<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Keep Your Network Safe Archives - Foster Institute</title>
	<atom:link href="https://fosterinstitute.com/tag/keep-your-network-safe/feed/" rel="self" type="application/rss+xml" />
	<link>https://fosterinstitute.com/tag/keep-your-network-safe/</link>
	<description>Cybersecurity Experts</description>
	<lastBuildDate>Tue, 15 Dec 2020 16:15:23 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.1</generator>

<image>
	<url>https://fosterinstitute.com/wp-content/uploads/2021/02/Favicon.png</url>
	<title>Keep Your Network Safe Archives - Foster Institute</title>
	<link>https://fosterinstitute.com/tag/keep-your-network-safe/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Emergency Update if Your IT Team Uses SolarWinds Products, and How to Protect Against Supply Chain Attacks</title>
		<link>https://fosterinstitute.com/emergency-update-if-your-it-team-uses-solarwinds-products-and-how-to-protect-against-supply-chain-attacks/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Tue, 15 Dec 2020 16:15:23 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[CCleaner]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Executives and IT]]></category>
		<category><![CDATA[Infection Vector]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[IT Risk Management]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[SolarWinds]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[cyber security expert]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[Keep Your Network Safe]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=3367</guid>

					<description><![CDATA[<p>Bad Actors compromised a product called SolarWinds Orion and then used that as a vector attack organization. Ask your IT team if they use SolarWinds products, and if so, they must visit SolarWinds dot com/security advisory immediately for more information. SolarWinds is a well-respected organization, and many organizations utilize their products. Not enough details are [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/emergency-update-if-your-it-team-uses-solarwinds-products-and-how-to-protect-against-supply-chain-attacks/">Emergency Update if Your IT Team Uses SolarWinds Products, and How to Protect Against Supply Chain Attacks</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Bad Actors compromised a product called SolarWinds Orion and then used that as a vector attack organization. Ask your IT team if they use SolarWinds products, and if so, they must <span id="more-3367"></span>visit SolarWinds dot com/security advisory immediately for more information.</p>
<p>SolarWinds is a well-respected organization, and many organizations utilize their products. Not enough details are known to discredit their organization. Clearly, attackers see them as valuable enough to use as an infection vector.</p>
<p>This is called a supply chain attack because bad actors use a trusted product in an organization&#8217;s supply chain to attack the organization. A similar well-publicized attack happened with a popular tool, with many benefits, called CCleaner. The attackers successfully compromised 2.3 Million PCs.</p>
<p>The CCleaner supply chain attack is an illustration of dwell time. Attackers waited five months from the time they gained access to CCleaner before they launched the attack on CCleaner users. Many computers were safe, but not 2.3 Million of them.</p>
<p>Remember: Just because your organization fixes a vector through which the infection came does not eliminate damage already done. As an analogy, if you were the king or queen of a castle, and you found that attackers entered your castle walls to attack your city, raising the bridge over your moat does not eliminate the attackers who already made it inside.</p>
<p>Supply chain attacks are one of many reasons to eliminate as much software as possible at your organization. If a program is not essential, remove it asap. SolarWinds is vital for many organizations.</p>
<p>Please forward this to your friends so they can alert their IT departments to address this situation, and know to remove all non-essential software from all computers.</p>
<p>The post <a href="https://fosterinstitute.com/emergency-update-if-your-it-team-uses-solarwinds-products-and-how-to-protect-against-supply-chain-attacks/">Emergency Update if Your IT Team Uses SolarWinds Products, and How to Protect Against Supply Chain Attacks</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Attackers Can Take Control of Your Network in Three Seconds, and How to Stop Them</title>
		<link>https://fosterinstitute.com/attackers-can-take-control-of-your-network-in-three-seconds-and-how-to-stop-them/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Fri, 23 Oct 2020 19:03:56 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Executive Tips]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[Remote Worker Security]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Technology Safety Tips]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[cyber security expert]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[Keep Your Network Safe]]></category>
		<category><![CDATA[risk management]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=3333</guid>

