Blog

May 16th, 2012

Everywhere you look business owners are inundated by issues pulling their attention in a multitude of directions. One issue almost every owner has managed to get under control is network security. These businesses are secure from external threats and because of this, believe their systems to be 100% safe, however, they may have missed the possibility of internal threats.

In recent years the majority of security threats and compromises have come from within the company. A common threat to companies is the logic bomb - malware that targets IT systems and deletes data. As a logic bomb is introduced from within the network, the blame often lies with a disgruntled employee with full access to internal systems.

Insider threats Giving employees full access to the network when they don’t need it is a common mistake often made by companies. There’s little need for an employee who does graphic design to have access to weekly sales records. This practice could set your company up for a considerable security problem in the future.

Dawn Cappelli, an insider-threat expert at the Carnegie Mellon Software Engineering Institute stressed, "These types of insider attacks happen to businesses of all sizes, from small companies to very large corporations." This is an important issue businesses should be aware of if they want to remain secure.

Take Precautions Security threats can be a particularly harsh nightmare for small businesses, as many don’t have an IT department or staff with the technical expertise needed to maintain a secure network. If you’re one of these organizations, it’s a good idea to hire an outside consultant to help you with your network security. With consultants, it’s important that you maintain close contact with them to ensure any issues that crop up are dealt with expeditiously.

If you don’t work with an external company there are a few things you should do when you have an employee leave the company. First, their accounts should be deleted immediately and their access privileges should also be revoked. Second, if you have accounts with shared passwords, you should change them to ensure an ex-employee can’t gain access to the system.

If you’d like to learn more about internal security, and measures you can take to ensure you are safe, we are ready to help you. Please contact us.

Published with permission from TechAdvisory.org. Source.

May 16th, 2012

Respect him or not, Mao Tse-tung had it right when he said, “The only real defense is an active defense.” Businesses have taken this literally and have adopted Business Continuity Plans (BCP) to ensure that when a disaster strikes they are ready with an active plan. Many of them are prepared technology wise, but the other assets may not be so ready.

Here are six key non-IT functions and processes that need to be in place to ensure your company is ready to effectively execute your BCP.

Easy to use plans Many continuity plans have been developed mainly for the IT department, as such, they can be a little complicated to understand and follow if employees don’t have a technical background. You should aim to have a plan that’s easy to follow and can be understood by all employees.

Communicate plans Remember that your plan encompasses all facets of your organization. It’s crucial that every employee knows their role and the relevant actions to take when the plan is executed. To do this, you need to ensure that all employees have access to a copy of the plan and any changes or updates are clearly communicated.

Test plans Beyond communication, it’s important to conduct regular tests, with every quarter being sufficient. The tests should be as real as possible and span all departments within the organization. This will ensure that employees are aware of how they, and the systems, will react under duress. It’ll be beneficial to your business if the first time the employees execute the plan isn’t during an emergency.

Short term and long term plans Your BCP should consist of both long term and short term elements that can be easily adapted to meet changing business environments and the emergence of new threats. You should aim for an even mix of short and long term solutions that cover as wide a variety of situations as possible.

Ensure buy-in from all levels If you’re in the process of instituting a BCP you should ensure that the whole organization is onboard with the plan. If an employee is unsure about the validity of a part of the plan, take the time to find out why and ask for suggestions. An uninformed or uncooperative employee could be the difference between survival and failure in a disaster situation.

Update and Review After every test, staff turnover and technological update, you should review the plans and make changes if necessary. Essentially, if anything in the company changes, review and update the plan. Remember: just because you have an effective plan this month, doesn’t mean it’ll be so in the future.

Continuity plans are only as strong as the weakest link. In an emergency, the last thing you want is an employee following the wrong process or be unsure of what they should be doing. If this happens, you could see an exponential growth in recovery time and costs. We’re ready to tell you more, so please contact us if you would like to talk continuity planning.

Published with permission from TechAdvisory.org. Source.

May 9th, 2012

One issue that’s sparked a large amount of debate is whether or not companies should allow their employees to access social media while at work. One thing's for certain, the number of employees who actually use social media on a regular basis is large, and growing. There will come a time when companies that block social media can no longer afford to do so.

