Archive for Business

Office 365 – important changes for Outlook users in October

Outlook users of Office 365 need to use 2010 version or newer

Anyone connecting to the Office 365 email system using Microsoft Outlook needs to be aware of important changes that are taking place at the end of October 2017.

From 31st October, Microsoft are changing the protocols that allow connection between the Outlook email program and Exchange – moving to a more secure ‘MAPI over HTTP’. They state that they are doing this as MAPI is more efficient with data transfer and allows more secure authentication, compared to the previous method.

Unfortunately, Outlook 2007 (and earlier Outlook versions) do not work with this new protocol and Microsoft will not ‘upgrade’ them to make them compatible. This means that anyone using these versions of Outlook with Office 365 will no longer be able to access their emails after 31st October and will need to move to a more recent Outlook version, to continue to access their emails through Office 365.

Also, any newer versions of Outlook must be up to date with their regular updates, to ensure that they work correctly after the 31st October.

Here are the Office version numbers that are the minimum needed to keep the connections working after the changeover (information supplied by Microsoft as at 28.9.17):–

Office 2010 – 14.0.7164.5002
Office 2013 – 15.0.4779.1002
Office 2016 – Subscription: 16.0.6568.20xx or MSI: 16.0.4312.1001.

To check the version of Office 2010, open Outlook, go to Help > About Office Outlook.

To check the version of Office 2013 or later, go to File > Office Account > About Outlook.

For further help give us a call on 01455 209505.

Share..Share on FacebookShare on Google+Tweet about this on TwitterShare on LinkedInPin on PinterestPrint this pageEmail this to someone

Too Many Passwords? Try a Password Manager

Keep your computer secure from scammers

One of the regular things we see is customers struggling with the number of passwords they need to remember – so many login details are needed these days. As we have advised previously, it is not a good idea to have just one password for everything so how can you keep track of all of them?

You can try using a Password Manager – this is a program or browser extension that allows you to store passwords in an encrypted form on your device, but also do much more. The bonus is that all you need is one Master password to manage it.

The passwords are saved in an encrypted password ‘vault’ and when you go to a specific website, the Password Manager inputs the password for you. Whilst many browsers already do this for you, a Password Manager does it in a more secure way.

Some Password Managers advise you as to how secure your passwords are – preferably using a mixture of letters, numbers, capitals and special characters. Some can automatically change passwords for you and as well as set up two-factor authentication – this is where you can open the password vault with your Master password, but you also use some form of verification (such as getting a code texted to your phone), which you type in to prove that you are authorised to access those important password details.

The main point is that you would not need to remember large numbers of passwords, which means that you can easily keep your online accounts as secure as possible.

There are a many Password Managers – here is a selection of the best known ones: –

LastPass

This is one of the original Password Managers and installs a browser extension or mobile app. With one master password you can access the password vault and manage passwords for all websites that you log into. It can even generate secure passwords for you.

At the moment the browser extension is free to use and more services are available in the premium version.

True Key

Intel has produced a Password Manager that is free to use for 15 passwords, which is enough for many people, and also a premium version which allows more and extra services. As well as the usual encrypted password facility, it allows multiple ways to access the password vault – master password, second device, email or even facial recognition.

Dashlane

As well as storing your passwords securely, this product helps you by providing a rating of your password security strength. The premium version also allows synching across multiple devices as well as two-factor authentication.

These are just three of the many Password Managers out there but whatever one you choose, do make sure that it is from a reputable company. If using a search engine, take particular care checking the website address the download is coming from as it needs to come from the company itself and not an address that is only similar.

Also you need to remember that whilst Password Managers help you keep track of your password security, you still need to maintain effective security software and keep a cautious eye on what you download from the internet.

If you would like help with password security, call us on 01455 209505.

Share..Share on FacebookShare on Google+Tweet about this on TwitterShare on LinkedInPin on PinterestPrint this pageEmail this to someone

Increase Your Business Email Impact with Smart Strategies

Be smart with your email

Most small businesses rely on email as their preferred form of communication – email is the go-to format we’d be lost without. It is no surprise – it’s quick, simple and provides a paper trail. But its convenience doesn’t always mean relaxed. In fact, poor email communication can hurt your reputation and cost you customers.

Here’s how to be smart with your business email:

Are you using a free email service?

