Endpoint Security Podcast: Recent Episodes

Endpoint Security Podcast

Keeping Businesses Safe Through Cyber Security Education

View Details

With the COVID-19 pandemic forcing many of us to work from home, this means tapping into technologies that allow us to remotely connect to our office, or otherwise access business resources from a remote location. This could in turn provide criminal hackers that same access. It is a particular danger for small businesses where their IT manager is not up to date on best cybersecurity practices, or where they may not even have an IT manager at all. To help shed some light on this and find some solutions, Robbie is joined by cybersecurity researcher, Stephen Cobb.

Resources: https://blog.endpointsecurity.ca/2020/03/24/making-work-from-home-safe-for-small-businesses-affected-by-covid-19/

The post Episode 8: Cybersecurity Safety in a Work From Home Environment appeared first on Endpoint Security Blog.

View Details

As 2020 settles in, Robbie visited Raf Bivar at ESET Canada’s head office in Toronto, Ontario to discuss the evolution of cyber threats, what we can expect in the year to come, and what it takes to truly protect ourselves from the ever-evolving threats to our companies.

The post Episode 7: The Biggest Threats to Your Company in 2020: Is Antivirus Obsolete? appeared first on Endpoint Security Blog.

View Details

It’s a new world when a single attack can affect hundreds of thousands of businesses. Software, services, and core components of your business have been progressively migrating to the cloud; the Managed Service Provider. Have we become complacent by thinking they’re too big to be compromized?

Robbie Ferguson takes us on a tour of the past few months with some real world examples of MSP services that were hit recently, and how the businesses who tap into their services were impacted.

Through this short episode, we’ll help you to be prepared for the potential risk of placing your company and client data in the hands of an MSP.

Transcript In October, 2019, it was revealed that the official Sesame Street online store had been compromised using a piece of malicious javascript code. This man-in-the-middle attack was able to steal every credit card number entered into the site’s ordering system.

Of course, the payment cards were verified by the payment processor as the legitimate transactions took place, so the hackers involved could easily vet which cards were good, and which should be discarded. Their resulting list, no doubt in whole or in part, could then be sold on the Dark Web, and the cardholders would be none the wiser until the bills start coming in.

But perhaps you don’t shop on the Sesame Street store. So you’re safe, right?

Marcel Afrahim, a researcher at security firm Check Point discovered the malicious code, and made a frightful observation: the Sesame Street store utilizes services from a Managed Service Provider (MSP) to run their web-based store. In this case, the MSP offering the services is Volusion, an e-commerce solution provider boasting over 30,000 active merchants using their service, and $28 billion dollars in sales across more than 185 million orders.

Remember, the compromised ordering system, while discovered on the Sesame Street store, was also in place for those 30,000 other merchant sites utilizing Volusion’s services.

Upon learning of the compromise, Volusion was swift to act and had the issue resolved within a day, but the damage is done for those whose credit card information has been stolen.

In an unrelated attack the same month, around 2,500 law firms were impacted when their case management software provider, TrialWorks, was hit by a ransomware attack. This locked lawyers out of their case files for nearly a week. Just think about how that would impact your business.

In yet another story, a Prairieville pediatrics practice came under lock-down when their IT company was targeted by a ransomware attack. The malicious party was able to infiltrate the clinic’s computers by way of the IT firm.

Then in September, the parent portal for all of Alabama’s Mobile County Public Schools were inaccessible when the school board’s external website provider was compromised by a ransomware attack.

At the end of July, insurance providers could not process claims for workers comp, auto, health, or disability when CorVel, a managed service provider for insurance companies was hit by ransomware.

Back in June, more than 20,000 real estate brokers and agents were unable to gain access to listings when MetroList, the largest real estate MLS provider in Northern California came under attack.

The month before that, First American Financial Corp., a title insurance provider, announced that 885 million mortgage documents dating back to 2003 had been exposed by a data breach which potentially exposed bank accounts and statements, mortgage and tax records, Social Security numbers, and wire transaction receipt.