There are four distinct advantages to allowing social media:

  • Increased productivity. There have been a number of studies that have found that judicious use of social media in the workplace will actually increase productivity. A study conducted by the University of Melbourne found that employees with access to social media are 9% more productive than those without.
  • Increased buy-in. Employees like to feel trusted and empowered. If they don’t you can expect to experience higher turnover and lower morale. A good way to gain trust is to allow employees to use social media in the workplace. If an employee feels like they are trusted, they’ll be more likely to stay with the company.
  • Recruiting. Small businesses have started to use social media for recruitment, but limit efforts to one account. If you have 10 employees in your organization, each with a social media account with 100 friends, you have the potential to reach 1,000 people. This is achievable if employees are allowed to access social media at work and are encouraged to share posts.
  • Identification of business opportunities. Through the use of social media, employees in charge of sales and business development can source new clients and build fruitful relationships.
There are many advantages to allowing access to social networks at the office. If you‘re hesitant to completely open the social media floodgates, try doing so in short periods, like the final three hours of the working day.

No matter what you decide, allowing access to social media is a good practice for your business. If you would like to learn more about social media and how you can leverage it in your business, we are happy to talk with you.

Published with permission from TechAdvisory.org. Source.

May 4th, 2012

Macs running OS X are often touted as the most secure machines. While OS X is definitely more secure than other operating systems, it may not be as secure as owners think. A new trojan that takes advantage of a security flaw in OS X has been discovered, and it’s a doozy. This has the potential to be a security nightmare.

If you mention “OS X” and “virus” in the same sentence, you’ll get some weird looks from Mac users. Traditionally viruses and trojans on OS X were near non-existent, but there’s a Mac specific trojan, codenamed Flashback, that has affected more than 600,000 computers. This is big news as it shows that machines running OS X may not be as secure as first thought.

Many Mac owners are unsure of what exactly the Flashback trojan is, what it does and how to ensure they’re not infected. We’re here to help clarify the situation.

What is a Trojan and What Does Flashback Do? In general terms, a trojan is a piece of malicious software that infects a computer and gives control of part, or the whole computer to hackers. The Flashback trojan takes advantage of an OS X Java vulnerability and infects computers by tricking them into downloading a fake Java update.

When the program is installed, Flashback will download and install the main trojan code without the need for permission from the administrator. From there it proceeds to hijack your browser, redirect search queries to websites developed by hackers, and then take advantage of pay-per-click advertising.

Why Should I be Worried? While this version hijacks your browser, there are far more sinister things it could do. As this trojan acts as a downloader, there’s nothing stopping the developers from updating the malware to steal passwords, banking information and other confidential information.

How do I Ensure My Mac is Clean? Apple has released an update for machines running OS X 10.6 and later. The first step you should take is to update your computer to patch the vulnerability. To update your Mac:

  1. Press the Apple logo, located in the top right hand of your screen.
  2. Select Software Update...
  3. Press Install and Restart.
While the patch will prevent Flashback from working, it won’t delete the program if you’ve been infected. The Internet security company F-Secure has developed a script that scans your computer and removes Flashback if found. Once you have downloaded the script, open and run it. The script will search your computer and place the infected files in an encrypted ZIP folder labeled Flashback_quarantine.zip.

Flashback has infected a higher number of Macs than any other trojan to date and goes to show that Macs also have security flaws. This also serves as a reminder that you should have a virus scanner and security program running on your Mac. If you have any questions regarding the security of your Mac or other devices, please don’t hesitate to contact us. We are here to help keep your machines secure.

Published with permission from TechAdvisory.org. Source.

May 4th, 2012

With the multitude of devices at our disposal we have become a society of interconnectedness, and have seen once clear divisions of work and personal life blend into one. This has created an international society of workers who are experts at balancing a number of tasks, while never really being able to focus on one task. There are just too many factors pulling our attention in multiple directions.

It’s time to reclaim our focus at work and here are seven tips to help you do so.

