<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Best Practices Archives - Foster Institute</title>
	<atom:link href="https://fosterinstitute.com/category/it-best-practices/feed/" rel="self" type="application/rss+xml" />
	<link>https://fosterinstitute.com/category/it-best-practices/</link>
	<description>Cybersecurity Experts</description>
	<lastBuildDate>Tue, 30 Jun 2026 02:23:07 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://fosterinstitute.com/wp-content/uploads/2021/02/Favicon.png</url>
	<title>IT Best Practices Archives - Foster Institute</title>
	<link>https://fosterinstitute.com/category/it-best-practices/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>An Executive’s Guide to Demystifying and Understanding the Four Families of AI Tools</title>
		<link>https://fosterinstitute.com/four_families_of_ai_tools/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Sun, 21 Jun 2026 14:29:57 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Technology Safety Tips]]></category>
		<category><![CDATA[Technology Tips]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=6216</guid>

					<description><![CDATA[<p>What a great time to be alive! AI tools and features are being released so quickly, too fast for most busy executives to keep up with. This article gives you a framework your brain can use to understand and file your knowledge about the tools that exist now and the new ones as they arrive. [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/four_families_of_ai_tools/">An Executive’s Guide to Demystifying and Understanding the Four Families of AI Tools</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>What a great time to be alive! AI tools and features are being released so quickly, too fast for most busy executives to keep up with. This article gives you a framework your brain can use to understand and file your knowledge about the tools that exist now and the new ones as they arrive.<br />
<img decoding="async" class="alignnone size-full wp-image-6239" src="https://fosterinstitute.com/wp-content/uploads/2026/06/four-families-map-v4.png" alt="" width="2400" height="1300" srcset="https://fosterinstitute.com/wp-content/uploads/2026/06/four-families-map-v4.png 2400w, https://fosterinstitute.com/wp-content/uploads/2026/06/four-families-map-v4-1280x693.png 1280w, https://fosterinstitute.com/wp-content/uploads/2026/06/four-families-map-v4-980x531.png 980w, https://fosterinstitute.com/wp-content/uploads/2026/06/four-families-map-v4-480x260.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) and (max-width: 1280px) 1280px, (min-width: 1281px) 2400px, 100vw" /></p>
<h2>Your Framework for Your Memory</h2>
<p>Inside each family, there are smaller groups of tools. Each family below lists those groups, with some example tools available now (June 2026) and where they fit. We do not endorse any of these tools, nor do we recommend or advise against any of them, although we do use many of them. The product names are here to make the differences between the families easier to recognize.</p>
<h3>Family 1 &#8211; Analysts: AI tools that Analyze</h3>
<p>For tools in this family, you chat with the AI. It can research a topic, summarize a long document, write a draft, pull out the key points, and work inside projects you have set up. For non-technical professionals, this is the most visible way to use AI as of June 2026. Think of this family as an analyst on your team. It studies things, reports back and then you decide what to do.</p>
<p>You will notice that many tools you already use have a built-in chat helper. When you ask that built-in helper to research or summarize, it behaves like a Family 1 Analyst, even though the chat feature is embedded in another program. The makers tend to label these helpers &#8220;Assistants.&#8221; A real human assistant can take action for you, and that is where the next family comes in.</p>
<ul>
<li><strong>General chat analysts:</strong> Claude, ChatGPT, Gemini, Perplexity, Microsoft Copilot. Microsoft sells Copilot in three tiers: the free Copilot, the individual Copilot Pro, and the business Microsoft 365 Copilot that natively accesses your company data, works inside several Microsoft Office apps, and, for now, lets you choose which AI model answers, including Anthropic&#8217;s Claude and OpenAI&#8217;s models alongside Microsoft&#8217;s own.</li>
<li><strong>Customized analysts:</strong> Claude Projects &amp; Skills, Custom GPTs &amp; GPT Projects, Gemini Gems, Perplexity Spaces, Microsoft 365 Copilot Agents, Microsoft Copilot Notebooks</li>
</ul>
<h3>Family 2 &#8211; Assistants: AI tools that Take Action</h3>
<p>You delegate tasks to AI, and it completes them. You can give these &#8220;task agents&#8221; selective access to your files, your mouse, and your screen, and they have connectors to other programs you use. Your instructions to a task agent can let it move a file, send an email, write a row in a spreadsheet, add a record to a database, notify your team, and more. Instead of dragging a dozen documents into a Family 1 Analyst and asking it to do a task, your task agent can find the dozens of files itself and do the work using those files, based on your instructions.</p>
<p>While using AI in Family 1 carries privacy and security risks, Family 2 requires even more attention. Don&#8217;t be afraid to use these tools, but approach them carefully and put safeguards in place. You must accept some risk in order to use these tools. &#8220;Cloud task agents&#8221; that run in the cloud put you at risk if an attacker can find a way to exploit weaknesses in them by using techniques such as &#8220;prompt injection&#8221; to trick your AI task agent into working for them. One goal threat actors have is to trick your task agent into sending them sensitive information. Once you start using &#8220;on your machine&#8221; task agents that might have access to your local computer, including accessing some files on your drives and the ability to imitate you by moving the mouse and clicking the mouse buttons, based on what it &#8220;sees&#8221; on your screen, your risk increases. If your AI behaves irrationally, or an attacker is able to take control of it, you&#8217;re more exposed.</p>
<ul>
<li><strong>Cloud task agents:</strong> ChatGPT Agent, Gemini Spark, Perplexity Computer, Microsoft Copilot Cowork (cloud task agent) run in the cloud. As with everything in all these families, be aware of privacy and security risks.</li>
<li><strong>On-your-machine task agents:</strong> Claude Cowork, Perplexity Personal Computer, OpenClaw, NanoClaw, and Microsoft Scout. Be especially aware that if you use these task agents running on your machine, they can pose enormous security risks in some cases. Scout, built on the open-source OpenClaw project, is experimental as of late June 2026.</li>
</ul>
<p>The difference in Family 2 compared to Family 1 is that here you end up with a completed task, something a task agent did for you based on your instructions right then.</p>
<h3>Family 3 &#8211; Tools that let you create workers</h3>
<p>This family is where you build highly skilled workers who can start on their own at an event, such as when an email arrives or at a set time of day. You manually start the Family 2 tools. Family 3 helps you produce task agents that can start automatically, without you needing to be present.</p>
<p>There are two kinds of workers you can make here. The first is a workflow in which you lay out every step yourself, so the result is predictable and repeatable. You have the option to add or not add AI to your workflow, and the difference is massive. AI reasons on its own, so you will not always get the same result if you use AI within a workflow. When you add an AI step to a workflow, it can return different results each time, and that variation can disrupt the operation of the otherwise predictable steps that follow. Workflows can be composed of steps that do not have to use AI at all, so the workflow is predictable, which is essential for work that must be accurate every time, such as exact statistical or financial calculations.</p>
<p>The second type of AI in Family 3 is a task agent builder. Instead of writing out every detailed step, you give the worker a goal and let it work out the steps on its own. You design a worker that you will not tell what to do; you just give it an outcome to achieve. Because you don&#8217;t define the steps exactly, a task agent may produce different results each time you use it.</p>
<p>Both kinds run automatically when an event occurs, such as an email arriving, and both let you hand off tasks you used to do manually. The difference is whether you want to define the steps or let AI choose its own steps to achieve your result. The first can be predictable if you leave AI out of the steps, and the second can be fluid, flexible and adaptable, but be prepared that you might not always get a result you expected.</p>
<ul>
<li><strong>Workflow automation:</strong> Zapier, Make.com, n8n, Gumloop, Microsoft Power Automate</li>
<li><strong>Agent builders:</strong> Zapier Agents, OpenAI Agents SDK, Botpress, StackAI, Microsoft Copilot Studio. (OpenAI&#8217;s no-code Agent Builder, which used to accompany the Agents SDK, is being retired on November 30, 2026.)</li>
</ul>
<h3>Family 4 &#8211; Tools that let you write programs</h3>
<p>With these tools, you explain a program in plain English, and the AI writes it for you. This activity is called vibe coding. AI helps you add features and upgrade your program whenever you want, without you needing to learn how to program. Experienced developers use this family too, to speed up their own work.</p>
<p>There are two kinds here. The first kind, called app builders, write the program and host it for you in their cloud, so you stay in plain English from start to finish. You won&#8217;t need to understand much about how programs work on the backend.</p>
<p>Other tools, called agentic coding tools, write code you can run wherever you like, giving you more power and showing you more of the moving parts. You&#8217;ll have an opportunity to get a little deeper into what is going on, and the AI tool can help you through the process. Having the flexibility not to be locked into a specific vendor&#8217;s cloud can be appealing in some cases.</p>
<ul>
<li><strong>App builders:</strong> Base44, Lovable, v0, Replit, GitHub Spark. GitHub Spark, which Microsoft owns, is still in preview as of late June 2026.</li>
<li><strong>Agentic coding tools:</strong> Claude Code, Codex App, Cursor, GitHub Copilot.</li>
</ul>
<h2>Terminology</h2>
<p>Now that we have covered the families as a framework, here are some terms in case any of them are new to you.</p>
<p><strong>Agent.</strong> The term &#8220;Agentic AI&#8221; refers to AI that can take action, and the word &#8220;agent&#8221; always benefits from a descriptor next to it, such as &#8220;coding agent&#8221; for an agent that writes code, &#8220;task agent&#8221; for an agent that performs tasks, and so on.</p>
<p><strong>Embedded AI.</strong> This is when software you already own has AI features built in, such as a chat helper in your email or a spreadsheet. Usually, embedded AI is a feature you enable, not a separate tool.</p>
<p><strong>Connections.</strong> Connectors provide access. This is how programs connect to other programs you use, online services, databases, and everything else. For AI to work in the real world, and to reach the data sitting in your databases and elsewhere, you need connectors. You may see the terms API and MCP; I will cover them in a future article. They are the backbone of most connectors that provide access. Access by itself is not enough, though. The tool also needs to know what to do with that access, which leads to the next term below, skill.md. Connectors carry a significant risk if a threat actor compromises one. We call this &#8220;east-west&#8221; security because it involves data flowing between programs, as opposed to the traditional &#8220;north-south&#8221; security that protects your data and systems via a firewall. Using connectors bypasses firewall protection because your SaaS applications can communicate with each other without the conversation ever passing through the traditional firewall at your network perimeter, where your network connects to the outside world. This east-west traffic is harder to see and control than traditional perimeter traffic, and it should be on your CISO&#8217;s radar, especially if workers set up connections without their knowledge or approval. Threat actors target connectors. I will cover service-to-service, API, and MCP security inside and between environments in more detail in a future article.</p>
<p><strong>SKILL.md.</strong> This is a file that teaches AI how to do a task the way you want it done. The skill file often includes instructions on how to work with another program you have connected to, and it can also hold your own process, such as your style, checklist, or standards. The connector gives the AI access; the skill file gives it the know-how to do a great job. As an aside, the &#8220;md&#8221; in the file name stands for &#8220;markdown,&#8221; and md files are saved as plain text you can read and edit in a basic app such as Notepad or TextEdit. People often say &#8220;skills&#8221; out loud, while the file itself is usually named SKILL.md. Just as you train a new worker at your organization, you can use a skill file, along with related markdown files, to train your task agents and other AI tools.</p>
<p><strong>AaaS.</strong> Agent as a Service is a way you can pay for task agents to perform specific tasks for you. Their features fit in Family 2 above, and they are useful when you just want to pay for a result. For example, you might pay a monthly fee for a task agent to run your lead follow-up and clean up your sales pipeline.</p>
<p><strong>Loops.</strong> Looping is a recursive process in which the AI plans, acts, observes, and refines, then repeats the cycle, starting with refined planning. Each pass through the loop can improve the result. Keep in mind that more loops do not always mean a better answer; the gains usually are higher during the first rounds. As of now, a loop can drift in the wrong direction if it is unsupervised and runs too many times. Looping also uses a lot of computing power, known as &#8220;compute,&#8221; which can mean a high token cost, the next term.</p>
<p><strong>Tokens.</strong> Companies such as Google, OpenAI, and Anthropic charge you to use their models, and the unit they use to measure usage is called a token. To give you a rough idea, a token is about three-quarters of a word in the English language. If you are using a Family 1 chat tool for a monthly fee, you usually are not billed by the number of tokens you use, but you might find yourself temporarily restricted if you reach a specified limit. The other families may have features that result in your getting charged per token. You use more tokens when you run more activities, open larger files, and run processes more often. You are charged for both what you send to the model and what it sends back to you. The topic of saving money with AI while being charged per token deserves special attention, because some companies are finding AI is becoming very expensive for them. I will write an article about that soon, probably next week.</p>
<h2>Conclusion</h2>
<p>You now have a shared vocabulary and, more importantly, a framework for filing AI tools into families. Share this with your friends so that, as new AI tools arrive, and they will keep arriving quickly, they can file each tool into its family and help keep their sanity while everything else keeps changing.</p>
<p>The post <a href="https://fosterinstitute.com/four_families_of_ai_tools/">An Executive’s Guide to Demystifying and Understanding the Four Families of AI Tools</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Wire Transfer Fraud Just Got Smarter &#8211; Your Defenses Need to Catch Up</title>
		<link>https://fosterinstitute.com/wire-transfer-fraud-just-got-smarter-your-defenses-need-to-catch-up/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Sat, 16 Aug 2025 05:46:22 +0000</pubDate>
				<category><![CDATA[ACH Fraud]]></category>
		<category><![CDATA[BEC]]></category>
		<category><![CDATA[Business Email Compromise]]></category>
		<category><![CDATA[Cyber Fraud]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Email Security]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[Wire Transfer Fraud]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=6104</guid>

