Three Ways to Improve Your Personal Cyber Safety

For National Cyber Security Awareness month there a couple of relatively easy-to-do things that I highly recommend if you want to improve your personal cyber safety. These important protections are easily available but not well documented.

One of the biggest cyber security problems impacting users today is the reuse of easy to guess passwords across multiple sites. All it takes is for one site to be compromised and the hackers can then use your password to log into others. This process is often automated and run against all sites. To help combat that ensure that you have a *unique*! password for each site. No one can remember multiple unique complex passwords so invest in using a tool like roboform or 1password to manage these passwords and keep them safe. Once you have installed a good password manager go back to each site you use and replace your common password of “petname123″ and let the password manager create a long and complex password for you like “yott2&uv0ugs7.” Save that password and go on to change the next one. Set a complex password that you DO remember for your password manager. It’s only one and it can be recalled from memory.

Don’t be afraid of the cloud! Losing all of your newly-created complex passwords to a hard drive crash would be a terrible loss. Make sure you sync your password file in the cloud to be able to access them across multiple devices (phones, tablets, laptops) and always have a backup. Roboform has its own cloud storage built in and 1password uses Dropbox or iCloud. Your passwords are encrypted withAES encryption so even if someone somehow broke into the cloud provider and stole your password list, they cannot decrypt your passwords without the one complex password you committed to memory.

The next step to ensure you won’t be an easy victim is to set up two-factor authentication for some sites that are more important to your personal cyber security like Gmail, eBay and PayPal.

Gmail
You may not have thought about it, but your personal Gmail account ties many things together. For example if you use Gmail as your email address for your Amazon account, if someone hacks your Gmail they can force a password change to access your Amazon account. Similarly, your bank and many other systems may use your email as a way to allow for password resets.

Criminals can also use your Gmail account to send out legitimate looking email requests for emergency help to all the people in your address book like the email below:

Hi,

How you doing? I made a trip to London (United Kingdom) unannounced some days back, Unfortunately i got mugged at gun point last night! All cash, Credit card and phone were stolen, i got messed up in another country, stranded in London, fortunately passport was back in our hotel room. It was a bitter experience and i was hurt on my right hand, but would be fine. I am sending you this message cos i don’t want anyone to panic, i want you to keep it that way for now!

My return flight leaves in a few hours but Im having troubles sorting out the hotel bills, wondering if you could loan me some money to sort out the hotel bills and also take a cab to the airport about ($1,550). I have been to the police and embassy here, but they aren’t helping issues, I have limited means of getting out of here, i have canceled my credit cards already and made a police report, I wont get a new credit card number till I get back home! So I could really use your help.

You can contact the hotel management through this telephone number (+449444045232), you could wire whatever you can spare to my name and hotel address via Western union:

Name: John Hastings
Location: 201 Bunaby Street, Chelsea,
Greater London
SW10 0PL.
United Kingdom

Your Gmail account plays an important part in your overall internet safety. It is very important you set a strong password and enable two-factor authentication. Here is how to do it:

  • Login to your Gmail account then go-to the following URL
    https://www.google.com/landing/2step/
  • Click on “Get Started” then “Start Setup.” Enter the number for your phone and verify the number by entering the numeric code that Google sends to the phone by either text message or voice call.

  • You can also choose to use the smart phone app Google Authenticator, which you would register through the same wizard shown above. To install Google Authenticator click here for iOS or here for Android. Either way works and will stop people from easily taking over your personal email (and of course your online identity!).

PayPal and eBay
If you use either of these services, they are high-value target accounts for crime. PayPal is especially problematic as it links directly (in most cases) to your bank account. EBay accounts, on the other hand, are often hijacked then used fraudulently to sell nonexistent items, leaving the account owner to work out the mess. I highly recommend you protect yourself by setting up two-factor authentication for both accounts.

Setup instructions for PayPal:

Go to https://www.paypal.com/us/cgi-bin/webscr?cmd=_register-security-key-mobile

This will give you the option to set up a secondary authentication method. You have three choices, pay a small amount and they will ship you a small fob that will provide one-time passwords to use as a secondary authentication for your account (i.e. a hacker can’t get into your account by just guessing your password or resetting it). The second choice is a more convenient one if you have a smartphone. You can download the Symantec VIP Access program for smartphones. Or you can just have PayPal send messages to your mobile like we did with Gmail.

