Wed, 05/01/2013 - 11:08

SEMA News—May 2013

FROM THE HILL
Dan Sadowski

SEMA Hammers Message to Save Johnson Valley HV Recreation Area

National Coalition Encourages Shared-Use Solution to Military Expansion

 The 2013 King of the Hammers, known as the ultimate desert race, was held at the Johnson Valley OHV Recreation Area in Southern California.
The 2013 King of the Hammers, known as the ultimate desert race, was held at the Johnson Valley OHV Recreation Area in Southern California. One hundred and twenty-five race teams and more than 60,000 spectators attended this year’s event.
  

Earlier this year, more than 50,000 off-highway vehicle enthusiasts gathered at the Johnson Valley Off-Highway Vehicle (OHV) Recreation Area in California for the seventh annual King of the Hammers. The event, known as the ultimate desert race, has evolved from 12 teams racing for bragging rights to more than 150 competing teams. Johnson Valley is the largest OHV area in the United States and draws at least 200,000 visitors annually while generating at least $260 million each year for the national economy. During the King of the Hammers event, racers take advantage of the area’s unique geography to race “Ultra 4” vehicles on a dry lakebed at speeds of more than 100 miles per hour and rock crawl through challenging boulder fields. This year, Congressman Paul Cook (R-CA) attended this important event in his home district and addressed a standing-room-only crowd at the drivers’ meeting.

King of the Hammers also allowed SEMA members and other enthusiasts to coordinate their efforts to save Johnson Valley from expansion of the nearby Twentynine Palms Marine Corps base. The U.S. Marine Corps (USMC) wants to expand its base to include ownership of nearly 147,000 acres of Johnson Valley land in order to conduct large-scale training exercises for two months a year. The land has been controlled for decades by the U.S. Bureau of Land Management (BLM), which provides special-use permits for various motorized recreation activities. SEMA has joined with the Off-Road Business Association (ORBA) and a coalition of other land-use advocacy organizations to propose a solution whereby the Marines would conduct their training exercises by obtaining BLM special-use permits.

“OHV racing is one of SEMA’s fastest-growing market segments,” said SEMA President and CEO Chris Kersting during the King of the Hammers Event. “Many of our member companies participate in these events while also providing the equipment necessary for teams to compete. Given the strong interest our members have in preserving Johnson Valley for enthusiast use, SEMA will continue to work with the Marine Corps to find a solution that allows for both military training and recreational opportunities.”

 Randy Slawson, the winner of the 2013 King of the Hammers, celebrates his team’s victory at the start/finish line in Hammertown, USA.
Randy Slawson, the winner of the 2013 King of the Hammers, celebrates his team’s victory at the start/finish line in Hammertown, USA.
  

When considering expansion of the Twentynine Palms base, the USMC considered six different expansion options and approved an option that would permanently close nearly 104,000 acres of Johnson Valley. Although another 43,000 acres would be available for shared-use purposes, including the unique rock crawling terrain known as the Hammers, the land could be later closed since live-fire munitions could make the area unsafe for recreational activities. To obtain the land, the Marines are required to request a land transfer from the U.S. Congress as part of the National Defense Authorization Act.

“The current perimeter between Johnson Valley and the Marine Corps base is not secured or properly identified, and base incursions occur frequently,” said Fred Wiley, president and CEO of ORBA. “The Marines’ preferred option does not address costs to secure a new base perimeter or guarantee public safety. In fact, Johnson Valley has been open to the public for so many years that families recreating will not be aware that they are trespassing on the expanded military base.”

The USMC has acknowledged the significant economic impact this base expansion plan could have on the local community but offered no solution to replace the lost revenue generated. Under a law passed by Congress earlier this year, the Marines were required to submit a report to Congress describing potential alternatives for sharing the land and addressing potential economic harm. The report concluded that there was no available alternative.

Randy Slawson, the winner of the 2013 King of the Hammers, celebrates his team’s victory at the start/finish line in Hammertown, USA.
Detailed map of the Johnson Valley in Southern
California.
 Randy Slawson, the winner of the 2013 King of the Hammers, celebrates his team’s victory at the start/finish line in Hammertown, USA.
Map of Johnson Valley and the SEMA-supported
“Alternative 4” proposal.
   

“The OHV community is offering a solution for sharing the land that was first identified by the USMC itself,” said Jeff Knoll of the California Motorized Recreation Council. “Only three changes need to be made to an alternate plan first proposed by the Marines: reverse the direction of maneuvers (to west-to-east), have live fire only on Twentynine Palms land and retain BLM management of the land via special-use permits.”

“This is a reasonable approach that relieves the USMC from managing and securing the land, protects the local economy and preserves OHV recreation,” added Greg Adler, president and CEO of Transamerican Auto Parts and a member of the boards of directors for SEMA and ORBA. “The Marines will be able to meet their military training objectives, and future generations will enjoy public access to the remote backcountry of the California desert.”

The fight to save Johnson Valley is not over. The OHV community has petitioned the White House for support of the special-use permit approach. Coalition members were critical in helping gather more than the 25,000 signatures required for an official administration response in just two weeks. The community is now awaiting the White House response.

SEMA PAC President’s Club In the Spotlight

 Randy Slawson, the winner of the 2013 King of the Hammers, celebrates his team’s victory at the start/finish line in Hammertown, USA.
Van Woodell (right), accompanied here by his wife Carol, is a nine-year member of the SEMA PAC President’s Club.
  

Van Woodell is the President of SEMA member company Weathers Auto Supply, which is located in Petersburg, Virginia. Woodell is a nine-year member of the SEMA PAC President’s Club and currently serves on SEMA’s Board of Directors.

“SEMA PAC allows us to foster critical relationships with key lawmakers,” Woodell said.

 “Over the years I have developed a strong working relationship with my own Congressman, Rep. Randy Forbes, as a direct result of my involvement with SEMA PAC.

Through the work of our Government Affairs office in Washington, SEMA is very fortunate to have many champions in the U.S. Congress. Please join me and many of our fellow SEMA members in supporting SEMA PAC.”

For more information on SEMA PAC, contact SEMA PAC Manager Christian Robinson at 202-783-6007 x20 or christianr@sema.org.

 

Wed, 05/01/2013 - 11:08

SEMA News—May 2013

FROM THE HILL
Dan Sadowski

SEMA Hammers Message to Save Johnson Valley HV Recreation Area

National Coalition Encourages Shared-Use Solution to Military Expansion

 The 2013 King of the Hammers, known as the ultimate desert race, was held at the Johnson Valley OHV Recreation Area in Southern California.
The 2013 King of the Hammers, known as the ultimate desert race, was held at the Johnson Valley OHV Recreation Area in Southern California. One hundred and twenty-five race teams and more than 60,000 spectators attended this year’s event.
  

Earlier this year, more than 50,000 off-highway vehicle enthusiasts gathered at the Johnson Valley Off-Highway Vehicle (OHV) Recreation Area in California for the seventh annual King of the Hammers. The event, known as the ultimate desert race, has evolved from 12 teams racing for bragging rights to more than 150 competing teams. Johnson Valley is the largest OHV area in the United States and draws at least 200,000 visitors annually while generating at least $260 million each year for the national economy. During the King of the Hammers event, racers take advantage of the area’s unique geography to race “Ultra 4” vehicles on a dry lakebed at speeds of more than 100 miles per hour and rock crawl through challenging boulder fields. This year, Congressman Paul Cook (R-CA) attended this important event in his home district and addressed a standing-room-only crowd at the drivers’ meeting.

