Summary ในช่วง 2 ปีที่ผ่านมา ภัยออนไลน์ที่เกิดจากคนในองค์กรมีเพิ่มขึ้นกว่า 44% ทุกคนที่มี login สามารถเข้าระบบขององค์กรได้นับว่ามีความเสี่ยงทั้งนั้น แล้วเราควรแบ่งกลุ่ม จัดระดับคนเหล่านั้นเพื่อสร้างระบบจัดการบ้างกันภัยออนไลน์ที่เกิดจากคนในได้อย่างไร #InsiderThreats #Cybersecurity #InsiderRiskPrevention #InsiderRisk One of the most difficult types of attacks to detect are those performed by insiders. An “insider” would be anyone that has legitimate access to your company network and data. This would be via a login or other authorized connection. Ways to Mitigate Insider Threats · Thorough Background Checks · Endpoint Device Solutions · Multi-factor Authentication & Password Security · Employee Data Security Training · Network Monitoring One of the most difficult types of attacks to detect are those performed by insiders. An “insider” would be anyone that has legitimate access to your company network and data. This would be via a login or other authorized connection.Because insiders have authorized system access, they bypass certain security defenses. Such as those designed to keep intruders out. Since a logged-in user isn’t seen as an intruder, those security protections aren’t triggered.There are three troubling statistics from a recent report by Ponemon Institute They illustrate the importance of addressing this threat. Insider attacks are getting worse, taking longer to detect and becoming more extensive.The report found that over the last two years:Insider attacks have increased by 44%It takes organizations 85 days to contain an insider threat, compared to 77 days in 2020.The average cost of addressing insider threats has risen by 34%It’s important for companies to understand what makes up an insider threat. That’s the first step towards mitigation.4 Types of Insider ThreatsOne reason that insider threats can be hard to detect is that there is not just one kind. Employees, vendors, and hackers can all perpetrate insider security breaches. To further complicate detection, some may be malicious and others accidental.Here are the four main types of insider threats faced by company networks.Malicious/Disgruntled EmployeeA sales employee that is leaving the company may decide to take all their contacts with them. This is a malicious theft of company data.Another example of this type of insider attack is a disgruntled employee. They may be upset with their manager who just fired them and decide to do the business harm. They could plant ransomware or make a deal with a hacker to give over their login credentials for cash.Careless/Negligent EmployeeSome insider threats are due to lazy or untrained employees. They don’t mean to cause a data breach. But may accidentally share classified data on a non secure platform. Or they may use a friend’s computer to access their business apps. Being completely unaware of the security consequences.3rd Party with Access to Your SystemsOutsiders with access to your network are also a very real concern. Contractors, freelancers, and vendors can all constitute an insider breach risk.You need to ensure that these third parties are fully reviewed. Do this before you give them system access. You should also allow your IT partner to review them for any data security concerns.Hacker That Compromises a PasswordCompromised login credentials are one of the most dangerous types of insider threats. This has now become the #1 driver of data breaches around the world.When a cybercriminal can access an employee’s login, that criminal becomes an “insider.” Your computer system reads them as the legitimate user.Ways to Mitigate Insider ThreatsInsider threats can be difficult to detect after the fact. But if you put mitigation measures in place you can stop them in their tracks. Being proactive keeps you from suffering a costly incident. One that you may not know about for months.Here are some of the best tactics for reducing insider threat risk.Thorough Background ChecksWhen hiring new employees make sure you do a thorough background check. Malicious insiders will typically have red flags in their work history. You want to do the same with any vendors or contractors that will have access to your systems.Endpoint Device SolutionsMobile devices now make up about 60% of the endpoints in a company. But many businesses aren’t using a solution to manage device access to resources.Put an endpoint management solution in place to monitor device access. You can also use this to safelist devices and block unauthorized devices by default.Multi-factor Authentication & Password SecurityOne of the best ways to fight credential theft is through multi-factor authentication. Hackers have a hard time getting past the 2nd factor. They rarely have access to a person’s mobile device or FIDO security key.Couple this with password security. This includes things like:Requiring strong passwords in your cloud appsUsing a business password managerRequiring unique passwords for all loginsEmployee Data Security TrainingTraining can help you mitigate the risk of a breach through carelessness. Train employees on proper data handling and security policies governing sensitive information.Network MonitoringOnce someone has user access to your system, how can you catch them doing something wrong? You do this through intelligent network monitoring.Use AI-enabled threat monitoring. This allows you to detect strange behaviors as soon as they happen. For example, someone downloading a large number of files. Or someone logging in from outside the country.Need Help Putting a Stop to Insider Attacks?A layered security solution can help you mitigate all four types of insider threats. We can help you with a robust yet affordable solution. Contact us today for a free consultation. Your Title Here This is a text box. Write your own content here. This is an excellent place for you to add a paragraph. Your Title Here This is a text box. Write your own content here. This is an excellent place for you to add a paragraph.
