Rate Us:

Synapse Blog

Stay updated with the latest IT insights from Synapse IT Consultants in Victoria. Explore cybersecurity, cloud, and business tech tips. Read our blog now!

IT Security Banner
Latest News, Security

Notifiable Data Breach legislation – What you need to know

Many small businesses still do not understand, or pay attention to, the Notifiable Data Breach scheme introduced by the government in 2018. This is a summary of the scheme and why it matters to you.

Firstly, what is a “data breach”?

A data breach is when data, or information, could have been accessed by someone that is not supposed to have access. Some examples of data breaches are:

  • You accidentally email a file to the wrong person
  • Your laptop or mobile phone gets stolen
  • You leave your computer on and logged in while you wander off to do something else
  • You store files in a cloud based storage system that is not properly secured
  • A hacker breaks into your company’s server over the internet and downloads your files

Clearly breaches can be accidental, malicious, or anything in between but they do happen all the time.

Why did the government decide to change the legislation?

We are in the information age. People you deal with are actively collecting and storing information about you. Big companies like Facebook and Google collect information, and even retail stores ask you to share information in return for joining their loyalty program. Every business has data about customers, partners, suppliers and employees.
Hacking and stealing this data is big business, to the extent that cyber crime is now the largest form of organised crime in the world.
Prior to the introduction of the NDB scheme, in many cases if an organisation that held your information had a data breach they did not need to tell anyone about it. Your information could be being used against you, for identity theft for example, and you would not know. With no accountability, the holder of the data does not have much incentive to improve their systems.

What is the NDB Scheme?

The NDB Scheme is legislation that is part of the Privacy Act. It makes organisations more accountable for the data they hold. Organisations are required to take steps to protect data and are also required to notify the government and other impacted parties if they have an notifiable data breach. The NDB Scheme also provides penalties for non compliance.

Which organisations are covered by the NDB Scheme?

Broadly, any organisation turning over more than $3 million must comply. There are also some sectors such as health services or credit providers that must comply.

How would I know if I have been breached?

If you have any reason to suspect a breach you must perform a “reasonable and expeditious” assessment to confirm or discount the breach, and identify what information has been breached. There is an expectation that organisations will have reasonable practices, procedures and systems in place to protect data and allow for prompt assessment of any suspect activity.

Do I need to report every breach?

Organisations only need to report “notifiable” data breaches. Typically these are serious breaches that may cause harm to the people whose data has been breached. If confidential information, or personally identifiable information such as names, addresses, credit card info, tax file numbers, financial details, etc, are leaked this could be considered a notifiable breach.
Other less serious breaches do not need to be notified.

Who decides what breaches are notifiable?

Ultimately the responsibility to decide whether a “reasonable person” would think that a breach would result in serious harm lies with the breached business, however the OAIC has some guidelines.
We suggest that at a minimum, you need to have a few things in place to be able to make this determination. You need to:

  • Have systems in place to detect a breach and identify what data was accessed.
  • Know what data you have, where it is, and how sensitive it is.
  • Have an incident response plan prepared in advance so you know what to do in the event of a breach.
  • Have a legal advisor who can provide formal advice about your obligations.

What happens if I don’t report a breach?

The penalties for not complying with the NDB are specified in the Privacy Act. Currently, the act allows for monetary penalties of up to $1.8 million for organisations and $360,000 for individuals. In addition to penalties, the Commissioner may investigate non compliance and require the organisation to pay compensation to affected parties.
If organisations do not have appropriate systems and procedures protections in place, this may be viewed as a breach of the directors’ duty of care and therefore company directors may also personally face penalties.

Who can assist with this?

The Office of the Australian Information Commissioner publishes significant amounts of information on these topics at https://oaic.gov.au.
Ultimately, we suggest discussing this with an appropriate legal advisor to ensure you are aware of your obligations. We can, of course, assist with helping you to define and improve your cyber security posture.

In Summary

Businesses are now more accountable for protecting data that they store. At a minimum, you should be aware of how your business is protecting it’s data, how you would detect a breach when one occurs, how you would determine the extent of the breach, and what steps you would take to mitigate and notify as required.

Business professional presenting tablet with upward growth chart, symbolizing IT-driven business success
Latest News

Inquiring SMBs Want to Know… What’s the Difference Between a Help Desk and NOC?

Inquiring SMBs Want to Know… What’s the Difference Between a Help Desk and NOC?

It’s no secret that any growing small-to-medium sized business must monitor and manage its business technology in the most cost-efficient way. The tricky part is figuring out how to do this without sacrificing the overall experience of the end-user. End-users can be clients and customers or employees. Both rely on the efficiency of a firm’s network, servers, and applications, and the availability of the company’s data center.

