Blog

April 11th, 2012

Peer-to-peer networking (P2P) and cloud storage services have both been hot topics in the news lately. Whether it’s about the seizure of servers or security threats, both have been causing businesses problems with regards to recoverability and security of data. Does your company use P2P or cloud storage? If so, there are a number of things you should be aware of.

With the seizure of a number of cloud storage and sharing websites, including Megaupload, and the seemingly omnipresent malware in P2P files and the shaky security in relation to P2P networks, businesses have had their hands full staying secure. Do you know what your options are when it comes to data security?

Cloud Services Knowhow The recent seizure of Megaupload’s files and servers by the US Government caught many people and businesses unprepared. While Megaupload’s main purpose was file sharing, it was found that a large number of organizations were using their services to store files. If you had files stored on Megaupload, the chances of getting the files back are non-existent.

It needs to be pointed out that many cloud services don’t guarantee that files stored on the service will be recoverable in the event of a crash, or disruption in service, e.g., a government seizing servers. If you read the user agreements of a number of major cloud services, they all have clauses stating that if data stored on their service is lost for any reason, it’s gone forever, and the hosts can’t be held liable for losses.

Risks of P2P With high speed Internet widely available at low prices, P2P file sharing has become incredibly popular, it’s almost uncommon to find someone who has never used a P2P service. If you or your employees use P2P at your office, there are a number of potential security threats you should be aware of:

  • The unknown share: If you put a file in a folder that is shared on a P2P network, it’ll be shared with all other people connected to that folder and almost anyone can access it. This is normally done by mistake, i.e., not looking where the file will be saved when you save it. There’s also malware out there that will move files into a shared folder which the developer of the malware can find and upload with ease and without the user knowing it is happening.
  • Open network: Typically P2P works on open networks: users give and share. What this means is that when using P2P on a poorly configured network, the whole network could be unsecure, allowing for access to other computers connected to the network.
  • Untracked data: If you share a document with another person, and they then share it with others, there is potentially, an unlimited amount of people that can get the data. If you want to take it back, it can be impossible to do so, even if the original document is deleted.
  • Storage hijacking: There’s news of malware that has been developed with the purpose of downloading illegal material onto your hard drive. This could pose a problem if the data is found, as you will be liable.
What Should I do? With regards to cloud services, as with anything that comes with a contract, the first thing you should do is gain an understanding of it by utilizing reading material such as blogs, news articles and Wikis. It’s a pain in the neck, but it’ll help you understand the boundaries of the program and your responsibilities. Remember that if you go to court to get files back from a company, and it becomes known that you didn’t read the agreement, you’ll probably end up losing that case.

Second, it’s not recommended to keep single copies of data on one cloud service. Chances are high that in your business, you store your data and backups in a place separate from the computer. This makes sense with the cloud as well - keep your data with a number of different cloud services. If it’s important enough, have physical backups of what you put in the cloud.

For P2P networks there are also a number of steps you can take to protect the data on your network:

  • The most obvious one is to ban employees from using any file sharing services outside of your network.
  • If you do allow file sharing, it’s a good idea to establish and strictly enforce a protocol for this. You should also set which users are allowed to share files, and what files are appropriate to share. Be sure that all staff are aware of your policy and the measures that will be taken in the event of any deviations.
  • Develop a system to classify documents by whether or not they can be shared, and who they can be shared with.
  • If you work in an office where you need to share files, but don’t want to use a P2P network or the cloud, and are unsure of other solutions out there, don’t worry. There are companies that specialize in document sharing solutions that should be able to provide you with assistance.
The most important thing is that whatever the situation is, you take action to try to solve the problem while frequently revisiting the actions to ensure that they are working. If you’d like to learn more about document sharing over the cloud, or via P2P networks, give us a buzz. We’re more than happy to help.
Published with permission from TechAdvisory.org. Source.