					<description><![CDATA[<p>An attacker can plug into any network port in your building and, within 3 seconds, take control of your entire network. The attacker does not need to know any passwords; they do not even need a username. They plug in a cable, and 3 seconds later, they&#8217;ve completely compromised your network. An attacker posing as [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/attackers-can-take-control-of-your-network-in-three-seconds-and-how-to-stop-them/">Attackers Can Take Control of Your Network in Three Seconds, and How to Stop Them</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>An attacker can plug into any network port in your building and, within 3 seconds, take control of your entire network.<span id="more-3333"></span></p>
<p>The attacker does not need to know any passwords; they do not even need a username. They plug in a cable, and 3 seconds later, they&#8217;ve completely compromised your network. An attacker posing as a visitor, a copier repair person, or a member of a cleaning crew can all compromise your organization. They can steal sensitive information, install ransomware, and can shut down operations entirely. They bypass the majority of, if not all, of your other protections because now they&#8217;re a Domain Administrator.</p>
<p>This exploit is so severe that the Department of Homeland Security directed all federal agencies to apply the patch in accordance with the Federal Emergency Directive 20-04.</p>
<p>Take these three steps ASAP:</p>
<p>First, ask your IT team if they&#8217;ve backed up your Domain Controller servers and applied Microsoft&#8217;s patches that address the Zerologon exploit CVE-2020-1472. They must do this immediately. Be compassionate if they&#8217;ve not. IMPORTANT: Realize that if an attacker already took over a network, the patch doesn&#8217;t help.</p>
<p>Second, if you have Domain Controllers using operating systems older than Windows Server 2008 R2, your IT professionals must shut them down for good. Be sure to migrate any mission-critical services to other servers.</p>
<p>Third, does your organization rely on third parties to support you? What if one of your major suppliers, a distributor, or your biggest customer falls prey to an attack? Prepare your organization now for an interruption of their operations. Be sure their executives know about this flaw and these three steps. You do not want a catastrophe at their organization to domino and cause a disaster for you, even though you&#8217;ve protected your systems.</p>
<p>Additional steps:</p>
<p>Inform your work-from-home team members that, in some cases, the attacker can take over your network using a VPN connection. Do you have an armed guard at every work-from-home user&#8217;s home to watch visitors? Of course not. But your entire organization might rely on their security. What if a teenager&#8217;s friend feels like playing around, experimenting, with this new cool exploit on a mom or dad&#8217;s computer?</p>
<p>The patches only protect you from attacks from Windows devices. If an attacker accesses a network port or cable with a non-Windows machine, the attacker can still take control of your network. Microsoft will release a second patch on February 9, 2021. Ask your IT team to configure alerts now to monitor security log events 5827 thru 5831 to see when connections are allowed or denied.</p>
<p>The average time for IT Professionals to apply critical security patches is five months, but you need to help yours be above average. Ask them what you can do to help them have time to test and install all critical security patches within 14 days or sooner. They might want to have a patch management tool. They might need more time to devote to applying updates.</p>
<p>Confirm that your IT Team disconnects or disables all unused Ethernet ports, including those in conference rooms. Lock doors to any offices and conference rooms that contain active Ethernet ports. Train everyone to be proactive and remove opportunities for anyone, including guests and repair people, to plug a device into a network port.</p>
<p>Keep in mind that 911 systems, airlines, governments, and every organization that you depend on are at risk for Zerologon exploit CVE-2020-1472 until they take action too.</p>
<p>Please forward this to fellow executives you care about so they can support their IT Professionals successfully backing up servers and applying the emergency patch.</p>
<p>The post <a href="https://fosterinstitute.com/attackers-can-take-control-of-your-network-in-three-seconds-and-how-to-stop-them/">Attackers Can Take Control of Your Network in Three Seconds, and How to Stop Them</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>If You Get Hacked, Do Not Email Anyone About It</title>
		<link>https://fosterinstitute.com/if-you-get-hacked-do-not-email-anyone-about-it/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Thu, 15 Oct 2020 21:17:38 +0000</pubDate>
				<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Business Email Compromise]]></category>
		<category><![CDATA[Cyber Scams]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Executives and IT]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[it risk management]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[Keep Your Network Safe]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=3329</guid>

