IRAN AND CYBERSECURITY
This is not a political treatise… By Thomas Andersen President TRA Consulting, Inc. In the regional conflicts involving superpowers, a lot of companies large and small get caught in the mix. If you have been following the news at all, you know that the USA and Iran have been in an escalation of words and actions lately. I am here to remind you that from a cyber-security threat aspect, Iran is actually one of the most prolific state-sponsored cyber-security threats in the world. When regional conflicts flare up, it is common for us to see the number of cyber threats spike. Because cyber threats are harder to trace than real world threats, state-sponsored actors love to ratchet up the attacks. They cause a lot of damage to businesses and economies, and gain the attackers a big foothold in the target. In the case of the current conflict, the US can expect to see 2020 as a big year for continued attacks mainly coming from Iran, Russia, China, and North Korea. Have you done your due diligence in securing your network? all of your data backed up, on-premises and in the cloud? sufficient coverage? Do you have a competent IT company proactively monitoring your network? When you need them, does your IT company respond to emergencies quickly? If you answered no to any of the questions above, you might want to give us a call Visit our website here: https://traconsulting.com/ Call Us for a free analysis here: (562) 551 8TRA Check out our LinkedIn here: linkedin.com/company/tra-it
O365 SUPERIORITY OVER GSUITE
I’m a little partial, but that doesn’t change the fact… By Thomas Andersen President TRA Consulting, Inc. In the war of email providers, let’s get real. If you are running G-Suite, you are doing your company a disservice. It really just isn’t that good. Let’s go through some of the technical basics. Security: By default, O365 has SPF turned up, Native DKIM servers, better logging features, and more granular security controls. For an added fee, DLP protections with standard legal templates, Anti-Phishing and Anti-Malware protection, litigation archiving and litigation discovery. Pricepoint: on a per-user-basis, apples-to-apples, O365 is slightly cheaper. Communications and Chat: O365 has Teams, which is the fully-featured successor to Skype for Business. G-Suite has Google Hangouts (Who is in charge of the marketing here?), which fully integrates into the Outlook applications and mobile presence. Collaboration: Have you ever tried to migrate out of Google Drive? Good luck. Microsoft’s Sharepoint 365 is a cloud collaboration tool with a more linear backend with a more diverse application suite for more functionality in the cloud. For your IT department: Don’t get me started about the beauty of PowerShell and how beautifully O365 integrates into your domain via ADSync for Windows Server for true Federation and SSO. Your IT department will thank you for the amount of time you save them in spinning up and down users within your organization, and sync users and logins across all their devices. If you are running a serious business, and if you want to streamline the way your users work and communicate, decrease the cost of supporting the organization, and increase productivity; there is no better platform in town. Talk to us and see what Microsoft O365 can do for you. P.S. if you are really in love with G-Suite for business and dead set to stay in the Google ecosystem, we can support you too. We can help you overcome some of the challenges of the platform and still integrate some of the natively missing features and security in G-Suite. Visit our website here: https://traconsulting.com/ Call Us for a free analysis here: (562) 551 8TRA Check out our LinkedIn here: linkedin.com/company/tra-it
MINI COMPUTERS OR WORKSTATIONS?