Most businesses use a domain name – that is a web address where their name can be used for either a website and/or email addresses. If you are using a free email service instead of an address with your business name, will that put off any customers? What impression may it give? It is very easy to set up a domain name and have a professional looking email address – and it is much less expensive than you think.

Manage your inbox

Your inbox is only for items you still need to access. Once you’re finished with an email, you should delete it or archive it. If you were to imagine your inbox as physical letters, you’d never let it grow to a 6-foot high stack of chaos. Instead, you’d either throw them out or do the filing. It’s not hard to identify which ones to keep for reference, so create inbox folders to sort them accordingly. As emails arrive and are actioned, move them to the relevant folder or the delete bin.

Write professional messages

Stepping across the line from casual to careless is easy if you skip the basic elements of good business writing. Grammar will always be important and the sentence structure of your language hasn’t changed. All email programs include a spell-checker, many of which draw attention to errors immediately, so there’s really no excuse. Typing in all CAPS is seen as yelling, and breaking your text into paragraphs makes your message so much more readable. One last thing before you click send, quickly glance over your email to make sure your tone is appropriate and no mistakes have snuck through.

Embrace the subject line

Many emails are missed because the subject line was empty or meant nothing to the receiver. Writing these attention-grabbing nuggets can be tricky, but if you simply summarize the message, it will be better. Just remember to keep them under 5-8 words so they fit on mobile displays.

The subject line is also checked by anti-spam filters, so it is even more important to have one that makes sense to the receiver.

Be smart with attachments

Keep attachments small – under 2MB – as they can clog up the email server as well as your email program and other people’s. For larger attachments, share the file location as a link using cloud storage. When you’re sent an attachment you’d like to keep, save the file and then delete/archive the email.

And as always, be careful with unexpected attachments, especially from unknown senders. It’s more important than ever to scan all attachments with an antivirus before opening.

Keep your CC/BCC under control

The carbon copy (CC) and blind carbon copy (BCC) let you send the email to additional stakeholders, more as an FYI than anything else. As a rule, use BCC if you’re using an email list or privacy is an issue. But before you add extra people to the email, make sure the email IS relevant to them. There’s nothing worse than being stuck in a pointless email chain!

If you want help to make your business email better or need a domain name and email account setting up, please call us on 01455 209505.

Share..Share on FacebookShare on Google+Tweet about this on TwitterShare on LinkedInPin on PinterestPrint this pageEmail this to someone

NHS Cyber Attack – how to build up your protection

Malware terms

Here is some more information about the NHS cyber-attack that started on Friday.

The Ransomware variant is called WanCrypt0r and 81,000 infections were reported in the first 12 hours. It has not only targeted the NHS but has also gone for Banks, Telecoms and Utilities worldwide.

It has been established that the criminals are exploiting a known vulnerability in Windows (MS17-010)  which has already been patched, but those computers which do not have up to date Windows Updates are still vulnerable.

We have warned customers before about the Ransomware threat and the extent of this attack means that we should all consider increasing our defences, especially businesses but also homes, as Ransomware can be spread via emails.

As there is no way to guarantee 100% protection against threats, we have to make it as difficult as possible for the threat to take hold and how much you decide to do depends on the level of risk you wish to take.

1. Ensure that Windows Updates is kept up to date

Windows Updates contain security fixes (amongst other things) and computers that have not been kept up to date are vulnerable, as in the case in this attack. Admittedly Windows 10 gives you little choice when it comes to Updates (you have to have them) but if you are using any previous version of Windows – make sure that Updates are kept up to date.

If you are still using Windows XP or Vista, you shouldn’t be. These versions of Windows no longer get Windows Updates.

Update:
Microsoft have now issued a patch for XP and Vista. Go to this web page to download the patch if you are still using XP and Vista (demand is high so it may take more than one try). Please note – this patches this vulnerability only so you should still move away from these unsupported operating systems.

2. Make sure that you have a good antivirus product that is kept up to date

Good security products give a better degree of protection but they have to be kept up to date, with active subscriptions. Free antivirus is better than nothing but does not give protection that is as comprehensive as paid versions.

3.    Install extra protection.

Usually, you should not have more than one security product installed on your computer at any one time, but there is a product called Malwarebytes, which can be installed as well as your existing antivirus. This increases your protection especially from Ransomware, if you install the premium version.