  1. Practice productivity wind-sprints. While at work, we’re normally doing work while browsing Facebook or chatting. This can be harmful for productivity and shifts your focus from important work related activities. Interval training is a great way to increase your focus. Get a timer, set it for ten minutes, and focus solely on your work. When the timer goes off take a two minute break.
  2. Defensive scheduling. Our days are filled with commitments and we struggle to keep up with our projects or find time to work uninterrupted. Schedule a meeting with yourself at a convenient time. Treat this meeting like a real meeting, no interruptions. This is your time to focus on important tasks or projects.
  3. Socialize with your tablet. Separate work from social activities with a tablet. We’re often just hitting our stride with work when BING, we get a chat message. What do we do? Immediately reply to the message. When we do that we lose our focus and struggle to regain it. Why not use use your tablet for all social activities and work computer strictly for work? Combined with tip one, this could really help you focus.
  4. Realize your unconscious focus. The vast majority of managers often aren’t sure what the top issue in their mind is. It comes with multitasking, we’re always making less important ideas critical, and this takes our focus off the most important issues. To realign your focus take some time, let your mind wander, and make note of the ideas you keep returning to. These are your most critical issues.
  5. Focus on most important tasks first. When you get into the office in the morning switch off your phone and email alerts. Focus on your most important priorities, this will give you time to get your most important work out of the way, before you shift your focus onto other less important projects.
  6. Disconnect. Many of us don’t take time to give our brains a rest, we’re always thinking and possibly worrying about work. It’s beneficial to your mental and physical health if you take time each day to disconnect from the office. Temporarily sever all ties with the office and focus on something you enjoy doing. Remember, this is your time don’t think of work, focus on the activity.
  7. Can’t focus? Consider if what you’re doing is right for you. If you find that you really can’t focus, even with the previous techniques, it might be time to consider that what you’re doing is actually something you don’t care about or enjoy. If this is true for you, then it’s time to start looking for a change.
With these tips you should see an increase in your focus and productivity. If you would like to know more about how to improve your productivity please contact us, we can help.
Published with permission from TechAdvisory.org. Source.

April 12th, 2012

One issue that’s gaining steam, especially with SMEs, is business continuity planning. Many companies are starting to develop plans so that they can continue to operate through both problems large and small. If you’re one such company, and are stuck at the point where you need to choose between software and templates, we have some advice for you.

The decision between templates and software can be a tough one to make, as whichever one you choose, you’ll be using and relying on for a long time. To help you we’ve covered some pros and cons on both choices:

Using Software If you choose to go with a software program, you will be walked through the whole process allowing you to develop a useable plan. Another benefit of using software is that you’ll be able to develop reports if needs be.

The drawbacks of using software include cost, inflexibility and learning time. For the most part, business continuity planning software is not cheap, and at times can be inflexible due to limits within the program. If you have a niche need, the software may not cover it. In addition, as with mastering any program, the learning curve can be quite steep.

In general, using software would be advantageous for companies that have a bigger budget for the development of a continuity plan. Software is also a good bet if you don’t have staff who are experts in continuity planning, or if you operate in an industry where a continuity plan is necessary, e.g., companies working with healthcare insurance, or manufacturing companies that have introduced ISO 9000.

Using Templates If you feel that your company is not ready for software you can use templates to help you develop your plan. These solutions are mostly written plans that you adapt to meet your business needs. They’re useful if you’re just starting to do continuity planning, as they provide a normally solid foundation, and are generally a lot cheaper than software.

A limitation to using templates is that they can be a little too basic at times, and may not meet your needs. Granted, most plans will follow a basic structure and your developer will need to adapt some steps for your relevant region and industry.

As each industry is different, it’s hard to make a recommendation on what type of planning style companies should take. We recommend you take your time, do your due diligence and weigh out what’s best for your business. No matter which method you choose to go ahead with, ensure that it’s easy to implement, and that you’ll be able to teach your staff how to run the plan.

If you feel really lost or are not sure what to do, talking to professional consultants could go a long way in helping you develop a plan. If you’d like to learn more about business continuity planning please contact us - we are happy to help.

Published with permission from TechAdvisory.org. Source.

April 11th, 2012

Does your company use cloud storage services or peer-to-peer (P2P) networks for the storage and sharing of data? Many businesses are now using both these services in an effort to make work less complicated. But did you know that there are potential issues in relation to recoverability and security of data?

With the seizure of a number of cloud storage and sharing websites, including Megaupload, and the seemingly omnipresent malware in P2P files and the shaky security in relation to P2P networks, businesses have had their hands full staying secure. Do you know what your options are when it comes to data security?