					<description><![CDATA[<p>You&#8217;ve trained your users to be vigilant for symptoms of cybersecurity issues. Now teach them to share their concerns confidentially. Alert your users today: Tell them to, if they suspect something, avoid opening a support ticket or emailing your IT professionals about the concern. More often than ever before, bad actors infiltrate organizations in a [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/if-you-get-hacked-do-not-email-anyone-about-it/">If You Get Hacked, Do Not Email Anyone About It</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>You&#8217;ve trained your users to be vigilant for symptoms of cybersecurity issues. Now teach them to share their concerns confidentially.<span id="more-3329"></span><br />
Alert your users today: Tell them to, if they suspect something, avoid opening a support ticket or emailing your IT professionals about the concern.</p>
<p>More often than ever before, bad actors infiltrate organizations in a slow, methodical way. They can remain undetected for weeks, months, even years. The FBI uses the term dwell time to designate the period from when attackers infiltrate systems until you discover them. The FBI warns businesses that attackers can cause significant damage during dwell time. Bad actors quickly establish backdoors to ensure access, even if you block their first point of entry. They deploy keyloggers on systems to record keystrokes. If your cyber assets are compromised, the bad actors can potentially monitor your messages to find out when you discover their presence in your network, computers, applications, cloud resources, websites, or anywhere else.</p>
<p>Once attackers know you&#8217;ve discovered their infiltration, that triggers them to move forward with their next phase, often contacting you to demand a ransom. Sometimes they threaten severe consequences if you attempt to recover your system in any other way than paying them. Since they are in your systems, you must take the threats seriously.</p>
<p>Establish a protocol for workers to communicate suspicions in some method other than email.</p>
<p>Even your IT department must avoid emailing each other questions such as, &#8220;I received an alert that someone is resetting an administrator password. That&#8217;s odd. Is that you?&#8221; Instead, they must communicate by mobile phone or radio.</p>
<p>If you suspect a breach and contact us, consider phoning. If you must email, use a personal account outside of your company account, and use a phone or some device other than a company computer&#8217;s keyboard to send the message.</p>
<p>I’m not talking about when users receive a phishing message. I’m talking about if they receive a phishing message that includes customer account information, if an important file is missing or won’t open, or if they receive an unexpected login request on a website or to open a file. IT needs to investigate these early-warning signs.</p>
<p>Please forward this to other executives who you care about to establish a mobile hotline number for users to reach the IT team to report suspicious activity. Help avoid triggering attackers’ responses before your IT team has time to react and, hopefully, mitigate a potential cybersecurity disaster.</p>
<p>The post <a href="https://fosterinstitute.com/if-you-get-hacked-do-not-email-anyone-about-it/">If You Get Hacked, Do Not Email Anyone About It</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Be Smart and Avoid This Comforting Belief</title>
		<link>https://fosterinstitute.com/be-smart-and-avoid-this-comforting-belief/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Fri, 02 Oct 2020 20:03:41 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Executive Tips]]></category>
		<category><![CDATA[IT Risk Management]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[Keep Your Network Safe]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=3322</guid>

					<description><![CDATA[<p>Someone told me today, as is common: Attackers are only interested in hacking large businesses. Believing that small to mid-size businesses are not targets helps business owners and executives sleep better at night. The thought is comforting. However, the reality is that instead of choosing targets based on organization size, the majority of attackers choose [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/be-smart-and-avoid-this-comforting-belief/">Be Smart and Avoid This Comforting Belief</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Someone told me today, as is common: Attackers are only interested in hacking large businesses.<span id="more-3322"></span></p>
<p>Believing that small to mid-size businesses are not targets helps business owners and executives sleep better at night. The thought is comforting.</p>
<p>However, the reality is that instead of choosing targets based on organization size, the majority of attackers choose soft, easy to breach, targets. In particular, that category includes work-from-home computers.</p>
<p>In our consulting business, we&#8217;re seeing many firms suffer major breaches that originate at an unsuspecting work-from-home user&#8217;s computer.</p>
<p>Please forward this to your friends so they know that it may feel comforting to believe attackers only go after the big companies, that belief is putting their organization at tremendous risk.</p>
<p>The post <a href="https://fosterinstitute.com/be-smart-and-avoid-this-comforting-belief/">Be Smart and Avoid This Comforting Belief</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Two Tips to Make Your Online Meetings Better</title>
		<link>https://fosterinstitute.com/two-tips-to-make-your-online-meetings-better/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Fri, 15 May 2020 19:50:31 +0000</pubDate>
				<category><![CDATA[Executive Tips]]></category>
		<category><![CDATA[Online Meetings]]></category>
		<category><![CDATA[Zoom]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[cyber security expert]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[Keep Your Network Safe]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=3165</guid>

