Security On A Shoestring SMB Budget

Posted by William McBorrough | Attacks, Network, Social Networking, Systems | Thursday 8 July 2010 11:03 am

The e-mail appeared to be an invitation from an old, junior high school friend. Yet when the hospital employee clicked on the link, it instead led her to a malicious site that installed a Trojan horse on her computer. In a little over a week, international cybercriminals used that beachhead to steal more than $600,000 from the woman’s employer, according to a terse description of the incident on the Information Systems Security Association’s Web site.

A number of similar incidents to this one highlight the threats of online crime facing small and midsize businesses (SMBs), says Stan Stahl, president of Citadel Information Group and president of the Los Angeles chapter of the ISSA.

“Typically, they say, ‘We have firewalls in place and have AV on all the desktops, so I guess we are secure,’” Stahl says. “But today cybercrime is so sophisticated that is not enough anymore.”

Read full article at http://www.darkreading.com/smb-security/security/attacks/showArticle.jhtml?articleID=225702557&cid=RSSfeed

Moving data storage to the cloud? What’s your business continuity plan?

Posted by William McBorrough | Network, Systems | Monday 5 July 2010 2:59 pm

Many trumpet increased as a reason to move to the cloud but what happens when your cloud provider is no longer available?

Some companies are faced with this very question this week as storage provider, EMC  announced its plan to shut down its Atmos Online cloud storage service immediately, according to a posting on its website.

EMC launched Atmos Online in May 2009, calling it “Cloud Optimized Storage [with] capabilities that can scale effectively, coupled with and management tools.”  This placed EMC in direct competition with some of its service provider partners who used EMC’s Atmos technology to provide cloud storage to its customers.

EMC has now  downgraded Atmos Online to a development platform and is offering no guarantee as to the of user data moving forward. EMC used its web posting to “strongly encourage [companies to] migrate any critical data or production workloads currently served via Atmos Online to one of our partners offering Atmos based services,”

The provider going out of business is one of the many risks companies have to address when considering moving their critical data into the cloud. In this case, companies now have to spend resources doing the necessary due diligence in selecting an alternative cloud storage provider.

According to Morris Cody, CIO at Washington D.C. based Information Services Firm, Secure Intervention, companies moving to the cloud better consider the following:

1) Disaster Recover Plan –  The bottom line is that no cloud provider can guarantee 100% up time all the time. Even a cloud provider as large as Google has experienced an outage in it’s cloud environment.  In that case, a solid disaster recover plan will help mitigate loses from several different perspectives (i.e., monetary, branding, current clients, new clients)

2) BCP – Having a business continuity plan in place that will work in conjunction with you cloud provide capabilities will mitigate the risk of an outage do to an scheduled / unscheduled event (not necessarily a disaster) in you cloud provider environment.

3) SLA – a strong SLA should be established with your cloud provider that will hold them accountable for losses or damages (define losses and damages) do to changes in their environment that effect your business.  For example, if your cloud provider decides to shutdown the cloud hosting services, then they should be responsible for the cost to migrate your apps/data to the new hosting provider”

Get Adobe Flash playerPlugin by wpburn.com wordpress themes