					<description><![CDATA[<p>&#160; EXECUTIVE SUMMARY New Business Email Compromise (BEC) attacks targeting wire transfers cost organizations billions annually. Threat actors have developed new techniques to bypass even sophisticated email protection filters in organizations like yours and can use new AI deepfakes as a new way to bypass voiceprint protection at the banks. This article reveals these new [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/wire-transfer-fraud-just-got-smarter-your-defenses-need-to-catch-up/">Wire Transfer Fraud Just Got Smarter &#8211; Your Defenses Need to Catch Up</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>&nbsp;</p>
<h2 style="margin-bottom: 15px;">EXECUTIVE SUMMARY</h2>
<p><strong>New</strong> Business Email Compromise (BEC) attacks targeting wire transfers cost organizations billions annually. Threat actors have developed <strong>new techniques to bypass even sophisticated email protection filters</strong> in organizations like yours and can <strong>use new AI deepfakes as a new way to bypass voiceprint protection at the banks</strong>.</p>
<p>This article reveals these new threats. So that you can have more wire transfer security in one document, this article covers several key components to have in your organization’s wire transfer process to help protect against <strong>new</strong> and old threats. It also includes some<strong> new protective changes your IT Team can implement </strong>in your computer systems and processes, including ways to protect against both existing and new threats.</p>
<p style="margin-bottom: 15px;">The losses can be devastating &#8211; one organization lost hundreds of thousands and a top executive. Review your wire transfer policy today, and conduct a tabletop exercise this quarter. Your organization’s financial survival may depend on it.</p>
<h2 style="margin-bottom: 15px;">It is Time to Update Your Wire Transfer Process Policy and Procedure Documentation</h2>
<p style="margin-bottom: 15px;">Fraudulent wire transfers, part of an attack referred to as Business Email Compromise (BEC), are very frequent and expensive for organizations that fall prey to these attacks. The FBI IC3 reports that BEC costs organizations billions of dollars each year. I want to help you avoid being a victim.</p>
<p style="margin-bottom: 15px;">Something new that&#8217;s related to wire transfer fraud: The threat actors have a <strong>new technique that successfully bypasses spam filters.</strong> We&#8217;re receiving concerned email questions, as we should be, like this one from a very savvy IT Pro who wrote in frustration: &#8220;The email bypasses one of our main filters for external mail.” The “main filter” he is referring to is a very expensive email protection service that is very effective at preventing external phishing. At least it was, until now. Attackers found a way through not just his, but any systems not protected by the new technical fix we gave him right away, which is included below. <strong>Your protection may be vulnerable too</strong>. The need for you to know what to fix is the primary reason I penned this article.</p>
<p style="margin-bottom: 15px;"><strong>In another new development,</strong> Sam Altman, CEO of OpenAI, which makes ChatGPT, is warning the Federal Reserve: Fraudsters can use improved AI-generated voice to completely defeat voice-print authentication. He says that threat actors will be able to call a bank, pass the voice recognition test for access to their victim’s accounts, and move money wherever they want.</p>
<p style="margin-bottom: 15px;">One of our customers got compromised. When one of their vendors called asking about hundreds of thousands in unpaid bills, the company realized they&#8217;d been paying a fraudster for a year.</p>
<p style="margin-bottom: 15px;">Our customer had a strict protocol: The vendor must fill and sign a specific form, then, following separation of duties, one person approves the change and another updates the routing and account numbers. Unfortunately, fraudsters breached the victim company&#8217;s email and easily identified the process by tracking a legitimate request.</p>
<p style="margin-bottom: 15px;">The hackers breached the email system of one of the victim&#8217;s largest suppliers. They immediately sent an email from that company to the person who approves transfers and another directly to the person who changes the routing and account number using a forged approval signature.</p>
<p style="margin-bottom: 15px;">It was almost impossible to catch that, and they only found out after a year when the large vendor contacted them, saying they&#8217;d had a glitch that resulted in no statements being sent, and asked about the hundreds of thousands of dollars the victim company owed the vendor. And, of course, the victim company had been paying all along, but the money was going to a happy fraudster who enjoyed a significant income for their efforts. The loss was devastating. A top executive, one of the smartest and kindest people I&#8217;ve ever known, left the company soon after.</p>
<p style="margin-bottom: 15px;">Threat actors successfully bypass spam protection by tricking anti-phishing systems into believing their message, sent from an external server, came from inside your network. The duped spam filter doesn&#8217;t check the message and allows it through because, by default, all internal email messages are allowed. This trickery removes the need for the threat actors to breach the victim company&#8217;s email system.</p>
<p style="margin-bottom: 15px;">You&#8217;ve seen the online videos of deepfakes and how difficult it is to tell some of them apart from a real human. Although it isn&#8217;t common yet, threat actors could theoretically use AI to use deepfake voices that sound very convincing during an approval process. OpenAI is specifically warning banks about this risk right now. Threat actors are using deepfake video in job interviews now, so it is reasonable to expect that they will use audio impersonation to fake a vendor representative&#8217;s voice to successfully and fraudulently complete the approval process.</p>
<p style="margin-bottom: 15px;">Have a Wire Transfer Process Policy that your team adheres to. Be sure there is extensive training and regular samples. If your team knows there could be a test message at any time, they&#8217;re more likely to stay vigilant.</p>
<p style="margin-bottom: 20px;">I know you can use AI to write one, but here is a sample wire transfer policy we&#8217;ve spent a lot of time compiling that you can adjust to fit your organization:</p>
<ol style="margin-bottom: 20px;">
<li style="margin-bottom: 15px;"><strong>Receive and log the request</strong> into whatever logging system you&#8217;re using now. Even a spreadsheet would work. Record:
<ol style="list-style-type: lower-alpha; margin-top: 10px;">
<li style="margin-bottom: 10px;">Entity requesting the transfer</li>
<li style="margin-bottom: 10px;">How they contacted you: email, phone, etc.</li>
</ol>
</li>
<li style="margin-bottom: 15px;"><strong>Look for Obvious Problems:</strong>
<ol style="list-style-type: lower-alpha; margin-top: 10px;">
<li style="margin-bottom: 10px;">Carefully check the email address to confirm the text after the @ sign matches the company&#8217;s domain. If they don&#8217;t, check your email history to see what domain name they typically use. And of course, you already know the source and reply-to email addresses can be spoofed anyway. If anything is off in the addresses, consider the message fraudulent.</li>
<li style="margin-bottom: 10px;">Does the request indicate some urgency? If so, be very suspicious that it is fraudulent.</li>
<li style="margin-bottom: 10px;">Does it ask you to keep something secret, such as a surprise or gift? If so, be very suspicious of this, too.</li>
<li style="margin-bottom: 10px;">Do you already have different payment details on file for that company? If so, be extra careful.</li>
<li style="margin-bottom: 10px;">If something feels &#8220;off&#8221; about the request, trust your gut feeling and escalate it for secondary review. Sometimes our brains can detect subtle clues that aren&#8217;t obvious, and fraud is so expensive that you must honor all indications, even when it is just an odd feeling about the message. It is better to err on the side of safety than lose a fortune to fraud.</li>
<li style="margin-bottom: 10px;">If someone phones you, keep in mind that AI is excellent at helping threat actors create deep-fake audio impersonations. If you&#8217;re unsure, start a casual conversation and ask specific questions about their city. If they can&#8217;t answer even simple ones, or they make an excuse like having just moved there, that is a big red flag. If a threat actor is using a voice chatbot responding to you directly, it will know the answers to your questions right away, but at least it gives you more time to see if the voice sounds AI-ish.</li>
<li style="margin-bottom: 10px;">Just because you confirm that an email is from a company, that doesn&#8217;t mean it is valid. Threat actors earn lots of money if they succeed, so they are motivated to invest a lot of time and use sophisticated techniques to hack into the email of one of the companies you already transfer money to. Then they can send and receive email via the company&#8217;s actual mail servers. The company whose email they hacked has no idea.</li>
<li style="margin-bottom: 10px;">Tell other members of your team about messages that concern you so they can spot them quickly.</li>
</ol>
</li>
<li style="margin-bottom: 15px;"><strong>Mandatory Callback Verification</strong> if the message passed the initial review
<ol style="list-style-type: lower-alpha; margin-top: 10px;">
<li style="margin-bottom: 10px;">Verifications must be conducted out-of-band, meaning in a different way than the request arrived. For example, if the request arrived by email, verify it in a different way</li>
<li style="margin-bottom: 10px;">If your organization utilizes secure communication methods, such as encrypted email or a secure portal, contact the person that way to confirm the transfer or account number update.</li>
<li style="margin-bottom: 10px;">If you need to use email, forward, not reply, the request to the supposed person at the company domain (not another domain; watch for minor typos in the domain name) and ask if they sent that message.</li>
<li style="margin-bottom: 10px;">Call the person requesting the transfer or account number update. Avoid calling the phone number provided in the email message. Find the phone number you typically use or look up the phone number at the company&#8217;s website or another independent way.</li>
<li style="margin-bottom: 10px;">Ask the person to call you back so you can verify that the phone number matches the one on the company&#8217;s website. If the number doesn&#8217;t match exactly, the area code, prefix, and first one or two numbers should.</li>
<li style="margin-bottom: 10px;">If this is a new setup, or a change in account number, contact a second person at the organization to independently confirm the worker&#8217;s identity whom you contacted.</li>
<li style="margin-bottom: 10px;">Document all of this in your log.</li>
</ol>
</li>
<li style="margin-bottom: 15px;"><strong>Dual Approval for transferring money</strong>
<ol style="list-style-type: lower-alpha; margin-top: 10px;">
<li style="margin-bottom: 10px;">See if your bank will allow you to set up dual approval so that two people must confirm each wire transfer. If your business processes dozens of wire transfers every day, consider setting a threshold where you only need two people if the transfer is over a specific amount.</li>
<li style="margin-bottom: 10px;">Even if your bank doesn&#8217;t have the two-person verification option, you can still use that process internally on your own by having the person who is about to make the transfer get the sign-off of another worker who can verify it.</li>
</ol>
</li>
<li style="margin-bottom: 15px;"><strong>After you make the transfer</strong> or update the routing and account numbers, send a confirmation to the user at the company using the email address you independently verified. Do not assume the email address or the &#8220;reply to&#8221; address is accurate. Update the log entry that corresponds with the transaction you started when the request arrived, so you&#8217;ll be able to review the details if you need to.</li>
<li style="margin-bottom: 15px;"><strong>Immediately activate the response plan</strong> described below if you suspect fraud has happened. Speed is of the essence because the sooner your bank and the authorities know about the fraud, the more likely it is that they can recover some or all of the money. There are no guarantees, but act quickly anyway.</li>
</ol>
<p style="margin-bottom: 20px;">Here is a list of other essential steps we created for you. Some are more technical, but you can always lean on your IT team to help:</p>
<ol style="margin-bottom: 20px;">
<li style="margin-bottom: 15px;">By default, most spam filters allow all internal messages between your workers to pass through without inspection. As mentioned above, attackers can successfully trick your email systems into believing the sender is inside the company. They can trick your anti-fraud tools to pass their wire transfer requests without scrutiny. Ask your IT Department to change the settings to remove this bypass and <strong>require all messages, internal and external, to be tested thoroughly.</strong></li>
<li style="margin-bottom: 15px;"><strong>Thoroughly educate your team</strong> about preventing BEC and wire fraud.</li>
<li style="margin-bottom: 15px;"><strong>Check your regulatory and legal requirements</strong> for your industry and your situation. There is a chance that there are specific wire transfer regulations that will apply to your organization.</li>
<li style="margin-bottom: 15px;"><strong>Ask your bank and your application providers what forms of fraud protection services they offer.</strong> AI is empowering banks and other financial institutions to watch for suspicious behaviors. The tools can watch trends with all of the transactions they process and also watch for irregularities from your organization&#8217;s typical usage. AI is getting better and better at catching fraud quickly. Make sure yours is set at the highest level.</li>
<li style="margin-bottom: 15px;">You can <strong>utilize the security principle of &#8220;separation of duties&#8221;</strong> by ensuring that the person approving the transfer is different from the one making the transfer. This is the &#8220;separation of duties&#8221; principle that can help catch fraud since more than one person has a chance to recognize an issue.</li>
<li style="margin-bottom: 15px;"><strong>An attacker might use deepfakes</strong> to dupe you into thinking everything is legitimate. After all, if they stand to make a mint, they will go to great lengths, the stuff Hollywood is made of. Someday, it might get to the point that some transactions must happen in person. If going in person is not practical, an alternative that would be very difficult, as of today, for an attacker to simulate would be a video call with multiple people whom you recognize from the other organization in the same online meeting at the same time, especially if the vendor&#8217;s representatives are in a setting you recognize. The threat actor would have to accurately depict the background, animate all the people at the company and give them the right voices and the right things to say in a very human way. The technology just isn&#8217;t that good yet.</li>
<li style="margin-bottom: 15px;">Ensure your IT Department has configured <strong>alerts that will trigger the moment a new email rule is created.</strong> It is very common for threat actors to breach a company, configure email forwarding rules, and then get out before they&#8217;re noticed, all to prepare for lucrative fraudulent email requests. In post-incident forensics processes, we frequently discover that the threat actor was only in the network for a few minutes and was gone before even the best EDR, XDR, and other automated detection tools could notice. To the system, it appeared to be a typical user logging in and logging out, nothing out of the ordinary.</li>
<li style="margin-bottom: 15px;"><strong>Be sure you set up MFA at your bank.</strong> Ask if they support you logging in with a physical token, an authenticator app on your phone or using a passkey, all of which are more secure than a text message. Even then, know that hackers can bypass MFA, so it cannot positively prevent a threat actor from accessing your account. But use MFA anyway.</li>
<li style="margin-bottom: 15px;">Here&#8217;s the <strong>technical stuff to send to IT</strong>, but executives, please read the next section after this section.
<ol style="list-style-type: lower-alpha; margin-top: 10px;">
<li style="margin-bottom: 10px;">Ask them to enable Spoof Intelligence in Microsoft 365 Defender</li>
<li style="margin-bottom: 10px;">Ensure Anti-Spam Policy &gt; Spoof settings blocks failed SPF and DMARC internal spoof attempts</li>
<li style="margin-bottom: 10px;">Enable domain and user impersonation protection in an Anti-Phish Policy for your Accepted Domains</li>
<li style="margin-bottom: 10px;">Disable or at least restrict any inbound connectors that accept mail from untrusted IPs</li>
<li style="margin-bottom: 10px;">Add an Exchange Mail Flow transport rule so that if a message is authenticated as Anonymous but claims to be from inside your domain, check the message: If AuthAs=Anonymous AND InternalOrgSender=True, treat it as external and run spam and phishing filters again.</li>
<li style="margin-bottom: 10px;">Be sure your IT Department has configured technology they will recognize called SPF, DKIM, and DMARC to help protect you from fraudulent email messages. But they need to implement it in phases to ensure you don&#8217;t lose essential messages and that your company&#8217;s outbound email messages don&#8217;t get blocked due to the settings. They can start SPF with ~all (soft fail) while monitoring, then move to -all (hard fail) for SPF after they&#8217;ve identified all the approved sources of email, and separately configure DMARC to progress from p=none &gt; p=quarantine &gt; p=reject over time. Important: Don&#8217;t move DMARC to p=reject until both SPF and DKIM are properly configured and aligned, as this could block legitimate emails.</li>
</ol>
</li>
<li style="margin-bottom: 15px;">You already have <strong>incident response plans</strong> for what happens if there is a security breach, and be sure to have one for fraudulent wire transfers, too.
<ol style="list-style-type: lower-alpha; margin-top: 10px;">
<li style="margin-bottom: 10px;">Include immediate notification of your bank, cyber-insurance carrier, the FBI, your data breach lawyer, and the executives of your organization. Include all contact information right in the plan so there are no delays. Sometimes, when money gets transferred to a fraudulent account, the threat actors cannot access the full amount right away; they must remove the money in smaller increments. Sometimes you can recover some of the money if you act quickly. Other times, the funds are moved immediately to overseas mule accounts.</li>
<li style="margin-bottom: 10px;">Include an instruction to ask your IT department to immediately run an Exchange message trace on the specific messages related to the fraud; they&#8217;ll understand the request.</li>
<li style="margin-bottom: 10px;">Ask IT to also check the admin audit logs for recent rule/connector modifications.</li>
</ol>
</li>
<li style="margin-bottom: 15px;">To combat the voice-print dangers, you need to consider both someone impersonating your company to the bank, and someone pretending to be the bank calling you. For the former, ask your bank to <strong>require multiple forms of authentication, not just voice-print.</strong> They will probably suggest pre-arranged code words or security questions that only you and your bank know. Here’s something many people learn the hard way: Do not answer with a fact. In other words, you might say your high school was Sea of Tranquility High on the Moon. Good luck to any attacker trying to find that on your LinkedIn profile, even if they are using AI to assist them! And if someone calls you claiming to be from your bank, hang up and call the bank back on a number you can verify as being legitimate.</li>
<li style="margin-bottom: 15px;">And last, it is an excellent idea to <strong>ensure everyone who pays you by wire transfer</strong> does everything in this document and more. After all, if they pay all the money they owe you to a fraudster, they might not have enough money left to pay you, too. We&#8217;ve seen that happen to some of our best clients; their customers suffered a BEC and transferred money to threat actors, and then couldn&#8217;t afford to pay our customers. This is an example of how another company&#8217;s breach can hurt your organization, too.</li>
</ol>
<p style="margin-bottom: 20px;">This simple process could save you many hundreds of thousands of dollars, as fraudulent emails requesting wire transfers are becoming too frequent. Review your policy today and have a table-top exercise this quarter.</p>
<h3 style="margin-bottom: 15px;">About the Author</h3>
<p style="margin-bottom: 10px;"><strong>Mike Foster, CISSP®, CISA®</strong><br />
Cybersecurity Consultant and Keynote Speaker<br />
📞 805-637-7039<br />
📧 mike@fosterinstitute.com<br />
🌐 www.fosterinstitute.com</p>
<p style="margin-bottom: 15px;">Mike Foster is a leading cybersecurity consultant with decades of experience helping organizations across North America secure their digital assets. He holds CISSP® and CISA® certifications and is the author of The Secure CEO. As the founder of The Foster Institute, Michael has delivered over 1,500 keynote presentations and consulting engagements, equipping executives and IT leaders to strengthen their cybersecurity posture and defend against evolving threats.</p>
<p>&nbsp;</p>
<p>The post <a href="https://fosterinstitute.com/wire-transfer-fraud-just-got-smarter-your-defenses-need-to-catch-up/">Wire Transfer Fraud Just Got Smarter &#8211; Your Defenses Need to Catch Up</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Executives &#8211; Any User Can Accidentally Expose All Your Data Unless IT Changes This Default Setting</title>
		<link>https://fosterinstitute.com/executives-your-employees-might-be-one-click-away-from-exposing-all-sensitive-data-heres-how-to-stop-it/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Wed, 04 Jun 2025 21:08:04 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[IT Pro Tips]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[IT Settings]]></category>
		<category><![CDATA[Microsoft Settings]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=6097</guid>

