Recent Blog Posts

Cybersecurity Lessons to Be Learned from the Colonial Pipeline Attack

Let?s take a few minutes to dive into the situation at hand to see what insights can be gleaned from these events. The Colonial Pipeline Situation On May 7, Colonial Pipeline first became aware of a ransomware infection in its systems, prompting the fuel supplier to pull the plug on its pipeline operations along the southeast coast so that the malware wouldn?t spread. Leaning on a relatively new form of ransomware attack, those responsible for the attack?a group called Darkside?utilized a method known as double extortion, where the cybercriminal motivates their victim to pay up by not only locking their data down but also threatening to leak it out. For its part, Darkside primarily operates as a kind of cybercriminal service provider, developing threats to provide them to other groups with their support. In response to this threat, Colonial Pipeline quickly halted its operations? and as a result, a wide portion of the country experienced gas shortages due to the cutoff of supply. Many found themselves waiting for hours at the pumps, assuming that any gasoline was available at all. Despite stating that there were no plans to pay the almost $5 million in cryptocurrency that the hackers were demanding, it has been reported that the company did ultimately do so. Once the payment was received, the distributor was provided with a very slow decryption tool that they supplemented with their own backup solutions. This situation has highlighted a few serious considerations that will need to be addressed by businesses of every size, while also revealing a few things about the current state of cybersecurity in clearly critical pieces of infrastructure. Ransomware-as-a-Service is a Serious Threat Darkside had risen to prominence in a relatively short time in the cybercriminal business world, creating a network of affiliate hackers to collaborate with for a share of the cut. With a net gain of at least $60 million in its seven months of existence ($46 million of which came in during Q1 2021 alone), this approach is apparently quite lucrative. While the affiliate hackers retain the majority of the ransom fees, Darkside handles a lot of the work on their behalf: writing the ransomware itself, billing the targeted victims, hosting the data that has been stolen, and even serving as the cybercriminal?s IT support and PR team. This is serious, simply because it can significantly lower the barrier to entry that cybercriminals face when implementing ransomware, making it a feasible attack vector for more of them to put into place. Double Extortion Makes Ransomware Even Worse You may have caught that Colonial Pipeline did, in fact, have a data backup available to them? so, it may seem confusing that they still paid the ransom to have their data released. After all, the data backup should have enabled them to simply wipe and restore their entire infrastructure from scratch. It?s the fact that this attack was using the double extortion method that makes the difference. Instead of simply threatening to delete the data if the ransom is not paid, a double extortion attack doubles down by threatening to leak the data if the ransom is not paid in time. Depending on the industry that is being targeted, some of this data could bring significant repercussions to the business that allowed it to leak. Government […]

How Will the Lessons of the Pandemic Apply to Businesses Operations?

To begin, let?s review how businesses saw their situations change when circumstances demanded them to adapt? and how they have done so. What COVID Did to Businesses As much should be obvious, but COVID-19 wreaked havoc on businesses, causing many to close and others to struggle to continue their operations. Compounding upon this, universal complications arose in many industries due to the struggles felt by others?particularly due to the issues felt amongst production, shipping, and retail establishments. Sudden panic buying and the unexpected nature of this catastrophe led to many retailers struggling to keep up with demand, with shortages popping up in various goods including toilet paper, canned goods, computer chips, and most pressingly, medical equipment and sanitizing products. In addition to this, there were also the operational changes that other types of businesses faced. Some of these changes were due to the difficulty in procuring the supplies needed to operate, while others were brought about due to widespread social distancing measures and a lack of remote work capabilities.  As their on-premise doors were closed, some businesses were forced to lock up for good, as the strain that so many sudden changes imposed was too much for them to adapt to. Others, many of which had already implemented many of the technologies that helped facilitate these changes, found the sudden transition much easier. While there were certainly still some growing pains, many businesses were able to regain their stride while still adhering to the restrictions that precautionary health measures inherently placed on them. Hopefully, once this crisis passes, these businesses and industries will be able to preserve some of these advanced processes and adjusted workflows by continuing their use of the cloud. Indeed, with 47 percent of surveyed businesses responding that they expected to invest more in the cloud in the future, this seems like a likely prospect. Is Your Company Prepared for a More Cloud-Based Work Environment? Cloud solutions and services supply businesses with a considerable list of advantages. You can find a better path to these advantages with help from White Mountain IT Services. Our team is here to consult you and assist you in your implementation of today?s most useful business solutions and technologies. Learn more about what we can do for you by calling (603) 889-0800.