4.    Consider your backup situation

If a computer is infected, the virus goes across a network and it is possible that any connected storage will also get infected – this includes cloud storage such as Dropbox. Having said that, Dropbox state that within 30 days of the event they can restore your files (here) and you can subscribe to extend the 30 days to 1 year if you choose. If you are using any other Cloud storage, check with them to see if they have a similar service.

It is vital that your important files are backed up and a copy kept separate from your computer. In the event of an infection, you can at least relax a little that your important data has not been encrypted.

5.    Consider downtime – system backups

When a computer has Ransomware, if you have backups of important files you will not need to pay the criminals. It is likely that the computer will need to be wiped clean and Windows reinstalled, which takes time.

There is software available that can take a copy of your whole computer, which could be used to reinstall the whole system in much less time than a full reinstall. A copy once every 2 or 3 months would allow you to get back up and running in much less time.

As mentioned earlier, many viruses are spread through emails, so never click on links in emails and do not open attachments unless you know that they are genuine emails – if in doubt call the sender.

If you would like help with any of the above, give us a call on 01455 209505.

Share..Share on FacebookShare on Google+Tweet about this on TwitterShare on LinkedInPin on PinterestPrint this pageEmail this to someone

Mac Computers and Viruses – Truth versus Myth

Compromised app containing a virus

We have lost count of the number of times that we’ve heard the phrase “Macs don’t get viruses” or “I’ve never had protection on my Mac”. Whilst this may have been true in the past it isn’t as cut and dried today and the Mac OSX operating system actually can be vulnerable, so protection is worth seriously considering especially in a work or business situation.

More difficult to exploit

The Mac is based on the UNIX operating system (as is Linux) which is more difficult to exploit as it is built on a sandbox-type principle, where malicious code cannot usually get as far as it might get in a non-UNIX based system.  Also, Apple has built in a certain degree of malware prevention in the Mac, for example their ‘Gatekeeper’ software actually blocks apps that have been downloaded from the internet (i.e. anywhere other than the Apple Store) that do not have a Developer ID supplied by Apple certifying that they are safe to use.

Unfortunately, in spite of this robustness the Mac is now becoming a victim of its own success because its increasing popularity means that cybercriminals are paying more attention to it – and finding ways of making money from you even if you are a Mac user. It’s not just that popularity – Macs are usually much more expensive to buy, so the cybercriminals may believe that Mac users are attractive targets.

Not impossible to exploit

For example, a popular Mac DVD-ripping and Video Conversion app called ‘Handbrake’ was recently compromised, by criminals hacking the software company download server and inserting malicious code into the app download. When this download was installed on a Mac, it also installed a ‘backdoor’ (a means of bypassing security). The user then was asked for their administrator password, which was passed over the internet in plain text so that the criminals could access any part of the system from that point.

By successfully avoiding having to use the ‘direct attack’ approach, this allowed important information such as password keychains and browser data to be extracted and passed to the crooks.

This compromise has now been corrected and the infected code was from a download between 2nd and 6th May 2017. If you have installed Handbrake version 1.0.7, check the SHA1 checksum of the file by opening a Terminal, typing in shasum and dragging the installation file into the Terminal Window.

If the checksum is 0935a43ca90c6c419a49e4f8f1d75e68cd70b274 then the file is malicious.

To disinfect it remove the Launch Agent plist file fr.handbrake.activity_agent.plist, and the activity_agent.app file located in ~/Library/RenderFiles/. Reboot then change your passwords.

In the past year or so a Ransomware-type malware was discovered for the Mac, so this isn’t the first time that there has been a potential issue.

Even though the Mac is more robust and secure than its main competitor, it is by no means invulnerable to malicious code and it is a risk to think otherwise. You may feel that the risk is small enough to continue to use your Mac as you always have, but at least consider the pros and cons first – as well as being very careful about where you get your apps from.

If you would like help in securing your Mac, give us a call on 01455 209505.