I could go on and on, and those real life examples are just a few I’ve picked from the past few months.

I’m telling you about all these attacks for a simple reason: while there’s no direct connection between any of these attacks, one thing links them all: in each case, thousands of individual companies were impacted by not themselves, but their service provider being compromised. Like Sesame Street: it wasn’t simply the Sesame Street web site stealing credit card information. Oh, no: it was 30,000 independent e-commerce web sites, all linked by their MSP who fell victim to the attack. All these companies have that one thing in common: They’re tapping into MSP services for core components of their business.

MSPs have become a very appealing target for attackers, and perhaps we’ve become complacent, thinking that because they’re big, they won’t fall victim. If there’s anything these examples show, it’s that these centralized services not only do fall victim, but in fact can be lucrative targets for an attacker, which makes them all the more appealing.

The answer is not to stop using MSPs–that’s not practical. But we simply need to wake up to the fact that the MSP is in the crosshairs of attackers, and if all our data is in the MSP datacenter, we are at risk by proxy. Our customers are at risk. Our business is at risk. While many such attacks are ransomware since that tends to turn a quick pay day for the hacker, data theft is also prevalent. So while having and maintaining regular local backups is a must to protect your company against ransomware, it does nothing toward data theft. We must also be diligent in ensuring the companies we do business with are reputable, and that they themselves have systems and procedures in place to prevent data loss, and data theft.

There’s no “magic formula,” but you should be able to open a conversation with your service providers and get answers about how they protect your data and ensure the safety of your customer information. Also, employ local protection, including a bi-directional firewall like that included with ESET Endpoint Protection Advanced. That can help prevent the spread of ransomware within your network. Also be sure you have common entry-points such as remote desktop disabled on all your systems. It goes without saying, but I’ll say it anyways: Backup, backup, backup. The challenge I pose to my customers is this: if everything crashed tomorrow, or if your MSP went belly-up, where are your files? Where are your backups? And how long would it take you to recover. Don’t be ashamed if you don’t know: you’re not alone. But take action and realize that when disaster occurs, the companies that survive are the ones who are prepared.

You already know that having all your data on a single hard drive is just asking for trouble. So now it’s time to equate that to the MSP–the “cloud”–and put systems into place to protect your data, ensure redundancy that can’t be touched by an active ransomware threat, and do everything in your power to preemptively understand and reduce the time involved in recovering should an attack take place.

If you have questions, my team and I are at the ready to help. Visit EndpointSecurity.ca for more information about our products, or give me a call. We’ll figure out together how we can help you to be prepared.

Sources “Cookie monster eats data from Sesame Street store” BBC News
https://www.bbc.com/news/technology-49986737

“The count of managed service providers getting hit with ransomware mounts” Ars Technica
https://arstechnica.com/information-technology/2019/10/the-count-of-managed-service-providers-getting-hit-with-ransomware-mounts/

“Company” Volusion
https://www.volusion.com/v1/company

“Ransomware Attack Reportedly Hits Practice Management Company, Locking Lawyers Out of their Case Files” LawSites
https://www.lawsitesblog.com/2019/10/ransomware-attack-reportedly-hits-practice-management-company-locking-lawyers-out-of-their-case-files.html

“Prairieville pediatrics clinic working with FBI, notifying patients after computer attack” The Advocate
https://www.theadvocate.com/baton_rouge/news/communities/ascension/article_b6194b7a-eba2-11e9-a388-5b6eedc7c596.html

“MCPSS website is back up after ransomware hack” WKRG News 5
https://www.wkrg.com/news/mcpss-website-hacked-by-virus/

“Calif. MLS Giant Temporarily Shuts Down After Malware Attack” REALTOR Magazine
https://magazine.realtor/daily-news/2019/06/13/calif-mls-giant-temporarily-shuts-down-after-malware-attack

“885M Mortgage, Title Docs Exposed in Data Breach” REALTOR Magazine
https://magazine.realtor/daily-news/2019/05/28/885m-mortgage-title-docs-exposed-in-data-breach

“CorVel’s problem may be ransomware” Joe Paduda
https://www.joepaduda.com/2019/07/26/corvels-problem-may-be-ransomware/

The post Episode 6: The Ripple Effect of Attacks on the Managed Service Provider appeared first on Endpoint Security Blog.