April 10th, 2012

Do your employees want to BYOD? That is to say, “Bring Your Own Device” to work? If you answered yes, you are not alone. This is a rising trend that’s causing many companies to consider implementing BYOD policies. The issue isn’t going to go away anytime soon, but there are some things you should be aware of before you make any decisions.

When employees use their own device for work, it can be hard for their company to manage what the user is doing, after all it’s a personal item. Add to this the growing number of malware programs aimed at stealing information from devices, and you’ve got an issue that’s not going to go away anytime soon.

What Exactly is BYOD? BYOD came about when businesses began to assign laptops to employees for use at home or on the road. Companies quickly came to realize that the laptops were not as secure as the desktops at the office, and that employees were also using the laptops for personal use. To address this, companies introduced security measures and procedures to keep data on the laptops safe, while limiting personal use. This worked well until the introduction of the smartphone, which has now given employees the ability to access their office data on their personal devices, and has moved them off the machines provided by the company. Because of this trend, companies are being forced to examine or implement a BYOD policy.

Pros of BYOD The most obvious benefit of BYOD is the fact that the cost of the the technology is shifted from your company to the user. Think about it: no more costly hardware upgrades and minimal to nonexistent upkeep costs, thus bringing about significant savings.

The next upside to BYOD is user satisfaction. If your employees are allowed to use their own devices, they’ll generally be more satisfied with the systems they’re using, because they’ve already made the personal choice to buy that particular device.

There are some ancillary advantages to BYOD as well, including having employees on the most up-to-date systems, as many employees will buy newer, or top of the line models. The other advantage is that the usually slow update cycle can be exterminated, employees will be in charge of keeping their devices current, not the company.

Cons of BYOD As with all stories, there are two sides to this one. The biggest disadvantage of BYOD is that you’ll lose control of the hardware, and employees will generally be more reticent in allowing other employees to use their device.

Another major issue to overcome is usage policies. As employees will be using their own device, it’ll be harder to tell them what is considered acceptable use. As opposed to when employees are using company devices you can implement a fair-use policy.

The final negative side of BYOD is of what happens when an employee leaves your company? If they’ve been using their own device it can be a chore to get the data back, let alone establish who owns the data in the first place.

So What Can I do? If you take a step back and observe, you’ll notice that smartphones are becoming more and more mainstream, and while in the short term you could say no to personal devices at work, it won’t work in the long term. It would be beneficial if you developed a BYOD plan that clearly states your expectations, and has a usage policy regarding network and data use. You don’t have to implement it right away, but it’ll help to have the plan ready, for when you do decide to allow employees to use their own devices. You could also set up a trial with some employees, observe how they get on with the devices and reevaluate your position after the trial period.

You should also establish a set point of security measures that are not optional. This is particularly important for companies that operate under set data security mandates, e.g., mandates regulating data storage in relation to point of sale and credit systems. Methods of increasing security include software that must be installed, and basic security measures such as a locked screen, or regular data backup.

It is also important to establish a process for when an employee leaves your company. Set up a policy regarding who owns what data and the steps to be taken at the end of employment. If your employee uses a device with a removable memory card, you could set up a partition - mini non-physical hard-drive within the larger physical hard-drive - on the card where data from the business is to be stored, allowing for easy access and retrieval.

Should your company go BYOD, or abstain? Be aware that this is a major trend and in the near future employees will start to push to use their own devices at work, if they haven’t already. If you’d like help setting up a BYOD plan or more information concerning security measures, please contact us.

Published with permission from TechAdvisory.org. Source.

April 2nd, 2012

A common trend among new software is in giving users the ability to personalize certain areas. This could be something as simple as adding your picture or changing the layout. Many programs that have traditionally been utility in nature, such as office suites, are starting to offer ways for users to customize. Microsoft Office 365 is one of those such programs offering these features.