					<description><![CDATA[<p>Everyone is concerned about video conferencing security, and they should be. But when the hardware and software are not working right, safety seems like a distraction. Use at least two monitors. You can often separate the presentation so that you see slides on one screen and all the participants&#8217; faces on another. When you buy [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/two-tips-to-make-your-online-meetings-better/">Two Tips to Make Your Online Meetings Better</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Everyone is concerned about video conferencing security, and they should be. But when the hardware and software are not working right, safety seems like a distraction.<span id="more-3165"></span></p>
<p>Use at least two monitors. You can often separate the presentation so that you see slides on one screen and all the participants&#8217; faces on another. When you buy new, seek 4K resolution. Investigate 15-inch portable monitors if you need to move around, or 27-inch screens if portability isn&#8217;t necessary.</p>
<p>Second, straining to hear someone&#8217;s voice over a poor connection is very distracting. Rather than using your computer&#8217;s built-in mic, consider using a suitable USB Microphone. Position the mic close to your mouth. Some people prefer headset mics – especially if they are in a noisy environment. I wear a wireless lapel mic when presenting online keynote speeches and webinars. All of those provide better sound than a laptop&#8217;s built-in mic.</p>
<p>Please forward this to everyone you know because, when their video conferences run smoothly, they can pay more attention to security and being mindful of what they say. Stay safe!</p>
<p>The post <a href="https://fosterinstitute.com/two-tips-to-make-your-online-meetings-better/">Two Tips to Make Your Online Meetings Better</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Video Conferencing &#8211; Avoid Installing Meeting Programs When Possible</title>
		<link>https://fosterinstitute.com/video-conferencing-avoid-installing-meeting-programs-when-possible/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Fri, 01 May 2020 20:38:53 +0000</pubDate>
				<category><![CDATA[Executive Tips]]></category>
		<category><![CDATA[Executives and IT]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[Remote Worker Security]]></category>
		<category><![CDATA[Zoom]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[cyber security expert]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[Keep Your Network Safe]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=3158</guid>

					<description><![CDATA[<p>CEOs and Executives: Avoid installing video conferencing software on your computer just because some other company tells you to. When you launch video conferencing programs, many of them ask you to install a program or app on your computer or device. What if the program is a virus? Here is another essential tactic to help [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/video-conferencing-avoid-installing-meeting-programs-when-possible/">Video Conferencing &#8211; Avoid Installing Meeting Programs When Possible</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>CEOs and Executives: Avoid installing video conferencing software on your computer just because some other company tells you to. When you launch video conferencing programs, many of them ask you to install a program or app on your computer or device. What if the program is a virus?<span id="more-3158"></span></p>
<p><iframe src="https://player.vimeo.com/video/413795842" width="640" height="360" frameborder="0" allow="autoplay; fullscreen" allowfullscreen></iframe></p>
<p>Here is another essential tactic to help protect your remote workers.</p>
<p>There&#8217;s a company in Saint Louis that ran into a problem your organization might face too.</p>
<p>Their remote workers must attend many video conference calls, online meetings, webinars, and online training sessions. Their IT Pro doesn&#8217;t want to install different programs on his users&#8217; computers if he can avoid it.</p>
<p>As you know, a significant way to improve cybersecurity is to uninstall nonessential software, not to add more programs.</p>
<p>The company&#8217;s savvy IT Pro discovered an excellent solution. He found that all of the video conferencing and training tools his team needs can run inside their already-installed browsers. They don&#8217;t need to download and install extra software. They have Zoom already, but workers use their browsers for other kinds of meetings. They may not get all the advanced functionality, but they can still participate in the sessions just fine.</p>
<p>Please forward this to your friends so that they know, to improve cybersecurity, avoid installing software or apps whenever possible. Their IT Pro may find that workers can participate in many meetings using their browser only, without needing to increase the attack surface by installing more software. </p>
<p>The post <a href="https://fosterinstitute.com/video-conferencing-avoid-installing-meeting-programs-when-possible/">Video Conferencing &#8211; Avoid Installing Meeting Programs When Possible</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Plan Now for Slow Internet and Dropped Phone Calls</title>
		<link>https://fosterinstitute.com/plan-now-for-slow-internet-and-dropped-phone-calls/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Fri, 20 Mar 2020 20:01:55 +0000</pubDate>
				<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[Remote Worker]]></category>
		<category><![CDATA[Slow Internet]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[Keep Your Network Safe]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=3061</guid>