Summary 9 วิธีรอดพ้นกลโกงมิจฉาชีพบนโลกออนไลน์ในช่วงสิ้นปี ช่วงเวลาที่แสนพิเศษ ช่างน่าหอมหวานสำหรับมิจฉาชีพ ที่คอยสร้างเมลหลอกลวงอย่างฟิชชิ่ง เว็บไซต์ปลอม และสรรหากลโกงบัตรเครดิตในรูปแบบต่างๆ มา ช คือช่วงเวลาที่มิจฉาชีพกำลังจ้องตักตวงผลประโยชน์จากเรา #HolidayShoppingTips #OnlineSecurity #ShoppingSafely The holiday shopping season is taking off. This means that scammers have also revved up their engines. And you need to beware, so you’re not scammed. Here are some critical safety tips to improve your online holiday shopping: 1. Check for Device Updates Before You Shop 2. Don’t Go to Websites from Email Links 3. Use a Wallet App Where Possible 4. Remove Any Saved Payment Cards After Checking Out 5. Make Sure the Site Uses HTTPS (Emphasis on “S”) 6. Double Check the Site URL 7. Never Shop Online When on Public Wi-Fi 8. Be On High Alert for Brand Impersonation Emails & Texts 9. Enable Banking Alerts & Check Your Account Contact us today for a security checkup. It’s The Most Vulnerable Time Of The YearThe holiday shopping season is taking off. This means that scammers have also revved up their engines. They’re primed and ready to take advantage of all those online transactions.Don’t forget to stay safe online during the buying frenzy that occurs this time of year. An ounce of cybersecurity prevention is definitely worth a pound of cure. It can also save you from a financial or privacy nightmare.Here are some of the most critical safety tips to improve your online holiday shopping.Check for Device Updates Before You ShopComputers, tablets, and smartphones that have old software are vulnerable. While you may not want to wait through a 10-minute iPhone update, it’s going to keep you more secure.Hackers often use vulnerabilities found in device operating systems. Updates install patches for known vulnerabilities, reducing your risk. Make sure to install all updates before you use your device for online holiday shopping.Don’t Go to Websites from Email LinksYes, it’s annoying to have to type in “amazon.com” rather than just clicking a link in an email. But phishing scams are at an all-time high this time of year. If you click on an email link to a malicious site, it can start an auto download of malware.It’s best to avoid clicking links, instead visit the website directly. If you want to make things easier, save sites as shopping bookmarks in your browser. This is safer than clicking a text or email link.Use a Wallet App Where PossibleIt’s always a risk when you give your debit or credit card to a website. The risk is even higher if you’re doing holiday shopping on a site you haven’t purchased from before.Where possible, buy using a wallet app or PayPal. This eliminates the need to give your payment card details directly to the merchant. Instead, you share them with the wallet app service (Apple Pay, Google Pay, PayPal, etc.). But the retailer doesn’t get them.Remove Any Saved Payment Cards After Checking OutThere are many websites (including Amazon) that automatically save your payment card details. This is bad. Yes, it may make the next buy more convenient, but it puts you at risk. A hacker with access to your device or account could make purchases.There is also the risk of a data breach of the retailer. These are common and can leak sensitive customer payment information. The fewer databases you allow to store your payment details, the better for your security.Immediately after you check out, remove your payment card from the site. You will usually need to go to your account settings to do this.Make Sure the Site Uses HTTPS (Emphasis on “S”)HTTPS has largely become the standard for websites now. This is instead of “HTTP” without the “S” on the end. HTTPS means that a website encrypts the data transmitted through the site. Such as your name, address, and payment information.You should NEVER shop on a website that doesn’t use HTTPS in the address bar. An extra indicator is a small lock icon in front of the website address.Double Check the Site URLWe all make typos from time to time. Especially when typing on a small smartphone screen. One typo can land you on a copycat site (such as Amazonn(dot)com).Hackers buy domains that are close to the real ones for popular retailers. Then, they put up copycat sites designed to fool users that