Synapse Blog
Stay updated with the latest IT insights from Synapse IT Consultants in Victoria. Explore cybersecurity, cloud, and business tech tips. Read our blog now!
- 5 min read
- 5 min read
- Freed-Up Resources and a Renewed Emphasis on Core Business – Both business owners and internal IT staff would much rather focus on revenue enhancing tasks like product development or the creation of cutting-edge applications/services. This is one reason routine monitoring and maintenance tasks are often neglected by an internal IT person or team, which always proves to be detrimental much later.
- A True Partner Sharing Risks And Responsibilities – The goal of an MSP is to deliver on contracted services, measure, report, analyze and optimize IT service operations, and truly become an irreplaceable catalyst for business growth. Managed Service Providers not only assume leadership roles, they enable risk reduction, enhance efficiency and change the culture by introducing internal IT operations to new technologies and processes.
- Access to Expertise, Best Practices and World-Class Tools and Technologies – MSPs have experience with a variety of businesses and organizations. Managed Service Providers can keep your business relevant and on track with continually evolving technology, support, and productivity demands. Let’s face it, no small or medium sized business can afford to fall behind with technology trends in today’s business world.
- The Benefit of a Full-Time Fully Staffed IT Department at a Fraction of the Cost – Most small business owners live and die by proactive management. They just haven’t had the budget, resources or access to on-demand expertise to be proactive with information technology management. A Managed Service Provider gives business owners and overwhelmed internal IT staff affordable computer and server support, remote monitoring of critical network components like servers and firewalls, data backup and disaster recovery, network security, custom software solutions, and technology evaluation and planning.
- 5 min read
Think Quicker Recovery Time, Not Quicker Backup – While incremental backups are much faster than executing a full-backup, they also prolong recovery time. In the event of data loss, a full restore will require loading the most recent full backup and then each incremental backup tape. Having too many incremental backup tapes not only adds time to this restoration process, but it also increases the probability of not recovering all of your data. A tape could be lost, unintentionally skipped over, or contain corrupted data. Be sure to focus on optimizing the restore time to ensure faster data recovery. A quicker recovery time should be the main objective, not the need for a quicker backup process.
Maintain Sufficient Backup History – Within the blink of an eye, current data files can become corrupted and inaccessible. This will necessitate the loading of an earlier data backup that is clean of corruption. Many smaller companies make the mistake of failing to keep a sufficient backup history.
Be Sure to Backup Essential Data AND Applications – Some businesses don’t feel the need to backup all data, but be sure essential databases, documents and records are backed up frequently. Don’t overlook applications that are critical to day-to-day business operations either. Many companies fail to backup applications, only to realize when it’s too late that they don’t have access to the original installation disks when they’re trying to recover from data loss or an outage.
Have Off-Site or Online Backup – Some businesses backup data simply by moving essential files to tapes or external hard drives that are then stored somewhere onsite. But if they’re kept onsite, what happens if a fire, flood or other natural disaster takes out not just your server but your backup tapes and drives? Onsite backups can also be susceptible to theft. Having secure off-site, or even online backup, is simply the smart thing to do to ensure quick recovery when trouble comes to town.
Fix Broken Access Controls on Your File Server – Many businesses have folders with confidential data residing on a file server with overly permissive access controls. Why take the risk of having a disgruntled – even former – employee access and misuse this data when access can be limited to only those in the company who need it?
Be Sure to Test Restores – It happens time and time again. Business owners think they have a data backup plan in place. Tapes are changed diligently each day and everything appears to be backed up and good to go. However, it turns out the backups haven’t been working for months, sometimes even years, right at the very moment they’re needed. Either the backups had become corrupt and useless or large segments of data were not being backed up. This happens often. Don’t let it happen to you.
- 5 min read
Many SMB owners think IT downtime only costs them a few productive hours, but there’s a lot more at stake when your systems go down. Customer satisfaction and loss of brand integrity are just two of the key losses apart from the more evident costs such as lost productivity and a temporary dip in sales.
Here’s a few other ways downtime can hurt your business:
1. Customer Loss – Today’s buyer lacks patience !important; They are used to getting everything at the click of a mouse, at the tap of a finger. Suppose they are looking for the kind of products/services that you offer and your site doesn’t load or is unavailable—even if temporarily– you are likely to lose them to a competitor—permanently.
2. Damage to Brand Reputation – Customers are now using Social media platforms like Facebook and Twitter and blogs to vent their bad brand experiences. Imagine an irate customer who doesn’t know if their card was charged on your site, or not, due to a server error. If it’s your bad day, they could probably be using Facebook or Twitter to share their bad experience, and it could be viewed by hundreds of people, causing irreparable harm to your brand image.
3. Loss of Productivity – When your systems don’t work, this can have a direct impact on your employees’ productivity. Consider a research firm of 200 employees where they primarily rely on internet connectivity to access the knowledge base. If the server hosting the knowledge base is down, there’s a total loss of at least 1600 work hours for one day.