King of the Hammers also allowed SEMA members and other enthusiasts to coordinate their efforts to save Johnson Valley from expansion of the nearby Twentynine Palms Marine Corps base. The U.S. Marine Corps (USMC) wants to expand its base to include ownership of nearly 147,000 acres of Johnson Valley land in order to conduct large-scale training exercises for two months a year. The land has been controlled for decades by the U.S. Bureau of Land Management (BLM), which provides special-use permits for various motorized recreation activities. SEMA has joined with the Off-Road Business Association (ORBA) and a coalition of other land-use advocacy organizations to propose a solution whereby the Marines would conduct their training exercises by obtaining BLM special-use permits.

“OHV racing is one of SEMA’s fastest-growing market segments,” said SEMA President and CEO Chris Kersting during the King of the Hammers Event. “Many of our member companies participate in these events while also providing the equipment necessary for teams to compete. Given the strong interest our members have in preserving Johnson Valley for enthusiast use, SEMA will continue to work with the Marine Corps to find a solution that allows for both military training and recreational opportunities.”

 Randy Slawson, the winner of the 2013 King of the Hammers, celebrates his team’s victory at the start/finish line in Hammertown, USA.
Randy Slawson, the winner of the 2013 King of the Hammers, celebrates his team’s victory at the start/finish line in Hammertown, USA.
  

When considering expansion of the Twentynine Palms base, the USMC considered six different expansion options and approved an option that would permanently close nearly 104,000 acres of Johnson Valley. Although another 43,000 acres would be available for shared-use purposes, including the unique rock crawling terrain known as the Hammers, the land could be later closed since live-fire munitions could make the area unsafe for recreational activities. To obtain the land, the Marines are required to request a land transfer from the U.S. Congress as part of the National Defense Authorization Act.

“The current perimeter between Johnson Valley and the Marine Corps base is not secured or properly identified, and base incursions occur frequently,” said Fred Wiley, president and CEO of ORBA. “The Marines’ preferred option does not address costs to secure a new base perimeter or guarantee public safety. In fact, Johnson Valley has been open to the public for so many years that families recreating will not be aware that they are trespassing on the expanded military base.”

The USMC has acknowledged the significant economic impact this base expansion plan could have on the local community but offered no solution to replace the lost revenue generated. Under a law passed by Congress earlier this year, the Marines were required to submit a report to Congress describing potential alternatives for sharing the land and addressing potential economic harm. The report concluded that there was no available alternative.

Randy Slawson, the winner of the 2013 King of the Hammers, celebrates his team’s victory at the start/finish line in Hammertown, USA.
Detailed map of the Johnson Valley in Southern
California.
 Randy Slawson, the winner of the 2013 King of the Hammers, celebrates his team’s victory at the start/finish line in Hammertown, USA.
Map of Johnson Valley and the SEMA-supported
“Alternative 4” proposal.
   

“The OHV community is offering a solution for sharing the land that was first identified by the USMC itself,” said Jeff Knoll of the California Motorized Recreation Council. “Only three changes need to be made to an alternate plan first proposed by the Marines: reverse the direction of maneuvers (to west-to-east), have live fire only on Twentynine Palms land and retain BLM management of the land via special-use permits.”

“This is a reasonable approach that relieves the USMC from managing and securing the land, protects the local economy and preserves OHV recreation,” added Greg Adler, president and CEO of Transamerican Auto Parts and a member of the boards of directors for SEMA and ORBA. “The Marines will be able to meet their military training objectives, and future generations will enjoy public access to the remote backcountry of the California desert.”

The fight to save Johnson Valley is not over. The OHV community has petitioned the White House for support of the special-use permit approach. Coalition members were critical in helping gather more than the 25,000 signatures required for an official administration response in just two weeks. The community is now awaiting the White House response.

SEMA PAC President’s Club In the Spotlight

 Randy Slawson, the winner of the 2013 King of the Hammers, celebrates his team’s victory at the start/finish line in Hammertown, USA.
Van Woodell (right), accompanied here by his wife Carol, is a nine-year member of the SEMA PAC President’s Club.
  

Van Woodell is the President of SEMA member company Weathers Auto Supply, which is located in Petersburg, Virginia. Woodell is a nine-year member of the SEMA PAC President’s Club and currently serves on SEMA’s Board of Directors.

“SEMA PAC allows us to foster critical relationships with key lawmakers,” Woodell said.

 “Over the years I have developed a strong working relationship with my own Congressman, Rep. Randy Forbes, as a direct result of my involvement with SEMA PAC.

Through the work of our Government Affairs office in Washington, SEMA is very fortunate to have many champions in the U.S. Congress. Please join me and many of our fellow SEMA members in supporting SEMA PAC.”

For more information on SEMA PAC, contact SEMA PAC Manager Christian Robinson at 202-783-6007 x20 or christianr@sema.org.

 

Wed, 05/01/2013 - 11:08

SEMA News—May 2013

FROM THE HILL
Dan Sadowski

SEMA Hammers Message to Save Johnson Valley HV Recreation Area

National Coalition Encourages Shared-Use Solution to Military Expansion

 The 2013 King of the Hammers, known as the ultimate desert race, was held at the Johnson Valley OHV Recreation Area in Southern California.
The 2013 King of the Hammers, known as the ultimate desert race, was held at the Johnson Valley OHV Recreation Area in Southern California. One hundred and twenty-five race teams and more than 60,000 spectators attended this year’s event.
  

Earlier this year, more than 50,000 off-highway vehicle enthusiasts gathered at the Johnson Valley Off-Highway Vehicle (OHV) Recreation Area in California for the seventh annual King of the Hammers. The event, known as the ultimate desert race, has evolved from 12 teams racing for bragging rights to more than 150 competing teams. Johnson Valley is the largest OHV area in the United States and draws at least 200,000 visitors annually while generating at least $260 million each year for the national economy. During the King of the Hammers event, racers take advantage of the area’s unique geography to race “Ultra 4” vehicles on a dry lakebed at speeds of more than 100 miles per hour and rock crawl through challenging boulder fields. This year, Congressman Paul Cook (R-CA) attended this important event in his home district and addressed a standing-room-only crowd at the drivers’ meeting.

King of the Hammers also allowed SEMA members and other enthusiasts to coordinate their efforts to save Johnson Valley from expansion of the nearby Twentynine Palms Marine Corps base. The U.S. Marine Corps (USMC) wants to expand its base to include ownership of nearly 147,000 acres of Johnson Valley land in order to conduct large-scale training exercises for two months a year. The land has been controlled for decades by the U.S. Bureau of Land Management (BLM), which provides special-use permits for various motorized recreation activities. SEMA has joined with the Off-Road Business Association (ORBA) and a coalition of other land-use advocacy organizations to propose a solution whereby the Marines would conduct their training exercises by obtaining BLM special-use permits.

“OHV racing is one of SEMA’s fastest-growing market segments,” said SEMA President and CEO Chris Kersting during the King of the Hammers Event. “Many of our member companies participate in these events while also providing the equipment necessary for teams to compete. Given the strong interest our members have in preserving Johnson Valley for enthusiast use, SEMA will continue to work with the Marine Corps to find a solution that allows for both military training and recreational opportunities.”

 Randy Slawson, the winner of the 2013 King of the Hammers, celebrates his team’s victory at the start/finish line in Hammertown, USA.
Randy Slawson, the winner of the 2013 King of the Hammers, celebrates his team’s victory at the start/finish line in Hammertown, USA.
  

