<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:wfw="http://wellformedweb.org/CommentAPI/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
     xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    >
    <channel>
        <title>AdviserVoiceKamino Archives - AdviserVoice</title>
        <atom:link href="https://www.adviservoice.com.au/source/kamino/feed/" rel="self" type="application/rss+xml" />
        <link>https://www.adviservoice.com.au/source/kamino/</link>
        <description>Financial planner information &#38; financial planner education/CPD - AdviserVoice</description>
        <lastBuildDate>Mon, 03 Aug 2026 21:15:16 +0000</lastBuildDate>
        <language>en-US</language>
        <sy:updatePeriod>hourly</sy:updatePeriod>
        <sy:updateFrequency>1</sy:updateFrequency>
        <generator>https://wordpress.org/?v=7.0.2</generator>
                    <item>
                <title>The art of the password</title>
                <link>https://www.adviservoice.com.au/2018/11/the-art-of-the-password/</link>
                <comments>https://www.adviservoice.com.au/2018/11/the-art-of-the-password/#respond</comments>
                <pubDate>Thu, 29 Nov 2018 20:50:19 +0000</pubDate>
                <dc:creator>
                                    </dc:creator>
                		<category><![CDATA[FinTech]]></category>
                <guid isPermaLink="false">https://adviservoice.com.au/?p=59087</guid>
                                    <description><![CDATA[<h2>Our top tips for password management within Advice businesses</h2>
<p>When it comes to cyber security, the password is the topic de jour. Everyone knows that a password is the most common mechanism to provide authentication. Positively, unlike facial and fingerprint recognition, passwords can be changed.</p>
<p>However, the problem with “the password” is through 20 years of effort, we’ve successfully trained everyone to use passwords that are hard for humans to remember but easy for computers to guess.</p>
<p>In the old days, the quality of a password used to be linked to its length (entropy) – for example – ‘correcthorsebatterystaple’. But now the uniqueness of a password is considered an essential element when choosing a password, and conversely predictability is a key part of cracking them.</p>
<p>In other words, you want to make your password as unpredictable as possible. This means if you can pronounce your password, or if it includes words that commonly go together, it’s not a password and it’s easy to crack.</p>
<p>You may think your password is creative and difficult but it would actually surprise you just how common the same words, tricks and combinations you use are.</p>
<p>Here are the 50 most used passwords. You will want to make sure your passwords aren’t on this list as a basic minimum.</p>
<p><img fetchpriority="high" decoding="async" class="alignleft size-large wp-image-59088" src="https://adviservoice.com.au/wp-content/uploads/2018/11/50mostusedpasswords-1024x477.png" alt="" width="1024" height="477" srcset="https://www.adviservoice.com.au/wp-content/uploads/2018/11/50mostusedpasswords-1024x477.png 1024w, https://www.adviservoice.com.au/wp-content/uploads/2018/11/50mostusedpasswords-300x140.png 300w, https://www.adviservoice.com.au/wp-content/uploads/2018/11/50mostusedpasswords-768x357.png 768w, https://www.adviservoice.com.au/wp-content/uploads/2018/11/50mostusedpasswords.png 1659w" sizes="(max-width: 1024px) 100vw, 1024px" /></p>
<p>&nbsp;</p>
<p>Aside from picking common words, there are other red flags that may not be as obvious when it comes to picking a password</p>
<p>We recommend, as a general guide:</p>
<ol>
<li>DO NOT use one password across various applications – this means if a hacker manages to hack even just one application where you have used this password, they will now be able to access your login across all of the applications where you have used this password. Often this can mean access to private, personal, professional, financial and medical data. Alarm bells anyone?</li>
<li>DO NOT change your password routinely or enforce your staff to change their password routinely i.e. every 90 days etc. This used to be seen as a good idea – with the logic behind it being that if a password were stolen, then it would lose its value when the user goes to change it. In reality however, individuals end up just rehashing similar versions of their password over and over again, or even worse – just keep forgetting the latest iteration and then continually need to reset. It’s a nightmare.</li>
<li>DO NOT use a password that is an actual word – if you can pronounce your password, it’s not a password and it will be cracked. If you want to use real words rather than a jumble of characters, use a combination of words that have no relevance or connection to each other for example – aladdinlattetissuelipstick</li>
</ol>
<p>If you want to take some simple and easy steps when it comes to password management, make sure you ARE doing the following –</p>
<ol>
<li>DO use a password manager – for example LastPass. This way you can store all of your passwords in one place without the need of remembering all of them. You only need to remember one password – that’s your LastPass password.</li>
<li>DO use a strong password generator (you can find a range of them on google) to help you generate different difficult passwords for all your applications and then store them in LastPass.</li>