					<description><![CDATA[<p>Your employees might be one click away from exposing all sensitive data. Here&#8217;s how to stop it. We&#8217;re receiving calls from our cybersecurity customers when the IT Team discovers that ordinary users have given third-party applications access to all their organization&#8217;s files, email messages, calendar events, Teams chats and channels, and other data. How can [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/executives-your-employees-might-be-one-click-away-from-exposing-all-sensitive-data-heres-how-to-stop-it/">Executives &#8211; Any User Can Accidentally Expose All Your Data Unless IT Changes This Default Setting</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Your employees might be one click away from exposing all sensitive data. Here&#8217;s how to stop it.</p>
<p>We&#8217;re receiving calls from our cybersecurity customers when the IT Team discovers that ordinary users have given third-party applications access to all their organization&#8217;s files, email messages, calendar events, Teams chats and channels, and other data.</p>
<p>How can ordinary users have that much power?</p>
<p>By default.</p>
<p><strong>Situation:</strong> This configuration affects most companies. While the default settings for your Microsoft 365 system allow your users to approve third-party access, Microsoft recommends the following more restrictive settings to increase security.</p>
<p><strong>The Risk:</strong> Without this setting, workers may override protections without oversight and allow any application to access your company data, create and delete files in SharePoint and OneDrive, read and send email messages, edit calendar events, access and modify Teams chats and channels, update user profile information, and perform other tasks. While some applications might need this level of access, it must be granted only after the appropriate authorities, including your IT Team, thoroughly consider it.</p>
<p><strong>Reality Check:</strong> This setting catches many IT Teams by surprise. Microsoft is updating its security controls quickly, and it is nearly impossible for IT Teams to keep up with the changes. And when defaults promote ease-of-use over security, like this one, your systems can become at risk quickly without the team realizing it. Know that your IT Team&#8217;s level of expertise can be excellent, and situations like this sneak up on them anyway.</p>
<p><strong>Urgent Quick Verification:</strong> Your IT Team can quickly access the Microsoft Entra admin center &gt; Enterprise applications &gt; Consent and permissions &gt; User consent settings. There are three options:</p>
<ul>
<li>&#8220;Do not allow user consent.&#8221;</li>
<li>&#8220;Allow user consent for apps from verified publishers, for selected permissions.&#8221;</li>
<li>&#8220;Allow user consent for all apps&#8221; (the current risky default value)</li>
</ul>
<p><strong>Update If Necessary:</strong> Microsoft recommends you select “Allow user consent for apps from verified publishers, for selected permissions.” Different organizations have different data access needs. Your IT and compliance teams must determine the appropriate level for your situation. Smaller organizations might choose the first option if they don&#8217;t want users to expose data to third-party applications without checking with the IT team. Larger organizations with more complex needs often prefer the middle option with careful permission management to take some of the workload off busy IT professionals while providing protection.</p>
<p><strong>Next Step:</strong> Your Administrators will also need to specify which permissions are low-impact, as detailed in Microsoft&#8217;s article &#8220;Overview of user and admin consent.&#8221;</p>
<p><strong>Facilitate the Approval Process:</strong> Your team can optionally set up an admin consent workflow that users must follow when they want to provide permissions.</p>
<p>Forward this to your friends who are executives at other organizations so they can give their teams this heads-up, too.</p>
<p>The post <a href="https://fosterinstitute.com/executives-your-employees-might-be-one-click-away-from-exposing-all-sensitive-data-heres-how-to-stop-it/">Executives &#8211; Any User Can Accidentally Expose All Your Data Unless IT Changes This Default Setting</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>An Executive&#8217;s Handbook to Securing Modern Manufacturing Networks and Robots, AI or Not</title>
		<link>https://fosterinstitute.com/ai-advancements-meet-security-ceos-handbook-to-securing-robotics-and-manufacturing-networks/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Mon, 02 Sep 2024 17:05:18 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[it risk management]]></category>
		<category><![CDATA[recommendations]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=5643</guid>

