  </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="auto">Zero Trust</span></b><span data-contrast="auto"> is a security framework requiring all users, whether in or outside the organization’s network, to be authenticated, authorized, and continuously validated for security configuration and posture before being granted or keeping access to applications and data. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><a href="https://www.morganstanley.com/what-we-do/wealth-management/online-security/evolution-of-authentication/" target="_blank" rel="noopener"><b><span data-contrast="auto">Multi-factor authentication (MFA</span></b></a><span data-contrast="auto">): Also known as two-factor authentication, MFA requires you to provide at least two credentials when accessing your account—making it more difficult for hackers to gain access.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"><b><span data-contrast="auto">Unified Threat Management:</span></b><span data-contrast="auto">  Unified threat management (UTM) describes an information security system that provides a single point of protection against threats, including viruses, worms, spyware and other malware, and network attacks. It combines security, performance, management and compliance capabilities into a single installation, making it easier for administrators to manage networks.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"><b><span data-contrast="auto">Endpoint Detection and Response:</span></b><span data-contrast="auto">  Is a form of technology that provides continuous monitoring and response to advanced cybersecurity threats against enterprise networks and systems. EDR provides enhanced visibility into your endpoints (employees’ computers or smartphones) and allows for faster response time to these threats.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="auto">Business Continuity and Disaster Recovery Plans:</span></b><span data-contrast="auto"> Business Continuity Plan is predetermine process and procedures on how to run the business following a disaster. Disaster Recovery provides the plan on how to respond to a catastrophic event, such as a natural disaster, fire, act of terror, active shooter or cybercrime.  Businesses need both.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><b><span data-contrast="auto">NIST: </span></b><span data-contrast="auto">The National Institute of Standards and Technology is a company that helps set standards to protect consumers and keep industries competitive.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559685&quot;:360,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ul>
<p><span data-contrast="auto">This cyber word list doesn&#8217;t cover everything, but you can find out more by checking out the </span><a href="https://csrc.nist.gov/glossary" target="_blank" rel="noopener"><span data-contrast="none">NIST</span></a><span data-contrast="auto"> glossary.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">You might not be a cyber security expert but knowing a few cyber security terms can help you be a better, more secure business owner. Knowledge plays an important role in the ongoing battle against cyberthreats. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Don&#8217;t Let MFA Fatigue Get You Compromised</title>
		<link>https://csiomaha.com/dont-let-mfa-fatigue-get-you-compromised/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=dont-let-mfa-fatigue-get-you-compromised</link>
		
		<dc:creator><![CDATA[Alisa]]></dc:creator>
		<pubDate>Tue, 21 Jun 2022 10:00:45 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<guid isPermaLink="false">https://csiomaha.com/?p=2211</guid>

