Showing posts with label Business and Technology. Show all posts
Showing posts with label Business and Technology. Show all posts

Tuesday, 16 February 2016

Ransomware: A Growing Threat















Imagine opening an email with a word document. It looks innocent enough, but in seconds, strange letters flow across your screen. Your data becomes unusuable. And then a demand pops on the screen for payment to make it usuable again. You have been held to ransom. This is "ransomware", and it is closer than you may think.

BBC news had this recent report about Guernsey:

“Businesses in Guernsey are being targeted by cyber attackers who demand a ransom to recover lost files, computer engineers have said. Ten companies have been hit by attacks that lock a business out of its computer system until a ransom is paid. No engineer has had any success in getting files back for customers so far. One person has tried to pay the ransom, but the price went up from £400 to £1,000 in 24 hours.”

Computer engineer Paul Domaille said the problems for one company began when they opened an email with the subject "remittance advice enclosed". He said: "I clicked on this email, the screen went black, clicked a few times and when I tried to look at quick books it was all gone. Everything stored on the computer was quickly encrypted. Messages then started to appear on screen asking for a ransom, in order to get the data back ”.

“Victims range from hotels and restaurants, to small businesses and individuals. In every case, there was a demand for money to unlock the computer.”

"The advice is not to pay it, go back to back up and that's the only way to recover your files."

And in the UK recently, another case:

“Lincolnshire County Council's IT is back up and running after the council shut everything down last week following a ransomware attack in which the attackers turned out to have asked for a mere £350. Despite the BBC reporting that the council had been hit by a £1m ransom, a spokesperson told The Register that it had only been asked for $500 (c £350), unsurprisingly to be paid in Bitcoin.”

Ransomware began in 2005, but has recently re-emerged as a mature form of malware. It works by using phishing technicques - psychological tricks - to try and persuade a user to click on a link, or open a document. 

This opens up the PC to run the software, and in a matter of minutes, all the data will be encrypted and unusable – unless you have a key. After the data is rendered inaccessible, a blackmail demand is made, often asking for the ransom to be paid in bitcoins, which are relatively untraceable.

The most success variant at the moment, according to security firm Imperva is called Cryptowall 3.0. The report says that it has caused $325 million (£225.7m) in damages so far.

Jonathan Sander, VP of product strategy at security firm Lieberman Software, says that Cryptowall is easily avoided with a good backup policy. He commented:

"The other problem is that reporting Cryptowall issues to more savvy law enforcement sounds like reporting your bike was stolen when you didn’t bother to lock it up. Since a good back up strategy can be almost 100 percent effective to combat Cryptowall, police may simply feel the real crime was your own lack of preventative measures".

Even though the advice to back up a computer sounds simple, it is often not done until disaster hits, and the hard drive fails, or in this case – the system is rendered inoperative. Sander says it is like advice for healthy living:

"So much good security advice sounds like health advice. Everyone knows they should eat right and exercise, but so many simply shrug at this advice as they return to chips in front of the television. Every organization knows they need to back up, monitor file activity, protect admin privileges, and run basic perimeter defenses like antivirus and firewalls. Since none of that security seems to contribute to the bottom line and takes a modicum of effort, people’s laziness kicks in and they skip the basics".

Michelle Drolet of Network World makes the following recommendations:


  • Install reputable anti-virus and anti-malware software.
  • Don't open attachments in emails, unless you know what it is.
  • Don't follow links in emails, close the email, and go directly to the website in your browser.
  • Use strong passwords, and don't reuse the same passwords.
  • Make sure all of your system software and browsers are patched automatically with security updates.
  • You should apply all of these rules to whatever device you're using. Smartphones, tablets, and Macs are not immune to ransomware.
  • Finally, make sure you have solid back-ups of all your data.

The latter is most important and they stress:

“You can also mitigate the risk of ransomware by having a robust and regular backup routine. If your files are backed up and you can access them, there's no need to pay to unlock them, but it may still require some serious effort to rid yourself of the ransomware once your system is infected.”

That's because the actual PC may be still infected, so the first step is to get a computer engineer to disinfect that, and make sure it is clean, and then and only then can you safely restore from backup. And you do keep regular backups, and test they can be restored, don't you?

Thursday, 3 December 2015

Cloud Accounting for the Small Business












My new weekly business and technology blog follows below.