					<description><![CDATA[<p>Prepare now for slow Internet speeds and dropped mobile phone calls. Some customers report that their remote workers experience slow Internet speeds. The sheer number of people working from home, and others watching videos at home, is causing the Internet to experience slowdowns similar to traffic during rush hour. You may have heard that Netflix [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/plan-now-for-slow-internet-and-dropped-phone-calls/">Plan Now for Slow Internet and Dropped Phone Calls</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Prepare now for slow Internet speeds and dropped mobile phone calls. Some customers report that their remote workers experience slow Internet speeds. The sheer number of people working from home, and others watching videos at home, is causing the Internet to experience slowdowns similar to traffic during rush hour.<span id="more-3061"></span></p>
<p>You may have heard that Netflix agreed to reduce the picture quality of movies in the UK to reduce the load on the Internet. What&#8217;s that have to do with your company? Prepare a contingency plan now. Something easy to change is to instruct your workers to ask their family members to please download their movies at night rather than streaming the videos during work hours. That way, their family can watch their downloaded movies during the daytime without using up your workers&#8217; remote network speed.</p>
<p>If your remote workers use VPN connections, and they experience slow speeds, your IT team can enable something called split tunneling. Then, if they aren&#8217;t already, your workers&#8217; computers take a shortcut directly to the Internet without going a long way around through your primary office location&#8217;s firewall first. That trades speed for security, so executives have to make the decision, but the change might be worth it if your workers cannot work otherwise. There are other strategies too. Know that recorded video and audio conference calls will make it through even when a real-time conference is so slow it fails.</p>
<p>Other customers explain that the cellular towers in their area are so overloaded that phone calls get dropped, and voices are sometimes garbled beyond understandability. That&#8217;s when text messages, though less convenient, will be your plan B. At least text messages will usually go through even with weak or slow connections.</p>
<p>Please forward this message to your friends so they can have a plan in place at their company in case an Internet or cell phone traffic jam interferes with their business.</p>
<p>The post <a href="https://fosterinstitute.com/plan-now-for-slow-internet-and-dropped-phone-calls/">Plan Now for Slow Internet and Dropped Phone Calls</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Warn Your Workers about Attacker Decoy Tactics</title>
		<link>https://fosterinstitute.com/warn-your-workers-about-attacker-decoy-tactics/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Wed, 18 Mar 2020 20:43:39 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Coronavirus]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Decoy Website]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[cyber security expert]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[Keep Your Network Safe]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[Security expert]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=3057</guid>

					<description><![CDATA[<p>Alert your workers to be on guard looking for fake, decoy websites about coronavirus, even closings, and related alerts. Attackers design the content to be frightening or otherwise enticing so users click without thinking. Warn them that there are hundreds of new websites that hackers created to lure unsuspecting victims. Decoy websites look legitimate but [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/warn-your-workers-about-attacker-decoy-tactics/">Warn Your Workers about Attacker Decoy Tactics</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Alert your workers to be on guard looking for fake, decoy websites about coronavirus, <span id="more-3057"></span>even closings, and related alerts. Attackers design the content to be frightening or otherwise enticing so users click without thinking.  Warn them that there are hundreds of new websites that hackers created to lure unsuspecting victims. Decoy websites look legitimate but are loaded with malicious content. Attackers can access one unsuspecting user’s computer session and then use it to gain full access to your organization’s network. Official websites include <a href="http://cdc.gov" rel="noopener noreferrer" target="_blank">cdc.gov</a>, <a href="http://nih.gov" rel="noopener noreferrer" target="_blank">nih.gov</a> and <a href="http://who.int" rel="noopener noreferrer" target="_blank">who.int</a>. It is better for users to manually type those addresses into their browser instead of clicking links.</p>
<p>The post <a href="https://fosterinstitute.com/warn-your-workers-about-attacker-decoy-tactics/">Warn Your Workers about Attacker Decoy Tactics</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Are you rolling out the welcome mat to attackers?</title>
		<link>https://fosterinstitute.com/attackers/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Thu, 26 Apr 2012 04:00:14 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Keep Your Network Safe]]></category>
		<category><![CDATA[protect]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog//?p=1290</guid>