Share..Share on FacebookShare on Google+Tweet about this on TwitterShare on LinkedInPin on PinterestPrint this pageEmail this to someone

Helping to Control Spam in your Email

Getting rid of Spam in your Inbox

‘Spam’ emails get into everyone’s email Inbox and are a fact of life these days. Whether its “Russian Brides” or something else, Spam emails are annoying, especially if you regularly get a large number every day. It is not surprising that there is so much, as current estimates put Spam between 60%-80% of global email, depending on which report you read.

What many people do not realise, is that a lot of Spam emails are caught by your email company and discarded before you even get to see them – although some email companies filter out Spam much better than others do.

Having said that, there are ways to help reduce the number of Spam emails that you get – here are a few of them: –

Mark as Spam before doing anything

This is the most important thing. More often than not, we see that customers tend to delete the Spam emails, then carry on reading their ‘proper’ emails as normal – all this does is just delete it, so it doesn’t help you the next time they send an email from that address.

What you need to do is to mark the email as Spam, before deleting it. This tells your email company or email program what to do if this email address sends another email – that is get rid of it before you get it.

Email using Webmail

If you are using Webmail (getting your email through the email company website), mark the Spam email (usually on the left-hand side) and click on the Spam button, which may be marked as ‘Report’, ‘Spam’ or something similar. This identifies the email as Spam and tells the email company that you don’t want any more emails from that email address. The email company should automatically send any more emails from the same address, straight into the ‘Junk’ folder instead of your Inbox.

Email using an Email Program or App

Many email programs include a facility to mark an email as Spam. For example, if using Outlook, right-click the email(s) and select ‘Junk’. You will get options as to what to do, e.g. selecting ‘Block Sender’ (blocking just the email address) or ‘Block Senders Domain’ which will block all emails from the name after the ‘@’ symbol. Note that Outlook diverts emails into the Junk folder – they will still be coming from the email company.

Most email programs will have a similar method of diverting spam that has been received.

Many (non-free) security software programs include an anti-Spam facility, whether it blocks an email that it knows is spam using its own built-in spam filters, or “training” the program by marking the Spam emails and it blocks them for you in the future, in a similar way as above.

Businesses – hardware and online filtering

If you are a business with a business-class firewall, a Spam filtering facility can be included in the appliance, depending on the hardware device chosen, so speak to your I.T. person about this.

There are also ‘Cloud’ solutions that can route emails from your email company through the Cloud filters before you even get them – there are many solutions to choose from.

Third Party Anti-Spam programs

There are a large number of ‘Anti-Spam’ programs which say that they help in blocking and removing Spam – they are essentially adding another filtering layer for your Inbox. Having said that, you do need to check for compatibility with your email program or app, so research is essential, especially as some of these programs are more reliable than others..

As with all things, make sure that you have regular backups, in case the worst happens, but if you do nothing else make sure that you mark your emails as Spam, before getting rid of them.

If you would like help in battling Spam in your Inbox, give us a call on 01455 209505.

Share..Share on FacebookShare on Google+Tweet about this on TwitterShare on LinkedInPin on PinterestPrint this pageEmail this to someone

Microsoft Says Don’t Download Windows 10 Creators Update Yet

Windows 10 logo

Microsoft has advised users NOT to manually download the latest update to Windows 10 – called the Creators Update – but wait for it to be downloaded in the normal automatic update rollout instead.

Despite the massive publicity surrounding the latest Update release, they are finding issues with it particularly with older machines, such as some components no longer working after the Update has installed. This is why they are automatically updating newer machines first and hoping to identify and iron out bugs before the older systems get it during the normal course of events.

Even though Microsoft are deliberately rolling out the Update slowly, users can download the Creators Update themselves so Microsoft are worried that the issues that they have found will result in normal (e.g. non-geek) users having difficulties should they install the Creators Update before Microsoft want them to.

The Creators Update is the equivalent of an operating system upgrade (Windows 10.2 if you will) and it is a major undertaking even without the threat of parts of your machine not working afterwards. Certainly many of us in the I.T. world remember the problems caused by the last big Windows 10 update (the so-called ‘Anniversary Update’ last year) and even though we have learnt the hard way not to jump into the next ‘latest and greatest’ straight away (there are always bugs to be ironed out) it is surprising that they have asked users to stop manual updating so soon after release, so there must be further bugs that they are dealing with.

On the positive side at least Microsoft are warning people and not just releasing code that they know will cause problems to many people, although it is still a pity that testing didn’t show these issues before the Update was released to the public.