make a mistake when typing the URL.Take those extra few seconds to double-check that you’ve landed on the correct website. Do this before you start shopping.Never Shop Online When on Public Wi-FiWhen you connect your device to public Wi-Fi, you might as well expect a stranger to be stalking you. Hackers LOVE the holiday shopping season and will hang out in popular public Wi-Fi spots.They spy on the activities of other devices connected to that same free hotspot. This can give them access to everything you type in. Such as passwords and credit card information.Never shop online when you’re connected to a public Wi-Fi network. Instead, switch off Wi-Fi and move to your mobile carrier’s connection.Be On High Alert for Brand Impersonation Emails & TextsPhishing scammers were very active during the holiday shopping season of 2021. There was a 397% increase in typo-squatting domains connected to phishing attacks.While you need to be careful all the time about phishing, it’s even worse during the holiday season. Attackers know that people are expecting retailer holiday sales emails. They also get a flurry of order confirmations and shipping notices this time of year.Hackers use these emails as templates. They impersonate brands like Target, UPS, Amazon, and others. Their emails look nearly identical to the real thing. They trick you to get you to click and/or log in to a malicious website.Be on high alert for brand impersonation emails. This is another reason why it’s always better to go to a site directly, rather than by using an email link.Enable Banking Alerts & Check Your AccountCheck your bank account regularly. Look for any suspicious charges that could signal a breach. One way to automate a monitoring process is to set up banking alerts through your online banking app.For example, many banks allow you to set up alerts for events such as:When a purchase occurs over a specified dollar amountWhen a purchase occurs from outside the countryHow Secure Is Your Mobile Device This Holiday Season?Mobile malware is often deployed in holiday shopping scams. How secure is your device from malicious apps and malware? Contact us today for a security checkup. Drop us email via support@netway.co.th
NETWAY COMBO - November 2022 ต้อนรับอากาศแปรปรวน อัพเดทประกาศและข้อมูลล่าสุดจาก Netway Communication.Full Article: [[URL]]/.../latest.../november-2022-netwaycombo8 ข้อแนะนำในการช้อปปิ้งออนไลน์ ไม่ให้โดนโกงในช่วงเทศกาล โดย digicerthttps://bit.ly/3uaFYHs. Microsoft ได้เปิดตัว Microsoft Supply Chain Platform [[URL]]/.../microsoft-supply-chain-platform . E-book: 9 Tips for No Code Power Automate https://bit.ly/3A3bTNn . Microsoft Viva Sales แอปสร้างประสบการณ์การขายที่เข้าใจลูกค้ามากขึ้นhttps://bit.ly/3EHjJxS .Endpoint Protection การป้องกันภัยคุกคามทางไซเบอร์ที่ไม่ควรมองข้ามhttps://bit.ly/3gKGfOv.Checklist for Better Digital Offboarding of Employeeshttps://bit.ly/3gLx1kS
Summary Endpoints make up much of a company’s network and IT infrastructure. Small businesses with 50-100 employees have roughly 114 endpoints. Enterprise organizations with 1,000+ employees average 1,920 endpoints. Each of those devices is a chance for a hacker to penetrate a company’s defenses. Solutions focused the protection of endpoint devices: • Address Password Vulnerabilities • Stop Malware Infection Before OS Boot • Update All Endpoint Security Solutions • Use Modern Device & User Authentication • Apply Security Policies Throughout the Device Lifecycle • Prepare for Device Loss or Theft Reduce Your Endpoint Risk Today! Endpoints make up much of a company’s network and IT infrastructure. This is a collection of computers, mobile devices, servers, and smart gadgets. As well as other IoT devices that all connect to the company network.The number of endpoints a company has will vary by business size. Companies with less than 50 employees have about 22 endpoints. Small businesses with 50-100 employees have roughly 114. Enterprise organizations with 1,000+ employees average 1,920 endpoints.Each of those devices is a chance for a hacker to penetrate a company’s defenses. They could plant malware or gain access to sensitive company data. An endpoint security strategy addresses endpoint risk and puts focused tactics in place.64% of organizations have experienced one or more compromising