4. Overtime, Repair and Recovery, Compensatory costs – In the above case, imagine the overtime wages the business would have to incur if they were to make up for the work loss they faced owing to downtime. In addition, there’s always the cost of repair—the money the business would have to shell out to fix the issue that caused the downtime and get the server up and running again.
In some cases, businesses would have to incur additional costs to make customers happy. These could include giving away the product for free or at a discount, or using priority shipping to make up for a delayed order.
5. Possible Lawsuits – Businesses could also be at the receiving end of lawsuits. For example, a downtime that has an impact on production, delivery or finances of the customer could invite litigation.
6. Marketing Efforts Rendered Useless – Consider a pay-per-click advertisement that shows up for the right keywords on Google, or an extensive e-mail campaign that your business engages in. However, when the prospect clicks on the link, all they see is an error message – Isn’t that a waste of your marketing budget?
The bottom line—one natural disaster, one technical snag or just one power outage has the power to put you out of business – both virtually and in reality. It’s probably time to think about how you can mitigate the threat of a possible downtime and whether your MSP can act as an effective and efficient ally in this battle for you.
- 5 min read
Some people think that search engines allow them to access all the websites on the internet. Do you think the same?
Google and other search engines don’t give access to all the websites on the web. They barely allow you to scratch the web’s surface. Below this outer surface lie the internet’s many hidden layers – those that cannot be found through ordinary search. These hidden layers are called the “dark web”. The name sounds intimidating, right? Let’s take a look at what dark web is and what you can find once you access it!
Dark Web
The web is divided into three parts. The first part is called the surface web which includes normal websites that can be found through search engines. The second is the deep web that includes websites that search engines cannot index or present in search results. Online banking sites are examples of deep web websites. The third part is the dark web. Dark web is completely different from the other two parts as it can only be accessed through specialized browsers.
Dark Web Users
Dark web provides complete anonymity to users, which is why it is popular among certain parties who wish to keep their identity hidden. This tool is used for illegal and shady activities like sale of firearms, drugs and child pornography.
Silk Road was the first black market on the dark web. It led to the creation of other black market websites. The authorities shut down Silk Road in 2013. The founder of the website was also arrested and sentenced to life in prison. Many similar websites are still operating on the dark web and authorities haven’t taken any action against them yet.
Dark web isn’t just used for nefarious purposes. It also supports many conscientious actions. For example, Edward Snowden, the former NSA employee and later whistleblower, exposed United States government’s mass-surveillance program by sending information to media outlets and reports through dark web. Dark web is also used by activists and journalists to avoid getting traced by people who would want to cause them harm. In some countries, users aren’t allowed to access specific social media platforms and websites. Dark web can be used to access those restricted websites.
Entering the Dark Side of the Web
Dark web is mostly accessed through a browser called Tor. Tor allows users to access sites on the dark web which have a .onion domain at the end of their web address. These websites are not accessible through normal web browsers.
In addition to Tor other browers like I2P or Freenet can be used to access websites on the dark web. Tor and other browsers enable users to access deep and dark web sites while keeping their identity anonymous. However, it is important to note that Tor won’t protect users from malicious content on websites. Therefore, you should be careful when accessing dark web sites through Tor.
- 5 min read
Synapse is excited to announce that we are now a Datto Professional Partner. Being part of the Datto Professional Global Partner Program means we can help to protect essential business data for our customers, while delivering uninterrupted access to data on-site, in transit and even in the cloud. This service is an integral part of any Business Continuity plan.
So what is Business Continuity and why is it Important?
Business Continuity is about having a plan to deal with difficult situations that may arise within your business such as flood, fire, theft, cyber attack or hardware failure. It’s important to ensure your organisation can continue to function and is protected with as little disruption as possible when a difficult situation arises. Your plan should help you to:
- Identify and prevent risks where possible
- Prepare for risks that you can’t control
- Respond and recover if an incident or crisis occurs
Make a Plan
A good Business Continuity plan is the first place to start when thinking about BC. You need to ask yourself, how long would your business be down for in case of fire, theft, flood or hardware failure? How much time, data and money would you lose? A plan recognises any potential threats to an organisation and provides an analysis on the impact that threat may have on day-to-day operations of the business. It also provides you with a way to alleviate these possible threats by putting in place a framework to allow key functions of the business to continue operating and re-establish full function as quickly and smoothly as possible.
Key Elements – Resilience, Recovery and Contingency
A Business Continuity plan should have these three key elements:
- An organisation can increase their resilience by designing critical functions and infrastructures with different disaster possibilities in mind. This can include functions such as staffing rotations, data redundancy and maintaining a surplus or stock or capacity.
- After a disaster, rapid recovery to restore business functions is vital. Setting recovery time objectives for different systems, networks or applications can help to prioritise which elements need to be recovered first.