When considering expansion of the Twentynine Palms base, the USMC considered six different expansion options and approved an option that would permanently close nearly 104,000 acres of Johnson Valley. Although another 43,000 acres would be available for shared-use purposes, including the unique rock crawling terrain known as the Hammers, the land could be later closed since live-fire munitions could make the area unsafe for recreational activities. To obtain the land, the Marines are required to request a land transfer from the U.S. Congress as part of the National Defense Authorization Act.

“The current perimeter between Johnson Valley and the Marine Corps base is not secured or properly identified, and base incursions occur frequently,” said Fred Wiley, president and CEO of ORBA. “The Marines’ preferred option does not address costs to secure a new base perimeter or guarantee public safety. In fact, Johnson Valley has been open to the public for so many years that families recreating will not be aware that they are trespassing on the expanded military base.”

The USMC has acknowledged the significant economic impact this base expansion plan could have on the local community but offered no solution to replace the lost revenue generated. Under a law passed by Congress earlier this year, the Marines were required to submit a report to Congress describing potential alternatives for sharing the land and addressing potential economic harm. The report concluded that there was no available alternative.

Randy Slawson, the winner of the 2013 King of the Hammers, celebrates his team’s victory at the start/finish line in Hammertown, USA.
Detailed map of the Johnson Valley in Southern
California.
 Randy Slawson, the winner of the 2013 King of the Hammers, celebrates his team’s victory at the start/finish line in Hammertown, USA.
Map of Johnson Valley and the SEMA-supported
“Alternative 4” proposal.
   

“The OHV community is offering a solution for sharing the land that was first identified by the USMC itself,” said Jeff Knoll of the California Motorized Recreation Council. “Only three changes need to be made to an alternate plan first proposed by the Marines: reverse the direction of maneuvers (to west-to-east), have live fire only on Twentynine Palms land and retain BLM management of the land via special-use permits.”

“This is a reasonable approach that relieves the USMC from managing and securing the land, protects the local economy and preserves OHV recreation,” added Greg Adler, president and CEO of Transamerican Auto Parts and a member of the boards of directors for SEMA and ORBA. “The Marines will be able to meet their military training objectives, and future generations will enjoy public access to the remote backcountry of the California desert.”

The fight to save Johnson Valley is not over. The OHV community has petitioned the White House for support of the special-use permit approach. Coalition members were critical in helping gather more than the 25,000 signatures required for an official administration response in just two weeks. The community is now awaiting the White House response.

SEMA PAC President’s Club In the Spotlight

 Randy Slawson, the winner of the 2013 King of the Hammers, celebrates his team’s victory at the start/finish line in Hammertown, USA.
Van Woodell (right), accompanied here by his wife Carol, is a nine-year member of the SEMA PAC President’s Club.
  

Van Woodell is the President of SEMA member company Weathers Auto Supply, which is located in Petersburg, Virginia. Woodell is a nine-year member of the SEMA PAC President’s Club and currently serves on SEMA’s Board of Directors.

“SEMA PAC allows us to foster critical relationships with key lawmakers,” Woodell said.

 “Over the years I have developed a strong working relationship with my own Congressman, Rep. Randy Forbes, as a direct result of my involvement with SEMA PAC.

Through the work of our Government Affairs office in Washington, SEMA is very fortunate to have many champions in the U.S. Congress. Please join me and many of our fellow SEMA members in supporting SEMA PAC.”

For more information on SEMA PAC, contact SEMA PAC Manager Christian Robinson at 202-783-6007 x20 or christianr@sema.org.

 

Wed, 05/01/2013 - 10:11

SEMA News—May 2013 

INTERNET
By Joe Dysart

Easy Prey

New Wave of Hacker Technology Threatens Unsuspecting Businesses

Regularly making chump meat of the most sophisticated of computer defenses, hackers will be unleashing a new wave of malware in the coming year on the unsuspecting—many of whom will be completely unprepared, according to Sophos, a computer-security firm.Regularly making chump meat of the most sophisticated of computer defenses, hackers will be unleashing a new wave of malware in the coming year on the unsuspecting—many of whom will be completely unprepared, according to Sophos, a computer-security firm.

“Cybercriminals tend to focus where the weak spots are,” said Gerhard Eschelbeck, chief technology officer at Sophos. “Protecting data in a world where systems are changing rapidly and information flows freely requires a coordinated ecosystem of security technologies.”

Perhaps even more disturbing, hackers will be increasingly targeting small- and medium-size businesses, according to Mark Brophy, director of information technology at Rogers Townsend & Thomas. The reason, he said, is that defenses of smaller business are generally weaker, and these less-protected systems are seen by hackers as easy back doors to the much larger clients those businesses trade with. Essentially, once hackers penetrate the relatively weak defenses of a small business, they can plunder the data on its network to go after their bigger-game clients, according to Brophy.

Not surprisingly, many giant and multinational corporations are hip to the trend, and they’re responding by performing tough security audits of their smaller trading partners. If they find a security risk, many decide to simply pull work from the offending business rather than risk a “break-in by association,” according to Brophy.

Small- and medium-size businesses looking to pass these hard-nosed audits—or reassure trading partners that their mutual data is safe—will need to convince trading partners that they have a hard IT perimeter. And they’ll need to show defenses against some of the newest threats looming in the coming year.

High on the list of the new and the brutal is cloud-server-snapshot software. An insidious intruder, snapshot software can infect a cloud server where a business stores its data and take a complete snapshot of all the data that’s there—including passwords, Eschelbeck said. Meanwhile, increasing numbers of hackers are also using text-messaging theft software, which is surreptitiously added to the phone of unsuspecting users. Once activated, the software forwards all text messages sent to that phone to a hacker, Eschelbeck said.

“The potential exists for attacks like these to target Internet banking services,” he said. “Many banks send authentication codes to your phone. Malware on your phone is capable of intercepting those messages.”

Sophos has also detected increasing use of “ransomware” against small- and medium-size businesses. These apps can infect both phones and computers and render the devices inoperable. Hackers inflicting the software on businesses often demand major dollars for its removal. Not surprisingly, they rarely—if ever—follow up on removal even if the business does pay the ransom, according to Eschelback.

 A Sophos employee at work neutralizing would-be hackers.
A Sophos employee at work neutralizing would-be hackers. 
  
Yet another new threat is coming from computer users with average skills who can become formidable hackers with superkit software, according to Eschelbeck. These do-it-yourself packages often offer more than a dozen state-of-the-art ways to infiltrate even the most sophisticated cyber defenses. Criminals buying the software on the black market don’t really need to know how it works; they simply need to know how to point-and-click.

Granted, businesses of all sizes should be using firewalls and other network protections to help neutralize hacker break-ins. And most businesses realize that even the most sterling of computer security defenses can be thwarted without similar vigilance at the individual-device level.

“End-user computers are the weakest spot,” said Shane Sims, director of investigations and forensic services for PriceWaterhouseCoopers. “Typically, these computers are protected only by antivirus software, and the most sophisticated hackers attack at that point.”

But dollar for dollar, the best return on an investment in computer security is employee education, according to Brophy. Take the time to educate new employees about the critical need for computer security, he said. And continually reinforce top-of-mind security with regular e-mail tips, tricks and news about IT security.