					<description><![CDATA[<p>Sadly, as reckless as it seems, some companies that create applications to control machinery will no longer provide technical support to your IT team if the operating system on the workstations is upgraded or has security patches.</p>
<p>The post <a href="https://fosterinstitute.com/ai-advancements-meet-security-ceos-handbook-to-securing-robotics-and-manufacturing-networks/">An Executive&#8217;s Handbook to Securing Modern Manufacturing Networks and Robots, AI or Not</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>While we&#8217;ll discuss AI, the security principles outlined here are equally crucial for all computer-controlled manufacturing systems, whether they incorporate AI or not.</p>
<p><strong>AI&#8217;s Growing Role in Controlling Devices:</strong></p>
<p>As AI starts entering more workplaces, it is crucial to recognize that AI will become more interconnected with hardware devices in your organization. You might want AI to control room lighting and air conditioning to make it voice-controlled or adapt to the changing activities in the room. AI can also control massive machinery, including robots and high-powered lasers for cutting steel. We&#8217;ll all be surprised at how many real-world tangible controls AI can assist. For AI to control devices, computers must drive the machines. Threat actors could exploit weaknesses to disrupt companies, damage equipment, cause expensive delays, and worse.</p>
<p><strong>Machines Driven by Computers, Including Those Running AI and Traditional Computer Control Systems, Introduce a Security Threat:</strong></p>
<p>As AI becomes integral to your operations, remember: Everything from climate control and identity detection to robots and laser cutters hinges on computer systems. AI&#8217;s potential is vast, and its growing adoption means more devices linked to our networks.</p>
<p>However, this surge in AI adoption produces an often-overlooked danger that all organizations with industrial controls must consider. The computer systems hosting your AI and traditional solutions can become obsolete faster than the devices they control. Neglecting to update operating systems and using other security controls exposes your organization to cybersecurity threats. While devices might seem to run smoothly, the escalating sophistication of cyber attackers can&#8217;t be underestimated.</p>
<p><strong>Executives: Unchain Your IT Pros from the Security Limitations:</strong></p>
<p>Is your IT Team prohibited from applying critical cybersecurity updates to operating systems or upgrading to supported operating systems on workstations that control instruments, lasers, robots, and other machinery? If they are, those workstations <strong>pose a security threat to your organization.</strong></p>
<p>Executives must understand that using workstations with old operating systems or without the most recent critical security updates is a significant security risk. <strong>In some cases, executives must ask the IT Team if they have encountered this situation.</strong> Sometimes, executives are inclined to delegate decision-making to the IT Pros. Instead, the IT team must alert the executives of the pros, cons, and expenses. The executives need to decide if it makes sense to pay to upgrade the applications that control robotics, manufacturing, or other equipment on a network.</p>
<p><strong>Three Definitions:</strong></p>
<p>In case nobody&#8217;s explained these terms, it is essential to differentiate between upgrades and updates:</p>
<ol>
<li><strong>Operating System <em>Upgrades</em>:</strong> An example is upgrading from Windows 10 to Windows 11. Newer operating systems often have more security features. Microsoft and Apple will naturally be tempted to assign their best and brightest people to develop and update the newest operating systems, so they eventually drop support for old operating systems. Unsupported operating systems are designated EOL (End of Life.) Using an operating system after it is no longer supported is a significant security risk.</li>
<li><strong>Operating System <em>Updates</em>, a.k.a. Patches:</strong> Security updates are rated by the severity of the security risk and how likely an attacker will exploit the weakness. Critical security updates are the most important to apply. Staying up to date with patches can be a significant struggle in many situations.</li>
<li><strong><em>Application</em> Upgrades:</strong> Upgrades to new versions of the software that controls devices such as CNC machines, robotics, lasers, laboratory equipment, instruments, or any other hardware that connects to a computer.</li>
</ol>
<p><strong>The Shocking Reality:</strong></p>
<p>Some applications that control devices may prohibit operating system upgrades and security patches. The applications might break if the IT team deploys the patches or upgrades the operating systems. Sadly, as reckless as it seems, some companies that create applications to control machinery will no longer provide technical support to your IT team if the operating system on the workstations is upgraded or has security patches. Their software developers may be too busy to create flexible, secure applications and are forced to focus strictly on functionality.</p>
<p>Depending on the application vendor, paying for an upgraded version of a controller application can be very expensive. Fortunately, sometimes, the upgrade charge is reasonable or free. Sometimes, no upgrade is available to permit operating system upgrades or critical security updates.</p>
<p>Another consideration is the risk that upgrading might interrupt manufacturing flow if the upgrading process requires extensive troubleshooting or potentially interrupt production. When equipment operates 24/7, the IT Team is under more pressure since there is no downtime for maintenance.</p>
<p>If the new application&#8217;s user interface significantly differs, shop floor personnel might require additional training. Inadequate training can lead to costly mistakes and safety issues. Scheduling training will affect the timing of deploying the new applications.</p>
<p>So, as you can see, when robotics, scientific instruments, lasers, manufacturing, or other equipment works just fine, upgrading the application offers no valuable benefits, and the IT team is busy, we find during audits and security assessments that many manufacturing organizations have outdated operating systems or need critical cybersecurity updates.</p>
<p>The organization&#8217;s executives might accept the risk, especially if compensating controls are in place.</p>
<p><strong>Alternative Tactics Increase Security:</strong></p>
<p>Using compensating controls in networks is essential because systems sometimes have significant vulnerabilities before updates are released or installed. Compensating controls are even more essential to help protect workstations if patches are missing.</p>
<p>Compensating controls include, and are not limited to, isolating the machines that control robotics, manufacturing equipment and scientific instruments on a separate network away from your network. That separate network must have limited connectivity to only allow traffic to and from the specific devices necessary and limit the kind of data and how it traverses the network to reduce the attack surface and make it more difficult for a malicious program or third party to access that instance or device. I sometimes refer to this tactic in keynote presentations as creating filtered subnets.</p>
<p>Another compensating control is to harden the unpatched or EOL machines by removing all applications except those essential for the equipment&#8217;s operation. Examples of applications that must be removed include browsers and email clients since they are common vectors for successful attacks. If the employees operating those devices require internet and email access, consider adding a separate workstation that is patchable for email and web access.</p>
<p>EDR/XDR (Endpoint Detection and Response / Extended Detection and Response) technology is another helpful control. It involves installing a small program called an agent on each computer. The EDR/XDR agent monitors the system&#8217;s software, services, and behavior for any signs that threat actors might have already compromised the computer. If the EDR/XDR tool detects an IoC (Indicator of Compromise), it can respond by interrupting the process. When tuned to avoid false alarms, the best response is to allow the agent to effectively quarantine the workstation from the rest of the network until the IT team can investigate. This helps prevent attackers from spreading to more hosts.</p>
<p>However, it is common for IT teams to succumb to the danger of relying too heavily on EDR/XDR to protect their organization and, therefore, neglect implementing other industry best practices to protect systems. Threat actors often set up EDR/XDR tools on their test networks to find ways to circumvent the protections. So, even if your EDR/XDR tool says everything is safe, it doesn&#8217;t necessarily mean threat actors aren&#8217;t active in your network.</p>
<p>To combat this, companies commonly conduct yearly red-team exercises, performed by exceptionally skilled IT teams that regularly perform these exercises and know the tricks and practices real-world threat actors use. These exercises are designed to test the effectiveness of the detection and response process. These exercises look for weaknesses in EDR/XDR and help keep the IT team in practice, ensuring they&#8217;re better prepared in the case of an attack.</p>
<p>Depending on your budget, if $20/user/month for EDR/XDR is not feasible, know that the other cybersecurity controls in this article, such as careful hardening and segmentation with very restrictive filtering, are much less expensive than EDR/XDR and have little if any ongoing expense. I don’t want to diminish the usefulness of EDR/XDR tools. If you are on a tight budget, unless your cybersecurity policy requires EDR/XDR, you might choose to focus on other compensating controls.</p>
<p>The IT Team must alert the executives about the expense of upgrading applications, isolating the shop floor instances on a separate network, deploying an additional network for web and email access, training users and operators, implementing EDR/XDR tools, and other expenses. Include time estimates along with financial estimates. Then, the executives can make an informed decision, and IT can follow their instructions and ask for support as necessary.</p>
<p><strong>Step-by-Step Guidance for IT Teams:</strong></p>
<p>Acknowledge that it can be a significant challenge and sometimes practically impossible to ensure that all workstations run with a current OS and that all critical security updates are applied. But keep applying updates if possible.</p>
<p>Inform your executives whether your team has time to make these changes. IT teams must alert executives of the time and expense involved. The executives will have options such as adding more IT professionals to augment the team, postponing other projects, or accepting the risk of continuing with unpatched systems or EOL OSs with the compensating controls listed below.</p>
<p>Explore all technical, training, and expense changes before upgrading applications.</p>
<p>Ask your supervisor to delegate the price checking to someone outside the IT department if feasible. Your IT team is very busy, so checking the prices might cause the upgrade to be delayed. It can be time-consuming to check with the robotic, manufacturing, and scientific equipment vendors to find the pricing for upgrades to their applications that control machinery.</p>
<p>Investigate more than the pricing. Ask about changes in the upgraded applications affecting the user interface and user experience. Ideally, the upgraded application software operates similarly and has the same interface. Unfortunately, some manufacturers significantly change the user experience when they upgrade their applications.</p>
<p>If users will need training, identify a trainer.</p>
<p>Determine how scheduling the training will affect the deployment timing.</p>
<p>Involve executives in decision-making and send them regular reports about the project&#8217;s progress.</p>
<p>Implement compensating controls on the workstations because of the high cybersecurity risk of missing critical patches or using EOL OSs. Compensating controls aren&#8217;t a replacement for missing patches, but the controls can help tremendously.</p>
<p>Remember that attackers can exploit security risks long before they are discovered. Only when the vulnerability is discovered will the operating system and application developers know to create or release patches to seal that security hole. Refrain from relying on patches as your sole security control for application software and operating systems.</p>
<p>Strongly consider isolating shop floor machines on a separate subnet, especially those you are prohibited from patching and those using EOL OSs. Isolate that subnet completely with an air gap or utilize aggressive filtering at the switch or router to limit traffic to only the required source, destination, ports, and protocols.</p>
<p>Additionally, hardening the workstations against attacks is strongly recommended.</p>
<p>Remove or restrict web and email access. This is one of the most effective ways to harden workstations, as web and email are two of the most common vectors for malware.</p>
<p>If the workers at those devices need access to the web and email, consider deploying a separate workstation to their station they can use for web and email. If feasible, that workstation should not be on the shop floor network. If you put those workstations on the equipment network, you would need to allow email and web traffic, and modifying access control lists to allow more sources, destinations, ports, and protocols can significantly reduce the security you would otherwise introduce to the equipment control network. Strive to exclude TCP ports 80 and 443 on the AI device network while allowing full functionality of the AI and other computer-controlled devices.</p>
<p>Be sure you limit the sources of inbound and destinations of outbound network traffic to the absolute minimum. If you need to run new cables to facilitate the additional workstations for web and email at the workers&#8217; stations, then running new cables might be a significant investment. Deploying a WiFi network for email and web access might be more economical. Keep the key secret. If you share the WiFi password, workers might connect other devices to the equipment network and compromise security. Completely blocking email and web access and access to external IP addresses will hamper the workers on the manufacturing network from exposing the hosts to many threats.</p>
<p>Strongly consider using EDR/XDR tools, along with the Red Team Exercises, to help ensure the configurations&#8217; effectiveness and allow your IT team to prepare for actual emergencies.</p>
<p><strong>Summary:</strong></p>
<p>Protect workstations that control hardware such as robotics, pharmaceuticals, lasers, and scientific instruments, regardless of whether they utilize AI. This helps ensure the safety and operability of your systems, protecting your organization and workers.</p>
<p>Subscribe to maximize your executive potential with Foster Institute&#8217;s E-Savvy Newsletter, packed with practical IT security solutions and actionable strategies for success: <a href="https://fosterinstitute.com/e-savvy-newsletter/">https://fosterinstitute.com/e-savvy-newsletter/</a></p>
<p>(Image source: Bing. Learn more at [Bing.com].)</p>
<p>The post <a href="https://fosterinstitute.com/ai-advancements-meet-security-ceos-handbook-to-securing-robotics-and-manufacturing-networks/">An Executive&#8217;s Handbook to Securing Modern Manufacturing Networks and Robots, AI or Not</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>AI Implementation Roadmap: The Executive&#8217;s Guide to Avoiding Million-Dollar Mistakes</title>
		<link>https://fosterinstitute.com/ai-implementation-roadmap-the-executives-guide-to-avoiding-million-dollar-mistakes/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Fri, 23 Aug 2024 21:15:15 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[CCPA]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Supporting IT Professionals]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=5866</guid>

