The loss of sensitive data can cost a business millions of dollars and severely ...
Many organizations do not want to pay for a full-time CISO or do not know if they are ready...
Cybersecurity governance provides a strategic view of how your organization controls...
The Cybersecurity Risk & Maturity Assessment (CSMA) is a gap analysis and risk assessment...
A vulnerability assessment systematically reviews security weaknesses in IT ecosystems...
A penetration test, or pen test, actively identifies, tests, and highlights your organization’s...
Social engineering is the act of exploiting human weaknesses to gain access to...
With the growing threat of cyberattacks and data breaches—and the potential costs...
At any time, your organization might be running hundreds of security controls...
Is your manufacturing business prepared for CMMC compliance? Learn what CMMC compliance is...
At Right Hand, we understand what it takes for companies doing work within a defense industry ...
The National Institute of Standards and Technology (NIST), a division of the U.S. Department...
SOC is a suite of reports from the American Institute of Certified Public Accountants (AICPA)...
PCI DSS designs a set of security standards to ensure that all companies accepting...
ISO 27001 is a set of standards and requirements for an information security management...
Is your IT team stretched to the breaking point supporting your business? Have you had...
Is your in-house IT staff overworked and overburdened managing routine tasks? Do you have...
Our Help Desk Services provide businesses with fast, professional IT care at an affordable...
Cloud computing is transforming the way organizations buy and consume software...
Is your current IT strategy prepared for the threats that your organization faces every day? From human...
We are experts in supporting manufacturing companies with their cybersecurity posture and compliance needs such as CMMC so they can win DoD contracts!
You may have found that as your practice has grown, IT maintenance, security, and repair...
A better approach to IT support for law firms is known as Managed IT Services...
Cloud computing is transforming the way organization buy and consume software...
Is your current IT strategy prepared for the threats that your organization faces every day? From human..
The loss of sensitive data can cost a business millions of dollars and severely ...
Many organizations do not want to pay for a full-time CISO or do not know if they are ready...
Cybersecurity governance provides a strategic view of how your organization controls...
The Cybersecurity Risk & Maturity Assessment (CSMA) is a gap analysis and risk assessment...
A vulnerability assessment systematically reviews security weaknesses in IT ecosystems...
A penetration test, or pen test, actively identifies, tests, and highlights your organization’s...
Social engineering is the act of exploiting human weaknesses to gain access to...
With the growing threat of cyberattacks and data breaches—and the potential costs...
At any time, your organization might be running hundreds of security controls...
Is your manufacturing business prepared for CMMC compliance? Learn what CMMC compliance is...
At Right Hand, we understand what it takes for companies doing work within a defense industry ...
The National Institute of Standards and Technology (NIST), a division of the U.S. Department...
SOC is a suite of reports from the American Institute of Certified Public Accountants (AICPA)...
PCI DSS designs a set of security standards to ensure that all companies accepting...
ISO 27001 is a set of standards and requirements for an information security management...
Is your IT team stretched to the breaking point supporting your business? Have you had...
Is your in-house IT staff overworked and overburdened managing routine tasks? Do you have...
Our Help Desk Services provide businesses with fast, professional IT care at an affordable...
Cloud computing is transforming the way organizations buy and consume software...
Is your current IT strategy prepared for the threats that your organization faces every day? From human...
We are experts in supporting manufacturing companies with their cybersecurity posture and compliance needs such as CMMC so they can win DoD contracts!
You may have found that as your practice has grown, IT maintenance, security, and repair...
A better approach to IT support for law firms is known as Managed IT Services...
Cloud computing is transforming the way organization buy and consume software...
Is your current IT strategy prepared for the threats that your organization faces every day? From human..
If you have not heard about the Meltdown and Spectre vulnerabilities announced late last week, you must have been off the grid. Welcome Back!
The media was having a field day with this story, considered one of the most significant security vulnerabilities in history. If you are like me, you probably immediately start asking, “What does this really mean to me?” In our case, we are asking, “What does this means for our clients?”
It is true that Meltdown/Spectre is a massive vulnerability. Several things make this such a big story. Here are a few of them.
How can this be used against me? The nitty gritty of it is that this hardware vulnerability allows unauthorized applications to read data out of your computer’s memory. Everything you run, type, or click on your computer goes through the memory. This includes passwords, bank account numbers, emails, and other confidential information. With this vulnerability, there is the potential for a malicious program to read that data.