Cloud Services Knowhow The recent seizure of Megaupload’s files and servers by the US Government caught many people and businesses unprepared. While Megaupload’s main purpose was file sharing, it was found that a large number of organizations were using their services to store files. If you had files stored on Megaupload, the chances of getting the files back are non-existent.

It needs to be pointed out that many cloud services don’t guarantee that files stored on the service will be recoverable in the event of a crash, or disruption in service, e.g., a government seizing servers. If you read the user agreements of a number of major cloud services, they all have clauses stating that if data stored on their service is lost for any reason, it’s gone forever, and the hosts can’t be held liable for losses.

Risks of P2P With high speed Internet widely available at low prices, P2P file sharing has become incredibly popular, it’s almost uncommon to find someone who has never used a P2P service. If you or your employees use P2P at your office, there are a number of potential security threats you should be aware of:

  • The unknown share: If you put a file in a folder that is shared on a P2P network, it’ll be shared with all other people connected to that folder and almost anyone can access it. This is normally done by mistake, i.e., not looking where the file will be saved when you save it. There’s also malware out there that will move files into a shared folder which the developer of the malware can find and upload with ease and without the user knowing it is happening.
  • Open network: Typically P2P works on open networks: users give and share. What this means is that when using P2P on a poorly configured network, the whole network could be unsecure, allowing for access to other computers connected to the network.
  • Untracked data: If you share a document with another person, and they then share it with others, there is potentially, an unlimited amount of people that can get the data. If you want to take it back, it can be impossible to do so, even if the original document is deleted.
  • Storage hijacking: There’s news of malware that has been developed with the purpose of downloading illegal material onto your hard drive. This could pose a problem if the data is found, as you will be liable.
What Should I do? With regards to cloud services, as with anything that comes with a contract, the first thing you should do is gain an understanding of it by utilizing reading material such as blogs, news articles and Wikis. It’s a pain in the neck, but it’ll help you understand the boundaries of the program and your responsibilities. Remember that if you go to court to get files back from a company, and it becomes known that you didn’t read the agreement, you’ll probably end up losing that case.

Second, it’s not recommended to keep single copies of data on one cloud service. Chances are high that in your business, you store your data and backups in a place separate from the computer. This makes sense with the cloud as well - keep your data with a number of different cloud services. If it’s important enough, have physical backups of what you put in the cloud.

For P2P networks there are also a number of steps you can take to protect the data on your network:

  • The most obvious one is to ban employees from using any file sharing services outside of your network.
  • If you do allow file sharing, it’s a good idea to establish and strictly enforce a protocol for this. You should also set which users are allowed to share files, and what files are appropriate to share. Be sure that all staff are aware of your policy and the measures that will be taken in the event of any deviations.
  • Develop a system to classify documents by whether or not they can be shared, and who they can be shared with.
  • If you work in an office where you need to share files, but don’t want to use a P2P network or the cloud, and are unsure of other solutions out there, don’t worry. There are companies that specialize in document sharing solutions that should be able to provide you with assistance.
The most important thing is that whatever the situation is, you take action to try to solve the problem while frequently revisiting the actions to ensure that they are working. If you’d like to learn more about document sharing over the cloud, or via P2P networks, give us a buzz. We’re more than happy to help.
Published with permission from TechAdvisory.org. Source.

April 9th, 2012

In many businesses, including yours, a good presentation can be the difference between success and failure. The majority of your employees have a degree of competence and comfort while creating presentations. The key questions are: do they reach the target audience, and are they effective? Unfortunately, the majority of the time the answer is no.

It’s important that you, that as a manager, you ensure that your employees are creating PowerPoint presentations that are effective. Here are a few tips you can give to your employees to help them improve their presentations.

Simplify and minimize The best presentations are simple and minimal, often shifting focus from the presentation to the presenter. Minimal presentations follow the 6-6-6 rule. There should be no more than: 6 bullet points per slide, 6 words per bullet and 6 slides full of words in a row. Being visual creatures, you should encourage your employees to create slides with engaging and related visuals. A caveat: be sure that you have the rights to use the images.

A great rule taught in business schools across the country is: KISS (Keep It Simple, Stupid). Refrain from using confusing words, jargon, uncommon acronyms and irrelevant information. Keep it short, sweet, and to the point. Following these rules will help engage the audience and hold their attention for a longer period of time.