					<description><![CDATA[<p>As a cybersecurity professional specializing in cybersecurity and AI, I&#8217;ve seen firsthand the importance of involving key stakeholders when implementing AI solutions. This guide highlights many essential steps to help ensure a smooth, secure, and compliant AI deployment in your organization. 1. Assemble Your AI Implementation Team Choose a person or team to lead AI [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/ai-implementation-roadmap-the-executives-guide-to-avoiding-million-dollar-mistakes/">AI Implementation Roadmap: The Executive&#8217;s Guide to Avoiding Million-Dollar Mistakes</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p class="whitespace-pre-wrap break-words">As a cybersecurity professional specializing in cybersecurity and AI, I&#8217;ve seen firsthand the importance of involving key stakeholders when implementing AI solutions. This guide highlights many essential steps to help ensure a smooth, secure, and compliant AI deployment in your organization.</p>
<h2 class="font-600 text-xl font-bold">1. Assemble Your AI Implementation Team</h2>
<ul class="-mt-1 list-disc space-y-2 pl-8">
<li class="whitespace-normal break-words">Choose a person or team to lead AI implementation</li>
<li class="whitespace-normal break-words">Include representatives from leadership, legal, and IT</li>
</ul>
<h2 class="font-600 text-xl font-bold">2. Educate Your Team on AI Applications</h2>
<ul class="-mt-1 list-disc space-y-2 pl-8">
<li class="whitespace-normal break-words">Watch the 7-minute educational video showcasing <a href="https://fosterinstitute.com/top-conversations-the-executives-playbook-for-conversing-with-ai-short-fast-paced-video/" target="_blank" rel="noopener">23 Business Uses for Chatbots in 7 minutes</a></li>
<li class="whitespace-normal break-words">Alternatively, schedule a &#8220;lunch and learn&#8221; webinar or workshop to explore practical AI uses</li>
</ul>
<h2 class="font-600 text-xl font-bold">3. Collaborate and Brainstorm</h2>
<ul class="-mt-1 list-disc space-y-2 pl-8">
<li class="whitespace-normal break-words">Discuss insights from the video/workshop</li>
<li class="whitespace-normal break-words">Identify potential AI applications relevant to your business</li>
</ul>
<h2 class="font-600 text-xl font-bold">4. Explore Multiple AI Tools</h2>
<ul class="-mt-1 list-disc space-y-2 pl-8">
<li class="whitespace-normal break-words">Test various chatbots (e.g., Perplexity, Anthropic Claude, ChatGPT, Microsoft Copilot, Google Gemini)</li>
<li class="whitespace-normal break-words">Consider paid plans, privacy of sensitive information, and the ability to create custom chatbots</li>
<li class="whitespace-normal break-words">The setting to make the model better for everyone means your data will be less private</li>
</ul>
<h2 class="font-600 text-xl font-bold">5. Review Industry-Specific AI Tools</h2>
<ul class="-mt-1 list-disc space-y-2 pl-8">
<li class="whitespace-normal break-words">Investigate AI solutions tailored to your industry</li>
<li class="whitespace-normal break-words">Consult a curated list of AI tools for practical options</li>
</ul>
<h2 class="font-600 text-xl font-bold">6. Consult with Your IT Team</h2>
<ul class="-mt-1 list-disc space-y-2 pl-8">
<li class="whitespace-normal break-words">Discuss potential added support requirements</li>
<li class="whitespace-normal break-words">Address concerns about job complexity</li>
<li class="whitespace-normal break-words">Develop strategies to integrate AI without overburdening your IT team</li>
</ul>
<h2 class="font-600 text-xl font-bold">7. Engage Your Legal Counsel</h2>
<ul class="-mt-1 list-disc space-y-2 pl-8">
<li class="whitespace-normal break-words">Address privacy concerns</li>
<li class="whitespace-normal break-words">Review automatic ingestion vs. uploading of data for different AI tools</li>
<li class="whitespace-normal break-words">Analyze privacy and security policies of prospective AI solutions</li>
<li class="whitespace-normal break-words">Consider internal data access and permissions per user or department</li>
<li class="whitespace-normal break-words">Evaluate potential implications for mergers and acquisitions</li>
<li class="whitespace-normal break-words">Consider that data from recordings of meetings will be discoverable during the due diligence phase</li>
</ul>
<h2 class="font-600 text-xl font-bold">8. Assess User Access Control</h2>
<ul class="-mt-1 list-disc space-y-2 pl-8">
<li class="whitespace-normal break-words">Discuss with IT about controlling access to AI tools</li>
<li class="whitespace-normal break-words">Implement measures to manage access to AI on company networks and devices</li>
</ul>
<h2 class="font-600 text-xl font-bold">9. Establish an AI Ethics Framework</h2>
<ul class="-mt-1 list-disc space-y-2 pl-8">
<li class="whitespace-normal break-words">Develop guidelines for ethical AI use within your organization</li>
<li class="whitespace-normal break-words">Address issues like bias, fairness, and transparency</li>
</ul>
<h2 class="font-600 text-xl font-bold">10. Create a Data Governance Strategy</h2>
<ul class="-mt-1 list-disc space-y-2 pl-8">
<li class="whitespace-normal break-words">Establish protocols for data handling, storage, and access in AI systems</li>
<li class="whitespace-normal break-words">Ensure compliance with relevant data protection regulations (e.g., GDPR, CCPA)</li>
</ul>
<h2 class="font-600 text-xl font-bold">11. Implement Security Measures</h2>
<ul class="-mt-1 list-disc space-y-2 pl-8">
<li class="whitespace-normal break-words">Work with IT to set up necessary security protocols for AI systems</li>
<li class="whitespace-normal break-words">Consider encryption, access controls, and monitoring systems</li>
<li>Utilize sensitivity labels and permissions to limit employee access by role, etc.</li>
<li>Establish data retention time policies</li>
</ul>
<h2 class="font-600 text-xl font-bold">12. Plan for Ongoing Monitoring and Evaluation</h2>
<ul class="-mt-1 list-disc space-y-2 pl-8">
<li class="whitespace-normal break-words">Establish KPIs to measure the effectiveness and impact of AI implementation</li>
<li class="whitespace-normal break-words">Set up regular review processes to assess and adjust AI usage</li>
</ul>
<h2 class="font-600 text-xl font-bold">13. Develop a Crisis Management Plan</h2>
<ul class="-mt-1 list-disc space-y-2 pl-8">
<li class="whitespace-normal break-words">Prepare for potential AI-related incidents or breaches</li>
<li class="whitespace-normal break-words">Outline response procedures and communication strategies</li>
</ul>
<h2 class="font-600 text-xl font-bold">14. Draft an AI Policy</h2>
<ul class="-mt-1 list-disc space-y-2 pl-8">
<li class="whitespace-normal break-words">Based on input from IT and legal, create a comprehensive AI usage policy</li>
<li class="whitespace-normal break-words">Define the scope and purpose of the AI policy</li>
<li class="whitespace-normal break-words">List approved AI tools and outline acceptable use cases</li>
<li class="whitespace-normal break-words">Establish guidelines for data handling and privacy compliance</li>
<li class="whitespace-normal break-words">Specify required security measures for AI use</li>
<li class="whitespace-normal break-words">Address ethical considerations like bias and fairness</li>
<li class="whitespace-normal break-words">Clarify ownership of AI-generated content and intellectual property</li>
<li class="whitespace-normal break-words">Outline required AI literacy training for employees</li>
<li class="whitespace-normal break-words">Define monitoring procedures and consequences for policy violations</li>
<li class="whitespace-normal break-words">Set criteria for selecting and evaluating AI vendors</li>
<li class="whitespace-normal break-words">Provide a framework for responding to AI-related incidents</li>
<li class="whitespace-normal break-words">Establish a schedule for reviewing and updating the policy</li>
</ul>
<h2 class="font-600 text-xl font-bold">15. Conduct User Training</h2>
<ul class="-mt-1 list-disc space-y-2 pl-8">
<li class="whitespace-normal break-words">Train employees on approved AI resources</li>
<li class="whitespace-normal break-words">Educate staff about the new AI policy, including ethics and protecting sensitive information</li>
<li>Encourage users to look at their daily tasks and see which tasks AI might streamline or improve in other ways</li>
</ul>
<h2 class="font-600 text-xl font-bold"></h2>
<p class="whitespace-pre-wrap break-words">By following all these steps, you&#8217;ll be more prepared to deploy AI in your organization while addressing some essential security, legal, and operational concerns. Successful AI implementation is an ongoing process requiring continuous attention and adaptation. AI is here to stay; you want to be thoughtful sooner to avoid costly problems later.</p>
<div class="et_pb_module et_pb_post_content et_pb_post_content_0_tb_body">
<p>&nbsp;</p>
<p><strong>Subscribe</strong> to maximize your executive potential with Foster Institute’s E-Savvy Newsletter, packed with practical IT security solutions and actionable strategies for success: <a href="https://fosterinstitute.com/e-savvy-newsletter/">https://fosterinstitute.com/e-savvy-newsletter/</a></p>
</div>
<p>The post <a href="https://fosterinstitute.com/ai-implementation-roadmap-the-executives-guide-to-avoiding-million-dollar-mistakes/">AI Implementation Roadmap: The Executive&#8217;s Guide to Avoiding Million-Dollar Mistakes</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>What Executives Must Know: VPNs and Public Network Security</title>
		<link>https://fosterinstitute.com/what-executives-must-know-vpns-and-public-network-security/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Sun, 07 Jul 2024 04:19:40 +0000</pubDate>
				<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Executive Tips]]></category>
		<category><![CDATA[hotspot]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[Remote Worker]]></category>
		<category><![CDATA[Remote Worker Security]]></category>
		<category><![CDATA[Technology Safety Tips]]></category>
		<category><![CDATA[wi-fi best practices]]></category>
		<category><![CDATA[wi-fi security]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=5834</guid>