Thanks to the evolution of managed services, it’s actually possible these days to reduce costs, which strengthens IT support and infrastructure. It’s just a matter optimally integrating all available resources.

It’s a Staffing Conundrum for Most SMBs

Most SMBs tend to be short staffed. This isn’t just another reference to the many SMBs with little to no onsite tech support. While that’s true, and problematic, it’s actually all operations that tend to be short staffed.

Small yet growing companies and organizations aren’t just short on tech support; it seems like even their administrative assistant needs an assistant to keep up. Customer support and sales teams are also overworked, and often hindered by having to understand and troubleshoot tech problems when they have no tech expertise whatsoever.

There is no, “Hold for a moment, Sir. I’m about to transfer you to our tech support team.” There is no tech support team.

This is where managed service providers (MSPs) step in to save the day. MSPs help SMBs better manage their technology to achieve greater ROI (Return-on-Investment). One way they do this is by augmenting a SMBs existing on-site staff with the remote support of a 24/7 Network Operations Center (NOC) and Help Desk.

What’s the Difference Between a NOC and Help Desk?

This question is asked a lot because it’s really not uncommon to see both referenced interchangeably, which leaves many to assume they are one in the same. They are not. Here is the easiest way to distinguish between the two.

NOC: Most of the work performed by a NOC focuses on the network and systems. The NOC can almost be viewed as a mission control center. They monitor and manage an IT network. A 24/7 NOC typically monitors the network and system security, performance, and backup processes.

Help Desk: The Help Desk is more customer-oriented. The Help Desk has interaction with the end-user, or someone representing the end-user, to directly respond and resolve technical problems as they arise. Customers or employees can typically reach the Help Desk by clicking a support icon, emailing them, or dialing a toll-free number.

Do the Help Desk and the NOC Interact?

Although the NOC and Help Desk are different, they do work together, along with any in-house tech support, to provide cohesive tech solutions to end-users. The Help Desk typically has three tiers of support and may sometimes have to escalate tickets to the NOC for resolution.

This open communication, and ease of escalation, improves the end-user experience and serves as a proactive cost-efficient approach to managing SMB technology.

Contact us at Synapse IT Consultants Pty Ltd

Hand touching digital cloud computing icon with technology service symbols representing cloud solutions
Latest News

Understanding Managed Services and How They Benefit SMBs

Understanding Managed Services and How They Benefit SMBs

Small to medium sized businesses (SMBs) receive a lot of calls each day from slick sales people peddling the next technology trend that’s going to save them money and revolutionize how they do business. They’re all too quick to caution that if you don’t listen to them, you’ll fall behind the times, and eventually be swimming in a sea of debt and out of business.

No doubt you’ve heard, or you’ve at least read about, the benefits of managed services. Managed services refer to clearly defined outsourced IT services delivered to you at predictable costs. You know the exact IT services you’ll be getting and what you’ll pay for them. There is no surprise sky-high bill for services rendered. So are solicitation calls that pertain to managed services worth listening to? We think so. Then again, we’re in the managed services industry. There may be a bit of a bias here.

How Managed Service Providers Work

Managed service providers (MSPs) use remote monitoring and management (RMM) tools to keep an eye on their performance and overall health of the IT infrastructure that powers your business operations.

Your MSP should have a 24/7 Network Operations Center (NOC) that acts as your mission control center. If the monitoring alerts them to any issue with your servers, devices, hardware or software, they respond quickly to resolve the issue.

Additionally, the NOC performs regular systems maintenance such as

  • Automated tasks like the cleaning of temporary files
  • Applying tested security patches as required
  • Installing virus and Malware protection
  • System backup and disaster recover/business continuity processes
Additionally, your MSP should give you access to a Help Desk that services your customers and employees – speaking to and working with them directly as if they’re part of your staff.

This proactive maintenance, stabilization of your IT environment, and rapid as-needed remediation helps SMBs control technology costs and better serve the end-users who rely on their technology.

Is Managed Services Better than Other Ways to Manage IT

We find that far too many companies have no real perspective about how much IT management costs them. Let’s review some of the alternatives to managed services.

Hiring In-House IT Support

Typically, a firm with anywhere from 20-60 employees may feel that one person can manage their technology. Understand that this one full-time employee can demand a significant salary since they’ll have to be proficient with desktop, server and network support, and interact with both end-users in the Help Desk role and management. They will likely be overworked and vulnerable to error or oversights that may prove to be costly. And what happens if they’re out sick or on vacation?

The Break/Fix Mentality

The majority of smaller companies take this route because they feel as if they’re too small for a more sophisticated 24/7 approach to IT management. They also feel pressure to direct all resources on the product or service, not behind-the-scenes operations. They decide to use on-call IT techs when broken technology has already disrupted business. The on-call team’s response time and overall lack of familiarity with your systems extends downtime and proves to be a much more expensive resolution to IT management. It’s reactive, not proactive, and it’s a costly mistake too often made.