					<description><![CDATA[As with most IT Managed Service Providers and network administrators, we recommend users to use multi-factor authentication (MFA) for all their important accounts (i.e., Office 365, VPN, bank accounts, and pretty much everything in between).   MFA is usually done in one of three ways and often times the user can pick which one they want.  [&#8230;]]]></description>
										<content:encoded><![CDATA[<p><span data-contrast="auto">As with most IT Managed Service Providers and network administrators, we recommend users to use multi-factor authentication (MFA) for all their important accounts (i.e., Office 365, VPN, bank accounts, and pretty much everything in between). </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">MFA is usually done in one of three ways and often times the user can pick which one they want.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559685&quot;:1080,&quot;335559737&quot;:1440,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<ol>
<li><strong>A PUSH notification – which means you have the MFA app installed on your phone and when you login to the application your phone automatically pops up the option to APPROVE or DENY the login request.</strong></li>
<li><strong>Revolving Token – which means you have the MFA application installed on your phone that creates a code called a revolving token.  The typical 6-digit code changes every minute of so in the app hence ‘revolving’.  When you login to an application with username and password, it asks you for the MFA token and you enter in that number from the phone app.</strong></li>
<li><strong>Text or Email you a code – when you login to the application it sends a random number code to your email or text and you enter that code during the login process.</strong></li>
</ol>
<p><span data-contrast="auto">If you are following that advice and using MFA, as you should be, you are likely getting </span><i><span data-contrast="auto">a little</span></i> <i><span data-contrast="auto">fatigued</span></i><span data-contrast="auto"> by the seemingly constant need to approve your sign-ins on your phone or entering MFA codes.  </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">The bad guys are counting on the fact that you are getting &#8220;MFA Fatigued&#8221;. If they do have your compromised credentials, they are hammering away with the hope that you accidentally approve one of their sign-ins through your MFA push notification. Want to learn more about multi-factor authentication, here is a good article for you to read </span><a href="https://vpnoverview.com/news/attackers-are-compromising-office-365-users-with-mfa-fatigue/" target="_blank" rel="noopener"><span data-contrast="none">click this link</span></a><span data-contrast="auto">.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">Here are 5 important things to remember about MFA notifications.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<ol>
<li data-leveltext="%1." data-font="Arial" data-listid="1" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">If you receive an MFA push notification on your phone, be sure that it came immediately in response to a login event that you know you created.  Don&#8217;t approve an MFA notification on your phone if it was </span><i><span data-contrast="auto">even a few minutes after your known login event</span></i><span data-contrast="auto">, because that could have been enough time for the bad guy to have received your phished credentials and be trying to use them on their end.</span></li>
<li data-leveltext="%1." data-font="Arial" data-listid="1" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Never approve an MFA notification just because your phone is blasting you with a bunch of them.  Don&#8217;t APPROVE just to make it go away and then later try to figure out why.</span></li>
<li data-leveltext="%1." data-font="Arial" data-listid="1" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1">Always contact your IT managed service provider or network administrator when you get MFA notifications that you do not believe you triggered yourself.  Because remember that if you get an MFA notification that you didn&#8217;t trigger then the bad guy already knows your username and password, so your credentials are compromised, and something needs to be done.</li>
<li data-leveltext="%1." data-font="Arial" data-listid="1" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1">Likely getting your password changed and monitoring for more malicious login attempts.</li>
<li data-leveltext="%1." data-font="Arial" data-listid="1" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Eliminating PUSH notifications and always requiring a revolving token to be entered for MFA is one way to reduce the risk of MFA fatigue.  But it is understandable that users often do really like the push notifications for ease of use and so that needs to be considered also for the applications you are protecting.  </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:252}"> </span></li>
</ol>
<p><span data-contrast="auto">In the meantime, keep diligent and don&#8217;t let your guard down.  We do not want </span><i><span data-contrast="auto">MFA fatigue</span></i><span data-contrast="auto"> to be the reason you get compromised.  </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Educating Employees Prevents Phishing</title>
		<link>https://csiomaha.com/educating-employees-prevents-phishing/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=educating-employees-prevents-phishing</link>
		
		<dc:creator><![CDATA[Alisa]]></dc:creator>
		<pubDate>Thu, 05 May 2022 16:13:23 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<guid isPermaLink="false">https://csiomaha.com/?p=2214</guid>