Productivity Apps Aren?t Just a Fad

Productivity in Software Productivity software isn?t a flashy item. Every business needs certain apps to do business and most businesses need the same apps. There are a lot of options to choose from, and many of the options might seem pretty similar. What?s important is that you get the tools your business needs.  Productivity software, which is generally made up of a word processor, a spreadsheet program, a presentation software, note-taking software, and other useful task management tools, isn?t much different from one to another. What is different?and makes a difference?is how the apps are deployed and how they are managed by the developer. It?s fair to say that you get what you pay for, and some productivity apps are just stronger than others.  What Should You Look For? When trying to sort out which productivity apps to use, you obviously will want to consult your budget and your needs. As we mentioned above, most word processors are going to do the job you?d expect out of a word processor, but with more innovative solutions, you will get more options that will help your overall productivity. That?s extremely important. Let?s take a look at some variables you should consider: Reliability  If your software isn?t reliable, it isn?t worth it, period. Reliability can be measured in several ways. Is it still being developed consistently so you know it isn?t a security risk? Does it have the options you need? Is it easy to use and won?t take a long time to get the hang of? Some apps will promise you benefits that you will never see, but what you can bank on is if the applications cause you a steady stream of problems, you?ve probably made a bad choice.  Interoperability If a lot of your team is working remotely on their own computers, you may find that not everyone is going to have the same OS, the same chipset, etc. You will need any productivity app that you choose to work on several different systems. This includes mobile devices. You may think you?re getting a great deal, but if a handful of your workers are working on macOS and the software isn?t compatible with it, you?re going to be kicking yourself.  Accessibility As many people continue to work remotely, or in some type of hybrid work system, having apps that work from anywhere is extremely important. Today, a lot of options are available as Software as a Service (SaaS) offerings to help businesses avoid the expense of setting up their own cloud server or remote access tools. Either way, you need to be able to get your remote workers the tools they need to be productive. Collaboration Features Speaking of productivity, a lot of businesses are asking their people to do more. We are in unprecedented times and business decisions have to be made down to the dollar. When the productivity software your business uses has collaboration features built-in, it can make a world of difference. Workers can work in the same file, share files, and consistently stay up to date on workflows. A lot of the productivity suites available will also come with some form of project management software. This is a good way to oversee your team?s progress on a project and work right alongside them in real-time.  If […]

Maps May Soon Be Less Trustworthy Than Ever

What Are Deepfakes? Deepfakes are manipulated images or videos that have been altered to revise the truth with the assistance of artificial intelligence. The Internet is full of lighthearted examples, where a comedian?s face is changed during an interview to be replaced with the celebrity who they are impersonating, or different actors are cast in classic movies. Mobile applications that allow you to create a rough lip-synch video from a still image are growing in popularity. Of course, there are much more convincing examples of deepfake technology that we can point to. For instance: This Person Does Not Exist. This website pulls the results of a generative adversarial network trying to create the most convincing face it can possibly generate. Each time that page is refreshed, a new face pops up that looks just like a real person?despite no such person actually existing. While these applications are quite entertaining, they undermine the real risks that deepfakes pose to security. Explicit deepfakes are already being generated that depict people in assorted adult situations without their consent to be used in blackmailing schemes. Deepfakes have also been spread to manipulate political impressions and sway the tides of some elections. Unfortunately, there is an additional threat that these doctored images are now being used to support: geographic deepfakes. What is a Geographic Deepfake? Instead of manipulating someone?s face or the words they say, geographic deepfakes alter satellite imagery to manipulate our impression of the landscape and what is present. With deepfake technology as a whole improving all the time, geographic deepfakes could create some serious problems for businesses and governments alike. How a Geographic Deepfake Could be Abused Let?s run through a potential scenario for a moment, just to illustrate how serious this threat is: A platoon of soldiers are out in the field, advancing on a target. All they need to do is reach a bridge that will take them to their objective. Satellite imaging shows a clear path to the bridge, but once the platoon reaches it, they actually find themselves face-to-face with the enemy, who has taken the bridge and created an ambush for them to walk right into?or perhaps they find no enemy troops, but also no bridge for them to cross? ruining their plan, and possibly many others that were contingent upon it. This latter possibility was actually proposed in 2019 by a National Geospatial-Intelligence Agency analyst named Todd Myers, as it draws from a tactic as old as cartography itself. Maps Have Always Been Manipulated History is full of times where maps have played a key role in disinformation campaigns and propaganda alike, in addition to providing a form of copyright protection for cartographers. By changing some details of a map?occasionally making up features and towns that didn?t actually exist there?a mapmaker could easily identify if their work had been copied. Geographic deepfakes could simply add an additional level of complexity to such efforts, as the University of Washington recently explored in an academic study. In this study, the researchers abbreviate the very long history of map manipulation and embellishment, starting from the Babylonian 5th century B.C. but focusing much more closely on the modern applications. Things like location spoofing and how they?re weaponized were covered, with practical examples provided by the researchers that they generated as […]

Need a Reason to Invest in RMM? Here’s Four

Remote Monitoring and Maintenance (RMM)? In managed services, there is a rule. If you can do something remotely, you should. This is exactly the opportunity that the RMM capabilities provide us. We are able to remotely monitor and manage all aspects of a business? IT infrastructure and network. How does this benefit them? It?s simple. With the RMM, we can detect inconsistencies in the components of the hardware and software on the network. For most of the issues, we can use the RMM to fix them so any issue we detect doesn’t have the chance to become an operational problem.  Let?s go through some of the benefits that come with using RMM to manage your business? IT infrastructure.  RMM is Proactive The idea of being proactive in any regard is to mitigate the risks that could interfere with progress down the line. In the case of using an RMM for managed services, we look to fix all the issues on your network, and you would be surprised how many there can be, before they can kill productivity. Getting out in front of any issue is the key to keeping it from negatively affecting your business.  Minimized Downtime The dreaded downtime is one of the worst things for a business. Depending on how bad a downtime event gets, your business could be dealing with a lot of lost revenue and a halt to productivity. With our remote monitoring and management service we can ensure that if a problem can be handled before it causes downtime, it will be.  Improved Security RMM can help keep your business out of the line of fire of many problematic threats. One of the primary reasons that cyberattacks can get to be so severe is that they have time to fester and deploy payloads if they are not detected in time.  Streamlined Cost of Ownership Technology is expensive, and that is kind of an overstatement. If you can avoid having to buy new hardware with constant proactive maintenance in place, you will get more out of your existing technology. If you can control hardware and other technology costs, you will, and with RMM it is a good way to do so.  If you would like to talk to one of our consultants about getting a RMM service in place at your business and be able to proactively keep your technology running smoothly now and in the future, give us a call today at (603) 889-0800.