This is why many SMBs today feel that managed services are the most cost-effective way to support their IT infrastructure and the best way to get more bang for their buck.

Contact us at Synapse IT Consultants Pty Ltd

Close-up of financial stock market chart analysis with pen pointing at data trends
Latest News

Are Managed IT Services Right For You? A Few Things to Consider

Are Managed IT Services Right For You? A Few Things to Consider

How do you get a small business to recognize the value of manages IT services? In the start-up environment, we encounter an eclectic bunch of personality types. There is a reason people become entrepreneurs or C-level execs. When we meet the owners or decision makers at smaller companies and organizations, we can tell right away why they’re where they are. They’re visionaries. They’re risk takers. They’re competitive. They want to be in charge.

Therefore, they aren’t always quick to place the fate of their business technology in the hands of a third party. They’ve come as far as they have by being in control and they’re hesitant to give up that control. But we’ve learned a few things along the way.

For example, the Type A personality is highly independent but also very competitive. So we tap into the competitive advantage that managed IT services gives them.

The Type B personality is creative and doesn’t like static routines. But their ears perk up when they hear terminology like “cutting-edge” and we can then paint the big picture for them once their listening.

But anyone we do business with has to be committed to the efficiency, security, and stability of their business technology to see our value proposition. And they have to recognize that managing their IT infrastructure is an investment they cannot take lightly.

So here are a few things we commonly have to address before any deal for managed IT services is signed.

Is my business large enough to even consider managed services?

The truth is, any company, regardless of its size or the number of people they employ, will run more efficiently if its technology is monitored, maintained, and managed properly.

These are facets of your operations that drive profitability and give our Type A personalities that competitive edge they crave. And they can rest easy whenever business is booming because their technology is built to sustain their growth. That’s the big picture that our Type B personality can appreciate.

How is making another IT investment a cost-savings move for my business?

There are still many SMBs who feel a greater focus and investment should go towards their core operations or marketing and sales. They only worry about technology when it breaks, figuring they’ll just call a service technician to come to the office and fix whatever the problem is. Or buy some new hardware at Office Depot.

There are some very obvious flaws to this strategy.

  • You’re paying way too much when it’s way too late – An issue that was likely preventable with early detection has escalated into a full blown business disruption and that on-call technician likely charges a high hourly rate, on top of hardware replacement costs, and may not get to your site right away. Being proactive rather than reactive to technology issues is important.
  • Don’t forget productivity killers – It’s taking your employees too long to boot their computers. Servers and applications are running slowly. Employee devices are full of Malware. Non-technical employees are running around troubleshooting tech problems. If you see this, your present approach to IT management is killing employee productivity and your bottom line.
  • What happens internally is noticed externally – Don’t think for a second that customers or clients don’t notice outdated or slow internal technology and mismanagement. If your site or applications are down often, run slowly, or your customer service rep tells them “I’m sorry, our system is down”, they’re noticing and it’s hurting your business.

When all is said and done, professionally managed IT services will give you a competitive edge, guarantee your business is always leveraging the newest most cutting-edge technology, and enhance your relationships with customers and clients – all while reducing costs.

Contact us at Synapse IT Consultants Pty Ltd

Global network connectivity illustration showing interconnected devices around the world
Latest News

Breaking News: Downtime Kills Small Businesses

Breaking News: Downtime Kills Small Businesses

Downtime is bad news for any business whether big or small.

A recent two-hour New York Times’ downtime occurrence sent Twitter ablaze and their stock price plummeting.

Google going down for one to five hours resulted in lost revenue up to $500,000 and decreased overall web traffic by 40%.

We know what you’re thinking. Holy crap, Google makes $100,000 an hour? Yeah… insane, huh?

While the hourly cost of downtime for a small-to-medium sized business won’t be nearly as large as that astronomical Google figure, downtime is often more detrimental to smaller companies. Smaller enterprises are more susceptible to downtime and are neither large nor profitable enough to sustain its short and long-term effects.

Downtime Leads to Unhappy/Unproductive Employees

Even the happiest of employees become dissatisfied when they can’t perform basic day-to-day job functions or properly service customers or clients.

While some employees may use downtime as an excuse to lean back, put their feet up, and comfortably collect their hourly pay, we’re talking about those employees who come to work to actually work.

And don’t forget your IT guy or tech crew. They can’t necessarily sit back and twiddle their thumbs when downtime occurs because they’re typically taking the brunt of the storm. They will ultimately grow tired of the daily routine of having to put out fires and having neither the additional manpower nor resources to change things for the better.

These things lead to high employee turnover and the expenses that come with training and re-training a revolving door of employees.

