One of the best online resources for cyber criminals is Google. While businesses seek to utilize their company website, Facebook, Twitter, LinkedIn, and the like for marketing and recruitment purposes, they are unintentionally leaking information that can be useful to cyber criminals. At the same time, their employees are also guilty of both disclosing more details about their job duties as well as connecting to and friending people based on invites without any due diligence.
For businesses, below are some typical areas where internal information is disclosed:
Press Releases: Expanding your business? Offering a new product? That is great and something to brag about. But pick and choose what details you make public. Let's say you are offering a new product or service, and you bought a new piece of equipment to provide it, or have a new vendor to help you support it. If possible, don't name business partners or describe any new additions of equipment by name. While these details don't sound like anything of importance, internal details can be used in spear-phishing to gain the trust of your employees. Let's say you name your new business supplier (XYZ Corp) in your press release. A few weeks later an e-mail is sent to your accountant that appears to be from XYZ Corp saying they just changed banks and to use the below banking information to pay future invoices. You figure out that it was a phishing e-mail when XYZ Corp starts calling you because of all the unpaid invoices, and now you are out the money.
Job Postings: One of my pet peeves is all of the information you can glean from an organization's job postings. An example is if your company is hiring a Database Administrator, you don't have to say in the posting "Must be experienced with MS SQL Server 2008 R2 Express" This tells the public what version of your database you are running, and what security issues you may be vulnerable to. Simply saying "Must be experienced with MS SQL Server" will suffice.
Vendor Endorsements: I never give public vendor recommendations (posted on the vendor's website). Why? Because I don't want anyone knowing too much about the inner workings of my business, such as my vendors. The reason being is that a cyber criminal can use that relationship to try to spear phish either company. Also, this may not be something you want your competitors to know about either. If you have a really good vendor relationship and they want a recommendation, offer to give one-off personal recommendations. Just don't put it out on the web for the world to see.
Website Contacts: If possible (granted it is a must for some industries), do not have a directory of your employee's names and contact information on your company website. This is a treasure trove for cyber criminals for both phishing e-mails as well as scam phone calls. Use generic contact e-mails in your Contact US sections such as sales@xyzcorp.com, or even better is a contact form that does not disclose company e-mail addresses.
Tips for your employees:
Social Media: Encourage your employees to leave their job duties generic when updating their LinkedIn profile or online resumes. If you are an Accountant for a business, that is great. You don't have to put on LinkedIn that you handle all of the business's banking, send wire transfers, or are familiar with Wells Fargo's business banking portal. This is way too much information to be giving out to potential cyber criminals and can be utilized in a Business Email Compromise (BEC) or spear -phishing attack. Save the details for the resume you submit to a potential employer. The one you publicly post should be a summary.
Technology questions using company e-mail address: Technology folks will often visit tech blogs and websites soliciting information and knowledge regarding a problem they are trying to resolve. This is all well and good, but sometimes they post detailed questions that disclose the names/versions of systems and applications using their company e-mail address, and therefore identifying the organization with the problem. Information about current IT issues (whether security related or not) should not be publicly disclosed. It's not something you want hackers to see, and it doesn't look good to current or future customers to see.
Be Secure!
@tjmprofessional
Showing posts with label online brand. Show all posts
Showing posts with label online brand. Show all posts
Tuesday, October 16, 2018
Information Leakage - Using the Internet Judiciously
Monday, December 4, 2017
Google thy self,,,,and often
Two cyber risks that can impact both individuals and
businesses is information leakage and online damage to your brand.
Information leakage is where private information about you
has found its way onto the Internet.
Examples could be your passwords, bank account information, unlisted
phone numbers, photos, videos, private documents, etc.. In my career, I have found scanned
copies of checks, credit cards, medical records, marketing plans and drivers licenses that where either inadvertently
posted to a public section of a website, or the website was supposed to have been secured, and wasn’t. In addition, when cyber criminals either
obtain someone’s userID/e-mail and password, they tend to post it on a hacker
password listing site. For businesses,
you would be surprised how many times your employees inadvertently post
sensitive information online. Many times
it’s an IT employee posting on a technical site seeking guidance from
peers. Unfortunately, more times than
not they post using their company e-mail address which identifies the
organization, and then in their posting, they disclose which version of the
system/application that they are seeking advice on, and potentially a security vulnerability. If your organization doesn't already have one, a Policy regarding posting on public forums, comments sections, reviews, etc. using your company e-mail address, should be drafted ASAP to forbid this practice.
Online damage to your brand can negatively impact your
reputation which can cause you to miss opportunities (jobs, customers,
partnerships, hiring talent, etc.).
Negative reviews, ratings, stories could be the result of disgruntled
current/former employees, dissatisfied customers, or your competitors. Identifying what is out there, and then
determining why and who will guide you in how to resolve any negative posts
about you and/or your organization.
To see if you or your organization is currently exposed to
these risks, a good practice to get into is to Google yourself and your
organization at least monthly. What you
want to find out is what does the rest of the online world see when they are looking you up online. As an
individual, this could have an impact on job applications, college acceptance, business opportunities and applying for credit. For an organization, it could impact customer growth, revenue, recruiting talent, and investment.
On Google, use the following search strings (using the
quotes):
- “Your Name”
- “Your organization name”
- “@your domain” (your organization’s e-mail) – This will show you all company e-mail address postings
On IXQuick you can do some more sensitive searches as
IXQuick does not share your search strings with online marketing companies:
- “Your e-mail address”
- “Your phone number”
- “Your e-mail address : * ” – This will show you if your e-mail password has been posted online.
- “Your company userid : *” – This will show you if your company login credentials have been posted.
- You could also search on variations of your SSN or TIN, ie. “All numbers” or with dashes.
The asterisk “ * “ is a wildcard
which may give you back your userid and your password if it has been
compromised.
In addition, for businesses, you should look at your
organization’s reviews and ratings on Google, BBB, Glassdoor, and all of your
social media sites or any other websites you advertise on that offers ratings
or reviews.
By doing this, you can stay on top of any private
information that is posted, and hopefully contact those sites Web Admins to
have erroneous information removed, and be aware of reviews, ratings, and
complaints against your organization and respond to them timely and
professionally.
Remember, a customer
complaint needs to be converted into an opportunity for improvement, and always
take the high road as your responses will be viewed by future potential
customers, employees and investors.
Subscribe to:
Posts (Atom)