When you get the token software installed on your smartphone, authenticate it to your PayPal account and register its unique ID. Now when anyone wants to use your PayPal account, they will have to have both your username and password and the one-time token password your phone or fob would generate. Note: you can also tie this token to your eBay account.

There was a lot of work to do to get to this stage. It is unfortunate that this process is obscure and not built-in or easier to enable. I am sorry to say that there is one more step if you use Gmail with any applications that auto-check email. I have several, such as the Microsoft Outlook client for Mac. These applications do the authentication automatically. For convenience with only a small security risk I can use Gmail to set up application- or device-specific passwords. These fixed passwords can ONLY be used by the same app on the same device. You can do this by editing the “authorizing applications & sites” button in the Gmail account settings.

When you click edit, it will force another authentication then allow you to set up, manage and track application-specific passwords.

So that’s it. I wish it was easier, but these are a couple of steps that can make your internet identity much harder to abuse.

Gavin Reid, Vice President/Threat Intelligence, Lancope

[Cloud Security Alliance Blog]

2016 Recruiting Forecast for IT Professionals

When thinking about the recruiting landscape for 2016, my first thought is that it all depends on which side of the interview you are on. 2015 has shown the strongest demand for skillsets that ISACA members have (IT audit, governance, security and risk) that we have seen since 2005-2007, during the first years of Sarbanes-Oxley Act (SOX) compliance. Currently, conditions are extremely tough for hiring managers who are trying to lure top talent to their teams, and I do not expect this to change anytime soon.

Why the talent shortage? IT audit, governance, security and risk skillsets are an increasingly bright spot on the radar of organizational leaders. This is partly due to increasing regulatory and compliance requirements and high-profile data breaches, but also because of years of efforts to transform IT audit from a “necessary evil” to a value center.

Because of the increased understanding of the value IT risk and controls professionals provide, there has been a significant uptick in non-audit positions since 2012—especially IT risk and compliance roles. These “second line of defense” roles were gaining traction in 2007-2008, but funding in this space tightened (or just plain vanished) during the recession in the US. Now, in a steadily improving economy, budgets for these roles have replenished and the resulting demand has stretched a thin talent pool even thinner by recruiting heavily from IT audit groups.

Another factor is that some of the primary talent generators in our field, the “Big 4” and similar client service firms, made deep staffing cuts during the recession and also dramatically reduced hiring off college campuses from 2009-2012.

These factors have created rosy conditions for most IT professionals seeking new opportunities. Barring a significant global political or economic disturbance, I expect the strong demand in our space to extend at least through 2016.

I am often asked, “What are the top skills in demand?” That is a difficult question to answer for a constituency as diverse as ISACA’s, for example, which covers many disciplines in the IT controls world, ranging from the deeply technical to more general relationship management roles. Cyber security is the word on almost everyone’s lips right now. You can question whether or not cyber security is “new” or just the next iteration of complexity in technology assurance, but regardless, rebranding your skillset toward cyber security activities is a sound career strategy in the near term.

In the long term, whether you are focused on IT audit, governance, risk, compliance, or security, your success will depend on aptitude, attitude, and altitude. By aptitude, I mean your ability to continually learn and adapt quickly to technology and business developments in an increasingly complex and competitive business climate. By attitude, I mean approaching your work with dedication, resilience, optimism and empathy. By altitude, I mean seeing IT risks from the viewpoint of the C-suite, and communicating the impact of risks in business language to a variety of stakeholders.

So, how do you position yourself for continued success in 2016? You have heard the saying, “if it ain’t broke, don’t fix it.” I say, “if it ain’t broke, do preventative maintenance.” Each of you probably knows at least one professional who learned a painful lesson during the recession. Many faced involuntarily unemployment for the first time, and were caught having allowed their skills to get stagnant. Now is the time to do preventative maintenance and to be proactive about future-proofing your skillset. Earn an additional certification. Seek out a mentor to help you determine three specific soft and hard skills for you to acquire or improve, and then put an action plan in place to achieve those goals.

Some people will read this and think, “I should do that,” but then it will get shuffled to the side, as life’s many professional and personal demands take a higher priority. I understand. I will leave you with this: I am optimistic that the steady climb in demand for the discussed IT skillsets will continue in 2016, but go ahead and plan your career as if it will not. Either way, you will be a winner.