endpoint attacks.In this guide, we’ll provide you with straightforward solutions. Solutions focused on protection of endpoint devices.Address Password VulnerabilitiesPasswords are one of the biggest vulnerabilities when it comes to endpoints. The news reports large data breaches all the time related to leaked passwords. For example, there is the RockYou2021 breach. It exposed the largest number of passwords ever – 3.2 billion.Poor password security and breaches make credential theft one of the biggest dangers to cybersecurity.Address password vulnerabilities in your endpoints by:Training employees on proper password creation and handlingLook for passwordless solutions, like biometricsInstall multi-factor authentication (MFA) on all accountsStop Malware Infection Before OS BootUSB drives (also known as flash drives) are a popular giveaway item at trade shows. But an innocent-looking USB can actually cause a breach. One trick that hackers use to gain access to a computer is to boot it from a USB device containing malicious code.There are certain precautions you can take to prevent this from happening. One of these is ensuring you’re using firmware protection that covers two areas. These include Trusted Platform Module (TPM) and Unified Extensible Firmware Interface (UEFI) Security.TPM is resistant to physical tampering and tampering via malware. It looks at whether the boot process is occurring properly. It also monitors for the presence of anomalous behavior. Additionally, seek devices and security solutions that allow you to disable USB boots.Update All Endpoint Security SolutionsYou should regularly update your endpoint security solutions. It’s best to automate software updates if possible so they aren’t left to chance.Firmware updates are often forgotten about. One reason is that they don’t usually pop up the same types of warnings as software updates. But they are just as important for ensuring your devices remain secure and protected.It’s best to have an IT professional managing all your endpoint updates. They’ll make sure updates happen in a timely fashion. They will also ensure that devices and software update smoothly.Use Modern Device & User AuthenticationHow are you authenticating users to access your network, business apps, and data? If you are using only a username and password, then your company is at high risk of a breach.Use two modern methods for authentication:Contextual authenticationZero Trust approachContextual authentication takes MFA a step further. It looks at context-based cues for authentication and security policies. These include several things. Such as, what time of day someone is logging in, their geographic location, and the device they are using.Zero Trust is an approach that continuously monitors your network. It ensures every entity in a network belongs there. Safelisting of devices is an example of this approach. You approve all devices for access to your network and block all others by default.Apply Security Policies Throughout the Device LifecycleFrom the time a device is first purchased to the time it retires, you need to have security protocols in place. Tools like Microsoft AutoPilot and SEMM allow companies to automate. They deploy healthy security practices across each lifecycle phase. This ensures a company doesn’t miss any critical stepsExamples of device lifecycle security include when a device is first issued to a user. This is when you should remove unnecessary privileges. When a device moves from one user to another, it needs to be properly cleaned of old data. And reconfigured for the new user. When you retire a device, it should be properly scrubbed. This means deleting all information and disconnecting it from any accounts.Prepare for Device Loss or TheftUnfortunately, mobile devices and laptops get lost or stolen. When that happens, you should have a sequence of events that can take place immediately. This prevents company risk of data and exposed business accounts.Prepare in advance for potential device loss through backup solutions. Also, you should use endpoint security that allows remote lock and wipe for devices.Reduce Your Endpoint Risk Today!Get help putting robust endpoint security in place, step by step. We can help! Contact us today for a free consultation.