Once you have the organization sufficiently alerted, the computer security experts recommend these best practices:

Encrypt All Mobile Devices: Secure all mobile devices, including Android devices, by getting your IT department to fully encrypt the units, Eschelbeck said. Make sure all SID cards used in those devices are also encrypted. And ensure that all data and applications on the devices can be erased remotely if the mobile device is lost or stolen.

Encrypt All Cloud Data: Before cutting any deal with a cloud provider, ensure that your contract enables your company to encrypt all the data your business generates before it sends that data to the cloud, according to Ken Rashbaum, principal at Rashbaum Associates. With that safeguard, your data—and the data of your trading partners—should be impenetrable even if a hacker takes a snapshot of the cloud server that’s storing that data.

Defeat Ransomware: Ransomware programs such as Reventon, Citadel and Troj/Ransom can be neutralized by rebooting your computer with an anti-virus software program that contains its own operating system. Essentially, the tool runs your computer with its own operating system, finds the ransomware on your system and destroys it, restoring your computer, Eschelbeck said. Sophos’ solution for this problem is Sophos Bootable Anti-Virus. Unfortunately, there is still some ransomware so sophisticated that even these tools cannot defeat it, according to Eschelbeck.

Deep-Six the Superkits: While there’s no bulletproof shield against all the ravages of a superkit, there are some common-sense precautions. Be sure to install updates to all the software on your system as soon as possible, Eschelbeck said. And be sure to disable security-vulnerable software, such as Java and Flash, whenever you’re not using those programs.

Armor Passwords: Strictly forbid employees from using the same passwords at work and at home, Brophy said. Hackers are aware of this habit and regularly troll personal e-mail accounts, hoping to find passwords they can also use on employee work accounts.

Respect the Rule of 12: Prohibit the use of passwords shorter than 13 characters. The darker corners of the web are rife with programs that can auto-crack any password that is 12 characters or less. Essentially, hackers simply activate these programs on a specific e-mail account and let the program run indefinitely until the account’s password is revealed.

Joe Dysart is an Internet speaker and business consultant based in Manhattan.
For more information:
646-233-4089
joe@joedysart.com
www.joedysart.com.

Wed, 05/01/2013 - 10:11

SEMA News—May 2013 

INTERNET
By Joe Dysart

Easy Prey

New Wave of Hacker Technology Threatens Unsuspecting Businesses

Regularly making chump meat of the most sophisticated of computer defenses, hackers will be unleashing a new wave of malware in the coming year on the unsuspecting—many of whom will be completely unprepared, according to Sophos, a computer-security firm.Regularly making chump meat of the most sophisticated of computer defenses, hackers will be unleashing a new wave of malware in the coming year on the unsuspecting—many of whom will be completely unprepared, according to Sophos, a computer-security firm.

“Cybercriminals tend to focus where the weak spots are,” said Gerhard Eschelbeck, chief technology officer at Sophos. “Protecting data in a world where systems are changing rapidly and information flows freely requires a coordinated ecosystem of security technologies.”

Perhaps even more disturbing, hackers will be increasingly targeting small- and medium-size businesses, according to Mark Brophy, director of information technology at Rogers Townsend & Thomas. The reason, he said, is that defenses of smaller business are generally weaker, and these less-protected systems are seen by hackers as easy back doors to the much larger clients those businesses trade with. Essentially, once hackers penetrate the relatively weak defenses of a small business, they can plunder the data on its network to go after their bigger-game clients, according to Brophy.

Not surprisingly, many giant and multinational corporations are hip to the trend, and they’re responding by performing tough security audits of their smaller trading partners. If they find a security risk, many decide to simply pull work from the offending business rather than risk a “break-in by association,” according to Brophy.

Small- and medium-size businesses looking to pass these hard-nosed audits—or reassure trading partners that their mutual data is safe—will need to convince trading partners that they have a hard IT perimeter. And they’ll need to show defenses against some of the newest threats looming in the coming year.

High on the list of the new and the brutal is cloud-server-snapshot software. An insidious intruder, snapshot software can infect a cloud server where a business stores its data and take a complete snapshot of all the data that’s there—including passwords, Eschelbeck said. Meanwhile, increasing numbers of hackers are also using text-messaging theft software, which is surreptitiously added to the phone of unsuspecting users. Once activated, the software forwards all text messages sent to that phone to a hacker, Eschelbeck said.

“The potential exists for attacks like these to target Internet banking services,” he said. “Many banks send authentication codes to your phone. Malware on your phone is capable of intercepting those messages.”

Sophos has also detected increasing use of “ransomware” against small- and medium-size businesses. These apps can infect both phones and computers and render the devices inoperable. Hackers inflicting the software on businesses often demand major dollars for its removal. Not surprisingly, they rarely—if ever—follow up on removal even if the business does pay the ransom, according to Eschelback.

 A Sophos employee at work neutralizing would-be hackers.
A Sophos employee at work neutralizing would-be hackers. 
  
Yet another new threat is coming from computer users with average skills who can become formidable hackers with superkit software, according to Eschelbeck. These do-it-yourself packages often offer more than a dozen state-of-the-art ways to infiltrate even the most sophisticated cyber defenses. Criminals buying the software on the black market don’t really need to know how it works; they simply need to know how to point-and-click.

Granted, businesses of all sizes should be using firewalls and other network protections to help neutralize hacker break-ins. And most businesses realize that even the most sterling of computer security defenses can be thwarted without similar vigilance at the individual-device level.

“End-user computers are the weakest spot,” said Shane Sims, director of investigations and forensic services for PriceWaterhouseCoopers. “Typically, these computers are protected only by antivirus software, and the most sophisticated hackers attack at that point.”

But dollar for dollar, the best return on an investment in computer security is employee education, according to Brophy. Take the time to educate new employees about the critical need for computer security, he said. And continually reinforce top-of-mind security with regular e-mail tips, tricks and news about IT security.

Once you have the organization sufficiently alerted, the computer security experts recommend these best practices:

Encrypt All Mobile Devices: Secure all mobile devices, including Android devices, by getting your IT department to fully encrypt the units, Eschelbeck said. Make sure all SID cards used in those devices are also encrypted. And ensure that all data and applications on the devices can be erased remotely if the mobile device is lost or stolen.

Encrypt All Cloud Data: Before cutting any deal with a cloud provider, ensure that your contract enables your company to encrypt all the data your business generates before it sends that data to the cloud, according to Ken Rashbaum, principal at Rashbaum Associates. With that safeguard, your data—and the data of your trading partners—should be impenetrable even if a hacker takes a snapshot of the cloud server that’s storing that data.

Defeat Ransomware: Ransomware programs such as Reventon, Citadel and Troj/Ransom can be neutralized by rebooting your computer with an anti-virus software program that contains its own operating system. Essentially, the tool runs your computer with its own operating system, finds the ransomware on your system and destroys it, restoring your computer, Eschelbeck said. Sophos’ solution for this problem is Sophos Bootable Anti-Virus. Unfortunately, there is still some ransomware so sophisticated that even these tools cannot defeat it, according to Eschelbeck.

Deep-Six the Superkits: While there’s no bulletproof shield against all the ravages of a superkit, there are some common-sense precautions. Be sure to install updates to all the software on your system as soon as possible, Eschelbeck said. And be sure to disable security-vulnerable software, such as Java and Flash, whenever you’re not using those programs.

Armor Passwords: Strictly forbid employees from using the same passwords at work and at home, Brophy said. Hackers are aware of this habit and regularly troll personal e-mail accounts, hoping to find passwords they can also use on employee work accounts.