Derek Duval, CPC
Duval Search Associates, LLC

[ISACA Now Blog]

Channel Scoop – October 23, 2015

Sit back and relax. Let us do the information gathering and give you the channel scoop.

  • We have 6-business days left in Q1. We have countless folks around the globe ready to help you maximize your Q1 close. If you still need help please email your question/request tonextwave@paloaltonetworks.com.
  • Need a little extra help getting your customer to upgrade from the PA-2000 Series to PA-3000 Series or from the PA-4000 Series to PA-5000 Series? Don’t forget we recently launched the Customer Care Upgrade Program, designed to provide an incentive to help fuel the conversion of our customer install base. Click here to learn more.
  • Customer success stories are key to accelerating the sales cycle. What if you could easily take a Palo Alto Networks customer testimonial to your next customer meeting? Now you can with our new prevention e-story, which allows you to see and hear from Palo Alto Networks customers. Click here to access the web version of our e-story or to be able to download the e-story to your smartphone or tablet via the Android or Apple App stores.
  • Looking for that key data point or research fact to help move your customer to close. Our2015 Application Usage and Threat Report has new and compelling data. For example, over 40% of email attachments examined by WildFire were found to be malicious. Click hereto access the report and to learn more, including a quick 90 second summary video.
  • Need help convincing your customer that security is a top priority for today’s executive leadership? Click here to access the Governance of Cybersecurity Report for 2015infographic, which you can quickly share with your customers.

What topics you’d like the scoop on next? Let us know by commenting on this blog.

[Palo Alto Networks Blog]

The Cybersecurity Canon: Locked Down: Information Security for Lawyers

We modeled the Cybersecurity Canon after the Baseball or Rock & Roll Hall-of-Fame, except for cybersecurity books. We have more than 25 books on the initial candidate list, but we are soliciting help from the cybersecurity community to increase the number to be much more than that. Please write a review and nominate your favorite

The Cybersecurity Canon is a real thing for our community. We have designed it so that you can directly participate in the process. Please do so!

Book Review by Canon Committee Member, Christina AyiotisLocked Down: Information Security for Lawyers (2013) by Sharon D. Nelson, David G. Ries, and John W. Simek

FULL DISCLOSURE: I have known Sharon and John personally and professionally for more than a decade and consider them good friends. We have participated together on panels, spoken at the same conferences, and served on committees and boards of directors together. We have similar areas of expertise and civic commitment. 

EXECUTIVE SUMMARY

Sharon, David and John published an important book on information security for lawyers and law firms three years ago. Given the number of law firm breaches since, it appears that few lawyers read or heeded their advice. Locked Down is an easy-to-read overview of why lawyers need to implement good information security, not just cybersecurity, and how. It is even more relevant today than when first published. This book belongs in the Cybersecurity Canonbecause it provides cybersecurity professionals context regarding the legal profession’s requirements and strategies for dealing with cyber and information risk and obligations.

Introduction

Cybersecurity is such an important topic in the legal field that lawyers are starting to pay actual money to be a part of a brand-new Legal Services Information Sharing & Analysis Organization (sold to them by the FS-ISAC) [1]. While my fellow Cybersecurity Canon Committee member Ben Rothke wrote an Amazon review of this book in May 2013 [2], he did so from a Cybersecurity/IT professional’s perspective. My review will primarily be from the perspective of a Cyber Attorney, former Deputy General Counsel of a technology services multinational, Privacy Expert, Certified Records Manager and active member in good standing of the Virginia State Bar for 24 years.

REVIEW

When Locked Down was published, the American Bar Association (a private sector voluntary professional association with no lawmaking power or regulatory authority that relies on the

State Bars as an independent enforcement organization ) was still considering updates to its Model Rules of Professional Conduct that would bring them into the 21st Century. While those updates are now in effect, and they include being competent regarding the “benefits and risks associated with relevant technology,” there is little evidence that the more than one million lawyers in the U.S. have sufficiently educated themselves to be considered competent. Reading this book would be a good start. Then, taking it to their IT colleagues (or consultants, if they are solo or a small firm) and working together to understand how the various strategies are (or could be) implemented would be the next logical step.