Microsoft Office 365 is first and foremost a suite of familiar office software for businesses to use in their day-to-day operations. But just because this software is instantly recognizable as a Microsoft product, it doesn’t mean that you can’t make some small changes to personalize your computing workspace. Here are a few ways you can do just that:

Set Your Profile Picture You can set a profile picture which will show up on any window or application that has the ability to show your image - e.g., Microsoft Lync. To set your picture:

  1. Log into Office 365 and go to the Home page.
  2. Click the My Profile header. It’s located in the top right hand side of the screen, underneath your name.
  3. Click Change Photo.
  4. Choose your photo by selecting Browse. It’s recommended that your picture be under 100kb in size, you’ll get an error message telling you if it is any larger. When you have selected your picture, press Save.
Add a Signature to Your Emails Many business emails include a signature at the bottom, a way to make each email seem a little more personal, or provide more information including contact details and a potential message about an upcoming promotion. To set your signature:
  1. Navigate to the Outlook page, click on Options. It’s located in the top right hand side of the screen, underneath your name.
  2. Click See all options from the drop-down menu that opens.
  3. Select My Account, followed by Settings which is located in the left hand menu.
  4. Under the Mail Tab, you will have an option to edit your signature. If you want Outlook to automatically place your signature on every outgoing email, click the radio button below the signature that says Automatically include my signature on messages I send.
If you don’t choose to have Outlook automatically add your signature, you can add the signature in your email by selecting the Messages Tab in each new email, and clicking the little arrow below Signature. A list of created signatures will be shown, select the one you wish to use.

Add Your Picture or Logo to Your SharePoint Site If your company uses SharePoint, you can add a logo or picture to enhance what is a relatively plain environment.

  1. First, you need to create an image. You can use almost any picture, just ensure you can legally use it. Get creative, this is your space!
  2. When you have the image you want to use, open SharePoint, click Site Actions and select More Options.
  3. Select Picture Library, and in the window that opens, select a name for a new library, and press Create.
  4. Your new Library should be on the left side of the screen. Click to open it and select Upload.
  5. When your picture shows up in the library, select it twice, so it’s in its own window. Copy the web address from the top of the page.
  6. Under Site Actions select Site Settings followed by Look and Feel.
  7. Beside Logo URL and description paste the URL you just copied. Click Ok and your image will show up on your SharePoint site.
With a few steps you can make Office 365 a little more personal. Just be sure that you can legally use the images you select. If you would like to learn more about Microsoft Office 365 or any other Microsoft products, give us a call.
Published with permission from TechAdvisory.org. Source.

March 24th, 2012

For those on the go, and out in the field, smartphones are extremely useful in maintaining productivity and communication - efficiency doesn’t have to suffer just because you’re on the move. It is important though, that businesses effectively manage these resources, and the usage of mobile devices properly.

Using smartphones for business purposes can indeed lead to increased efficiency and improved productivity, but if left mismanaged and unregulated, smartphone usage can cause more trouble than it’s worth. Here are a few tips to help you get the most out of mobile devices:

  1. Formulate a Specific Policy For IT: One common mistake many businesses make is that they lack a policy specifically for the use of mobile devices. This is where you determine whether employees can use their own personal devices for work or not, indicate reimbursable expenses and other costs, and control networks where business-purpose devices can connect to.
  2. Have a Security Action Plan: Data security is a major issue for any IT device, especially one that employees can take outside of the office. It is then imperative that any device used for business has the proper security to protect it from online attacks, and remote access features that allow it to be completely wiped, or “bricked” if said device is stolen.
  3. Consider Developing Your Own Applications: Customized applications that employees can use for their business needs can prove to be much more secure, and more efficient than other third-party apps. As they’re made specifically for you, you can be sure that tasks done through mobile devices and the corresponding output are better tailored to fit into your organization’s work flow.
If you would like to know more about how to better manage the use of mobile devices for your business, please don’t hesitate to get in touch with us. We’d love to sit down with you and discuss a possible blueprint that addresses your business’s specific needs.
Published with permission from TechAdvisory.org. Source.