Be consistent “Consistency is key” - a saying often used but rarely followed in the creation of PowerPoint presentations. You should ensure that grammar and spelling are all consistent, and errors are minimal, if existent at all. Have another employee or manager review it for errors and inconsistencies.

For the slides, use the same background and font throughout. The easiest way to ensure this is by using a template. A word of warning: don’t use templates that are heavily animated because they can cause significant distractions, and don’t choose backgrounds that are similar in color to your font. The best slides have a light color for a background with a darker font for your text.

Summarize The goal of most presentations is to build interest and inform or update the audience. In fact, the majority of audiences just want a short summary so they can develop their own questions to ask after the presentation, or at a later meeting.

When creating the presentation, be sure to keep the audience in mind. If a presentation is being made to IT managers, chances are it does not need to have advanced financial spreadsheets. If you are presenting on a topic that has lots of graphs, extra information, or appendices, put the most important information in the presentation and the rest in a handout. This will keep the audience’s attention on the presenter, not the slides.

Practice, preview, review Practice makes perfect. In an ideal world there would be hours and hours to practice and tweak a presentation. Normally, that’s not true. Schedule at least a comparable amount of time the day before a presentation for a dry run. Always review the presentation with your team and ask them for feedback. This will help encourage employees to keep improving and developing themselves.

For more tips and tricks on giving presentations using Microsoft PowerPoint and other Microsoft products, please contact us.

Published with permission from TechAdvisory.org. Source.

March 29th, 2012

Most businesses have started to take social media seriously. They are spending time and effort developing their profiles and reaching out to customers. It makes sense for a business to have an online presence beyond their website. Are you taking advantage of all the available options the Internet has to offer? If not, it may be time to start.

Social media, once called a fad, has become the norm and is going to be with us for some time. A large number of companies already have an online presence, and are taking advantage of the benefits that social media can bring. Here are a number of things you can do to get your social media adventures underway.

Be Clear on Social Media It’s important that before you start looking into the different forms of social media that are out there, you are clear on what social media is, and what it isn’t. Social media is a way to meet people, and share content and ideas with them. For companies it’s a form of non-traditional marketing - think of it as soft marketing - it’s not meant to be the place where you flog your products, rather a place to develop interest in your company, so people will want to do business with you. By using social media you can show people who your company is, and connect with them on a more personal level. If you are clear on what social media is from the beginning, there’s a higher chance that you’ll be successful when you develop your online presence.

Before You Launch Into Social Media There are a number of things that your company needs to have either already done, or considered, before you jump in:

  • Have a website: It’s a good idea to have a solid website with information about your company, contact information, products and services. Most potential customers will look at your website after looking searching for you online, and before they choose to do business with you, so your website needs to provide the relevant information they are looking for. If you don’t have a website, or feel yours is lacking, it’s easier than ever to get a professional looking site. With a quick search you will be able to find some competent designers.
  • Get educated: It will be beneficial to educate yourself on current trends regarding social media. This can be done by simply going to social media websites, taking the free introduction tours and reading blogs related to the sites. Beyond that you should also research your competitors’ websites and Internet presence. Observe what content they have online, and more importantly: what they don’t have. It will also help to connect with and observe industry experts, see what they post online, and note the style and tone they use. This will help provide you with a sound knowledge base from which you can then create a more effective online presence.
  • Set goals: As with any step in business, you should have a plan with realistic goals. Aim for results that are achievable for your company. If you’re a small, local IT company that focuses on providing support for banks, don’t expect to have the same massive hype that Microsoft and Apple do. Clearly set objectives and review periodically.
  • Develop a focus: In real life, you can’t be all things to all people. The same goes for social media. You need to develop a focus on what type of online content you would like to share. You should aim to create content that your customers will want to share with people.
  • Stake a claim: You should to go to the main social media websites - Google+, Facebook, LinkedIn and YouTube - and reserve your personal and business usernames. This is important because it will make you look more professional by having the same username across all sites, and users will be able to find you easier.
  • Ask for help if you need it: While some companies make social media sound easy, it can be deceptively hard to master. If you feel lost, or are having a tough time with it, there are knowledgeable consultants out there who are happy to help.
Time to Get Social When you feel you know what direction you will take, it’s time to start developing your online profiles. It can be tough to decide which social media tools to utilize. Unfortunately there is no right answer. Most small businesses follow the crowd, and this means having pages on Facebook and Linkedin. This does not mean that you should join these networks simply because they have the most users. It is recommended that you follow what similar businesses or direct competitors are doing. If they are on one service but not another, do the same to begin with, but be on the lookout for new social media sites, or features being added to existing sites.