					<description><![CDATA[It can happen to anyone, at any company and at any time, a phishing scam. Even when utilizing all the advanced security protocols that we advise our clients to use, and still a phishing email gets through.    The employee receives an email appearing to come from their boss asking them to act &#8220;right away&#8221;.  Often [&#8230;]]]></description>
										<content:encoded><![CDATA[<p><span data-contrast="auto">It can happen to anyone, at any company and at any time, a phishing scam. Even when utilizing all the advanced security protocols that we advise our clients to use, and still a phishing email gets through.  </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">The employee receives an email appearing to come from their boss asking them to act &#8220;right away&#8221;.  Often the request is plausible so the employee needs to make a decision on taking action or questioning the action.  Will your employees pass this test?</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">Sure, the firewalls, antivirus and encryption software can provide protection but your biggest asset for preventing a phishing scam threat is your employees. At the end of the day, your employees are your greatest defense against intruders — or your greatest weakness.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">According to 2022 data from the </span><a href="https://static.poder360.com.br/2022/01/pfpt-us-tr-the-cost-of-insider-threats-ponemon-report.pdf" target="_blank" rel="noopener"><span data-contrast="none">Ponemon Institute</span></a><span data-contrast="auto">, employee negligence causes about 56% of security incidents, and each incident costs companies an average of $484,933. Your unsuspecting, friendly, and helpful employees are like sitting ducks in the cross hairs of a high-powered hunting rifle. They are perhaps the weakest point of attack and will almost certainly be taken advantage of… unless they are trained to be vigilant and alert.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">Having a comprehensive security awareness training program that each employee must participate is a grand goal. Getting the employees to internalize and live by what they learned is the challenge. Here are three ways to turn your employees from your greatest weakness to your biggest asset.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><b><span data-contrast="auto">Develop A Culture of Security.</span></b><span data-contrast="auto"> Cultures are defined and lived from the top down. Leadership and Management teams must commit to these cybersecurity policies, procedures, and processes. They must communicate the importance of good cybersecurity protocol. Employees should understand why it is critical that they be good cybersecurity stewards. Management should proactively police to make sure everyone is following protocol and often communicate the importance.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><b><span data-contrast="auto">Educate And Train.</span></b><span data-contrast="auto"> Create and implement a Security Awareness Training program that is mandatory, meaningful, and relevant. Teach your employees about common threats and dangers such as Social Engineering attacks. Make the training simple to understand and engaging by telling stories your employees can relate to. Show them how to use software and computers in a secure fashion. Explain what the correct processes and procedures are. Provide them with the critical training they need to effectively fight cybercrime.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><b><span data-contrast="auto">Evaluate The Effectiveness.</span></b><span data-contrast="auto"> There are only two ways to find out. One, wait for a real attack to occur and hope for the best – or – two, launch a simulated attack yourself. Controlled Phishing attacks, penetration tests, tabletop incident response exercises or even a Monday morning pop quiz can all be effective exercises to evaluate your employees’ level of understanding and compliance. Use the test results as an opportunity to re-engage with employees or even re-tool training efforts. Everyone will get better with practice. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">By putting a strong cybersecurity policy in place, you can be assured that your weakest link will become your strongest asset.  At CSI we offer </span><a href="https://csiomaha.com/it-solutions-computer-systems/email-solutions/"><span data-contrast="none">robust email filtering and encryption tools</span></a> <span data-contrast="auto">as well as security awareness training and phish testing to help you and your team build a defense against phishing scams.  Reach out to us and we can tell you more. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Why Vulnerability Assessments Are Important</title>
		<link>https://csiomaha.com/why-vulnerability-assessments-are-important/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=why-vulnerability-assessments-are-important</link>
		
		<dc:creator><![CDATA[Alisa]]></dc:creator>
		<pubDate>Wed, 30 Mar 2022 14:55:56 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<guid isPermaLink="false">https://csiomaha.com/?p=2193</guid>