					<description><![CDATA[<p>Many of us believe that a Virtual Private Network (VPN) alone is enough of a security measure to protect users who connect at a coffee shop, hotel, or other public network. Still, it can expose your organization to threat actors who could compromise the user’s laptop and, consequently, your entire organization. &#160; While VPNs have [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/what-executives-must-know-vpns-and-public-network-security/">What Executives Must Know: VPNs and Public Network Security</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Many of us believe that a Virtual Private Network (VPN) alone is enough of a security measure to protect users who connect at a coffee shop, hotel, or other public network. Still, it can expose your organization to threat actors who could compromise the user’s laptop and, consequently, your entire organization.</p>
<p>&nbsp;</p>
<p>While VPNs have long been a staple for securing connections in coffee shops and other public networks, by integrating advanced security measures, you can fortify your organization&#8217;s defenses and stay ahead of emerging threats.</p>
<p>&nbsp;</p>
<p>The goal of this article is to empower you with insights and strategies to bolster your IT team&#8217;s efforts. By equipping them with cutting-edge tools and knowledge, you can elevate your organization&#8217;s cybersecurity posture. Remember, cybersecurity is a dynamic, ever-changing domain that demands continuous adaptation and vigilance.</p>
<p>&nbsp;</p>
<p><strong>Introduction:</strong></p>
<p>A VPN, a virtual private network, is designed to provide privacy of traffic across untrusted networks and through the Internet by encrypting data between the user’s device and the company network. It functions as a network connection from one point to the other. In the case of a remote access VPN, those two points are the user’s laptop and your company’s VPN terminus in your data center or elsewhere.</p>
<p>&nbsp;</p>
<p>Some companies commonly allow or encourage remote users to connect via VPNs while out of the office, under the impression that the VPN alone protects remote users from security risks on a public network.</p>
<p>&nbsp;</p>
<p>While a VPN can protect data in transit, it does not protect against all threats on the local network, such as those present on a Wi-Fi network at a public location. The evolving nature of cybersecurity threats means additional measures are necessary.</p>
<p>&nbsp;</p>
<p>The often-overlooked risk is that when connected to a public network and using a VPN, the user&#8217;s laptop remains exposed to network sweeps, vulnerability scans, and other network attacks. VPNs still play an essential role by encrypting traffic.</p>
<p>&nbsp;</p>
<p>Ideally, users should avoid connecting to public networks. If connecting to a public network is necessary, it is crucial to implement additional cybersecurity controls, such as using a properly configured physical hardware firewall, to protect against network attacks.</p>
<p><strong> </strong></p>
<p><strong>Real-World Ways Attackers Breach VPN Users on Public Networks:</strong></p>
<p>Here are three notable examples of how threat actors attack workers who connect to a public network using a VPN:</p>
<p>&nbsp;</p>
<p><strong>Attacking a VPN Client via Airport Wi-Fi:</strong></p>
<p>Advanced Persistent Threat (APT) groups are targeting enterprise VPN vulnerabilities. A recent example is the 2024 VPN attacks against Ivanti. For example, an employee connects to their corporate network using vulnerable VPN software at an international airport. Attackers exploit the VPN vulnerability, bypass encryption, and install malware on the employee’s laptop. This allows them to infiltrate the company’s network, stealing proprietary manufacturing processes and trade secrets, causing significant financial losses and requiring a major incident response.</p>
<p>&nbsp;</p>
<p><strong>Attacking and Breaching VPN Users on Public Library Wi-Fi:</strong></p>
<p>A severe security flaw known as PrintNightmare can be exploited by threat actors against computers, even those of users connected to a VPN over a WiFi network. A typical instance is an employee of a prestigious law firm working remotely from a public library, using the corporate VPN to access internal resources. Attackers on the same network exploit the PrintNightmare vulnerability, executing malicious code on the employee’s laptop. This breach allows the attackers to move within the firm’s network, accessing confidential client information and case details. This leads to legal repercussions and reputational damage, prompting a thorough overhaul of its security practices.</p>
<p>&nbsp;</p>
<p><strong>Tech Company Infiltrated via Coffee Shop Wi-Fi:</strong></p>
<p>Threat actors can utilize Mirai malware that spreads to devices on networks, including public WiFi networks, affecting users even when they are utilizing VPNs. A case in point is an employee of a tech company connecting to their office VPN from a coffee shop’s public Wi-Fi network. The network contains compromised devices infected with Mirai malware. The employee’s laptop, running outdated Windows, becomes infected. The malware uses the VPN connection to infiltrate the company’s network, leading to data theft and unauthorized access to sensitive projects. The company must enforce strict security protocols and undergo a comprehensive network data discovery and clean-up.</p>
<p>&nbsp;</p>
<p><strong>The Core Issue with VPNs on Public Networks:</strong></p>
<p>VPNs play a vital role in encrypting data and maintaining privacy by encrypting data in transit. They do not fully protect you from local threats found on public networks like those in coffee shops, hotels, or airports. Complementing VPNs with additional tools, such as travel routers or cellular hotspots, as explained below, can significantly mitigate these risks.</p>
<p>&nbsp;</p>
<p><strong>Simplifying the VPN Concept:</strong></p>
<p>Some think of a VPN as a tunnel through the Internet that provides a network connection. This tunnel can allow you to work as if you were connected in person at your office, but remember, the VPN provides privacy for your data but not comprehensive security for your laptop.</p>
<p>&nbsp;</p>
<p><strong>Understanding the VPN Paradox to Prevent Breaches</strong></p>
<p>The common belief that a VPN alone guarantees security in a coffee shop scenario is not only incomplete &#8211; it&#8217;s potentially dangerous. Addressing this belief is crucial for your company&#8217;s cybersecurity.</p>
<p>&nbsp;</p>
<p><strong>The Danger of a False Sense of Security</strong></p>
<p>When workers believe that a VPN makes them secure, they may unknowingly increase their risk by connecting to insecure networks, thinking they are safe. This false sense of security can lead to substantial cybersecurity incidents within an organization.</p>
<p><strong> </strong></p>
<p><strong>Solutions for Executives to Consider:</strong></p>
<p>Two relatively simple solutions to help remote users be secure are to prevent them from connecting to the coffee shop, hotel, or other network and connect with a mobile phone or cellular hotspot. Alternatively, the user can be provided with and trained to use a properly configured small hardware firewall to help protect their laptop from the risks of the public network.</p>
<p>&nbsp;</p>
<p>Addressing these challenges with your IT Team can strengthen your defenses against sophisticated cyber threats. Implementing portable hardware firewalls or alternative connectivity options can bolster users’ security as they work remotely.</p>
<p>&nbsp;</p>
<p><strong>Introduction to Ways to Help Keep Remote Users and VPNs Secure:</strong></p>
<p>What follows is detailed information, described in plain English, for executives and IT Pros who want more information about the risks and how to protect remote users connecting through a remote access VPN connection. Allowing users to use a VPN on a public network could result in a breach at your organization, hence the reason for this document.</p>
<p>&nbsp;</p>
<p><strong>Actionable Steps:</strong></p>
<p>This article&#8217;s purpose is to highlight the potential security enhancement provided by eliminating the incidence of users connecting to the public network or, if they do connect, using a hardware firewall to isolate them from the public network.</p>
<p>&nbsp;</p>
<p>A threat actor doesn’t need to be in the coffee shop; the attacks can originate from an innocent user’s laptop that they do not realize has been compromised by a threat actor or a malicious program or service running on another computer connected to the guest network.</p>
<p>&nbsp;</p>
<p>To avoid connecting to the public network, users can use their properly configured phone or a cellular hotspot to connect from the coffee shop, hotel, or other public area. Cellular networks can have security concerns, too. Fake cellular towers or insiders working at the cellular company are examples of threats, but cellular connections are arguably more secure than public WiFi networks. The benefit of this method is how quick and convenient the connection is. Drawbacks include the need for a reliable cellular signal and potentially increased recurring data charges by the cellular carrier. Additionally, if the user exceeds the carrier’s data limit for the month, the carrier might throttle (slow down) the user’s data rate for the rest of the month.</p>
<p>&nbsp;</p>
<p>If the user doesn’t have access to a cellular connection, wants to avoid wireless carrier fees, or wants to connect to the public network for any other reason, they could use a portable firewall, commonly known as a travel router, to help isolate them from the risks of the public network. Useful travel routers are available for a one-time purchase for less than $100. Keep in mind that the user’s data rate will be restricted to the data rate of the public network or slower if the user uses a VPN across the public network. Public network speeds can vary greatly, as can cellular data speeds, even during different times of day.</p>
<p>&nbsp;</p>
<p>It is essential to note that while travel routers and firewalls can help mitigate many risks, they must be appropriately configured to be effective. Their configuration screens can be complex, potentially leading to insecure configurations. A user with an improperly configured travel router connection is dangerous since the user might have a false sense of security. It is essential to involve your IT Team in the planning, configuring, and deploying travel routers, as well as the necessary training for users to use the devices securely.</p>
<p>&nbsp;</p>
<p>Using a travel router requires additional user training for them to complete three steps. After powering on the firewall device, the laptop user must first connect their laptop to the travel router as if it were a cellular hotspot or another Wi-Fi connection. This is a relatively simple process and will likely be the same routine for the life of the travel router. Many travel routers accept wireless and wired connections. The second step is for the user to use a window in their browser to connect the travel router to the public network’s name. This step is potentially precarious due to the complexity of the configuration screen on some travel routers. Your IT Team must be involved in creating precise documentation, user training, and configuring the devices. Third, the user goes through the process of logging into the public network if the public network requires some kind of login process, such as a room number and last name at a hotel. If the user doesn’t see the hotel login screen, they can open a new tab in their browser to neverssl dot com or nossl dot com, and the hotel login screen will usually pop up.</p>
<p>&nbsp;</p>
<p>Typically, the public network recognizes the firewall as if the user is connected directly from their laptop. Now, the user does their work as usual. The travel router acts as a firewall between the laptop and the potentially risky public network.  The connection process is usually speedy if the user frequents the same public hotspots. Even at a new network, if the user is trained, going through the three-step process usually takes five minutes.</p>
<p>&nbsp;</p>
<p>VPNs are essential for encrypting data and protecting privacy, including the sites users visit while connected to a network. Users wishing to use a VPN to control privacy can use the VPN client on their laptop as usual. This applies whether the user uses their cellular connection or a travel router. Many travel routers include a VPN feature, too. Secure Access Service Edge (SASE), pronounced sassy, is a technology that provides a more comprehensive approach to secure access that can sometimes replace traditional remote connection strategies. Everything in this article about protecting a user’s laptop from security threats against the public network connection still applies in SASE.</p>
<p>&nbsp;</p>
<p>Technologies that sound like alphabet soup and are explained below, such as IDS (Intrusion Detection System), IPS (Intrusion Prevention System), EDR (Endpoint Detection and Response), and XDR (Extended Detection and Response), can help protect the laptop against threats potentially lurking on public networks. However, attackers also obtain these protection tools. They are constantly probing for weaknesses they can exploit, so you must continue to use additional tools and techniques to protect your organization in a layered approach.  And the necessity of maintaining and monitoring those technologies can create a significant burden on your IT Team. More on that below.</p>
<p>&nbsp;</p>
<p><strong>Multi-factor Authentication is Not a Shield:</strong></p>
<p>Multi-factor authentication (MFA), such as a text message or authenticator app, is an essential part of your cybersecurity strategy that you must adopt immediately if it isn’t already in use. While MFA helps secure the authentication process, it does not address network attacks or other ways that could allow an attacker to compromise the laptop. If attackers compromise the laptop, they can bypass MFA by utilizing the user’s active session. The attacker can wait for the authorized user to log in using MFA on their behalf, and then the attacker can have the same level of access as the authenticated user. The point is that MFA is an essential, if not mandatory, cybersecurity control, but it does not protect the user against network attacks on a public network.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong> </strong></p>
<p><em>For those of you familiar with my articles, you know my focus is to present cybersecurity topics in non-technical terms. The following section is more technical than usual. Consider passing this along to your IT team if they want more technical details.</em></p>
<p><strong> </strong></p>
<p><strong>The Technical Details to Protect Yourself and Your Organization</strong></p>
<p>In the next portion of this document, we&#8217;ll explore configuring the data center&#8217;s networking environment and the remote hosts to make using a remote access VPN safer.</p>
<p><strong> </strong></p>
<p><strong>Quick Definitions Used in this Document</strong></p>
<ul>
<li>Remote Access VPN: This type of VPN allows individuals to connect to their company&#8217;s network, unlike site-to-site VPNs, which connect two office locations or data centers.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Unmanaged Computer: A computer not maintained by your IT professional who uses specialized knowledge and tools. These endpoints are more vulnerable.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Public Network: Think coffee shops, cruise ships, resorts, hotels, airports, etc.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>MFA (Multi-factor Authentication): This adds a layer of security for the authentication process beyond just passwords. Examples of MFA include a text message or an authenticator app on your phone. However, MFA doesn&#8217;t shield you from threats of malicious signals on a network scanning your laptop for vulnerabilities and security misconfigurations.</li>
</ul>
<p>&nbsp;</p>
<p><strong>The Core Issue with Remote Access VPNs</strong></p>
<p>A significant concern with remote access VPNs is that attackers gain the same access as the remote user if a remote host is compromised.</p>
<p>&nbsp;</p>
<p><strong>Protective Strategies</strong></p>
<p>Please keep reading to learn how to safeguard your network and host computers, ensuring they don&#8217;t become conduits for attackers to infiltrate your network.</p>
<p>&nbsp;</p>
<p><strong>Part 1: Fortifying User Devices Against Infection: Such as Protecting the User at the Coffee Shop</strong></p>
<p>&nbsp;</p>
<p>While a VPN doesn&#8217;t inherently secure a device on a public network, the following measures can bolster your device’s security:</p>
<p>&nbsp;</p>
<ul>
<li>Fundamental Cybersecurity Controls on Endpoints: Use core cybersecurity controls for laptops. For example, regular critical security updates should be applied soon after release. To help stop attacker programs, restrict what applications can run using application control. Prevent users from installing applications by controlling their permissions or using third-party tools. Restrict enabled services to essential functions only that the user would use. Close all open ports. Follow other cybersecurity best practices.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Endpoint Protection: Some organizations deploy Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) on remote users’ devices. Using Endpoint Detection and Response (EDR), Extended Detection and Response (XDR), or Managed Detection and Response (MDR) agents on the laptops can increase security by monitoring for malicious behavior known as an indicator of compromise (IoC). EDR/XDR tools provide many benefits, including continuously monitoring network devices and watching for suspicious activities or evidence that an attacker is compromising a system. EDR/XDR is designed to identify, isolate, and mitigate threats. Response options include stopping the threat actor by shutting down processes and services or, as a more comprehensive response, quarantining the remote device until the IT Team can investigate. The thorough response would be for the IT team to erase and reload the workstation if there is any indication that the device was compromised. Some organizations use automated means of initializing workstations to facilitate this reloading process. IDS, IPS, EDR, and XDR must be effectively monitored, managed, and updated. One way many organizations ease the burden on their internal IT Teams is to utilize a third-party MSSP to perform these tasks. Managed Detection and Response (MDR) means you pay a third-party provider to manage your EDR/XDR. One key point to remember is that attackers can obtain these protection tools, too, and are always looking for ways to bypass the tools. We perform Red Team Exercises at companies to test the capabilities of the EDR and XDR protections. Do not make the common mistake of letting your guard down in other security areas after implementing EDR or XDR.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Shielding from Public Networks: Equip remote users with a filtering device, such as a portable firewall or travel router, to act as an intermediary between their laptop and the public network. In some cases, these devices can establish VPN connections directly to the data center, offering an added layer of security since the laptop is shielded from the network. Proper configuration of travel routers is crucial. They should be set up to help ensure secure connections, such as using the most secure Wi-Fi security protocols, regularly updated with the latest firmware to protect against vulnerabilities, secure configuration policies, and other steps to enhance security.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Alternative Connectivity: When a secure filtering device isn&#8217;t available, it is recommended that remote users connect via a cellular network to avoid the risks of public Wi-Fi. When you are disconnected from public Wi-Fi, you are also disconnected from potentially harmful devices on that network.</li>
</ul>
<p>&nbsp;</p>
<p>By implementing these practices, you can significantly enhance your security posture against the potential risks associated with remote VPN access.</p>
<p>&nbsp;</p>
<p><strong>Part 2: Securing Your Organization’s Network Against Compromised Users’ Laptops on a Remote Access VPN: Protecting the Organization from the User at the Coffee Shop</strong></p>
<p>&nbsp;</p>
<p>To help prevent unauthorized network access through a compromised VPN user&#8217;s device, consider these strategies:</p>
<p>&nbsp;</p>
<ul>
<li>Restricted Access: Restrict VPN use to company-issued computers only. Your IT team must manage robust security measures like patch management, EDR/XDR solutions, stringent configurations, and more.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Ban Personal Devices on VPN: Consider prohibiting the use of family or personal devices for VPN access. These unmanaged devices are more susceptible to malware, which can spread to your corporate network.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Network and Firewall Strategies at the Data Center:</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Server Segmentation: Isolate RDS and file servers in separate network segments or VLANs. This approach allows for tailored security policies and mitigates the spread of potential breaches.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>VPN Traffic Isolation: Create a dedicated network segment for VPN traffic to act as a buffer zone, keeping incoming connections separate from the core network.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Firewall Implementation: Place firewalls strategically to monitor and control traffic between the VPN and other network segments. Implement Firewall Access control Lists (ACLs, a.k.a. Firewall Rules) to define and enforce permissible traffic types, sources, and destinations between these segments.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Traffic Protocol Rules: Specifically, allow only necessary protocols like RDP and file-sharing through the VPN to the designated servers, using protocol filtering and port restrictions to enforce this.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Session Management: Configure firewalls to limit session numbers and durations, reducing the risk of prolonged unauthorized access.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Deep Packet Inspection: Employ firewalls capable of DPI to scrutinize traffic content, ensuring it aligns with expected patterns.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Vigilant Monitoring: Set up logging for all traffic passing through the firewalls and regularly review these logs for anomalies.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Firewall and Infrastructure Firmware Patches and Updates: Keep firewall firmware and configurations up to date to counter emerging threats.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Regular Audits: Conduct periodic audits to validate the effectiveness of your security measures.</li>
</ul>
<p>&nbsp;</p>
<p><strong>Part 3: Don’t Provide an Easy Path for Attackers to Access Your Files</strong></p>
<p>&nbsp;</p>
<ul>
<li>Omitting Drive Mapping to Remote Hosts: Consider alternative solutions for file sharing rather than mapping server drives for remote VPN users. If you share a drive through the VPN and an attacker compromises a host, the attacker can access the drive. The mapping makes it easier for the attacker to encrypt or delete files on your servers.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>If you won&#8217;t map drives, and the remote users need direct access to the exact instances of the files local users have, strategies include:</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Cloud Storage: To avoid drive mapping, the files could be stored in a cloud location, from Microsoft or a third-party solution, for all users to access.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>File Synchronization Considerations: If cloud storage is not an option, and the files must be stored on traditional servers for local users, some form of file synchronization could be utilized to copy the files to a hosted location accessible to remote users. This would be effective if remote users only read, not edit, the files. If multiple users edit files simultaneously, data inconsistencies are likely. The synchronization would need to consider the possibility of a local user editing a file while a remote user editing a file in the shared storage environment. In this case, the synchronization process would need to know which saved version to preserve and what to do with the conflicting version. It should also alert the users that they could have lost their edits.</li>
</ul>
<p>&nbsp;</p>
<p><strong>VPNs and MFA: A Misunderstood Safety Net</strong></p>
<p>In my experience, some well-meaning IT professionals proclaim, &#8220;If you are in a coffee shop, you can protect yourself from the security risks if you use a VPN backed up with MFA.&#8221; This well-intentioned advice, however, needs a deeper dive to uncover the whole truth.</p>
<p><strong> </strong></p>
<p><strong>MFA and VPN Security:</strong></p>
<p>Multi-factor authentication (MFA) significantly enhances security by helping ensure that only authorized users can access VPNs. However, it&#8217;s crucial to understand that while MFA helps in securing the authentication of users, MFA does not safeguard against attacks exploiting vulnerabilities on devices connected to the public network. For example, MFA cannot protect against an attacker scanning for open ports on a laptop connected to a compromised Wi-Fi network. These attacks can occur independently of the authentication process that MFA protects, highlighting the need for comprehensive endpoint security measures and robust authentication protocols.</p>
<p>&nbsp;</p>
<p>To guard against a wide range of threats, organizations must implement a layered security approach that includes strong authentication measures like MFA and endpoint protection strategies. This should involve regularly patching and updating software and operating systems, closing unnecessary ports, employing host-based firewalls, and continuously monitoring suspicious activities. By addressing device-level security with authentication controls, organizations can provide a more robust defense against attackers&#8217; diverse tactics.</p>
<p>&nbsp;</p>
<p><strong>Consider Alternative Solutions for Remote Access: </strong></p>
<p>A Remote Desktop Services (RDS) gateway can allow remote users to access internal network resources without requiring a traditional VPN connection. This approach can reduce the network&#8217;s attack surface by not providing a tunnel for attackers to exploit. However, RDS gateways come with other security challenges and require robust configuration and protection. User devices using RDS still need robust security measures to help protect against potential compromises, including an attacker compromising a remote user’s laptop.</p>
<p>&nbsp;</p>
<p>Similarly, allowing remote users to operate cloud-based virtual desktops, such as those provided by Windows 365, can eliminate the need for drive mappings to the remote user’s computer.</p>
<p>&nbsp;</p>
<p>However, it is essential to recognize that if the remote host system—whether a cloud-based virtual desktop or a machine accessed via an RDS gateway—is compromised, an attacker may still be able to hijack a user&#8217;s session. This potential risk underscores the necessity for robust security measures, including continuous monitoring and response strategies, to quickly detect and address any such compromise.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>In Conclusion:</strong></p>
<p>VPNs provide significant security benefits by encrypting data, which is crucial for privacy and protection against eavesdropping. However, they should be part of a broader security strategy that includes secure endpoints and awareness of public network risks. An attacker, physically present in the coffee shop or remotely controlling another patron&#8217;s device, could exploit open ports, unpatched vulnerabilities, or other security loopholes. This is where malware, often lurking unnoticed, can exploit weaknesses on your laptop.</p>
<p>&nbsp;</p>
<p>Threat actors rely on the misconception that using a VPN is the only cybersecurity control necessary to protect users on public networks. Some of the most significant cybersecurity predictions relate to threat actors attacking VPNs. Additionally, using a VPN with drive mapping is a common practice for remote work but includes significant inherent risks.</p>
<p>&nbsp;</p>
<p>Bolster your organization’s security by empowering your users to avoid connecting to a public network and consider some form of securely configured cellular connection. If they connect to the public network, consider facilitating their security with a properly configured hardware firewall to help isolate their laptop from the public network.</p>
<p>&nbsp;</p>
<p>Combining multiple tools and best practices is essential for a layered security approach. As always, regular user training is an essential component of keeping your organization secure.</p>
<p>&nbsp;</p>
<p>Note: This document provides guidelines for enhancing remote access security through VPNs and alternative methods. It does not address the security specifics of the VPN client application or browser plugins. Readers are encouraged to follow cybersecurity best practices for those components as well.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Disclaimer: The information provided in this blog is for general informational purposes only. Technology changes constantly, and some of this information might become obsolete or incorrect. We do not endorse or receive compensation for mentioning products, services, or brand names. Any outbound links provided are for your convenience and to get you started, but we cannot guarantee the security or safety of those external websites. Conducting your research and making an informed decision about any products or services mentioned here is essential. We shall not be held responsible for any actions taken based on the information provided.</p>
<p>&nbsp;</p>
<p>The post <a href="https://fosterinstitute.com/what-executives-must-know-vpns-and-public-network-security/">What Executives Must Know: VPNs and Public Network Security</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Have You Explored ChatGPT Plus&#8217;s File Upload Feature Yet?</title>
		<link>https://fosterinstitute.com/have-you-explored-chatgpt-pluss-file-upload-feature-yet/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Sun, 12 Nov 2023 03:27:32 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[Save time]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Technology Tips]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=5700</guid>