View Details

The relationships between departments have evolved immensely over recent years–and they must, thanks in part to the current cybersecurity landscape and new data privacy regulations. The difference is especially apparent when reviewing the old silo mentality that segregated the IT Department from the C-Level, forcing data security decisions to fall squarely on the computer support team’s shoulders. On this podcast, our host Robbie Ferguson welcomes ESET Director of Sales and Partner Alliances, James (Jim) Chalmers, to discuss what is needed to truly protect our corporate network these days. You may be surprised to find that the immediate answer is not “more software” or “more expense,” but rather involves the utilization of resources that are freely available to you and your staff.

We’ll cover topics such as:

  • Data privacy as a driving factor in the changes in our approach to cyber threats.
  • How cybersecurity issues have forced IT issues to flow into the C-Suite.
  • How C-level staff have had to grow their knowledge and understanding of issues that were previously contained within the IT department’s silo, and why this has become necessary.
  • The Starwood/Marriott breach of 2017 and what it reveals about a needed shift in how the C-Suite approaches (and understands) IT issues.
  • Cybersecurity is a business issue, not a technology issue.
  • What cybersecurity specialists can do to influence or manage up to executives.
  • How a breach can occur, even when security software is in place.
  • How to impact your staff by making cybersecurity awareness fun.
  • Resources available to you and your team to help educate your staff and protect your network.
  • How the Ashley Madison breach made us aware of hacktivism, and the risks involved in ethical hacking.

ESET offers free online cybersecurity training to help organizations like yours build a comprehensive and proactive strategy. For more information check out: eset.com/ca/cybertraining

This week’s Podcast is also available in video format: Read the companion blog: Cybersecurity: What Executives and the IT Department Need to Do The post Episode 5: Pulling Down the Silos: Protecting Your Company from Cyber Threats appeared first on Endpoint Security Blog.

View Details

The Internet of Things and the Industrial Internet of Things are huge markets that are growing rapidly as the technology progresses at a rapid pace. Robbie Ferguson welcomes back cybersecurity expert Tony Anscombe to discuss IIoT’s impact on business security.

We’ll cover topics such as:

  • Defining the distinctions between IoT and IIoT.
  • How IoT sensors are being used to save a single hotel millions of dollars.
  • How an aircraft manufacturer is using IIoT smart glasses to increase productivity and improve the quality of their work.
  • Sleeper technologies in business that could be entry points for cyber attack on other devices on a company network.
  • How seemingly unsuspecting IIoT technologies can be used for malicious purposes beyond the network.
  • The misconception that data on our own network is safe simply because it is on our own hardware.
  • Protecting your business by entirely separating your backup from your network.
  • Steps that are being taken to use artificial intelligence and machine learning to track down malicious hackers.
  • How traffic anomalies may help the system administrator find rogue machines and possible data breaches.
  • The worries presented by IIoT, and how having a security-first mindset can protect your company in the future.
  • The future of the Industrial Internet of Things.

This week’s Podcast is also available in video format: Read the companion blog: The Impact of IoT and IIoT on Security The post Episode 4: The Security of Things: Effects of IoT and IIoT on Business Security appeared first on Endpoint Security Blog.

View Details

The ESET Cybersecurity Barometer gives a great deal of insight into the cybersecurity threat zeitgeist in Canada. Robbie Ferguson speaks with its author, Stephen Cobb about whether Canadians are truly aware of the threats that exist in today’s connected world.