Cloud Accounting for the Small Business

The general trend in the marketplace at the moment is moving from desk based accounting packages for businesses towards cloud products. Cloud based systems are growing faster than desk based systems, although it should be noted that part of that is due to the greater penetration of the market share by desk based systems.

With this innovation comes a different model of pricing. Packages like Quickbooks and Sage are usually one off licensing payments, with extra payments for a support contract if the user decides to take it.

There are also extra costs involved in upgrading to the latest version of the software, and both Quickbooks and Sage operate a “sunset” policy whereby they retire support for all but the most recent three products.

Although software is usually treated as a revenue expense, as a one off sum, it is more akin to a capital expense, and more like a car, which may be replaced after 5.

Of course there is nothing to prevent a user continuing to use the product on their PC after it has ceased to be supported, but older versions which run on XP may well not run properly on later versions of the operating system. There is also the dependency on the operating system – desktop systems in the UK and Channel Islands run mostly on the Windows operating system.

Cloud based systems by their very nature, can run on a variety of platforms as the essential is that the browser platform supports them, and browsers such as Google Chrome run on a variety of operating systems, so that one user might use the product on a PC, while another uses a Mac book.

The pricing model is more akin to a hire charge, a much lesser amount than a one off payment, but payable every month, so that it will work out more expensive, over time, than a one-off payment.

But included in that price is a helpdesk, often available online from within the product itself, and enhancements are added incrementally rather than having to upgrade to get them, and users can themselves suggest changes.

As these products are relatively new, the development teams are keen to enhance them to aid users, so feedback and suggestions are taken on board, and the products themselves are changing at a more rapid pace than their desk bound counterparts.

In some cases, the desk bound counterparts are playing catch-up. Xero has had streamlined bank feeds for some time. Sage has had bank input but is just implementing more bank streams in the latest iteration of the product.

However, this may mean that some features are not present – batch input entry of invoices, for example – is not yet available. It is something of a trade-off, to see how well the fit is between what a business wants to do, and how.

Desk products may have more features, but suffer from product bloat as successive versions have added features to the point where it would be useful to be able to turn some off. Cloud products do not as yet suffer from this, being relatively young products to the market place.

Handling large volumes of data can also be an issue. Different cloud products may cope better with larger amounts of data, and the same is true of the desk products, where Quickbooks becomes unwieldy but Sage runs rather well, and has mechanisms to archive off older data. Sage has also much better networking than Quickbooks.

An example of the rapid development of the cloud products is that after 7 years in existence, Xero is looking at some kind of archive option to speed some of the slightly slower reporting,

Interestingly Sage is starting to develop a hybrid design, whereby a Sage Drive can retain Cloud backups of data on a regular or automated basis, and these can be shared with third parties, such as accountants.

Backup is another concern, where desktop products require physical offline backups, while cloud based products are automatically backed up. Backup should be investigated to ensure it is robust with Cloud products, which is why the market leaders like Quickbooks and Xero will probably be favourites – they have solid systems in place.

While risk of internet disruption may seem a reason for preferring desktop over cloud, most disruption happens when there are localised power cuts affecting the end user, in which case neither product can be used. Reliability of electricity supply is by far the greater risk factor in today’s technology heavy world.

Another concern of end users may be where data is stored, especially given the breakdown of “Safe Harbour”. I have addressed this in a previous blog, and refer the user there.

As far as the market goes, Sage’s cloud product, Sage One, has virtually no penetration of the markets to compare with the two main rivals for small to medium businesses. The latest data shows that QuickBooks Online is ahead in the US and Canada, while Xero dominates the markets in Australia, New Zealand and the UK.

In countries like India, where internet connectivity is very poor, there is little market penetration by cloud products, and desk products dominate. A good solid internet infrastructure is a necessary condition for take-up.

On a global scale, the statistics show that QuickBooks Online has about twice as many paid subscribers as Xero. However, part of that reflects on the relative size of the geographical markets – the US and Canada has a vastly larger population than Australia, New Zealand and the UK.

Wednesday, 25 November 2015

The End of Safe Harbour: Check Your Data










Safe Harbor was a self-certifying arrangement whereby a company in the US (for example) would be able to provide protection for data stored there by EU users under the EU Data Protection Law. Hence the name - "safe harbor".