Respect the Rule of 12: Prohibit the use of passwords shorter than 13 characters. The darker corners of the web are rife with programs that can auto-crack any password that is 12 characters or less. Essentially, hackers simply activate these programs on a specific e-mail account and let the program run indefinitely until the account’s password is revealed.

Joe Dysart is an Internet speaker and business consultant based in Manhattan.
For more information:
646-233-4089
joe@joedysart.com
www.joedysart.com.

Wed, 05/01/2013 - 10:11

SEMA News—May 2013 

INTERNET
By Joe Dysart

Easy Prey

New Wave of Hacker Technology Threatens Unsuspecting Businesses

Regularly making chump meat of the most sophisticated of computer defenses, hackers will be unleashing a new wave of malware in the coming year on the unsuspecting—many of whom will be completely unprepared, according to Sophos, a computer-security firm.Regularly making chump meat of the most sophisticated of computer defenses, hackers will be unleashing a new wave of malware in the coming year on the unsuspecting—many of whom will be completely unprepared, according to Sophos, a computer-security firm.

“Cybercriminals tend to focus where the weak spots are,” said Gerhard Eschelbeck, chief technology officer at Sophos. “Protecting data in a world where systems are changing rapidly and information flows freely requires a coordinated ecosystem of security technologies.”

Perhaps even more disturbing, hackers will be increasingly targeting small- and medium-size businesses, according to Mark Brophy, director of information technology at Rogers Townsend & Thomas. The reason, he said, is that defenses of smaller business are generally weaker, and these less-protected systems are seen by hackers as easy back doors to the much larger clients those businesses trade with. Essentially, once hackers penetrate the relatively weak defenses of a small business, they can plunder the data on its network to go after their bigger-game clients, according to Brophy.

Not surprisingly, many giant and multinational corporations are hip to the trend, and they’re responding by performing tough security audits of their smaller trading partners. If they find a security risk, many decide to simply pull work from the offending business rather than risk a “break-in by association,” according to Brophy.

Small- and medium-size businesses looking to pass these hard-nosed audits—or reassure trading partners that their mutual data is safe—will need to convince trading partners that they have a hard IT perimeter. And they’ll need to show defenses against some of the newest threats looming in the coming year.

High on the list of the new and the brutal is cloud-server-snapshot software. An insidious intruder, snapshot software can infect a cloud server where a business stores its data and take a complete snapshot of all the data that’s there—including passwords, Eschelbeck said. Meanwhile, increasing numbers of hackers are also using text-messaging theft software, which is surreptitiously added to the phone of unsuspecting users. Once activated, the software forwards all text messages sent to that phone to a hacker, Eschelbeck said.

“The potential exists for attacks like these to target Internet banking services,” he said. “Many banks send authentication codes to your phone. Malware on your phone is capable of intercepting those messages.”

Sophos has also detected increasing use of “ransomware” against small- and medium-size businesses. These apps can infect both phones and computers and render the devices inoperable. Hackers inflicting the software on businesses often demand major dollars for its removal. Not surprisingly, they rarely—if ever—follow up on removal even if the business does pay the ransom, according to Eschelback.

 A Sophos employee at work neutralizing would-be hackers.
A Sophos employee at work neutralizing would-be hackers. 
  
Yet another new threat is coming from computer users with average skills who can become formidable hackers with superkit software, according to Eschelbeck. These do-it-yourself packages often offer more than a dozen state-of-the-art ways to infiltrate even the most sophisticated cyber defenses. Criminals buying the software on the black market don’t really need to know how it works; they simply need to know how to point-and-click.

Granted, businesses of all sizes should be using firewalls and other network protections to help neutralize hacker break-ins. And most businesses realize that even the most sterling of computer security defenses can be thwarted without similar vigilance at the individual-device level.

“End-user computers are the weakest spot,” said Shane Sims, director of investigations and forensic services for PriceWaterhouseCoopers. “Typically, these computers are protected only by antivirus software, and the most sophisticated hackers attack at that point.”

But dollar for dollar, the best return on an investment in computer security is employee education, according to Brophy. Take the time to educate new employees about the critical need for computer security, he said. And continually reinforce top-of-mind security with regular e-mail tips, tricks and news about IT security.

Once you have the organization sufficiently alerted, the computer security experts recommend these best practices:

Encrypt All Mobile Devices: Secure all mobile devices, including Android devices, by getting your IT department to fully encrypt the units, Eschelbeck said. Make sure all SID cards used in those devices are also encrypted. And ensure that all data and applications on the devices can be erased remotely if the mobile device is lost or stolen.

Encrypt All Cloud Data: Before cutting any deal with a cloud provider, ensure that your contract enables your company to encrypt all the data your business generates before it sends that data to the cloud, according to Ken Rashbaum, principal at Rashbaum Associates. With that safeguard, your data—and the data of your trading partners—should be impenetrable even if a hacker takes a snapshot of the cloud server that’s storing that data.

Defeat Ransomware: Ransomware programs such as Reventon, Citadel and Troj/Ransom can be neutralized by rebooting your computer with an anti-virus software program that contains its own operating system. Essentially, the tool runs your computer with its own operating system, finds the ransomware on your system and destroys it, restoring your computer, Eschelbeck said. Sophos’ solution for this problem is Sophos Bootable Anti-Virus. Unfortunately, there is still some ransomware so sophisticated that even these tools cannot defeat it, according to Eschelbeck.

Deep-Six the Superkits: While there’s no bulletproof shield against all the ravages of a superkit, there are some common-sense precautions. Be sure to install updates to all the software on your system as soon as possible, Eschelbeck said. And be sure to disable security-vulnerable software, such as Java and Flash, whenever you’re not using those programs.

Armor Passwords: Strictly forbid employees from using the same passwords at work and at home, Brophy said. Hackers are aware of this habit and regularly troll personal e-mail accounts, hoping to find passwords they can also use on employee work accounts.

Respect the Rule of 12: Prohibit the use of passwords shorter than 13 characters. The darker corners of the web are rife with programs that can auto-crack any password that is 12 characters or less. Essentially, hackers simply activate these programs on a specific e-mail account and let the program run indefinitely until the account’s password is revealed.

Joe Dysart is an Internet speaker and business consultant based in Manhattan.
For more information:
646-233-4089
joe@joedysart.com
www.joedysart.com.

Wed, 05/01/2013 - 10:11

SEMA News—May 2013 

INTERNET
By Joe Dysart

Easy Prey

New Wave of Hacker Technology Threatens Unsuspecting Businesses

Regularly making chump meat of the most sophisticated of computer defenses, hackers will be unleashing a new wave of malware in the coming year on the unsuspecting—many of whom will be completely unprepared, according to Sophos, a computer-security firm.Regularly making chump meat of the most sophisticated of computer defenses, hackers will be unleashing a new wave of malware in the coming year on the unsuspecting—many of whom will be completely unprepared, according to Sophos, a computer-security firm.

“Cybercriminals tend to focus where the weak spots are,” said Gerhard Eschelbeck, chief technology officer at Sophos. “Protecting data in a world where systems are changing rapidly and information flows freely requires a coordinated ecosystem of security technologies.”

Perhaps even more disturbing, hackers will be increasingly targeting small- and medium-size businesses, according to Mark Brophy, director of information technology at Rogers Townsend & Thomas. The reason, he said, is that defenses of smaller business are generally weaker, and these less-protected systems are seen by hackers as easy back doors to the much larger clients those businesses trade with. Essentially, once hackers penetrate the relatively weak defenses of a small business, they can plunder the data on its network to go after their bigger-game clients, according to Brophy.