Downtime Leads to Customer Dissatisfaction

Customers and clients grow weary whenever critical components of your operations – or the services they either expect or pay for – cannot be accessed.

Nearly 50% of customers will move on to a competitor if they encounter downtime of five minutes or more. These customers represent significant lost revenue.

While some suggest this is a bigger problem in the retail sector, other types of businesses are impacted as well. Have you ever clicked a link from search engine results only to quickly bolt when the page didn’t load, you couldn’t complete an online transaction, or you were greeted with a “Technical Difficulties – Be Back Up Soon!” message?

Did you give up on finding what you were looking for or did you wait it out? You did neither. You went back to Google and found someone else offering a similar service or product that satisfied your yearning for instant gratification.

Downtime Ruins Your Reputation

One of the most commonly overlooked consequences of downtime is the hit your company’s reputation takes online. In this age of social media, one person’s bad experience is broadcast to dozens or even hundreds of followers. Bad news spreads faster than ever and has lasting repercussions.

“It takes 20 years to build a reputation and five minutes to ruin it. If you think about that, you’ll do things differently.” — Warren Buffet.

Protect Your Bottom Line

The challenge for small businesses has always been how to minimize single-point-of-failure downtime using their limited IT resources. This is why downtime kills so many small businesses. They can’t prevent it and they can’t react quickly enough.

Thankfully, there are end-to-end business continuity solutions available today that integrate Remote Monitoring and Management (RMM) software, 24/7 access to a Network Operations Center (NOC), and advanced backup and disaster recovery solutions to alleviate this issue.

Not only do these methods minimize downtime and get businesses back up and running quickly, but they can reduce the cost of technology infrastructure maintenance by as much as 80 percent.

It’s time that small businesses stop being victims to the silent killer that is downtime.

Contact us at Synapse IT Consultants Pty Ltd

Hand touching digital cloud computing icon with technology service symbols representing cloud solutions
Latest News

8 Hard Truths for SMBs not Worried About Data Recovery and Business Continuity

8 Cold Hard Truths for SMBs Not Worried About Disaster Recovery and Business Continuity

The foundation of any successful business continuity solution is the ability to retrieve data from any point in time from anywhere. When the topic of data recovery and business continuity comes up, you get the feeling that many decision makers at smaller businesses and organizations wish they could channel their inner six year old, simply cover their ears, and sing “La, la, la. I Can’t Hear You. I’m Not Listening.”

Everybody thinks bad things only happen to other people. Just because we hear about a fatal car accident on the morning news, doesn’t mean we fixate on that news when we ourselves get into a car and drive to work.

So no matter how many times the owner or executive of a small to midsize business (SMB) hears of other small businesses being crippled by hurricanes, tornados, fires, or flooding, they aren’t necessarily overcome with fear to the point that they feel an urgency to take action.

Sure, they may think about backup and data recovery solutions a little more that day, but not enough to initiate immediate change or reverse a lenient approach to their processes.

If you fall into this category, here are eight cold hard truths to consider

  • It isn’t natural disasters or catastrophic losses like fires that take down small businesses but something far more sinister – malware. Cyber attacks through malware have grown exponentially in the past four years. Malware is hitting everything from PCs to Macs to mobile devices and it’s inflicting damage.
  • Over half of the small businesses in the U.S. have experienced disruptions in day-to-day business operations. 81% of these incidents have led to downtime that has lasted anywhere from one to three days.
  • According to data compiled by the Hughes Marketing Group, 90% of companies employing less than 100 people spend fewer than eight hours a month on their business continuity plan.
  • 80% of businesses that have experienced a major disaster are out of business within three years. Meanwhile, 40% of businesses impacted by critical IT failure cease operations within one year. 44% of businesses ravaged by a fire fail to ever reopen, and only 33% of those that do reopen survive any longer than three years.
  • Disaster recovery solution providers estimate that 60% to 70% of all business disruptions originate internally – most likely due to hardware or software failure or human error.
  • 93% of businesses unable to access their data center for ten or more days filed for bankruptcy within twelve months of the incident.
  • In the United States alone, there are over 140,000 hard drive crashes each week.
  • 34% of SMBs never test their backup and recovery solutions – of those who do, over 75% found holes and failures in their strategies.

It’s critical that small businesses review their backup and disaster recovery processes and take business continuity seriously. Given the vulnerabilities associated with the cloud and workforce mobility, the risk of critical data loss today is quite serious and firms must be truly prepared for the unexpected.

Contact us at Synapse IT Consultants Pty Ltd

Contact Us Today

Reach new heights in your industry through beginning the transition to managed IT solutions.

What can we do better?

We love to hear from our clients, please let us know if there are any areas that you think we could improve upon.