We’ll cover topics such as:

  • Canadians’ attitudes toward cybercrime.
  • What Canadians are doing to protect themselves against cyber attack.
  • The Canadian political landscape in matters of cybersecurity.
  • Securing our endpoints and understanding why it’s important to do so, even if they aren’t used for anything important.
  • New malware discovered on Android that allows the malicious party to steal cryptocurrency by overwriting your clipboard.
  • Recognizing phishing scams, even when they are quite convincing.
  • Steps individuals and businesses can take to prepare themselves against cybersecurity threats.

This week’s Podcast is also available in video format: Download the ESET Cybersecurity Barometer here. Read the companion blog: Cybersecurity: Are Canadians Ready? The post Episode 3: Are We Ready? appeared first on Endpoint Security Blog.

View Details

ESET Senior Security Researcher Lysa Myers joins our host, Robbie Ferguson, for a discussion about the current state of data breaches and what we can do to protect our company and personal data should a breach occur.

We’ll cover topics such as:

  • The Common Cause – Why data breaches are so commonplace in 2019.
  • The Mainstream Media Effect – How the lack of understanding by both the media and consumers leads to a fast news cycle and complacency.
  • The Corollary Cost – How data breaches continue to impact the economy long after they occur.
  • Growth and Evolution of Data Breaches – What we as consumers and business people can expect to occur in 2019, and what we should watch out for.
  • Protection from Data Breaches – For the average person, we’ll discuss what it takes to protect yourself from the ongoing effects of a data breach.
  • The Shelf Life of Compromised Data – Lysa warns that our data is never “safe,” but there are ways to minimize the impact of a data breach and detect it before it has caused irreversible damage.
  • Three Key Ways to Protect Your Company – It’s important to protect your company against data breach–whether of your own company data, or by being unwittingly complicit in the breach of another company’s data. Lysa will share three key ways to protect the data you are entrusted with.

Read the companion blog: Why Data Breaches Continue to Happen If you prefer to listen on YouTube: The post Episode 2: The State of Data Breaches in 2019 appeared first on Endpoint Security Blog.

View Details

Join host Robbie Ferguson and ESET cyber security expert Tony Anscombe as they speak about which cyber security threats are most likely to impact your business in 2019. From cryptojacking to data privacy, our first episode will help your staff take control of personal and company data, keeping it out of the hands of those who should not have access.

We’ll cover topics such as:

  • Cryptojacking – What it is, and why it’s becoming a threat to businesses. Robbie and Tony discuss how cryptojacking grew as a threat in 2018, and how companies can protect themselves against this resource-stealing practice in 2019.
  • The Internet of Things – From consumer products such as smart doorbells and Amazon Alexa, to smart office buildings, IoT (and IIoT) are here to stay. Robbie and Tony discuss how regulations can encourage manufacturers to pursue a security-first process, but consumers and employees need to be educated in order to protect confidential information.
  • Password Management – Employees can quickly succumb to security fatigue, being required to change passwords regularly can lead to employees rotating through a short list of recycled–and potentially easy to exploit–passwords. Tony will share some clever tips on how to better secure your environment through a new way of thinking about passwords.
  • Data Breaches – 2018 was seemingly the year of data theft. Tony surprises us by sharing a personal story in which he himself was the victim of a data breach, proving that even security-conscious employees can fall victim as it is not always a cause-and-effect process that results in data exploit. From using “throw away” email accounts to knowing which cards you should use online, Tony shares some excellent advice to help your users take conscious control of who has access to data.
  • The Susceptible Demographic – Tony shares a fact that is surprising–even shocking–about who is most susceptible to falling victim to a data breach or spearphishing scam.
  • Data Privacy – The GDPR made big news in 2018. Robbie and Tony discuss what it means for Canadian business in 2019 and beyond.
  • Three Pillars of Advice – For the consumer, the CEO, and the IT professional: Tony shares three important points to protect yourself and your company from cyber attack in 2019.

This week’s Podcast is also available in video format: Watch the full interview with ESET Cyber Security expert, Tony Anscombe. Read the companion blog: Cyber Security Outlook for 2019 The post Episode 1: Cyber Security Outlook for 2019 appeared first on Endpoint Security Blog.