It also doesn’t help when you consider that Home and Small Business customers are effectively testing the Update before Enterprise customers get it, as it will not be released to the Enterprise sector for months – until the bugs have been ironed out.

If you have installed the Creators Update already, there is a way to uninstall it until it is more stable, although be aware that some apps/programs may be uninstalled in the process.Of course, as always, you should take a backup of your important files first just in case.

Go to Start > Settings and click ‘Update and Security’. Click on ‘Recovery’ > ‘Go back to an Earlier Build’ or depending on how long ago it was, click on ‘Go back to the previous version of Windows 10’.

If you are experiencing problems with Windows Update, give us a call on 01455 209505.

Share..Share on FacebookShare on Google+Tweet about this on TwitterShare on LinkedInPin on PinterestPrint this pageEmail this to someone

Controlling Windows 10 Autoplay Settings

Autoplay settings in Windows 10

‘Autoplay’ in Windows was originally designed to automatically open removable media that you have plugged into your computer, such as CD/DVD or USB media – it was meant to speed things up for you, but it has had a checkered history.

In the old days, putting in a CD/DVD or USB media with Autoplay switched on was a good way of passing viruses from one computer to another, as viruses were automatically executed when the media was opened for you. This is why good security programs today either automatically scan removable media when inserted, or ask you to allow it to do so, but some programs are better than others and some may not stop a virus from executing itself in time.

Later versions of Windows switched Autoplay off by default and Windows 10 asks you what you want to do, when removable media is inserted. However we do see customers that switch it back on, for ease of use but this does pose a risk.

Even today, it is recommended that Autoplay is switched off. You can do this by going to Settings > Devices and select ‘Autoplay’ on the list on the left. Toggle the Autoplay switch to ‘Off’, Autoplay will be disabled and you will not see the pop-up window again. This allows you or your security software to scan the removable media before opening.

Alternatively, or you just find that annoying, the next safest thing is set Autoplay to ask you what to do every time media is inserted, rather than automatically opening it. In Windows 10 you can actually select different actions for different media, for example you can set memory cards to import photos from your camera (which is unlikely to be infected). The settings for this are in the same section as described above, and you go to the ‘Choose a default’ for each media showing in the list.

There is also even greater control of individual media by going to the ‘Autoplay’ setting in Control Panel, where you can choose a default for many more options such as Pictures, Video, Audio etc. that may be present on your removable media.

Rather than just automatically opening media, the final thing that you can do is to set Autoplay to open the media in File Explorer – but as some viruses reside in an area of removable media that is read when opening its file list, this is not that much better than automatic opening. We would recommend scanning all removable media before opening it in File Explorer.

Every day people are using the same USB drive in their home and office/business computers, or putting removable media into their computers that has been used in a friend or relative’s system. This means that the weakest point is the danger point for compromising the security of your computer – so the friend/relative that may not have a good security program, or a compromised office computer are routes to computer infection.

The last thing you want is to have your computer disinfected, so it pays to reduce the risk where possible.

If you would like help in securing your computer or believe that your computer may be infected, give us a call on 01455 209505.

Share..Share on FacebookShare on Google+Tweet about this on TwitterShare on LinkedInPin on PinterestPrint this pageEmail this to someone

Security – 4 Ways to Travel Safe for Your Business

or aMobile Security for your Business

Working from anywhere is now as simple as accessing the internet on any number of devices. Managers, owners, and employees are all embracing the flexibility of working while travelling, making it the new norm.

But while you were in the office, you were protected by professionally designed firewalls, security infrastructure, and robust software. As soon as you step away from the building, those protections disappear, leaving your device and the data inside at greater risk.

Cyber attackers love to collect any data they can obtain, often preferring to hack first, assess value later. It doesn’t help that almost all data can be sold, including your personal details, those of your clients and suppliers, as well as your proprietary business data. These days, the information stored on your device is usually worth much more than the device itself.

Here are 3 ways a hacker will attack:

Making use of Opportunity – getting hold of the device

Whether an employee left their laptop at a café or a thief stole the phone from their pocket, the outcome is the same – that device is gone. Hackers will take advantage of any opportunity to gain access to a device, including taking them from hotel rooms and even asking to ‘borrow’ them for a few minutes to install spyware, before handing it back.