					<description><![CDATA[Protecting your IT infrastructure and business data against a potential breach is vital for your business. You can’t stop what you don’t know is coming but you can identify and evaluate the gravity of weaknesses in your company’s IT infrastructure.  How does a business do this?  On a regular basis, businesses should access their vulnerability [&#8230;]]]></description>
										<content:encoded><![CDATA[<p><span data-contrast="auto">Protecting your IT infrastructure and business data against a potential breach is vital for your business. You can’t stop what you don’t know is coming but you can identify and evaluate the gravity of weaknesses in your company’s IT infrastructure.  How does a business do this?</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">On a regular basis, businesses should access their vulnerability to being a victim of an attack.  This is known as a Vulnerability Assessment or Vulnerability testing.  Vulnerability Assessment is the practice of identifying, classifying, remediating, and mitigating vulnerabilities within an organization’s network. Once the vulnerabilities are discovered you can correct them and lower your risk of becoming a victim of a cybersecurity attack. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:257}"> </span></p>
<p><span data-contrast="auto">A vulnerability assessment will discover common security weaknesses such as:</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:257}"> </span></p>
<ul>
<li data-leveltext="-" data-font="Calibri" data-listid="4" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Operating systems and applications that are not current with the latest security updates or patches.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="-" data-font="Calibri" data-listid="4" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Unsecure legacy operating systems that are no longer supported by manufacturers. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ul>
<ul>
<li data-leveltext="-" data-font="Calibri" data-listid="4" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Open ports on perimeter defenses and other devices that allow malicious attackers to easily gain access to your private computer network. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="-" data-font="Calibri" data-listid="4" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">All Common Vulnerabilities and Exposures (CVE) that exist on the computer network.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ul>
<p><span data-contrast="auto">Common Vulnerabilities and Exposures (CVE) is a database of publicly disclosed information security issues. The mission of the CVE® Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. There is one CVE Record for each vulnerability in the catalog. Information technology and cybersecurity professionals use CVE Records to ensure they are discussing the same issue, and to coordinate their efforts to prioritize and address the vulnerabilities.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">It is important to conduct vulnerability assessments regularly, at least every quarter if not more frequently. Typically, a vulnerability assessment can be completed in a day or two. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:257}"> </span></p>
<p><span data-contrast="auto">There are benefits to performing regular vulnerability assessments that include: </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="6" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Identify known security exposures before attackers find them.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="6" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Create an inventory of all the devices on the network, including purpose and system information. This also includes vulnerabilities associated with a specific device.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="6" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Create an inventory of all devices in the enterprise to help with the planning of upgrades and future assessments.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="6" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Define the level of risk that exists on the network.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="6" aria-setsize="-1" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Establish a business risk/benefit curve and optimize security investments.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></li>
</ul>
<p><span class="TextRun SCXW227705755 BCX0" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW227705755 BCX0">The results of a vulnerability assessment are documented and provided to the business with recommendations around remediating any weaknesses found.</span> <span class="NormalTextRun SCXW227705755 BCX0">Your reports often need the interpretation and insight of a security veteran</span><span class="NormalTextRun SCXW227705755 BCX0">. </span><span class="NormalTextRun SCXW227705755 BCX0">Working with </span><span class="NormalTextRun SCXW227705755 BCX0">an</span><span class="NormalTextRun SCXW227705755 BCX0"> IT Managed Services Provide</span><span class="NormalTextRun SCXW227705755 BCX0">r</span><span class="NormalTextRun SCXW227705755 BCX0">, </span><span class="NormalTextRun SCXW227705755 BCX0">like us, </span><span class="NormalTextRun SCXW227705755 BCX0">who </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW227705755 BCX0">know</span><span class="NormalTextRun SCXW227705755 BCX0"> which </span><span class="NormalTextRun SCXW227705755 BCX0">fixes</span><span class="NormalTextRun SCXW227705755 BCX0"> will be most effective in bringing your </span><span class="NormalTextRun SCXW227705755 BCX0">business </span><span class="NormalTextRun SCXW227705755 BCX0">databases, servers and other IT assets back to good health</span><span class="NormalTextRun SCXW227705755 BCX0">.</span></span><span class="EOP SCXW227705755 BCX0" data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:257}"> </span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Insuring Cybersecurity Risk Grows in the Business World</title>
		<link>https://csiomaha.com/insuring-cybersecurity-risk-grows-in-the-business-world/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=insuring-cybersecurity-risk-grows-in-the-business-world</link>
		
		<dc:creator><![CDATA[Alisa]]></dc:creator>
		<pubDate>Mon, 14 Mar 2022 19:28:39 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<guid isPermaLink="false">https://csiomaha.com/?p=2184</guid>

