Showing posts with label internet security. Show all posts
Showing posts with label internet security. Show all posts

Wednesday, April 12, 2017

Small Business Cybersecurity: The People Connection


Data from 2015 shows that 20% of U.S. businesses hacked are small with less than 250 employees. 60% of those fail after the attack. For small and medium-sized businesses, the average cost of a data breach is $21,000.

In 2016 an accountant was hacked and financial information and social security numbers from accounts were stolen. By the time the breach was discovered, a false return had been filed with the IRS in my family's name.

Cyber criminals or hackers use stolen information to obtain money. Sometimes they use the data, but often it is sold to other criminals. With names and social security numbers, criminals can file fraudulent claims for tax refunds.

Hackers also steal bank account information, credit and debit card numbers and authentication details, personal information, medical records, trademark information, trade secrets and others. A list of names, phone numbers, and addresses can be used by IRS scammers. Those criminals make threats and convince people to wire money or mail debit cards.

Preventing business cybercrime requires several levels of defense. Employee internet habits are one layer of cybercrime security that should be addressed. Since downloads of software are one of the primary causes of virus attacks, employee internet policies need to be solid and well communicated.


Steps to prevent cybercrime caused by employee behavior:


Company policies

Robust and clear company policies need to be written, distributed, and updated regularly.
These policies would cover the following areas:
  • email and internet use
  • protecting confidential information
  • policy communication and updates

Security training

Periodic meetings should be held to discuss security issues and concerns. Use recent news reports and videos to highlight different security concerns. Be clear about new threats from cyber crime and security changes to address those threats. Employees should be educated to be alert to phishing emails and suspicious attachments or links. A cybersecurity manager should be named who can respond to employee questions in a timely manner. This person should also insure policies are written, updated, and communicated.

Control Access

Limit administrative and password access. Regularly change passwords and establish limiting access to levels of data where possible. When employees are terminated, immediate changes in network access should be made.


Protecting organizations from cybercrime is a complex issue. Employee internet behavior is one area that should be managed to keep business information secure.

A cybersecurity tip sheet for small businesses by the Department of Homeland Security can be found here.

This article originally appeared on my Web Technology blog which can be found here.

Advertising on this blog supports my writing. By clicking an ad, you are under no obligation to buy. If you see an advertisement of interest, please click.

Friday, June 5, 2015

Managing the Quality of Internet-linked Products

This month's American Society of Quality Influential Voices topic is a review of an essay in the 2015 Future of Quality report. If you are an ASQ member, you have access to this compilation on 11 topics.

Internet of Things


I chose Jonathan Zittrain's Balancing Security With Openness in the Internet of Things. Mr. Zittrain is the author of The Future of the Internet - And How to Stop It (for purchasing info see link below).

The term "Internet of Things" refers to all the devices that can connect to the internet and create systems to share data.

Below is a 2-minute video by Intel that explains the Internet of Things (IoT). Another video by FW:thinking can be found here.

 
 Internet of Things Video



Traffic cameras, electronic signs, and bus communication create an Internet of Things that can steer traffic away from congested areas. In Zittrain's essay, an Internet-aware snow shovel could provide data on frequency of use (Have the kids performed this chore?), health data on the shoveler (Is his heart rate dangerously high?), or assumptions on snow levels based on usage (Where do the snow plows need to go?).



Managing Quality


What are the quality issues of the Internet of Things? To answer that question Zittrain reviews the evolution of both the PC and the Internet. In the beginning anyone could write and share software to be used on PCs. Similarly, code for use on the Internet was unregulated.

The second version of the iPhone introduced an effort to gain more control over outside code (apps) by offering them in a store with required certification. Currently there are app stores for PCs and phones across all operating systems.



To meet quality manufacturing requirements, the product needs to be robust. It needs to be safely manufactured of nontoxic materials, as well. As devices become connected to one another, quality issues will expand.


Will connectivity to other devices be limited to reduce variability in quality issues or will it be open to increase innovation and demand? What quality issues will open connectivity present? Will viruses run rampant and slow device efficiency or cause frequent crashes? How many and what type of sensors will be incorporated into products for connectivity and data sharing?


Managing quality of the Internet of Things devices requires significant corporate decisions that are integral to their business plan. The proposed ISO9001:2015 standard emphasizes quality as part of the business plan and not a stand-alone entity. This falls right in line with establishing corporate policy on a product that is part of the Internet of Things.

Laurel Nelson-Rowe, ASQ managing director, introduced May topics in her guest blog post: What's the Future of Quality? This article is available without ASQ membership.

 Advertising on this blog supports my writing. By clicking an ad, you are under no obligation to buy. If you see an advertisement of interest, please click.