Have you ever handed your smartphone to a stranger, asking them to take a photo for you?

Spoofing a Wi-Fi Hotspot

We’ve all come to expect free Wi-Fi networks wherever we go – we can even create them ourselves using smartphones. Hackers will take advantage of this trust to create their own free, insecure network, just waiting for a traveller to check a quick email.

When they do, they can monitor traffic and if your device is not secured, hackers can obtain all sorts of information.

Intercepting an Insecure Network

Hackers don’t need to own the Wi-Fi network to steal content from it. Data travelling across an insecure genuine network is visible and available to anyone with the right software.

Taking these four precautions will help to increase cyber safety and help to protect your business data while on the move: –

1.    Make a backup before you travel: In the event that your device is lost or damaged, you’ll be able to replace the device with a new one and quickly restore all the data from a backup, all with minimal downtime. (Also bear in mind that many devices have a remote delete or lock function in the event of a theft – if yours does you may want to consider it).

2.    Don’t use public Wi-Fi: Wait until you have access to a secure network before going online – even just to check email.

3.    Use passwords and encryption: At a minimum, make sure you have a password on your device, or even better, have full drive encryption. That way, even if your data storage is removed from the device, the contents are inaccessible.

4.    Act fast after loss: If your device is lost or stolen, immediately notify the appropriate people. This might include your IT provider so they can change passwords, your bank so they can lock down accounts, and any staff or colleagues who need to be aware of the breach, so they aren’t tricked into allowing further breaches.

So much personal, financial and business information is now held on our mobile devices that they are a potential goldmine for the wrong people. Think objectively and try to minimise the risk now, because a cyber breach is happening to someone else whilst you are reading this – don’t let it be you.

Need help with mobile cyber security? Call us at 01455 209505.

Share..Share on FacebookShare on Google+Tweet about this on TwitterShare on LinkedInPin on PinterestPrint this pageEmail this to someone

Is Anti-Virus Enough These Days?

Is Anti-virus protection enough these days?

Not too long ago, everyone was warned about computer viruses and ‘Anti-Virus’ became the in-word when it came to computers, because the last thing you wanted was for someone to cause damage using a virus program.

Since then, criminals have jumped on board the malicious software scene and big money can be obtained from data – especially yours.

Increasingly the media are telling us that there are more threats than basic viruses now, things like ‘Ransomware’ (a malicious program which encrypts your files so that you cannot access them again without payment), software aimed at stealing your credit card and identity data, telephone scams using remote software, plus others.

Protection – what can you do?

Clearly, if you want to go on the internet you do need anti-virus protection but unfortunately, protection from free programs is not enough these days. Yes they are definitely better than nothing, but you have to ask yourself if big corporations such as Yahoo and TalkTalk can get hacked, maybe minimal protection compared to paid-for protection, is not the way to go.

A good paid-for security suite is the minimum these days and even then, you have to be careful about what websites you visit, emails you open and what you download.

The One Anti-Virus Rule

Traditionally, the rule has been that you must only have one anti-virus program running at any one time on your computer. To have two anti-virus programs was definitely not recommended, as they compete with each other and at the very least slowed your computer to a crawl, if not actually corrupting your data. We have come across many computer systems with two or more anti-virus programs which have caused problems. That was up till now.

There is now a product called Malwarebytes, which has been designed to actually run alongside your traditional anti-virus program, without causing the problems as before. It compliments your current protection by looking for the ransomware / malware-type of threat and assists in the protection of your system by concentrating on the non-traditional danger to your computer, without causing problems having two protection programs.

As it is a paid-for product it runs in real time, bolstering the protection of your system. As the threats particularly of Ransomware are becoming a problem, especially for businesses, it is recommended to seriously think about adding to the scope of your protection.

Ultimately, no protection system is guaranteed 100% effective as they are always catching up with the “bad guys”, but it is worth considering whether or not one protection program is enough these days, bearing in mind online banking and other day-to-day internet use that involves sensitive personal and financial information.

If you do decide to go down the additional protection route, we can supply Malwarebytes at below retail prices, so if interested give us a call on 01455 209505.

Share..Share on FacebookShare on Google+Tweet about this on TwitterShare on LinkedInPin on PinterestPrint this pageEmail this to someone