					<description><![CDATA[<p>ChatGPT Plus&#8217;s file upload feature opens up new possibilities for interacting with AI, offering a seamless way to enhance your experience. If you haven&#8217;t tried it yet, here&#8217;s why you should consider exploring this versatile tool. File Uploads Made Easy ChatGPT Plus allows you to upload various types of files for a more integrated interaction. [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/have-you-explored-chatgpt-pluss-file-upload-feature-yet/">Have You Explored ChatGPT Plus&#8217;s File Upload Feature Yet?</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>ChatGPT Plus&#8217;s file upload feature opens up new possibilities for interacting with AI, offering a seamless way to enhance your experience. If you haven&#8217;t tried it yet, here&#8217;s why you should consider exploring this versatile tool.</p>
<p><strong>File Uploads Made Easy</strong></p>
<p>ChatGPT Plus allows you to upload various types of files for a more integrated interaction. Whether it&#8217;s a PDF document for analysis or an image of an object for detailed inquiries, the process is straightforward. This feature eliminates the need for extensive copying and pasting, enabling ChatGPT to analyze your data in its intended format for more accurate responses.</p>
<p><strong>Bypassing Prompt Length Limitations</strong></p>
<p>Encountered the “The message you submitted was too long” error? Uploading a file is an effective workaround. Be mindful, though, if your file is exceptionally large, it might exceed the token limit, affecting ChatGPT&#8217;s ability to process the entire content. As technology advances, expect to see expansions in these limits.</p>
<p><strong>Versatile File Types and Actions</strong></p>
<ul>
<li><strong>Documents</strong> (.pdf, .docx, .txt): Ideal for generating summaries, updates, translations, and more. ChatGPT&#8217;s proficiency in extracting information from PDFs is particularly impressive. For instance, try asking, “Address challenges with solutions” after uploading a document.</li>
<li><strong>Images</strong> (.jpg, .png, .gif): Upload images for descriptions, analysis, or creative storytelling. Imagine uploading a photo of your pet and asking, “Generate an image of my pet sitting in First Class on a plane.” Mobile app users can directly take and upload pictures.</li>
<li><strong>Spreadsheets</strong> (.xls, .xlsx): While capabilities continue to grow, basic functions like finding, counting, and analyzing data work smoothly. If you encounter difficulties, consider converting your spreadsheet to a PDF for more efficient processing.</li>
<li><strong>Presentations</strong> (.ppt, .pptx): Share your slides for summaries and improvement recommendations. Converting to PDF might enhance ChatGPT&#8217;s understanding.</li>
</ul>
<p><strong>How to Use the File Upload Feature</strong></p>
<p>Utilize the &#8216;Upload&#8217; button in the ChatGPT interface to interact with your chosen file. This feature is accessible both in the browser and mobile app versions. For more advanced capabilities, ChatGPT Plus members can enable Advanced Data Analysis in the Settings under Beta features.</p>
<p><strong>Privacy Considerations</strong></p>
<p>Prioritize your privacy when using this feature. ChatGPT offers options to disable chat history and assures not to use your data for training purposes. Stay informed by checking <a href="https://help.openai.com/en/articles/7730893-data-controls-faq" target="_blank" rel="noopener">OpenAI&#8217;s Data Controls FAQ</a> and <a href="https://fosterinstitute.com/chatbots-helpful-friends-or-privacy-foes-how-to-safeguard-your-information/" target="_blank" rel="noopener">additional insights on chatbot privacy</a>.</p>
<p><strong>Experience the Enhanced ChatGPT</strong></p>
<p>The file upload feature significantly broadens ChatGPT&#8217;s utility, catering to educational, professional, or exploratory needs. Dedicate a few minutes to import non-sensitive files and experiment with various prompts. You&#8217;ll discover its strengths and limitations, pushing the boundaries of AI interaction.</p>
<p><strong>Comparing With Other Platforms</strong></p>
<p>At a subscription fee of twenty dollars per month, ChatGPT Plus stands out for its file upload capability. Yet, other chatbots, including free versions like Perplexity.ai and Google Bard, offer similar features, indicating a trend towards standardizing file uploads across AI platforms.</p>
<p>&nbsp;</p>
<p><strong>Subscribe</strong> to maximize your executive potential with Foster Institute’s E-Savvy Newsletter, packed with practical IT security solutions and actionable strategies for success: <a href="https://fosterinstitute.com/e-savvy-newsletter/" target="_blank" rel="noopener">https://fosterinstitute.com/e-savvy-newsletter/</a></p>
<p>(Image source: DALL-E via ChatGPT Plus)</p>
<p>The post <a href="https://fosterinstitute.com/have-you-explored-chatgpt-pluss-file-upload-feature-yet/">Have You Explored ChatGPT Plus&#8217;s File Upload Feature Yet?</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Executives, Guard Your Company&#8217;s Future: Why Ensuring Email Boundaries is Crucial for Security.</title>
		<link>https://fosterinstitute.com/executives-guard-your-companys-future-why-ensuring-email-boundaries-is-crucial-for-security/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Mon, 23 Oct 2023 21:17:27 +0000</pubDate>
				<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Email Security]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Spear Phishing]]></category>
		<category><![CDATA[Technology Safety Tips]]></category>
		<category><![CDATA[Technology Tips]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=5689</guid>