					<description><![CDATA[Businesses are becoming more aware of the risk to its infrastructure with cyber attacks.  Like any other type of risk, insurance is available to mitigate the financial burden that could come from an attack.   Because the extent and variety of cybersecurity risk that businesses are trying to manage is overwhelming and resources to mitigate or [&#8230;]]]></description>
										<content:encoded><![CDATA[<p><span data-contrast="auto">Businesses are becoming more aware of the risk to its infrastructure with cyber attacks.  Like any other type of risk, insurance is available to mitigate the financial burden that could come from an attack. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">Because the extent and variety of cybersecurity risk that businesses are trying to manage is overwhelming and resources to mitigate or eliminate the risks are scarce, businesses are searching for a solution.  </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">Cybersecurity liability insurance cover expenses that a business would incur directly because of a cybersecurity attack or incident. Examples of these expenses include: </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Associated legal fees.</span></li>
<li data-leveltext="" data-font="Symbol" data-listid="1" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Digital forensic services.</span></li>
<li data-leveltext="" data-font="Symbol" data-listid="1" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Negotiation and payment of ransom to bad actors.</span></li>
<li data-leveltext="" data-font="Symbol" data-listid="1" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Incident response and recovery services.</span></li>
<li data-leveltext="" data-font="Symbol" data-listid="1" aria-setsize="-1" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Restoration of systems and applications.</span></li>
<li data-leveltext="" data-font="Symbol" data-listid="1" aria-setsize="-1" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Public relations services.</span></li>
<li data-leveltext="" data-font="Symbol" data-listid="1" aria-setsize="-1" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Breach notification and credit monitoring services.</span></li>
</ul>
<p><span data-contrast="auto">The cost of these policies has traditionally been very reasonable and benefit of transferring complex cybersecurity risk was very convenient.  As attacks increase and more businesses are realizing they could be vulnerable to an attack, the demand for coverage continues to increase. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">According to a special report published by FitchRatings in May of 2021 the cybersecurity insurance market grew by a whopping 22% in 2020. The same report indicated that the average paid loss for a cybersecurity claim grew to $359k in 2020 from $145k in 2019. Insurance carriers are excited about the growth of the industry but recognize that underwriting efforts need to be more stringent. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">Cybersecurity insurance will continue to be an available option for businesses looking to transfer risk, but insurance carriers are going to be much more stringent about their underwriting process. Here are some of the expected changes:</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">1. Expect a more comprehensive application process. Organizations will have to provide proof of specific controls such as:</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="2" aria-setsize="-1" data-aria-posinset="1" data-aria-level="2"><span data-contrast="auto">Written information security plans, incident response plans and disaster recovery plans</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="2" aria-setsize="-1" data-aria-posinset="2" data-aria-level="2"><span data-contrast="auto">Formal cybersecurity awareness training programs</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="2" aria-setsize="-1" data-aria-posinset="3" data-aria-level="2"><span data-contrast="auto">Strict access controls</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="2" aria-setsize="-1" data-aria-posinset="4" data-aria-level="2"><span data-contrast="auto">A sound data backup strategy</span></li>
<li data-leveltext="" data-font="Symbol" data-listid="2" aria-setsize="-1" data-aria-posinset="4" data-aria-level="2"><span data-contrast="auto">Adoption of Endpoint Detection &amp; Response (EDR) software</span></li>
<li data-leveltext="" data-font="Symbol" data-listid="2" aria-setsize="-1" data-aria-posinset="4" data-aria-level="2"><span data-contrast="auto">Current operating systems, firmware and applications all patched regularly.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ul>
<p><span data-contrast="auto">2. Expect underwriters to require proof of cybersecurity controls being implemented and functioning as intended.</span></p>
<p><span data-contrast="auto">3. Expect automatic declines if key underwriting requirements are not in place. Insurers will be careful to not issue coverage to organizations that have do not have the appropriate plans, controls, and processes in place to mitigate cybersecurity risk. </span></p>
<p>4. Expect premiums to increase, significantly.  The sharp increase of the average claim paid for cybersecurity insured has underwriters concerned about profitability. <span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">These changes being made to the underwriting process should encourage businesses to be more diligent about mitigating cybersecurity risk.  It is no longer good enough to purchase a policy, but businesses will need to allocate the proper resources (time, money, or human capital) required to build an effective cybersecurity program. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">Last fall we held a Cyber Security Awareness Webinar where we partnered with a national cyber security insurance company.  </span><a href="https://us02web.zoom.us/rec/play/I7YM0fqBuBjmfxtQI4pWZmcQ2J7zhi7syKWIK5mbr1Pj0YOYuyeU9JGUlyAlL76wmgR_esBHP1cNK_x_.a9zs8QNa05ItCYIk?startTime=1634749297000" target="_blank" rel="noopener"><span data-contrast="none">Click here to watch our webinar.</span></a><span data-contrast="auto">   If you want to find out if you are meeting the necessary protocol to get insurance, contact us.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cyber Attacks Find Vulnerable Businesses</title>
		<link>https://csiomaha.com/cyber-attacks-find-vulnerable-businesses/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cyber-attacks-find-vulnerable-businesses</link>
		
