Don't let your business become the next Colonial Pipeline.

If your inbox looks anything like ours it is full of news about the recent cyber attack which ransacked the Colonial Pipeline. In case you did not hear about it (in which case you live under a rock) here's a little recap of what occurred:

A U.S. drinking water treatment facility's cybersecurity was challenged when an unidentified cyber actor that gained access to the facility's supervisory control and data acquisition system. The actors were most likely accessed by finding soft spots in the treatment plants security system, such as weak password security and an outdated operating system.  Several government organizations, including the FBI, Cybersecurity and Infrastructure Security Agency (CISA), Environmental Protection Agency (EPA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC), have seen first-hand the cybersecurity criminals targeting and exploiting computer software on operating systems with end-of-life status to gain access to systems that they're not authorized to use. Click here to learn more about how you can protect your business from these criminals. 

Here are our top ten security recommendations so you can ensure that your business doesn’t become the next victim:

  1. - Use multiple-factor authentication.
  2. - Update to the latest version of the operating system (e.g., Windows 10).
  3. - Use strong passwords to protect Remote Desktop Protocol (RDP) credentials.
  4. - Ensure anti-virus, spam filters, and firewalls are up to date, properly configured, and secure.
  5. - Audit network configurations and isolate computer systems that cannot be updated.
  6. - Audit your network for systems using RDP, closing unused RDP ports, applying multiple-factor authentication wherever possible, and logging RDP login attempts.
  7. - Audit logs for all remote connection protocols.
  8. - Train users to identify and report attempts at social engineering.
  9. - Identify and suspend access of users exhibiting unusual activity.
  10. - Utilize the ‘Block and Allow’ list which enables a user to control which other organizational users of TeamViewer may request access to the system.
  11.  

Check out our Cybersecurity Awareness Training Webinar for more info.

*Source: https://us-cert.cisa.gov/ncas/alerts/aa21-042a

Popular posts from this blog

Microsoft Teams vs Zoom --- Which one to use during Quarantine?

The Covid-19 pandemic has led many people to stay in and work from home. We now have the liberty of choosing between several web and app-based video conferencing platforms to connect with our friends, family, and work colleagues. We all know how confusing it can be when deciding on which specific platform to use to best fit our needs as every platform has its own features and limitations. 

Breakout Rooms are coming to Microsoft Teams

Microsoft just announced its newest release... and breakout rooms are coming to Teams!! Breakout rooms allow meeting organizers to split main meetings into smaller sessions for focused discussions.