The Safe Harbor principles were agreed to on the basis that, even though U.S. law would not change, the private companies who signed up to the Safe Harbor list would adhere to the rules set out by the EU.

These rules included, but were not exclusive to, the EU enabling access for private organisations in the US to an individual's data upon request, and assurances that data security was effective enough to guarantee data protection. It was neat because it was self-certifying and did not therefore rely on lawyers to draw up contracts. However, there was mounting criticism of laxity even before the EU ruling.

The current situation is that what might be termed “Safe Harbour 2.0” is in progress at the time of the ruling. It is clear that this ruling will act as a bargaining point for stricter regulation of data transfer.

While the current situation has been prompted by a particular Court ruling, it has become clear from the revelations by Edward Snowden that breaches of Safe Harbour by the USA have been going on for some time on a regular basis.

“A company in Europe may run afoul of these rules if it uses a U.S. service provider that it sends data to, such as for email marketing. Or it might run afoul of these rules if it sends data to a U.S. subsidiary,” explains Daniel Castro of the Information Technology & Innovation Foundation.

The collapse of Safe Harbor does not mean the end of legal transfer of data. The EU commission itself says that other mechanisms can be used, and EU Model clauses are one such mechanism which they themselves suggest. In the meantime, there is a period of grace until 31 January 2015.

But in the meantime, business users in Jersey should question where their Cloud data is held, and how it is protected. This covers everything from online accounts packages like Quickbooks Online and Xero, to email systems using Hotmail and Gmail. etc.

Basecamp has this to note:  If you live in the European Union and store personal data in your Basecamp account, or you use your Basecamp account to do business with EU residents who may provide personal data, then the ruling on Safe Harbor may affect you.... We are currently in a grace period from enforcement groups through the end of January 2016.

I've not been able to find anything about Quickbooks Online, which is worrying.

It appears that Xero, perhaps because of its origin in New Zealand,  has not just relied on Safe Harbour but has also been using EU Model clauses as a backup in case there were problems with Safe Harbour, and these satisfy the requirements of data transfer from the EU to the US. It is highly likely that they knew the weakness of Safe Harbour and decided to reduce their risks accordingly.

A Xero Community Manager has stated:

"Like many SaaS companies, we use top-tier, third party data hosting providers' servers to host our online and mobile services. Our providers Amazon Web Services, Microsoft Azure, and Rackspace are located in the US. For our European and other non-US customers, it means that personal information is transferred to those hosting providers’ servers in the US.  To confirm, we have in place EU Model Clauses with each of these hosting providers, which continue to be recognized by the EU as a means of satisfying the requirements relating to the transfer of data from the EU to the US."

However, these model clauses will be placed under additional scrutiny and may have to be tightened. The particular reason is that the USA’s National Security Agency may well “ride roughshod” over them just as it did with Safe Harbour. But for the moment, they remain an alternative safeguard, and Xero clearly complies with those.

It is worth noting that for many other countries outside the USA, there were no “Safe Harbor” arrangements, and “model clauses” and “binding corporate rules” were always necessary to do business. The UK Data Protection guidelines state:

“Adequate safeguards may be put in place in a number of ways including using Model Contract Clauses, Binding Corporate Rules or Binding Corporate Rules for Processors (BCRs) or other contractual arrangements. Where “adequate safeguards” are established, the rights of data subjects continue to be protected even after their data has been transferred outside the EEA.”

“The European Commission has approved four sets of standard contractual clauses (known as model clauses) as providing an adequate level of protection. If you use these model clauses in their entirety in your contract, you will not have to make your own assessment of adequacy.”

“Another option is to adopt binding codes of corporate conduct, known as binding corporate rules or binding corporate rules for processors (BCR). This option only applies to multinational organisations transferring information outside the EEA but within their group of entities and subsidiaries." 

"These rules create rights for individuals, which can be exercised before the courts or data protection authorities, and obligations for the company. In all cases, the rules are legally binding on the companies in the multinational group and will usually be made so by unilateral declarations, intra-group agreements or the corporate governance of the group. To use BCR to transfer personal data freely within your group, they must be approved by all the relevant European data protection authorities who will co-operate with each other in assessing the standard of your rules.”

There is no need for immediate concern, but if your business uses cloud based storage of data, including personal data on individuals , the you need to consider where your data is held and what protective measures have been put in place.