- A good contingency plan should have procedures in place for a variety of external scenarios; these can include a chain of command that distributes responsibilities within the organisation. These particular responsibilities can include hardware replacement, leasing office spaces as well as damage assessment.
For more information on how we can assist you with your Business Continuity plan, please contact Synapse here.
- 5 min read
The ‘chronic failure’ to use secure passwords has grown increasingly concerning for individuals and companies alike. Password hacking software now enables passwords, thought to be safe, to be unscrambled within seconds.
We have compiled the top reasons why implementing a complex password policy is vital for your protection and exactly how to put it in place.
The most common passwords
According to Keeper Security the most common passwords of 2016 included ‘123456’, ‘qwerty’ and ‘password’, while approximately 50 per cent of people use the top 25 most common passwords. Shockingly, data reveals this list has remained relatively unchanged over the years, showing user understanding on the importance of complex password policies remaining limited.
The two main types of hackers
Although hackers differ in the methods they use to access your personal information, you can definitely educate yourself about the two main types of hackers.
Opportunistic
The motivation behind opportunistic hackers often lies behind simple boredom and the quest for notoriety, rather than a fixed goal. Such hackers often target a large group of people, adopt simple and well known hacking methods, yet make little attempt to conceal their actions. Trustware revealed the main warning signs you are being targeted by an opportunistic hacker include ‘missed delivery’ spam and phishing emails.
Planned
Planned security attacks, however are targeted attacks on a specific organisation or person. These attackers use modern and sophisticated hacking methods to cause damage and steal valuable data. Planned hackers go to great lengths and time to conceal their actions and are often experienced individuals who are motivated by high monetary gain. How do you know if you’re being targeted by a planned hacker? These individuals often call up companies imitating a specific person affiliated with the company and requesting information.
The 4 most common hacking methods
Brute-force attack
Brute-force attacks use automatic computer programs to decrypt files by calculating every password combination possible, at an incredibly fast rate, until correct. Used against any type of encryption, as updated and faster computer hardware becomes available, these attacks become more efficient and successful.
Dictionary crack
A dictionary attack occurs when a large list of words are entered into a software program in an attempt to generate a password. These attacks are incredibly popular as individuals and companies leave themselves vulnerable by choosing weak and common words as passwords. These attacks also occur through email spamming techniques whereby large amounts of emails are automatically generated and sent to random addresses in the attempt to spontaneously reach real email addresses.
Phishing
Seemingly obvious to avoid, phishing attacks are incredibly common whereby hackers simply ask users for their passwords. This most commonly occurs through emails claiming to be online banking requiring you to login and provide information. Banks will under no circumstances require you to provide such details over email, yet many unsuspecting individuals often fall trap to this hacking method.
Social engineering
An extension of phishing, social engineering occurs externally to online methods. In these cases, hackers actually call or come face to face with users, while impersonating someone affiliated with the business. The most common impersonation is that of an IT security tech, who calls the business and claims to need passwords to alleviate a security issue.
Most important things to include in your password policy
Due to the enormous security threats associated with a poor password, it is clear a company’s best interest is to implement a complex password policy. Although it would be ideal if website operators enforced basic password complexity policies, research shows the majority fail to do so. Therefore, the ultimate responsibility lies within the user to protect themselves with a secure password.
Create a strong password
The passwords most resistant to hacking are those made up of a mix of numerical, uppercase, lowercase and special characters, opposed to common words and simple number sequences. These passwords are incredibly effective against dictionary attacks as they are not common words and considerably slow down the efficiency of brute-force attacks. For example, create a password out of a complex sentence, which can even be about yourself! “I am 30 and work in IT’ can be translated to ‘Ia30awiIT’. This is considerably safer than your name and your profession.
Two-factor authentication
Ensure login processes include this multi factor authentication, which requires not only a password but another external piece of information that can only be accessed by the correct user, such as a phone number.
Different passwords for logins
Many companies require numerous passwords to access a vast array of different platforms. In this case, it is imperative each password is different to one another and do not vary in levels of complexity. In this case, if one password is compromised the others remain safe and protected.
How to remember your safe password
Now you’ve got your strong and unique password (potentially numerous of them!), you might be worried about how you’re going to keep track of them. Fortunately, there are many password manager platforms available, such as IPassword, which easily store your passwords and provide access with a simple click.
Here at Synapse IT, we can work with your business to create organizational group policies for password management. These policies enforce systems and rules to using strong passwords and will add a significant layer of protection for your company. If you would like further information regarding us, feel free to contact us!
Weak, predictable and common passwords leave your financial and private information vulnerable to hacking. It is essential that businesses and individuals alike enforce mandatory strong password policies, based on the information we’ve provided to significantly reduce the risk password hacking.
Contact Us Today
Reach new heights in your industry through beginning the transition to managed IT solutions.