While all of this truthfully sounds very scary, the reality is that if you are utilizing the appropriate layers of security within your business the chances that this will affect you is highly unlikely.
First, in order to exploit this vulnerability, a malicious user needs to run software on your computer. Hopefully, you are only running software that you authorized and know is legitimate.
Do not take this statement lightly. Hackers get people to run software every day on their computers. I am sure we all know someone that has been affected by ransomware or another malware on a computer system. Perhaps you have been affected by it yourself.
How did that situation happen? More than likely it came from a phishing email or a phony website. Hackers are getting better and better at social engineering (the art of tricking people into doing what you want them to), so you need to have training, awareness, and testing in place to get your employees knowing what to look for to avoid these costly mistakes. This is one layer of security.
Another layer to protect against phishing emails is spam filtering. While it is not 100%, it does reduce the chance that phishing emails make it to your inbox. When you couple this with the knowledge that comes from good training, you have drastically reduced your chances of becoming a victim.
So now you know a little about this vulnerability and how to protect yourself. But you shouldn’t be left on your own. What are Microsoft and other Information Technology vendors doing about this? The answer is quite a bit. Once these vulnerabilities are discovered, patch updates get created to fix the vulnerability. Microsoft has or will issue a patch that mitigates the risk. The vulnerability still exists at the hardware layer, but Microsoft can fix the way software is allowed to interact with the hardware. When Microsoft puts patches out for major security vulnerabilities similar to this one, you need to have a way to easily deploy those patches and verify that they installed properly. This is another layer of security that will help protect your business.
Is there anything more you can do? Additional security layers such as anti-virus, anti-malware, and firewalls can come into play to protect you as well. When a major vulnerability like this is discovered, these manufacturers jump into action looking for software that exhibits the behavior described in the report. When their products see this behavior, they can shut down and quarantine the software. Advanced Endpoint Software is an option that can really give you some robust protection. Most anti-virus programs run off “definitions” which are just lists of viruses that are already known. With the ever-evolving virus landscape – hundreds of thousands of new variants every day – you need more than just definitions. You need protection that acts as a profiler – analyzing the behavior of everything running on your computer. Advanced endpoint protection will give you this. With this layer in place, if you happen to fall for a phishing email, the advanced endpoint protection will recognize it and kill it.
These are just a few of the basics when it comes to protecting yourself against vulnerabilities like Meltdown or Sceptre from being exploited on your computer. When it comes to other viruses like ransomware, you may want another highly critical layer in place – good backups. Good backups are your failsafe. If malware makes it past your other security protections to encrypt, destroy, or steal your critical business data, a good backup system in place can quickly undo all that damage.
If you are unsure if you are doing everything you can to protect your network, your partners at Right Hand are here to help. Give us a call at 412-254-4448 to discuss!
Explore comprehensive phishing prevention strategies for financial institutions, including the FS-ISAC framework, employee education,…
Explore Shadow IT risks and benefits, and learn how consistent MSP support can help…
Navigate CMMC compliance complexity with our master guide. Explore key documents like SSP and…
The Certified Information Systems Security Professional is an information security certification with extremely high standards. Less than 132,000 people worldwide had this certification at the end of 2018.
It has also been formally approved by the DOD and is globally recognized in the field of IT security.
It covers the following topics:
Security and Risk Management
Asset Security
Security Architecture and Engineering
Communication and Network Security
Identity and Access Management (IAM)
Security Assessment and Testing
Security Operations
Software Development Security
This a system engineer certification and tests the user’s knowledge on the following topics:
Windows
SQL Server
Exchange Server
SharePoint
System Center (SCCM)
Lync
The A+ Certification demonstrates that the computer technician has the skill set needed to customize, install, maintain, and operate PCs.
In addition to these certifications, Right Hand also has strategic partnerships with some of the biggest names in the industry like Microsoft, Dell, Citrix, and Fortinet.
What could be more assuring than having these industry giants on your side?
As the name suggests, this certification is for Network Engineers. Everything from the installation and maintenance to troubleshooting of networks including the understanding of all related technologies is a part of the course.
This certification shows that the technician who has passed the Microsoft exam is capable of managing, migrating, deploying, planning, and assessing the technology, security, and compliance needs associated with Microsoft Office 365.
The CompTIA Security Plus SY0-501 course provides certifications in the following topics:
Threats
Vulnerabilities
Attacks
System Security
Network Infrastructure
Access Control
Cryptography
Risk Management
Organizational Security