March 23rd, 2012

“Cybercrime”, “malware”, “hackers”. Three common buzzwords that have caused businesses untold amounts of lost profits, breached data and so on. As much as we would like to say that cybercrime is being eradicated, we can’t. It isn’t going to go away, but if you are aware of the common cybercrime trends, you can take steps to protect your business.

A quick Google search for “cybercrime trends” yields over 78 million results, the majority of which are likely to affect large enterprises or governments. While it is beneficial for all businesses to be aware of the major trends, there are a number of threats that will affect small businesses more than others. Here are some current cybercrime trends that SMEs should be aware of.

Mobile Malware Smartphones are becoming ever more popular, and with this popularity has come an exploding number of apps. Malware developers have been picking up on this during the past few years and there have been an expanding number of apps dedicated to attacking your phone or mobile platform. The most common type of malware on mobile devices is spyware, followed by SMS Trojans. SMS Trojans run in the background of some applications, and make international calls or text messages from the developers’ services causing huge phone bills. The final form of malware targets online payment apps on the phone.

One of the main reasons this form of malware has become so popular is due to the openness of some markets, such as the Android Market. The owners of the app markets are working to track down and get rid of the guilty apps on their marketplaces, but you still need to remain vigilant. while installing apps. Look at the developer of the app - how many times has it been downloaded? Maybe double check the app’s integrity online before installing and double check the app on the internet.

Open-Source Malware Kits A common thing malware developers do is write code for malware and then sell it to interested buyers. But a rising trend is that developers are writing malware that is open-source—any person can download and change it. The worrying thing is, many developers of already powerful malware have been releasing open-source versions of their software. This means that there will be an increase in the number of malware attacks out there, as devious developers can easily come up with more elaborate hacks.

Banking Trojans Along with the open-source malware kits, there has been an increase in the number of banking trojans—aimed at stealing account information and passwords. While these trojans have been a threat ever since banks first started offering online banking, they have become popular again as people and businesses are starting to move their online banking onto mobile devices, and the trojan software is easily accessible. This makes mobile banking apps an easy target.

With cybercrime on the increase, now is a good time to review your security, ensure its up to date and remind employees of your mobile device policy. If you don’t have a policy in place, or feel that your security is inadequate, give us a call, we are happy to help you. Remember: with good security and knowledge, there is no reason you should fall victim to cyber theft.

Published with permission from TechAdvisory.org. Source.

March 21st, 2012

Many businesses have come to rely on both internal and external technology networks for day-to-day operations. If there is a problem with a network, a small business can lose more than just profit—with a large enough outage the business could go under. 24/7 networking can help prevent this from happening.

How can 24/7 network monitoring help your business, you ask? Through preventative operations. The main idea of network monitoring is to act as an “Early Warning System” to let managers and owners know of potential problems before they strike.

What Does Network Monitoring Monitor? There are a number of things you can monitor with Network Monitoring. The most popular areas include application and system performance, bandwidth usage, and server status. You can also set up monitoring of additional areas, for instance: server load, ink levels in printers, time left on software license agreements, which devices are connected to the network, their data usage, and more. This is all done 24/7.

The one thing Network Monitoring does not normally monitor is unauthorized access to networks. It can be set up to look for unauthorized access, but this is normally taken care of by another system.  

How Does Network Monitoring Help Me? Network Monitoring is a preventative system, intended to warn you about potential network problems so you can proactively seek solutions before a vital network goes down. This makes it, in a round-about way, a justifiable addition to business value since, when implemented right, there will be less network crashes—which means less or no profit loss.

What Should I Monitor? In an ideal world, you would monitor each and every network. Over time, you can get there, but if you’re like most Small Business owners or managers, you have neither the time nor the budget to implement a full system. As with most projects, it’s suggested that you implement a system like this in stages. The most common areas to start with are:

  • Local Area Network (LAN) Data
  • Internet data usage
  • server status
  • alerts to existing networks
If you’re unsure of where to start, try contacting a local Network Monitoring service, or hire a consultant to establish a system. If you would like to know more about 24/7 Network Monitoring, or other ways to improve business value, please contact us.
Published with permission from TechAdvisory.org. Source.