Do you like to save money? By Thomas Andersen President TRA Consulting, Inc. Let’s talk bottom line. As a guy who is a technician at heart, I want you (my customer) to have THE BEST experience possible at work. I want you to work efficiently. I want to decrease downtime. I want to boost your productivity. But as a purchasing decision-maker at your company, having the latest and greatest endpoints may not be in the cards. The cost of hardware has been decreasing dramatically; especially over the past 10 years. We have all seen this phenomenon play out. There is a class of PC that has been gaining steam recently, which brings your potential price point even lower. Enter, the mini-PC. Word to the wise: this class of PC is not meant for critical functionaries. It is not for your marketing and accounting department. Your CEO will kill you if you put this on his or her desk. It is appropriate for Kiosk and front desk staff who perform non-resource-intensive work, mostly in the cloud. That is the best way I can define the use case for these machines. With a starting price of $100-$300, these machines are cheap, easy to replace, and space saving devices which can decrease the cost of pre-configuration and replacement; and nearly eliminate the shipping cost to satellite locations. The super-low price point enables you to stock up on extra inventory in case of outage. They are easy to image, and they usually come preloaded with Win 10. Interested? Reach out to us and let’s see what we can do about turning a cost-center into a margin-saving endeavor. Visit our website here: https://traconsulting.com/ Call Us for a free analysis here: (562) 551 8TRA Check out our LinkedIn here: linkedin.com/company/tra-it
WINDOWS 7
WINDOWS 7 End of Life Jan 14, 2020 I like Windows 7. I’m old fashioned! By Thomas Andersen President TRA Consulting, Inc. Look, I really hope this isn’t the first time you are hearing about Windows 7 End of Life (EOL); but it may be time for me to throw my voice into the ring. You have to give it up. No, you can’t keep it. Yes, I know you like it. Yes, I understand how painful it was to switch from Windows ME to Windows 7. All jokes aside, the issue at stake is security:– 7 is outdated– It is a 10 years old operating system, running legacy programs that have been discontinued– The architecture of newer computers has changed significantly to the point that some of the newest security features are not applicable to Windows 7– Most importantly, Microsoft has a sustainable contender in Windows 10 to pass the torch to Many people are not aware of this, but some embedded versions of Windows 7 have already been discontinued (such as Windows 7 POS Ready, discontinued in 2016). In instances of these embedded OSes, some companies may be behind the ball by a series of years. What is at stake when Jan 14, 2020 comes and goes? Well, it is very likely that your PC or PCs will become sitting ducks, with nothing on the OS being further patched beyond the date. If you are running PCLs, POSes, or Handhelds with embedded versions of Windows 7, watch out even more. These legacy devices have even less security than your desktops in many cases. We can all see what happens when users use devices at the varying levels of skillsets they possess. Let’s take a look at the City of Baltimore Ransomware attack: https://en.wikipedia.org/wiki/2019_Baltimore_ransomware_attack Let’s also take a look at a more recent attack on the City of New Orleans: https://www.bleepingcomputer.com/news/security/new-orleans-suffers-ransomware-attack-emergency-services-intact/ You may save a few dollars by not upgrading. But do you really want to change your security on a few dollars? Do the right thing and upgrade or replace it. Call Us for a free analysis here: (562) 551 8TRA Visit our website here: https://traconsulting.com/ Check out our LinkedIn here: linkedin.com/company/tra-it
Tips to Secure Your Network
This is by no means a be all, end all guide… I am writing this blog article because I want to give whoever reads it a few easy-to-implement tips to secure their network against attack. You can implement some of these strategies yourself, if you are a do-it-yourselfer and feel confident in your abilities; or you can task your current IT provider for help with executing it. Most of these changes are not too expensive to implement in terms of hardware, software, or labor. First, some strategy. The best sort of defense to have is one we refer to as defense-in-depth. In other words, there is no be all, end all solution to security. The best way to make the job of an attacker difficult is to make the potential attack more complicated.
Learning and Constant Improvement
As an IT professional, I spend most of the year working within my comfort zone. Mitigating realized threats and potential threats; training and coaching my staff; developing relationships; doing project work; working with vendors and partners. I really enjoy what I do. The life of an IT Pro never gets dull. On the flip-side, it is easy to get complacent, stuck in the comfort zone, and eventually get left in the dust. This is where I insist that all my employees take the time to study and grow. Growth comes in many forms:
Do I Know You?