					<description><![CDATA[<p>Most people realize the extreme importance of training employees to recognize and avoid phishing emails. But there are other essential components. &#160; Keep Personal Matters Out of Company Email: Attackers sometimes gain access to websites used for personal activities like watching movies, paying utility bills, personal checking accounts, and more. Bad actors leverage this information [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/executives-guard-your-companys-future-why-ensuring-email-boundaries-is-crucial-for-security/">Executives, Guard Your Company&#8217;s Future: Why Ensuring Email Boundaries is Crucial for Security.</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Most people realize the extreme importance of training employees to recognize and avoid phishing emails. But there are other essential components.</p>
<p>&nbsp;</p>
<h3>Keep Personal Matters Out of Company Email:</h3>
<p>Attackers sometimes gain access to websites used for personal activities like watching movies, paying utility bills, personal checking accounts, and more. Bad actors leverage this information to craft convincing email messages, enticing users to click on malicious links or open harmful attachments.</p>
<p><strong>If your workers avoid using their business email for personal activities</strong> like online shopping or personal social media, then a phishing email related to these topics would immediately stand out as suspicious. <strong>They are much more likely to recognize the message as fake.</strong></p>
<p>On the other hand, if they have used their business email for personal tasks like online shopping or social media, they&#8217;re at a higher risk for spear phishing when an attacker knows details about their activities. If they receive an &#8216;urgent message&#8217; related to these personal tasks in their business email account, they might be more easily deceived into thinking it&#8217;s legitimate.</p>
<p>&nbsp;</p>
<h3>Worsened Notification Burden:</h3>
<p>Another drawback of using work emails for personal matters is the heightened risk of exposing sensitive personal data. If <strong>employees use their work email to conduct personal business</strong>, such as insurance applications or other private matters, the <strong>likelihood of sensitive personal data residing on your servers</strong> increases. In the unfortunate event of a data breach, their sensitive information could necessitate you sending notification letters to affected parties, <strong>increasing your company&#8217;s expenses and vulnerability to potential lawsuits.</strong></p>
<h3></h3>
<p>&nbsp;</p>
<h3>Personal Webmail on Company Devices is a Significant Security Risk:</h3>
<p>The above situations refer to workers using their work address for personal use. But you must also address the issue of allowing employees to access personal webmail on company devices. <strong>IT departments have no control over the security of these personal email accounts</strong>. While your business email systems can have robust filters to block malicious links and attachments, allowing workers to access personal webmail sites can significantly reduce the overall security of your network, <strong>making your organization&#8217;s security as weak as the weakest personal email account.</strong></p>
<p>&nbsp;</p>
<h3>To Enhance Security:</h3>
<ol>
<li>Ask your IT Team to <strong>limit email access</strong> on company devices <strong>to approved business email servers only.</strong></li>
<li>Continuously <strong>remind employees to use their company email address exclusively for work</strong>-related matters.</li>
<li>Ask your IT team to <strong>block access to all webmail sites except those essential for business</strong>. If employees need to access personal email, they should do so on their personal devices. If connectivity is an issue and you must allow employees to connect personal devices to your Wi-Fi, use a separate &#8220;guest&#8221; network instead of the primary company network.</li>
</ol>
<p>&nbsp;</p>
<h3>Conclusion:</h3>
<p>By drawing clear boundaries between personal and professional email usage, you can reduce the risk of cyber threats and help protect your company and your employees. Please tell your associates and friends; spread the word.</p>
<p>&nbsp;</p>
<p><strong>Subscribe</strong> to maximize your executive potential with Foster Institute’s E-Savvy Newsletter, packed with practical IT security solutions and actionable strategies for success: <a href="https://fosterinstitute.com/e-savvy-newsletter/" target="_blank" rel="noopener">https://fosterinstitute.com/e-savvy-newsletter/</a></p>
<p>(Image source: Bing. Learn more at [Bing.com].)</p>
<p>&nbsp;</p>
<p>The post <a href="https://fosterinstitute.com/executives-guard-your-companys-future-why-ensuring-email-boundaries-is-crucial-for-security/">Executives, Guard Your Company&#8217;s Future: Why Ensuring Email Boundaries is Crucial for Security.</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Urgent Security Patch for Hundreds of Millions of Dell Computers</title>
		<link>https://fosterinstitute.com/urgent-security-patch-for-hundreds-of-millions-of-dell-computers/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Thu, 06 May 2021 15:43:21 +0000</pubDate>
				<category><![CDATA[Application Updates]]></category>
		<category><![CDATA[Applying IT Patches]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cyber Attacks]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=4656</guid>

					<description><![CDATA[<p>Your IT Team has an opportunity to patch a security weakness in your Dell computers. If you facilitate them acting now, you will probably be one step ahead of attackers. The good news is Dell&#8217;s not detected any attacks in the wild. However, now bad actors have a new challenge, a puzzle to solve, a [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/urgent-security-patch-for-hundreds-of-millions-of-dell-computers/">Urgent Security Patch for Hundreds of Millions of Dell Computers</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Your IT Team has an opportunity to patch a security weakness in your Dell computers. If you facilitate them acting now, you will probably be one step ahead of attackers.</p>



<p class="wp-block-paragraph">The good news is Dell&#8217;s not detected any attacks in the wild. However, now bad actors have a new challenge, a puzzle to solve, a game with payoffs for them, and potential tragedy for their targets. Dell urges companies to install the update immediately.</p>



<p class="wp-block-paragraph">Executives decide whether to accept the risk or provide teams with time to implement the two-step solution from Dell.</p>



<p class="wp-block-paragraph">To exploit the security weakness, bad actors might effectively social engineer at least one user to click on a malicious link, open an infected attachment, or grant access to someone pretending to be a technical support professional.</p>



<p class="wp-block-paragraph">Alternatively, the attacker can steal or guess the user&#8217;s password. For example, we are auditing a business right now and discovered the following passwords: Password, Password!, Password1, and Password123. Users choosing those passwords is NOT the IT professional&#8217;s fault.</p>



<p class="wp-block-paragraph">Please forward this to your associates so they know that Dell is urging all affected customers to address this problem immediately.</p>



<p class="wp-block-paragraph">Time is your team&#8217;s most precious asset, and this fix takes time. Discuss ways they can postpone other projects to address the problem before attackers start exploiting the vulnerability to potentially:</p>



<ul class="wp-block-list"><li>Shut down systems</li><li>Spread ransomware</li><li>Threaten to expose stolen data</li><li>Delete your data stored in the cloud or on your servers</li><li>Or otherwise devastate organizations</li></ul>



<p class="wp-block-paragraph">Dell recommends acting immediately: <a href="http://dell.com/support/kbdoc/en-us/000186019/dsa-2021-088-dell-client-platform-security-update-for-dell-driver-insufficient-access-control-vulnerability" target="_blank" rel="noreferrer noopener">dell.com/support/kbdoc/en-us/000186019/dsa-2021-088-dell-client-platform-security-update-for-dell-driver-insufficient-access-control-vulnerability</a></p>



<p class="wp-block-paragraph">During the recent Pwn2own competition, a team demonstrated exploiting Exchange servers. With the new knowledge, attackers infiltrated servers before IT Professionals could apply patches. The Dell vulnerability could have the same outcome. Keep in mind that there are vastly more Dell computers in businesses than there are on-prem Exchange servers.</p>



<p class="wp-block-paragraph">Interestingly, the vulnerability only exists if the IT Team is applying Dell&#8217;s patches and updates. However, if your team is not using Dell&#8217;s other security updates, that is a problem too. They might not have enough time and need your understanding when they need to reprioritize their tasks, have additional help, or automate some processes they must do manually.</p>
<p>The post <a href="https://fosterinstitute.com/urgent-security-patch-for-hundreds-of-millions-of-dell-computers/">Urgent Security Patch for Hundreds of Millions of Dell Computers</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Three Essential Questions to Ask Your IT Team Today Because of the Massive Exchange Attack</title>
		<link>https://fosterinstitute.com/three-essential-questions-to-ask-your-it-team-today-because-of-the-massive-exchange-attack/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Mon, 08 Mar 2021 17:48:54 +0000</pubDate>
				<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cyber Attacks]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[recommendations]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[Security expert]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=3467</guid>

					<description><![CDATA[<p>So far, it appears that more than 30,000 organizations, including small businesses, are compromised. The US National Security Council urges organizations, including small businesses, to &#8220;take immediate measures&#8221; to detect compromise. &#8211;&#62; ONE: Ask your IT team, &#8220;Do we still have Microsoft Exchange Server email software installed anywhere?&#8221; If they answer affirmatively, even if they&#8217;re [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/three-essential-questions-to-ask-your-it-team-today-because-of-the-massive-exchange-attack/">Three Essential Questions to Ask Your IT Team Today Because of the Massive Exchange Attack</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>So far, it appears that more than 30,000 organizations, including small businesses, are compromised. The US National Security Council urges organizations, including small businesses, to &#8220;take immediate measures&#8221; to detect compromise.<span id="more-3467"></span></p>
<p>&#8211;&gt; <strong>ONE</strong>: Ask your IT team, &#8220;Do we still have Microsoft Exchange Server email software installed anywhere?&#8221;</p>
<p>If they answer affirmatively, even if they&#8217;re already moving to the cloud, you must continue:</p>
<p>&#8211;&gt; <strong>TWO</strong>: Ask them, &#8220;What can I take off your plate or postpone so that you can immediately test and deploy the patches to the Exchange Server right now?&#8221;</p>
<p>Essential: Applying security updates to your Exchange server does not resolve the issue if your organization is already compromised. There might be a small program on your system quietly waiting for an attacker&#8217;s commands.</p>
<p>To help determine if you are already compromised: <a href="https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/#scan-log" target="_blank" rel="noopener">https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/#scan-log</a></p>
<p>If your team cannot update immediately, send them here: <a href="https://github.com/microsoft/CSS-Exchange/tree/main/Security" target="_blank" rel="noopener">https://github.com/microsoft/CSS-Exchange/tree/main/Security</a></p>
<p>&#8211;&gt; <strong>THREE</strong>: Say, &#8220;The emergency is too great to postpone. Later, let&#8217;s discuss the pros and cons of moving email to the cloud.&#8221;</p>
<p>Pros include eliminating one server and associated headaches. Often, online email is better for remote workers too. But you could lose some integration features you have now, for example, an on-site phone system tied into Exchange. Because saving money and streamlining is essential, online Exchange is often less expensive.</p>
<p>The blog posting <a href="https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/#scan-log" target="_blank" rel="noopener">https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/#scan-log</a> has a plethora of other information and guidance for your team related to the updates. Some organizations are experiencing errors after applying the security updates. For example, some learned they must install the updates from an elevated command prompt window. Microsoft provides more guidance:</p>
<p><a href="https://msrc-blog.microsoft.com/2021/03/05/microsoft-exchange-server-vulnerabilities-mitigations-march-2021/" target="_blank" rel="noopener">https://msrc-blog.microsoft.com/2021/03/05/microsoft-exchange-server-vulnerabilities-mitigations-march-2021/</a></p>
<p><a href="https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-microsoft-exchange-server-2019-2016-and-2013-march-2-2021-kb5000871-9800a6bb-0a21-4ee7-b9da-fa85b3e1d23b" target="_blank" rel="noopener">https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-microsoft-exchange-server-2019-2016-and-2013-march-2-2021-kb5000871-9800a6bb-0a21-4ee7-b9da-fa85b3e1d23b</a></p>
<p><a href="https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-microsoft-exchange-server-2010-service-pack-3-march-2-2021-kb5000978-894f27bf-281e-44f8-b9ba-dad705534459" target="_blank" rel="noopener">https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-microsoft-exchange-server-2010-service-pack-3-march-2-2021-kb5000978-894f27bf-281e-44f8-b9ba-dad705534459</a></p>
<p>The post <a href="https://fosterinstitute.com/three-essential-questions-to-ask-your-it-team-today-because-of-the-massive-exchange-attack/">Three Essential Questions to Ask Your IT Team Today Because of the Massive Exchange Attack</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