		<dc:creator><![CDATA[Alisa]]></dc:creator>
		<pubDate>Thu, 24 Feb 2022 20:36:23 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<guid isPermaLink="false">https://csiomaha.com/?p=2125</guid>

					<description><![CDATA[Cyber Attacks Find Vulnerable Businesses With world focused on the Russia-Ukraine situation, cyber criminals see this as an opportunity to wreak havoc on the international business world.  Business owners and executives should be preparing for such attacks.  Many executives believe that their company or industry is safe or not inclined to cyber-attacks.  They must realize [&#8230;]]]></description>
										<content:encoded><![CDATA[<h1><strong><span class="TextRun SCXW95989526 BCX0" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW95989526 BCX0" data-ccp-parastyle="Normal (Web)">Cyber Attacks Find Vulnerable Businesses</span></span><span class="EOP SCXW95989526 BCX0" data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}"><br />
</span></strong></h1>
<p><span data-contrast="auto">With world focused on the Russia-Ukraine situation, cyber criminals see this as an opportunity to wreak havoc on the international business world.  Business owners and executives should be preparing for such attacks.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">Many executives believe that their company or industry is safe or not inclined to cyber-attacks. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"><br />
</span><span data-contrast="auto">They must realize by now that the any organization can be a target of malicious hackers. Additionally, executives must recognize that successful cybersecurity attacks can have impact revenue, credibility with customers and even threaten business solvency</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><strong>There are two simple truths related to cybersecurity.<br />
</strong><span data-contrast="auto">1.The risk and exposure related to cyber threats is at an all-time high and it is only getting worse.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"><br />
</span><span data-contrast="auto">2.Most organizations are struggling to build and maintain effective cybersecurity programs.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">Even as awareness is heightened about cyber-attacks, business owners are still not taking action or keep putting off adding additional layers of security.  Cyber attackers know this and love those businesses that keep putting off protecting themselves.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span><span data-contrast="auto">It means that these cyber attackers will continue to seize upon technology environments that have minimal defenses and target organizations that are unprepared to respond to cyber-attacks. Hackers love procrastination because it enables them to be successful.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span><span data-contrast="auto">So why are so many Executives procrastinating? The most common reasons why humans delay the start or finish of any given task are:</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<ul>
<li><span data-contrast="auto">They lack the confidence or expertise to accomplish the job.</span></li>
<li><span data-contrast="auto">They have a bias against the task itself.</span></li>
<li><span data-contrast="auto">They have a fear of failure </span></li>
</ul>
<p><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span><span data-contrast="auto">Let us share with you ways to overcome this lack of action and develop an effective cyber security program for your company.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<ul>
<li><strong>Face the inevitable</strong><span data-contrast="auto"> &#8211; Addressing cybersecurity concerns can be hard, annoying, unattractive, or downright overwhelming. But you must appreciate the fact that it needs to get done. Learn more about why businesses need to invest in multiple layers of <a href="https://www.cyberstonesecurity.com/news/cybersecurity-services/how-to-help-your-customers-see-the-value-of-cybersecurity/" target="_blank" rel="noopener noreferrer" data-auth="NotApplicable" data-linkindex="0">IT security</a>.  </span></li>
<li><b><span data-contrast="auto">Don’t worry</span></b><span data-contrast="auto"> &#8211; Do not worry about creating the perfect cybersecurity program, it will evolve and improve over time. The most important thing is to get started.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></li>
<li><b><span data-contrast="auto">Contact us &#8211;</span></b><span data-contrast="auto"> Call or email us immediately and schedule a complimentary consultation session with our team. We can evaluate your current systems and provide <a href="https://csiomaha.com/managed-it-support/">recommendations</a> based on our understanding all the nuances of cybersecurity.</span></li>
</ul>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>365 Multi-Factor Authentication</title>
		<link>https://csiomaha.com/365-multi-factor-authentication/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=365-multi-factor-authentication</link>
		
