Showing posts with label cyber security. Show all posts
Showing posts with label cyber security. Show all posts

Tuesday, February 7, 2017

Online Security - Best practices to protect your small business from internet threats

No one is excused from cyberattacks. Even your small business could fall victim to one attack or another. With all the important sensitive data you have involving your clients and staffs; the repercussion of a breach can be serious and frightening. For this reason, it is necessary to take precaution, establish rules and measures to use against attacks over the internet.

Here are some of the most important steps every small business should be taking to protect themselves from cyberattacks.

• There are a number of ways files can be lost unexpectedly, this is why it is important to frequently backup data. Save it in a secured remote location in case anything goes badly wrong with your computer.

• Choose the best security software that can:
- catch viruses and Trojan horse programs
- control spam that may contain malicious code or links
- detect financial hacking techniques

Many security software are available on the market. Make sure to install it on every PC and server running and up-to-date.

• Protect your network with a firewall to control internet traffic coming into and flowing out. You need to use a firewall whenever you go online to provide protection from unsafe internet sources.

• Implementing a strong password is the easiest and simplest way you can do to strengthen your protection. You should definitely avoid using your personal data in creating a password and consider setting a password protection policy where you can make user passwords expire after a certain number of days.

• Computers and electronic devices must contain passwords and stored and lock in a safe place. They contain highly sensitive data, thus, securing them is a must. In addition, limit the people who have access to records and ensure that they understand the sensitivity of the data they work with and their role to make it safe and secure.

• Stored paper receipts with personal and financial information shouldn’t be kept for a long time in your cabinet if it is no longer needed. Buy a paper shredder and shred those papers instead.

• Do not underestimate the importance of physical security. Get a surveillance camera and an alarm system to protect your personnel, hardware, and data from physical actions and events that may cause severe loss or damage to your business.


• Establishing IT security policies is essential to a company’s health. It must contain rules and measures that target the prevention and elimination of the common kinds of internet attacks that may threaten the company. Make sure that your employees will understand and follow each guideline and you yourself should set a good example to everyone else in the business.

Tuesday, January 31, 2017

Cyber Security - How to Minimize the Risk of Becoming a Victim of Identity Theft

The technology today provides new ways for cybercriminals to steal personal and financial informations to commit fraud. As authorities continue to create and improve cybercrime fighting tactics, the methods used by criminals to steal identities evolve over time as well. Below are some ways to defend yourself against attacks.

1. Many people have many different online accounts which use the same one, two or three passwords. This is the common mistake for many people as it makes them more vulnerable to cyberattacks. Do not use obvious passwords that can be easily guessed by cybercriminals and frequently change your passwords on each account.

2. Cybercriminals will definitely send emails pretending that they are from the bank and will require you to input your personal and financial details in one of their bogus websites. If this happens, ignore the message. If the email truly bothers you, call your bank instead.

3. Frequently check your financial reports for unquestionable transactions. Contact your bank immediately if you found one.

4. Shred your documents by using a paper shredder before dumping them all in the trash. Cybercriminals might obtain important information if you don’t properly dispose those receipts and bank statements you have.

5. Request for a compilation of all your credit transactions. Examine those credit reports for wrong details and quickly report it to your bank if there’s any.

6. If you notice questionable transactions on your account then file a "Fraud Alert". A fraud alert can make it harder for identity thieves to open more accounts in your name because it will require verifying your identity first before it issues credit.

7. Do not bring your Social Security card outside if it isn’t necessary. Unexpected things may happen, it is better left at home.


8.  Identity thieves can make a way to recover all your deleted files from a formatted hard drive, so it is better to completely remove data on hard drives using different ways available on the market.

Thursday, January 12, 2017

The Top Cyber Security Risks in Asia-Pacific In 2017


Cybercriminals will continue to innovate through ransomware

The malware business is a business like any other: cyber threat groups compete and innovate, with the most successful growing and spreading rapidly. Given the success of ransomware in 2016, we will see a continuation of ransomware attacks – with new innovations emerging and propagating, according to whichever attracts most payment.

2016 saw real innovation in the ransomware market, with a particularly interesting recent variant called ‘Popcorn Time’ that allows the victim’s files to be decrypted for free if they can infect two other people.

Commoditized versions of ransomware will, however, be a less pervasive threat for large corporations, as they gradually improve the management of this threat and their ability to mitigate it. Rather, criminals will target high-value assets using more sophisticated and innovative ransomware variants, and will develop additional functionality to seek out more lucrative individual targets within organizations, to enhance the chance of victims paying ransoms. Criminals will extort victims not only by threatening to deny access to data, but also by threatening to publish sensitive data.

Website defacements will be old school – website ransoms will be the new tactic

One specific kind of attack we expect to grow is website ransomware, where the contents of websites are targeted. This trend started emerging in Asia last year:

• In November, several websites were found to be compromised and their web contents encrypted by a ransomware variant called JapanLocker. Control Risks’ research into this variant reveals that it was developed by a hacker known as Shor7cut, a member of the Indonesian Defacer Tersakiti group. This group is well known in the Indonesian hacking community and has more than 22,000 members.

• In October, several Pakistani government websites were compromised and their contents encrypted by the CTB-Locker ransomware. The hackers, believed to be from the Indian group known as Hell Shield Hackers, used this method to retaliate after Pakistani hackers breached nearly 7,000 Indian websites.

• In March, a ransomware variant known as KimcilWare was spotted targeting websites running the Magento eCommerce platform. This variant is thought to have been developed in Indonesia.

• Also in March, Kaspersky Lab detected more than 70 servers, located in ten countries, compromised by the CTB-Locker ransomware. Most of the victims were from the US; this shows how threat actors in Asia Pacific are taking successful tools from other regions, adapting them, and applying them in their own region.


Such attack techniques will continue to emerge and evolve in 2017. We foresee further ransomware variants of this kind being developed by threat actors in Asia Pacific, and used for cyber activist and cybercriminal activities in the region.