One Thing to Not Forget There is one really important thing we can share with businesses thinking of pursuing social media: it isn’t a turnkey operation. You can’t just, “set it and forget it.” To be successful, you need to be active by posting updates, news, and above all interacting with the people who reach out to you. After all, they are your customers. If you do establish your social presence but forget to keep it up to date, you will be the company that’s forgotten.

If you would like help with your social media strategy, please get in touch with us. We’d love to hear from you.

Published with permission from TechAdvisory.org. Source.

March 27th, 2012

No matter what industry you are in, the size or location of your company, chances are high that you spend the majority of your day in front of the computer. The one major downside to this is that you could injure yourself, resulting in lost time and the need for physical therapy. Do you know what the most common computer work related injuries are and how to minimize them?

The majority of injuries sustained while working with computers are not instantaneous, they happen over time. The most common form of computer related injury is the Repetitive Strain Injury, also known as RSI. Soft tissue, muscles, tendons, nerves and ligaments are all susceptible to RSI. With proper maintenance and knowledge, almost all RSIs can be prevented. If left unchecked, an RSI could lead to lost time and possibly irreparable damage.

Eye Strain Eye strain happens when you have overexerted your eyes. The most common symptoms include:

  • pain around the eyes,
  • dry eyes,
  • fatigue,
  • photophobia (sensitivity to light) and
  • blurred vision.
Often, severe eye strain will also cause pain or tension in the neck and shoulders. The most common causes of eye strain are poor workspace layout and sub-par lighting conditions.

The good news is that in most cases, eye strain won’t lead to permanent vision complaints, but if left unchecked it could cause productivity problems. The easiest way to prevent eye strain is to work in a space with lighting that is neither too strong or weak, and have a light source that does not create glare. It is equally important to take short breaks from the monitor. Follow the 20-20-20 rule: every 20 minutes, look at something (not another monitor) 20 feet away for 20 seconds.

Posture Related There are a number of related injuries to your posture, including: back pain, neck pain and headaches. These injuries typically come from bad posture, combined with sitting for an extended amount of time. It may not seem like you can injure yourself by sitting in a chair all day, but your muscles are not designed to stay in the same position for such a long period of time, and doing so can result in muscle pain. Poor posture at work can also lead to an increased chance of a herniated disc, commonly called a “slipped disc”.

There are a number of things you can do to minimize posture related injuries.

  • Adopt a proper posture. Have a chair that pushes the small of your back (bottom) out, as this will promote a more natural spinal position. Try not to cross your feet, as comfortable as it is, as doing so puts pressure on your lower back.
  • Get up and move around every 20 minutes to half hour.
  • Stretch. Move your joints through their normal range of motion.
  • If you have kinks or muscle pain, gently massage the area with a kneading motion.
  • Get up. There is a rising trend of using a standing workstation - this could be another option.
Arm Related The most common type of injury to the arm is the well-known Carpal tunnel syndrome (CTS). This mainly happens in two places: the wrist and the elbow. CTS occurs when the median nerve (one of the main nerves) is compressed. CTS in the wrist is the most common RSI, and can be a costly injury. The median nerve also passes through the elbow. If compression occurs there, it can result in an injury commonly called “tennis elbow”. Symptoms include: numbness of the hand and arm, pain and weakness in grasping.

There are a number of things you can do to prevent CTS:

  • Keep your mouse and keyboard close together.
  • Type and hold the mouse gently.
  • Remove your hands from the mouse and keyboard when not using them.
  • Take frequent breaks to move your wrists and elbows through their natural range of motion. Be careful to not over extend.
With a combination of breaks, ergonomic workplaces, and other preventative measures you and your staff will see fewer injuries and higher productivity. If you would like to learn more ways to prevent injuries, or increase productivity please contact us.
Published with permission from TechAdvisory.org. Source.