		<dc:creator><![CDATA[Alisa]]></dc:creator>
		<pubDate>Tue, 06 Apr 2021 22:14:41 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<guid isPermaLink="false">https://csiomaha.com/?p=1609</guid>

					<description><![CDATA[If you read anything from us, READ THIS!!! People are having their Microsoft 365 accounts compromised at an alarming rate. It usually happens when you get an email from someone you know and trust. You click on the link they ask you to download, which eventually takes you to a webpage requesting for your Microsoft 365 credentials. [&#8230;]]]></description>
										<content:encoded><![CDATA[<p><img fetchpriority="high" decoding="async" class="alignnone wp-image-1620" src="https://csiomaha.com/wp-content/uploads/2021/04/virus_protection-1024x569.jpg" alt="" width="700" height="389" /></p>
<p><span data-contrast="none"><strong>If you read anything from us, READ THIS!!!</strong> People are having their Microsoft 365 accounts compromised at an alarming rate. It usually happens when you get an email from someone you know and trust. You click on the link they ask you to download, which eventually takes you to a webpage requesting for your Microsoft 365 credentials. The webpage looks just like the 365 login page but IT IS NOT. This would be a hacker’s web page, and if you just entered your 365 credentials, now they have your login info and everything in your email account is considered compromised.</span></p>
<p><span data-contrast="none">These hackers usually then send out email from your account to people you know trying to accomplish the same thing. This attack is extremely difficult to prevent because these bad guys are using very legitimate websites to host their fake 365 login pages and the URLs are very dynamic, keeping them from easily being blocked by URL/Web security systems.</span></p>
<p><b><span data-contrast="none">What can you do to stop this?</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<ol>
<li data-leveltext="%1." data-font="Arial" data-listid="1" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"><span data-contrast="none">The #1 way to stop these compromises is to have CSI help you enable Multi-Factor Authentication on your 365 accounts.  At this point, IT security pretty much requires that all important public login accounts should be using MFA. And your Microsoft 365 accounts definitely qualify as important accounts. storing tons of personal information and documents. </span>&nbsp;</li>
<li data-leveltext="%1." data-font="Arial" data-listid="1" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"><span data-contrast="none">Be extra cautious anytime you are prompted to enter in your Microsoft 365 credentials.  If you click on any links from an email that lead you to a web page asking for your 365 login info, assume it is likely a malicious website. Contact CSI to ask for help in identifying if an email is malicious.</span>&nbsp;</li>
<li data-leveltext="%1." data-font="Arial" data-listid="1" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"><span data-contrast="none">Don’t assume just because an email is from someone you know and trust that you should be OK clicking on links to access a file they supposedly sent you. Pick up the phone and check with them if you aren’t certain why they are sending you this email.</span><span data-ccp-props="{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></li>
</ol>
<p><span data-contrast="none">If you do realize that you just entered in your 365 credentials after clicking on links in an email that didn’t really take you to anything you needed, then <strong>contact CSI RIGHT AWAY!</strong>  We can help you confirm the legitimacy of the email. If you contact us quick enough, we may be able to reset your password before the bad guys even have a chance to compromise the account. Like we always say, we are here to help you!</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Keeping the hackers out!</title>
		<link>https://csiomaha.com/keeping-the-hackers-out/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=keeping-the-hackers-out</link>
		
		<dc:creator><![CDATA[Alisa]]></dc:creator>
		<pubDate>Wed, 24 Mar 2021 22:12:39 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<guid isPermaLink="false">https://csiomaha.com/?p=1604</guid>