Not surprisingly, many giant and multinational corporations are hip to the trend, and they’re responding by performing tough security audits of their smaller trading partners. If they find a security risk, many decide to simply pull work from the offending business rather than risk a “break-in by association,” according to Brophy.

Small- and medium-size businesses looking to pass these hard-nosed audits—or reassure trading partners that their mutual data is safe—will need to convince trading partners that they have a hard IT perimeter. And they’ll need to show defenses against some of the newest threats looming in the coming year.

High on the list of the new and the brutal is cloud-server-snapshot software. An insidious intruder, snapshot software can infect a cloud server where a business stores its data and take a complete snapshot of all the data that’s there—including passwords, Eschelbeck said. Meanwhile, increasing numbers of hackers are also using text-messaging theft software, which is surreptitiously added to the phone of unsuspecting users. Once activated, the software forwards all text messages sent to that phone to a hacker, Eschelbeck said.

“The potential exists for attacks like these to target Internet banking services,” he said. “Many banks send authentication codes to your phone. Malware on your phone is capable of intercepting those messages.”

Sophos has also detected increasing use of “ransomware” against small- and medium-size businesses. These apps can infect both phones and computers and render the devices inoperable. Hackers inflicting the software on businesses often demand major dollars for its removal. Not surprisingly, they rarely—if ever—follow up on removal even if the business does pay the ransom, according to Eschelback.

 A Sophos employee at work neutralizing would-be hackers.
A Sophos employee at work neutralizing would-be hackers. 
  
Yet another new threat is coming from computer users with average skills who can become formidable hackers with superkit software, according to Eschelbeck. These do-it-yourself packages often offer more than a dozen state-of-the-art ways to infiltrate even the most sophisticated cyber defenses. Criminals buying the software on the black market don’t really need to know how it works; they simply need to know how to point-and-click.

Granted, businesses of all sizes should be using firewalls and other network protections to help neutralize hacker break-ins. And most businesses realize that even the most sterling of computer security defenses can be thwarted without similar vigilance at the individual-device level.

“End-user computers are the weakest spot,” said Shane Sims, director of investigations and forensic services for PriceWaterhouseCoopers. “Typically, these computers are protected only by antivirus software, and the most sophisticated hackers attack at that point.”

But dollar for dollar, the best return on an investment in computer security is employee education, according to Brophy. Take the time to educate new employees about the critical need for computer security, he said. And continually reinforce top-of-mind security with regular e-mail tips, tricks and news about IT security.

Once you have the organization sufficiently alerted, the computer security experts recommend these best practices:

Encrypt All Mobile Devices: Secure all mobile devices, including Android devices, by getting your IT department to fully encrypt the units, Eschelbeck said. Make sure all SID cards used in those devices are also encrypted. And ensure that all data and applications on the devices can be erased remotely if the mobile device is lost or stolen.

Encrypt All Cloud Data: Before cutting any deal with a cloud provider, ensure that your contract enables your company to encrypt all the data your business generates before it sends that data to the cloud, according to Ken Rashbaum, principal at Rashbaum Associates. With that safeguard, your data—and the data of your trading partners—should be impenetrable even if a hacker takes a snapshot of the cloud server that’s storing that data.

Defeat Ransomware: Ransomware programs such as Reventon, Citadel and Troj/Ransom can be neutralized by rebooting your computer with an anti-virus software program that contains its own operating system. Essentially, the tool runs your computer with its own operating system, finds the ransomware on your system and destroys it, restoring your computer, Eschelbeck said. Sophos’ solution for this problem is Sophos Bootable Anti-Virus. Unfortunately, there is still some ransomware so sophisticated that even these tools cannot defeat it, according to Eschelbeck.

Deep-Six the Superkits: While there’s no bulletproof shield against all the ravages of a superkit, there are some common-sense precautions. Be sure to install updates to all the software on your system as soon as possible, Eschelbeck said. And be sure to disable security-vulnerable software, such as Java and Flash, whenever you’re not using those programs.

Armor Passwords: Strictly forbid employees from using the same passwords at work and at home, Brophy said. Hackers are aware of this habit and regularly troll personal e-mail accounts, hoping to find passwords they can also use on employee work accounts.

Respect the Rule of 12: Prohibit the use of passwords shorter than 13 characters. The darker corners of the web are rife with programs that can auto-crack any password that is 12 characters or less. Essentially, hackers simply activate these programs on a specific e-mail account and let the program run indefinitely until the account’s password is revealed.

Joe Dysart is an Internet speaker and business consultant based in Manhattan.
For more information:
646-233-4089
joe@joedysart.com
www.joedysart.com.

Wed, 05/01/2013 - 10:11

SEMA News—May 2013 

INTERNET
By Joe Dysart

Easy Prey

New Wave of Hacker Technology Threatens Unsuspecting Businesses

Regularly making chump meat of the most sophisticated of computer defenses, hackers will be unleashing a new wave of malware in the coming year on the unsuspecting—many of whom will be completely unprepared, according to Sophos, a computer-security firm.Regularly making chump meat of the most sophisticated of computer defenses, hackers will be unleashing a new wave of malware in the coming year on the unsuspecting—many of whom will be completely unprepared, according to Sophos, a computer-security firm.

“Cybercriminals tend to focus where the weak spots are,” said Gerhard Eschelbeck, chief technology officer at Sophos. “Protecting data in a world where systems are changing rapidly and information flows freely requires a coordinated ecosystem of security technologies.”

Perhaps even more disturbing, hackers will be increasingly targeting small- and medium-size businesses, according to Mark Brophy, director of information technology at Rogers Townsend & Thomas. The reason, he said, is that defenses of smaller business are generally weaker, and these less-protected systems are seen by hackers as easy back doors to the much larger clients those businesses trade with. Essentially, once hackers penetrate the relatively weak defenses of a small business, they can plunder the data on its network to go after their bigger-game clients, according to Brophy.

Not surprisingly, many giant and multinational corporations are hip to the trend, and they’re responding by performing tough security audits of their smaller trading partners. If they find a security risk, many decide to simply pull work from the offending business rather than risk a “break-in by association,” according to Brophy.

Small- and medium-size businesses looking to pass these hard-nosed audits—or reassure trading partners that their mutual data is safe—will need to convince trading partners that they have a hard IT perimeter. And they’ll need to show defenses against some of the newest threats looming in the coming year.

High on the list of the new and the brutal is cloud-server-snapshot software. An insidious intruder, snapshot software can infect a cloud server where a business stores its data and take a complete snapshot of all the data that’s there—including passwords, Eschelbeck said. Meanwhile, increasing numbers of hackers are also using text-messaging theft software, which is surreptitiously added to the phone of unsuspecting users. Once activated, the software forwards all text messages sent to that phone to a hacker, Eschelbeck said.

“The potential exists for attacks like these to target Internet banking services,” he said. “Many banks send authentication codes to your phone. Malware on your phone is capable of intercepting those messages.”

Sophos has also detected increasing use of “ransomware” against small- and medium-size businesses. These apps can infect both phones and computers and render the devices inoperable. Hackers inflicting the software on businesses often demand major dollars for its removal. Not surprisingly, they rarely—if ever—follow up on removal even if the business does pay the ransom, according to Eschelback.