While the book starts with “data breach nightmares,” it’s probably no longer necessary to start with fear. Information security is now a business imperative for clients, and they drive the requirements (most of which are conveniently explained). While it is 319 pages in total, the text runs only 170 pages; the rest of the book contains helpful Appendices and an Index.

Yes, lawyers have ethical obligations to keep client information confidential, but there are common law duties, as well as regulatory/statutory requirements for certain data types (that affect both lawyers and clients alike) and the authors provide that as background. The book then delves into all aspects of security (physical, information, cyber and personnel) and use real case studies to make their point. For example, the authors recount the horrifying and “amusing” story about Kevin Mitnick taking on a new identity as Eric Weiss, “the real name…of…Harry Houdini (sic)” to get a job as a systems administrator at a Denver law firm. Ironically, there has been an explosion of cybersecurity practices at law firms in the last few years—the shoemaker’s children excuse will definitely not work for them. It would not surprise me to see a day when a law firm is sued by a client because of a data breach and Locked Down is entered into evidence to demonstrate the “reasonable care” law firms should be taking with respect to security.

“Two lawyers and an IT expert” sounds like the beginning of a good joke, but it is the unique blend of perspectives and expertise the authors bring that makes the book so readable. A SANS Institute Glossary of Security Terms is conveniently located in Appendix M, so lawyers unfamiliar with such terms can easily look them up. Topics such as authentication, secure configuration, virtual private networking (VPN) should be part of every lawyer’s lexicon, if for no other reason than their clients have the exact same issues protecting information in their own environments.

Advice regarding securing desktops, laptops, mobile devices, email, voice communications, etc. are all general business issues that all professionals should be aware of. Outsourcing and cloud computing are even more prevalent today and managing that third-party risk is not just an ethical duty but also a business requirement; the authors’ recommendations in that regard are critical. It’s also important for law firms to acknowledge that clients consider them to be third-party vendors that must similarly meet baseline security requirements. Appendix H: “Lockdown: Information Security Program Checklist” is an excellent starting point.

The Certified Records Manager in me applauds the inclusion of Chapter 13: “Secure Disposal” and the authors get extra points for citing a relevant NIST standard. While the book focuses on information security, it is important to recognize that end-to-end information management (for both client and law firm information) is the goal (to mitigate risk and reduce costs). Chapter 15: “Securing Documents” is particularly important for lawyers because legal advice provided within documents and relevant communications channels must be kept secret in order to be protected by the attorney-client privilege (not to mention the requirements for trade secrets). There is also an important discussion regarding metadata (from both operating systems and applications perspectives) – not surprising given Sharon and John (along with Bruce A. Olsen) wrote The Electronic Evidence and Discovery Handbook: Forms, Checklists and Guidelines.

They cover cyberinsurance but caution that policies are confusing and care must be taken to understand what exactly is covered (and what is not). They end the book looking at “The Future of Information Security” and readers should beware that the topics covered (laws and regulations, BYOD, passwords, policies and plans, mobility, cloud computing, social media, and training) are all everyday issues now.

CONCLUSION

Given how quickly technology evolves, in the next edition of Locked Down the authors will likely have to add sections on wearables, biometrics as part of multifactor authentication, quantum encryption, virtual law practices, etc., but lawyers should feel comfortable knowing that mastering what’s in this book puts them in a defensible position.  Furthermore, good information security is now a business differentiator. Law firms that implement all of the book’s recommendations can use their superior cybersecurity standing when marketing their services. [3] They can even give clients a copy of Locked Down for their own use (and no, I’m not getting paid a commission on book sales).

SOURCES

[1] “Legal Services Information Sharing & Analysis Organization,” by the FS-ISAC, Last Visited 21 October 2015, http://www.fsisac.com/ls-isao

[2] “Top Customer Reviews: Locked Down: Information Security for Lawyers,” by Ben Rothke, Amazon, 20 May 20 2013, Last Visited 21 October 2015, http://www.amazon.com/Locked-Down-Information-Security-Lawyers/dp/1614383642

[3] Law firm makes a case for security certification,” by “Mary K. Pratt,  CIO.COM 28 August 28 2015, Last Visited 21 October 2015, http://www.cio.com/article/2969323/security/law-firm-makes-a-case-for-security-certification.html

[Palo Alto Networks Blog]

English
Exit mobile version