March 20th, 2012

Virtualization. Many business owners know exactly what it is and what their companies are doing in regard to it. Whether your company has virtualized some or all of your business, it’s evident that there are cost savings. A recent report found that some organizations have achieved up to 269% return on investment from the process. Read on to learn how.

What is Virtualization? Virtualization is the creation of a virtual computing environment, where one hardware system can run multiple virtual environments. Common types of virtualization include servers, storage devices, or networks. The benefits of virtualization include lower costs, improved IT management, and reduced energy consumption.

The Survey A report published by CDW-G focuses on government organizations in the United Sates. Many SME owners and managers like yourselves are probably asking, “How do study results involving the government help my business?” Well, if you look closer you can see that what the government organizations did can easily be replicated by SMEs, just on a smaller scale.

Results In recent years, many companies have had to tighten their belts due to economic difficulties. Government agencies are no exception. The results of the survey found that agencies and organizations realized investment returns as high as 134 to 269%. The survey found that if IT managers invest in Server Virtualization, Document Management, Storage Virtualization, and Cloud Computing in that order, the returns on Server Virtualization alone can help pay for, if not totally cover the cost of, the other three processes. CDW-G found that on average, the total cost of implementing all four separately is over USD 1.1million, but when implemented in order, the average cost was around USD 400,000.

While it is unlikely that SMEs will see a return on investments of this magnitude, it is highly likely that they will see increased returns if they follow this method of re-investing returns from Server Virtualization into the other three steps. In times of economic stress, this could be a huge boost to your bottom line.

Helpful Recommendations From the results, CDW-G offered some useful recommendations that all businesses can use:

  • When budget cuts are needed, first look for ways to increase efficiency without service cuts.
  • Review technologies and processes to identify inefficiencies.
  • Consider savings and efficiency opportunities in all new solutions.
  • Leverage available savings into new projects.
As with any new process, it’s equally important to ensure that you educate the users of the processes and stay on your toes to keep updated.
Published with permission from TechAdvisory.org. Source.

March 19th, 2012

In the past Business Intelligence (BI) software and practices were limited to MNCs and large enterprises. With the growing number of SMEs, BI software and system developers have been turning out many useful products for SMEs. Is your company planning on implementing BI practices?

If you are looking into integrating Business Intelligence at your company, no matter what system you choose or the size of the project, there are a number of things you need to be aware of in order to make the implementation successful.

4 Things to Know before You Start Before you start any BI project, there are 4 key BI implementation areas that you and your company will need to be clear on:

  1. Data or Information: In most SMEs there is a limited amount of data available, so you need to be sure where all the relevant data is located. This typically includes client and employee information kept on accounting systems, spreadsheets or contact manager databases, sales or business reports, industry and competitor information, and more.
  2. Technology: A large number of BI programs require technical systems that are stable and have minimal downtime. It’s a good idea to ensure that your systems meet the requirements and are stable. As with any software, be sure to do your homework and pick a system that is reliable and compatible with your business. Don’t just pick the cheapest system – pick the system that best meets your needs.
  3. Knowledge: Many SMEs have employees that wear more than one hat, and as such may not be experts in any one thing. It’s important that, when implementing BI, you have employees who understand it and the related systems. If you don’t, there are many qualified BI consultants out there you can turn to for help and training.
  4. Communication: It’s crucial that you have constant communication with the employees involved in the implementation, and that you explain what BI is, the analytics used, how to interpret what the results mean, and the actions to take.
Your Criteria To Success Once you have picked a good system, there are a number of criteria you should aim for to ensure successful implementation:
  • Align Business and Technical: It’s important that the business side of your company knows about the implementation and will actually use it. Both sides need to work together to ensure an aligned team.
  • Piece by Piece: It’s a good idea to not implement BI across your whole organization in one go because that involves far too much work and complication. Instead, look at the areas of your organization that could benefit the most from BI and start there. For the majority of organizations, Customer Service and Sales are a good choice.
  • Ease of Use: Chances are, your employees do different jobs and won’t concentrate solely on BI. Therefore, you might want to pick or develop a system that is easy to use. As a benchmark, pick a sales or business manager and, if possible, a business analyst, and see how long it takes them to learn the system. The bigger the gap between the learning time of these employees, the harder the system is to use.
  • Flexibility: It’s common knowledge that your business is always changing. Therefore, It’s a good idea to ensure that the BI system you choose is flexible and can be quickly and easily adapted to meet changing needs. If you have a rigid system, it will be successful in the short term, but a nightmare or even a failure in the future.
With planning and patience, BI will bring about an improved business and bottom line. If you would like to learn more about BI or would like help implementing it please contact us.
Published with permission from TechAdvisory.org. Source.