					<description><![CDATA[Some of you may not know the HOW behind email encryption and that is perfectly fine. We do, however, want you to understand the WHY.  What is actually contained in your office email is the most typical misconception surrounding encryption. It is a common belief that if you aren’t sending data sensitive emails that contain social security [&#8230;]]]></description>
										<content:encoded><![CDATA[<p style="text-align: left;"><img decoding="async" class="alignnone wp-image-1618" src="https://csiomaha.com/wp-content/uploads/2021/03/85-1024x569.jpg" alt="" width="700" height="389" data-wp-editing="1" /></p>
<p><span data-contrast="none">Some of you may not know the <strong>HOW</strong> behind email encryption and that is perfectly fine. We do, however, want you to understand the <strong>WHY</strong>. </span></p>
<p><span data-contrast="none">What is actually contained in your office email is the most typical misconception surrounding encryption. It is a common belief that if you aren’t sending data sensitive emails that contain social security numbers, login information, credit card or bank account numbers, encryption is not needed. Unfortunately, hackers who gain unauthorized access to an email account can access attachments, content, and even hijack your entire email account. 306.4 billion emails are sent and received every day. Think of how many emails you alone send and receive every day. Email is a very common and trusted form of communication, but it can be extremely vulnerable. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p style="text-align: left;"><span data-contrast="none">The 2020 Verizon Data Breach Investigations Report revealed small businesses account for 43% of breach victims. Additionally, the 2019 Varonis Global Data Risk Report revealed that only 5% of companies’ folders were properly protected. Is that shocking to you? We certainly think that it is… And the longer you use an email address, the more valuable that email address becomes.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p style="text-align: left;"><span data-contrast="none">Emails are at risk when they are being sent and where they are stored. Encryption renders the content of your emails unreadable as they travel from one place to the next, so even if someone intercepts your messages, they can’t interpret the content. Do you want to become one of the breach victims or keep your data safe? It’s really that simple. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p style="text-align: left;"><span data-contrast="none">As always, we are here to keep your data secure.</span><b><span data-contrast="none"> </span></b><span data-contrast="none">For more information on email encryption, </span><a href="https://csiomaha.com/contact-us/"><span data-contrast="none">contact us today</span></a><span data-contrast="none">.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Are your emails safe?</title>
		<link>https://csiomaha.com/are-your-emails-safe/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=are-your-emails-safe</link>
		
		<dc:creator><![CDATA[Alisa]]></dc:creator>
		<pubDate>Tue, 02 Mar 2021 22:09:57 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<guid isPermaLink="false">https://csiomaha.com/?p=1601</guid>

					<description><![CDATA[Do you send sensitive data through email? And when we use the term “sensitive”, we are referring (but not limited) to names, phone numbers, account records, confidential documents, employee data, and so on&#8230;   Email revolutionized communication, especially at the workplace. But with the reliance on email comes a responsibility to maintain the integrity of electronically [&#8230;]]]></description>
										<content:encoded><![CDATA[<p><img decoding="async" class="alignnone wp-image-1622" src="https://csiomaha.com/wp-content/uploads/2021/03/Email-Safety-1024x569.jpg" alt="" width="700" height="389" /></p>
<p><span data-contrast="none"><strong>Do you send sensitive data through email?</strong> And when we use the term “sensitive”, we are referring (but not limited) to names, phone numbers, account records, confidential documents, employee data, and so on&#8230; </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="none">Email revolutionized communication, especially at the workplace. But with the reliance on email comes a responsibility to maintain the integrity of electronically distributed information. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="none">Do you take precaution to encrypt data such as credit card numbers, employee records and banking information? What about vendor credit applications, billing statements and other seemingly harmless documents? All of these could be used to compromise your company. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="none">As your Managed Service Provider, we are responsible for your data &#8211; all of it. By implementing email encryption, we can help you avoid identity theft, phishing, viruses and spam. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><em>According to Hosting Tribunal: </em></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="2" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><strong>There is a hacker attack every 39 seconds </strong></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="2" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><strong>Cybercrime is more profitable than the global illegal drug trade. </strong></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="2" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"><strong>Hackers steal 75 records every second. </strong></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="2" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"><strong>66% of businesses attacked by hackers weren’t confident they could recover. </strong></li>
</ul>
<p><span data-contrast="none">These are just a FEW of the statistics. In 2021, everyone is a target. Don’t allow yourself, your employees, or your business to fall victim to hackers. Let us keep your data and your email secure. </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="none">For more information on data back-up, </span><a href="https://csiomaha.com/contact-us/"><span data-contrast="none">contact us today</span></a><span data-contrast="none">.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}"> </span></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