Summary Data entry can be a real drag for salespeople. But that data is vital. Microsoft has taken up the mantle of this challenge. It is about to launch a new digital experience for sales teams. Microsoft Viva Sales is a “CRM helper” application. Viva Sales Basics • Eliminate Forms • Powerful Data Leveraging • AI-Driven Help Viva Sales Features • Tag to Capture Sales Interactions • Collaborate • Call Summaries & Integrated Data • Download & Customize Contact us today for a free consultation to improve your team’s digital experience. Data entry can be a real drag for salespeople. The time they spend on administrative tasks is time away from customer interactions. But that data is vital.It’s important to capture customer orders, quotes, needs, and more. Lead and sales reporting help sales managers know where to direct their attention. Analytics also help drive more efficient ways of closing the deal.Microsoft has taken up the mantle of this challenge. It is about to launch a new digital experience for sales teams. Microsoft Viva Sales is part of the “Viva” line of applications. These include things like Viva Insights for improved staff wellbeing. As well as Viva Learning for staff development.The Viva apps natively integrate with MS Teams and the Microsoft 365 ecosystem. They include automation designed to eliminate boring tasks and enable more work engagement.Viva Sales is a “CRM helper” application. We’ll go through some of the most asked questions about the app, its features, and when you can get it.What Is Microsoft Viva Sales?Viva Sales is an application that will provide sales and lead insights. These insights populate throughout Office 365 and Microsoft Teams. The focus of the app is to cut unnecessary manual entry to give sellers more time to sell.How Does Viva Sales Work? Is It a CRM?Viva Sales is NOT going to replace your normal CRM platform. Instead, it connects to your CRM and other sales-related apps. It leverages the data from these connections. This makes it easier for salespeople to get the prospect data they need to enable their work.Salespeople spend approximately 34% of their time on administrative tasks.Viva Sales BasicsSome of the core advantages of Viva Sales are:Eliminate Forms: Data entry for sales professionals is greatly reduced. This frees them up for more customer relationship building.Powerful Data Leveraging: Viva Sales connects to several platforms. This includes non-Microsoft programs and CRMs. The integration allows salespeople to cross-reference data points and gain valuable insights.AI-Driven Help: Salespeople will get prompts that are AI-driven. These suggestions and reminders help them along in the sales process with a lead.Interconnected InterfaceMicrosoft Viva Sales provides sales-specific insights throughout the various M365 applications. Salespeople natively see important customer details, wherever they are. Including in their Outlook Calendar or when in their Microsoft or non-Microsoft CRM. Viva Sales FeaturesTag to Capture Sales InteractionsTagging is also known as using someone’s “@name” to get their attention. Tagging is a popular software integration used throughout many cloud-based apps. It’s also used within Microsoft 365.Salespeople can use the familiar tagging function. They can use it to capture data from another M365 application for a prospect or customer. This includes adding someone to a list of customers by using a tag for their Viva Sales name. The system will capture the contextual information on the lead or customer.CollaborateViva Sales makes it easier than ever to collaborate with your team on a sales prospect or customer. You don’t have to chase down information to copy/paste into a message. Use that tagging function to populate lead information from Viva Sales in seconds. You can also easily edit or open a lead/customer record. No need to look for and open another app. The process gets you where you need to go in as few clicks as possible.Call Summaries & Integrated DataOne thing that customers and salespeople hate is a lack of understanding. For example, when a salesperson doesn’t know about a recent customer interaction.This can happen when company communication systems store data from different sources separately. Such as phone call messages being in one place and a customer’s website chat session being in another.Viva Sales brings all that customer engagement data together into a single view. This allows the salesperson to see call summaries and capture call action items.Download & CustomizeSalespeople that prefer an Excel view of their contact list can get this from Viva Sales. Download lead and customer lists. Customize the application per the organization’s needs.When Will Viva Sales Be Available?Microsoft has announced that Viva Sales will be “coming in Q4 2022.” There is no exact date for the launch yet, but you can be sure that we will keep an eye on this!In the meantime, you can watch a video explaining the application on Microsoft’s site here.Take Advantage of Microsoft Viva AutomationMicrosoft built the Viva suite of digital experience apps for productivity. These apps help employees find information faster, feel more connected, and work more productively.Now is the perfect time to explore those that have already launched and get ready for Viva Sales.Contact us today for a free consultation to improve your team’s digital experience.