					<description><![CDATA[<p>One of the biggest surprises IT receives during an audit is that their network is basically configured to grant attackers access. So often, there are active user accounts for users who no longer even work at your organization. Some executives ask, “How did so-and-so break into our network? We fired them months ago!” All the [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/attackers/">Are you rolling out the welcome mat to attackers?</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>One of the biggest surprises IT receives during an audit is that their network is basically configured to grant attackers access.<br />
<span id="more-1290"></span><br />
So often, there are active user accounts for users who no longer even work at your organization. Some executives ask, “How did so-and-so break into our network? We fired them months ago!”  All the user needed to do was log in.</p>
<p>More often, the executives have administrative level permissions to access everything on the network and, additionally, the executive has a weak password. If an executive demands administrative access to a network, create two user accounts for the executive. One of the accounts is for day-to-day work and the administrative account is only for resetting passwords, deleting users, and whatever else the executive wants to do on occasion.</p>
<p>Any users who have administrative access should not have access to a web browser or to email. Avoid exposing administrative users to those common and dangerous attack vectors.</p>
<p>Please post your comments on this blog.</p>
<p>The post <a href="https://fosterinstitute.com/attackers/">Are you rolling out the welcome mat to attackers?</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Stop Drive-By-Downloads</title>
		<link>https://fosterinstitute.com/stop-drive-by-downloads/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Thu, 05 Apr 2012 04:00:20 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[IT security procedures]]></category>
		<category><![CDATA[Keep viruses out of your network]]></category>
		<category><![CDATA[Keep Your Network Safe]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog//?p=1272</guid>

					<description><![CDATA[<p>It is time to review your anti-spam filters and your web-filters to ensure you are adequately protected against targeted email attacks as well as drive-by-download attacks. The latter attacks happen when one of your users visits an infected site. The settings your IT department configured in 2011 probably need to be reconfigured to repel new [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/stop-drive-by-downloads/">Stop Drive-By-Downloads</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>It is time to review your anti-spam filters and your web-filters to ensure you are adequately protected against targeted email attacks as well as drive-by-download attacks. The latter attacks happen when one of your users visits an infected site. The settings your IT department configured in 2011 probably need to be reconfigured to repel new attacks.<br />
<span id="more-1272"></span><br />
When I perform IT audits, IT Professionals, more often than not, express frustration that the anti-spam and/or web protection is inadequate. Either you don’t have the proper tools, or usually you already have the tools but tied IT’s hands. Ask IT to make reconfiguring and/or activating these tools a priority.</p>
<p>Good anti-spam solutions block unwanted email, allow email you are interested in receiving, and even attempts to block viruses arriving via email. One of the biggest signs of a good service, in addition to working properly, is that the service saves your workers and your IT team time by not needing to babysit the anti-spam solution.</p>
<p>Eliminate specific E-mail attachments since they may contain malicious code. This infection vector is a significant source of infections that lead to attackers gaining control over major assets in your network.</p>
<p>It is important for security and productivity to implement a solution to block Internet access to inappropriate sites. While most everyone in an organization can quickly agree on blocking certain sites because the inappropriate content could endanger the organization. For other categories of web sites, there may be more than one point of view.</p>
<p>Consider, at least initially, only blocking the sites that everyone can agree need to be blocked. Simply activating the blocking tool will usually help reduce drive-by-downloads at some sites.</p>
<p>Many firewalls support web filtering although many firewalls do not provide reporting features with enough detail. If your solution is inadequate, then upgrade the firewall or add a tool that will provide this functionality.</p>
<p>Please post your comments on this blog.</p>
<p>The post <a href="https://fosterinstitute.com/stop-drive-by-downloads/">Stop Drive-By-Downloads</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