 A Sophos employee at work neutralizing would-be hackers.
A Sophos employee at work neutralizing would-be hackers. 
  
Yet another new threat is coming from computer users with average skills who can become formidable hackers with superkit software, according to Eschelbeck. These do-it-yourself packages often offer more than a dozen state-of-the-art ways to infiltrate even the most sophisticated cyber defenses. Criminals buying the software on the black market don’t really need to know how it works; they simply need to know how to point-and-click.

Granted, businesses of all sizes should be using firewalls and other network protections to help neutralize hacker break-ins. And most businesses realize that even the most sterling of computer security defenses can be thwarted without similar vigilance at the individual-device level.

“End-user computers are the weakest spot,” said Shane Sims, director of investigations and forensic services for PriceWaterhouseCoopers. “Typically, these computers are protected only by antivirus software, and the most sophisticated hackers attack at that point.”

But dollar for dollar, the best return on an investment in computer security is employee education, according to Brophy. Take the time to educate new employees about the critical need for computer security, he said. And continually reinforce top-of-mind security with regular e-mail tips, tricks and news about IT security.

Once you have the organization sufficiently alerted, the computer security experts recommend these best practices:

Encrypt All Mobile Devices: Secure all mobile devices, including Android devices, by getting your IT department to fully encrypt the units, Eschelbeck said. Make sure all SID cards used in those devices are also encrypted. And ensure that all data and applications on the devices can be erased remotely if the mobile device is lost or stolen.

Encrypt All Cloud Data: Before cutting any deal with a cloud provider, ensure that your contract enables your company to encrypt all the data your business generates before it sends that data to the cloud, according to Ken Rashbaum, principal at Rashbaum Associates. With that safeguard, your data—and the data of your trading partners—should be impenetrable even if a hacker takes a snapshot of the cloud server that’s storing that data.

Defeat Ransomware: Ransomware programs such as Reventon, Citadel and Troj/Ransom can be neutralized by rebooting your computer with an anti-virus software program that contains its own operating system. Essentially, the tool runs your computer with its own operating system, finds the ransomware on your system and destroys it, restoring your computer, Eschelbeck said. Sophos’ solution for this problem is Sophos Bootable Anti-Virus. Unfortunately, there is still some ransomware so sophisticated that even these tools cannot defeat it, according to Eschelbeck.

Deep-Six the Superkits: While there’s no bulletproof shield against all the ravages of a superkit, there are some common-sense precautions. Be sure to install updates to all the software on your system as soon as possible, Eschelbeck said. And be sure to disable security-vulnerable software, such as Java and Flash, whenever you’re not using those programs.

Armor Passwords: Strictly forbid employees from using the same passwords at work and at home, Brophy said. Hackers are aware of this habit and regularly troll personal e-mail accounts, hoping to find passwords they can also use on employee work accounts.

Respect the Rule of 12: Prohibit the use of passwords shorter than 13 characters. The darker corners of the web are rife with programs that can auto-crack any password that is 12 characters or less. Essentially, hackers simply activate these programs on a specific e-mail account and let the program run indefinitely until the account’s password is revealed.

Joe Dysart is an Internet speaker and business consultant based in Manhattan.
For more information:
646-233-4089
joe@joedysart.com
www.joedysart.com.

Wed, 05/01/2013 - 10:11

SEMA News—May 2013 

INTERNET
By Joe Dysart

Easy Prey

New Wave of Hacker Technology Threatens Unsuspecting Businesses

Regularly making chump meat of the most sophisticated of computer defenses, hackers will be unleashing a new wave of malware in the coming year on the unsuspecting—many of whom will be completely unprepared, according to Sophos, a computer-security firm.Regularly making chump meat of the most sophisticated of computer defenses, hackers will be unleashing a new wave of malware in the coming year on the unsuspecting—many of whom will be completely unprepared, according to Sophos, a computer-security firm.

“Cybercriminals tend to focus where the weak spots are,” said Gerhard Eschelbeck, chief technology officer at Sophos. “Protecting data in a world where systems are changing rapidly and information flows freely requires a coordinated ecosystem of security technologies.”

Perhaps even more disturbing, hackers will be increasingly targeting small- and medium-size businesses, according to Mark Brophy, director of information technology at Rogers Townsend & Thomas. The reason, he said, is that defenses of smaller business are generally weaker, and these less-protected systems are seen by hackers as easy back doors to the much larger clients those businesses trade with. Essentially, once hackers penetrate the relatively weak defenses of a small business, they can plunder the data on its network to go after their bigger-game clients, according to Brophy.

Not surprisingly, many giant and multinational corporations are hip to the trend, and they’re responding by performing tough security audits of their smaller trading partners. If they find a security risk, many decide to simply pull work from the offending business rather than risk a “break-in by association,” according to Brophy.

Small- and medium-size businesses looking to pass these hard-nosed audits—or reassure trading partners that their mutual data is safe—will need to convince trading partners that they have a hard IT perimeter. And they’ll need to show defenses against some of the newest threats looming in the coming year.

High on the list of the new and the brutal is cloud-server-snapshot software. An insidious intruder, snapshot software can infect a cloud server where a business stores its data and take a complete snapshot of all the data that’s there—including passwords, Eschelbeck said. Meanwhile, increasing numbers of hackers are also using text-messaging theft software, which is surreptitiously added to the phone of unsuspecting users. Once activated, the software forwards all text messages sent to that phone to a hacker, Eschelbeck said.

“The potential exists for attacks like these to target Internet banking services,” he said. “Many banks send authentication codes to your phone. Malware on your phone is capable of intercepting those messages.”

Sophos has also detected increasing use of “ransomware” against small- and medium-size businesses. These apps can infect both phones and computers and render the devices inoperable. Hackers inflicting the software on businesses often demand major dollars for its removal. Not surprisingly, they rarely—if ever—follow up on removal even if the business does pay the ransom, according to Eschelback.

 A Sophos employee at work neutralizing would-be hackers.
A Sophos employee at work neutralizing would-be hackers. 
  
Yet another new threat is coming from computer users with average skills who can become formidable hackers with superkit software, according to Eschelbeck. These do-it-yourself packages often offer more than a dozen state-of-the-art ways to infiltrate even the most sophisticated cyber defenses. Criminals buying the software on the black market don’t really need to know how it works; they simply need to know how to point-and-click.

Granted, businesses of all sizes should be using firewalls and other network protections to help neutralize hacker break-ins. And most businesses realize that even the most sterling of computer security defenses can be thwarted without similar vigilance at the individual-device level.

“End-user computers are the weakest spot,” said Shane Sims, director of investigations and forensic services for PriceWaterhouseCoopers. “Typically, these computers are protected only by antivirus software, and the most sophisticated hackers attack at that point.”

But dollar for dollar, the best return on an investment in computer security is employee education, according to Brophy. Take the time to educate new employees about the critical need for computer security, he said. And continually reinforce top-of-mind security with regular e-mail tips, tricks and news about IT security.

Once you have the organization sufficiently alerted, the computer security experts recommend these best practices:

Encrypt All Mobile Devices: Secure all mobile devices, including Android devices, by getting your IT department to fully encrypt the units, Eschelbeck said. Make sure all SID cards used in those devices are also encrypted. And ensure that all data and applications on the devices can be erased remotely if the mobile device is lost or stolen.

Encrypt All Cloud Data: Before cutting any deal with a cloud provider, ensure that your contract enables your company to encrypt all the data your business generates before it sends that data to the cloud, according to Ken Rashbaum, principal at Rashbaum Associates. With that safeguard, your data—and the data of your trading partners—should be impenetrable even if a hacker takes a snapshot of the cloud server that’s storing that data.