March 15th, 2012

Technology and software: two things many business owners and managers use on a daily basis. The majority of people in business have some knowledge and comfort working with computers, but when the software they are using stops working there’s a “What do I do now?” moment. Does it have to be so frustrating?

The answer is: No, it does not have to be. Microsoft Office 365 is a good example of a suite of programs with a strong background of troubleshooting and support resource data bases. If you have a question or problem while using Microsoft Office 365, there are a number of ways you can get the problem solved.

  • Troubleshooting Tool:  This tool should be the first place you look when you have questions or need support. When you go to the page you will asked four questions and presented with links to solutions based on the answers given.
  • Office 365 Community: The community, run by Microsoft, provides information on all aspects of Office 365 with the majority of the information being provided by users of the various products. This community also has information on updates and commonly asked questions. It’s a good idea to check with the community to see if there are any other users who have had the same questions or issues as you.
  • Office 365 Technical Blog: If you can’t find answers on the Community page, try looking at the Technical Blog. The blog is run by Microsoft engineers and is a direct link to the developers of the product you are using. Any answers to questions on this blog will often be straight from the source with the answers usually being more on the technical side with lots of explanations or update information.
  • Tools and Diagnostic Wiki: This is a wiki article that covers products in the Office 365 suite. Think of this as the umbrella section that covers troubleshooting of all issues, while providing you with links and updates related to troubleshooting. You can search issues based on product plan, specific products, services, and more. If you are having a problem not covered by the other resources, chances are you will find the answer here.
With comprehensive coverage and a number of different places to go to when you have questions or a problem, you should be able to get back on track in no time. Please contact us if you would like to know more about Office 365 or any other Microsoft products.
Published with permission from TechAdvisory.org. Source.

March 14th, 2012

One of the enemies of the IT department is the hacker. Hackers have always been a problem and continue to keep IT staff on their feet, and now there is a new hack out there that goes after your business’s banking information. Be aware that this hack is one of the most ingenious hacks to date and could cause widespread problems for your business.

The hack, a variation of the Man-in-the-browser (MITB) hack, is a form of Trojan horse that mainly infects a Web browser and has the ability to change a Web page, insert orders or transactions covertly. The user will not notice any change to the website. This particular hack infects user’s computers with a Shylock malware program, a new form of malware that focuses on bank accounts and financial transactions.

The user goes to a banking website, attempts to log in and is given an error message stating that security checks are being undertaken. After a few minutes a window pops up telling the user that a representative from the bank will be contacting them to go over their account details. A chat window will open up and the “representative”, who is really the hacker, will ask the user for their account information. While the user and hacker are talking, the hacker will log into the account and proceed to go to town, so to speak.

At this time, it seems like the hack is not widespread, but it is spreading, and it is one of the more sophisticated programs out there. To learn more about this or any other security threat that may have you worried, please contact us.

Published with permission from TechAdvisory.org. Source.