Insider Threats There are a lot of opinions about hackers – who they are, what they want, where they come from, how they do what they do, what recourse we have. But what kind of thought is given to the “Insider Threat”? What’s the big idea? It used to be that the only thing between you and your attacker was the perimeter of the network. Once the attacker got through the perimeter, it was GAME OVER. We practiced defense in depth, and did our best to keep the outside world OUT. The dynamic of the traditional network has changed radically in the last decade. We are doing more and more work OUTSIDE the traditional network. The Internet of Things (IoT) has put more network capable devices inside our networks. Insider threats from disgruntled and malicious employees/contractors are ever-present. We are outsourcing our internal infrastructure to cloud providers. Here is something to think about – the most successful attackers look EXACTLY like an insider. That means the best attacks are staged from inside the network, or using methodologies that disguise attacker as a privileged network user. Just look at these statistics from Gartner which highlight who is letting the “bad guys” in: What are the big gaping holes in the network perimeter? VPN EMAIL RDP DNS HTTP (internet traffic) The perimeter of the network is not what it used to be. It barely exists. Work is being done inside and outside the organization, using services that are a hybrid of inside and outside infrastructure. The modern network is designed to allow the worker access anything they need to do their work, from anywhere, at any time, with any device. Let’s address the new world risks. Deperimterization, Zero-Trust Model. It needs to be given that ANYONE can be a vector for attack at any time, anywhere. Don’t trust anything just because it is “inside” your firewall. 81% of breaches involve stolen or weak credentials. 70% of breaches involve compromised devices. We need to address the users, devices, and we need to layer security from the edge, to the endpoint. Modern security needs to involve complicated passwords, multifactor authentication, and endpoint protection; in addition to traditional edge protection. In the event that something is compromised, cloud and local backups need to be available. Users need to bound to known, trusted devices; and devices which are new to the network need to be segregated from sensitive network resources. Talk with us to see how we can secure your network and help you cope with the ever-evolving threat-landscape. Visit our website here: https://traconsulting.com/ Call Us for a free analysis here: (562) 551 8TRA Check out our LinkedIn here: linkedin.com/company/tra-it
The UNLV-UNR Cooperative Farming Project
Giving Back To The Educational Community The UNLV-UNR Cooperative Farming Project Not a case study, but a brief overview A few months ago, TRA Consulting, Inc. participated in a project to retrofit a cooperative agricultural venture of UNLV-UNR with a modern and robust outdoor WiFi system which would cover 13 irrigation timers scattered around the property. They had previously been tending to the irrigation timers manually. The 13 irrigation timers were located at various distances from the main office. Some were as close as 50’ and some were as far as 1000’ The purpose of the cooperative farming orchard is to study the effect of irrigation on desert plants that yield fruit; and to study the best methods to growing these plants using the least amount of water. In order to do this, irrigation timers must be adjusted regularly, and data must be recorded constantly. The study is still ongoing and will be long into the future. At the time we started planning this project, the date was February, 2019. We executed our plan in May, 2019 to great success. At the time of the writing of this blog article, the staff of the orchard have an easier time adjusting the watering schedule of the orchard, and also of recording data. We volunteered our time to work on this project so we could put our skills to the test and so that we could impact our community in a positive way. Here is a letter from the manager of the UNLV-UNR Cooperative: Here are some photos of the main office antennas, the orchard, and the team: Is your company looking to deploy an outdoor WiFi system for any reason? There are many options out there, many pitfalls, and various levels of complexity; depending on the use-case. Reach out to TRA Consulting, Inc. today to plan your next project! Visit our website here: https://traconsulting.com/ Call Us for a free analysis here: (562) 551 8TRA Check out our LinkedIn here: linkedin.com/company/tra-it
Phishing Defined
Phishing is the fraudulent use of electronic communications to deceive and take advantage of users. Phishing attacks attempt to gain sensitive, confidential information such as usernames, passwords, credit card information, network credentials, and more. By posing as a legitimate individual or institution via phone or email, cyber attackers use social engineering to manipulate victims into performing specific actions—like clicking on a malicious link or attachment—or willfully divulging confidential information. An attack can have devastating results. For individuals, this includes unauthorized purchases, the stealing of funds, or identify theft. An organization succumbing to such an attack typically sustains severe financial losses in addition to declining market share, reputation, and consumer trust. Depending on scope, a phishing attempt might escalate into a security incident from which a business will have a difficult time recovering. How to prevent phishing The best way to defend yourself against phishing attacks is to identify phony emails before you click on them. Phishing attack protection requires steps be taken by both users and enterprises. Here is a video we made explaining 5 tips to help you to prevent a phishing attack: Protect yourself with help of experts Cybersecurity is best handled by the pros. By outsourcing your security services, you can have an entire IT team working on your behalf. The monitoring, updates, and cloud systems offered will ensure that your company stays safe. At Tra Consulting Inc. We take pride in providing our clients with the best cybersecurity measures available Contact us today to do your due diligence and achieve an excellent cybersecurity posture. Visit our website here: https://traconsulting.com/ Call Us for a free analysis here: (562) 551 8TRA Check out our LinkedIn here: linkedin.com/company/tra-it