Defeat Ransomware: Ransomware programs such as Reventon, Citadel and Troj/Ransom can be neutralized by rebooting your computer with an anti-virus software program that contains its own operating system. Essentially, the tool runs your computer with its own operating system, finds the ransomware on your system and destroys it, restoring your computer, Eschelbeck said. Sophos’ solution for this problem is Sophos Bootable Anti-Virus. Unfortunately, there is still some ransomware so sophisticated that even these tools cannot defeat it, according to Eschelbeck.

Deep-Six the Superkits: While there’s no bulletproof shield against all the ravages of a superkit, there are some common-sense precautions. Be sure to install updates to all the software on your system as soon as possible, Eschelbeck said. And be sure to disable security-vulnerable software, such as Java and Flash, whenever you’re not using those programs.

Armor Passwords: Strictly forbid employees from using the same passwords at work and at home, Brophy said. Hackers are aware of this habit and regularly troll personal e-mail accounts, hoping to find passwords they can also use on employee work accounts.

Respect the Rule of 12: Prohibit the use of passwords shorter than 13 characters. The darker corners of the web are rife with programs that can auto-crack any password that is 12 characters or less. Essentially, hackers simply activate these programs on a specific e-mail account and let the program run indefinitely until the account’s password is revealed.

Joe Dysart is an Internet speaker and business consultant based in Manhattan.
For more information:
646-233-4089
joe@joedysart.com
www.joedysart.com.

Wed, 05/01/2013 - 10:11

SEMA News—May 2013 

INTERNET
By Joe Dysart

Easy Prey

New Wave of Hacker Technology Threatens Unsuspecting Businesses

Regularly making chump meat of the most sophisticated of computer defenses, hackers will be unleashing a new wave of malware in the coming year on the unsuspecting—many of whom will be completely unprepared, according to Sophos, a computer-security firm.Regularly making chump meat of the most sophisticated of computer defenses, hackers will be unleashing a new wave of malware in the coming year on the unsuspecting—many of whom will be completely unprepared, according to Sophos, a computer-security firm.

“Cybercriminals tend to focus where the weak spots are,” said Gerhard Eschelbeck, chief technology officer at Sophos. “Protecting data in a world where systems are changing rapidly and information flows freely requires a coordinated ecosystem of security technologies.”

Perhaps even more disturbing, hackers will be increasingly targeting small- and medium-size businesses, according to Mark Brophy, director of information technology at Rogers Townsend & Thomas. The reason, he said, is that defenses of smaller business are generally weaker, and these less-protected systems are seen by hackers as easy back doors to the much larger clients those businesses trade with. Essentially, once hackers penetrate the relatively weak defenses of a small business, they can plunder the data on its network to go after their bigger-game clients, according to Brophy.

Not surprisingly, many giant and multinational corporations are hip to the trend, and they’re responding by performing tough security audits of their smaller trading partners. If they find a security risk, many decide to simply pull work from the offending business rather than risk a “break-in by association,” according to Brophy.

Small- and medium-size businesses looking to pass these hard-nosed audits—or reassure trading partners that their mutual data is safe—will need to convince trading partners that they have a hard IT perimeter. And they’ll need to show defenses against some of the newest threats looming in the coming year.

High on the list of the new and the brutal is cloud-server-snapshot software. An insidious intruder, snapshot software can infect a cloud server where a business stores its data and take a complete snapshot of all the data that’s there—including passwords, Eschelbeck said. Meanwhile, increasing numbers of hackers are also using text-messaging theft software, which is surreptitiously added to the phone of unsuspecting users. Once activated, the software forwards all text messages sent to that phone to a hacker, Eschelbeck said.

“The potential exists for attacks like these to target Internet banking services,” he said. “Many banks send authentication codes to your phone. Malware on your phone is capable of intercepting those messages.”

Sophos has also detected increasing use of “ransomware” against small- and medium-size businesses. These apps can infect both phones and computers and render the devices inoperable. Hackers inflicting the software on businesses often demand major dollars for its removal. Not surprisingly, they rarely—if ever—follow up on removal even if the business does pay the ransom, according to Eschelback.

 A Sophos employee at work neutralizing would-be hackers.
A Sophos employee at work neutralizing would-be hackers. 
  
Yet another new threat is coming from computer users with average skills who can become formidable hackers with superkit software, according to Eschelbeck. These do-it-yourself packages often offer more than a dozen state-of-the-art ways to infiltrate even the most sophisticated cyber defenses. Criminals buying the software on the black market don’t really need to know how it works; they simply need to know how to point-and-click.

Granted, businesses of all sizes should be using firewalls and other network protections to help neutralize hacker break-ins. And most businesses realize that even the most sterling of computer security defenses can be thwarted without similar vigilance at the individual-device level.

“End-user computers are the weakest spot,” said Shane Sims, director of investigations and forensic services for PriceWaterhouseCoopers. “Typically, these computers are protected only by antivirus software, and the most sophisticated hackers attack at that point.”

But dollar for dollar, the best return on an investment in computer security is employee education, according to Brophy. Take the time to educate new employees about the critical need for computer security, he said. And continually reinforce top-of-mind security with regular e-mail tips, tricks and news about IT security.

Once you have the organization sufficiently alerted, the computer security experts recommend these best practices:

Encrypt All Mobile Devices: Secure all mobile devices, including Android devices, by getting your IT department to fully encrypt the units, Eschelbeck said. Make sure all SID cards used in those devices are also encrypted. And ensure that all data and applications on the devices can be erased remotely if the mobile device is lost or stolen.

Encrypt All Cloud Data: Before cutting any deal with a cloud provider, ensure that your contract enables your company to encrypt all the data your business generates before it sends that data to the cloud, according to Ken Rashbaum, principal at Rashbaum Associates. With that safeguard, your data—and the data of your trading partners—should be impenetrable even if a hacker takes a snapshot of the cloud server that’s storing that data.

Defeat Ransomware: Ransomware programs such as Reventon, Citadel and Troj/Ransom can be neutralized by rebooting your computer with an anti-virus software program that contains its own operating system. Essentially, the tool runs your computer with its own operating system, finds the ransomware on your system and destroys it, restoring your computer, Eschelbeck said. Sophos’ solution for this problem is Sophos Bootable Anti-Virus. Unfortunately, there is still some ransomware so sophisticated that even these tools cannot defeat it, according to Eschelbeck.

Deep-Six the Superkits: While there’s no bulletproof shield against all the ravages of a superkit, there are some common-sense precautions. Be sure to install updates to all the software on your system as soon as possible, Eschelbeck said. And be sure to disable security-vulnerable software, such as Java and Flash, whenever you’re not using those programs.

Armor Passwords: Strictly forbid employees from using the same passwords at work and at home, Brophy said. Hackers are aware of this habit and regularly troll personal e-mail accounts, hoping to find passwords they can also use on employee work accounts.

Respect the Rule of 12: Prohibit the use of passwords shorter than 13 characters. The darker corners of the web are rife with programs that can auto-crack any password that is 12 characters or less. Essentially, hackers simply activate these programs on a specific e-mail account and let the program run indefinitely until the account’s password is revealed.

Joe Dysart is an Internet speaker and business consultant based in Manhattan.
For more information:
646-233-4089
joe@joedysart.com
www.joedysart.com.