<li>DO use applications which encrypt your passwords. This means if you forget your password, the application should not be able to tell you what it is, because they aren’t storing them in their base form.</li>
</ol>
]]></description>
                                            <content:encoded><![CDATA[<h2>Our top tips for password management within Advice businesses</h2>
<p>When it comes to cyber security, the password is the topic de jour. Everyone knows that a password is the most common mechanism to provide authentication. Positively, unlike facial and fingerprint recognition, passwords can be changed.</p>
<p>However, the problem with “the password” is through 20 years of effort, we’ve successfully trained everyone to use passwords that are hard for humans to remember but easy for computers to guess.</p>
<p>In the old days, the quality of a password used to be linked to its length (entropy) – for example – ‘correcthorsebatterystaple’. But now the uniqueness of a password is considered an essential element when choosing a password, and conversely predictability is a key part of cracking them.</p>
<p>In other words, you want to make your password as unpredictable as possible. This means if you can pronounce your password, or if it includes words that commonly go together, it’s not a password and it’s easy to crack.</p>
<p>You may think your password is creative and difficult but it would actually surprise you just how common the same words, tricks and combinations you use are.</p>
<p>Here are the 50 most used passwords. You will want to make sure your passwords aren’t on this list as a basic minimum.</p>
<p><img decoding="async" class="alignleft size-large wp-image-59088" src="https://adviservoice.com.au/wp-content/uploads/2018/11/50mostusedpasswords-1024x477.png" alt="" width="1024" height="477" srcset="https://www.adviservoice.com.au/wp-content/uploads/2018/11/50mostusedpasswords-1024x477.png 1024w, https://www.adviservoice.com.au/wp-content/uploads/2018/11/50mostusedpasswords-300x140.png 300w, https://www.adviservoice.com.au/wp-content/uploads/2018/11/50mostusedpasswords-768x357.png 768w, https://www.adviservoice.com.au/wp-content/uploads/2018/11/50mostusedpasswords.png 1659w" sizes="(max-width: 1024px) 100vw, 1024px" /></p>
<p>&nbsp;</p>
<p>Aside from picking common words, there are other red flags that may not be as obvious when it comes to picking a password</p>
<p>We recommend, as a general guide:</p>
<ol>
<li>DO NOT use one password across various applications – this means if a hacker manages to hack even just one application where you have used this password, they will now be able to access your login across all of the applications where you have used this password. Often this can mean access to private, personal, professional, financial and medical data. Alarm bells anyone?</li>
<li>DO NOT change your password routinely or enforce your staff to change their password routinely i.e. every 90 days etc. This used to be seen as a good idea – with the logic behind it being that if a password were stolen, then it would lose its value when the user goes to change it. In reality however, individuals end up just rehashing similar versions of their password over and over again, or even worse – just keep forgetting the latest iteration and then continually need to reset. It’s a nightmare.</li>
<li>DO NOT use a password that is an actual word – if you can pronounce your password, it’s not a password and it will be cracked. If you want to use real words rather than a jumble of characters, use a combination of words that have no relevance or connection to each other for example – aladdinlattetissuelipstick</li>
</ol>
<p>If you want to take some simple and easy steps when it comes to password management, make sure you ARE doing the following –</p>
<ol>
<li>DO use a password manager – for example LastPass. This way you can store all of your passwords in one place without the need of remembering all of them. You only need to remember one password – that’s your LastPass password.</li>
<li>DO use a strong password generator (you can find a range of them on google) to help you generate different difficult passwords for all your applications and then store them in LastPass.</li>
<li>DO use applications which encrypt your passwords. This means if you forget your password, the application should not be able to tell you what it is, because they aren’t storing them in their base form.</li>
</ol>
<p>The post <a href="https://www.adviservoice.com.au/2018/11/the-art-of-the-password/">The art of the password</a> appeared first on <a href="https://www.adviservoice.com.au">AdviserVoice</a>.</p>
]]></content:encoded>
                                    <wfw:commentRss>https://www.adviservoice.com.au/2018/11/the-art-of-the-password/feed/</wfw:commentRss>
                <slash:comments>0</slash:comments>                            </item>
                    <item>
                <title>Protecting your client data held on third-party services and apps</title>
                <link>https://www.adviservoice.com.au/2018/07/protecting-your-client-data-held-on-third-party-services-and-apps/</link>
                <comments>https://www.adviservoice.com.au/2018/07/protecting-your-client-data-held-on-third-party-services-and-apps/#respond</comments>
                <pubDate>Thu, 05 Jul 2018 21:50:21 +0000</pubDate>
                <dc:creator>
                                    </dc:creator>
                		<category><![CDATA[FinTech]]></category>
                <guid isPermaLink="false">https://adviservoice.com.au/?p=56277</guid>
                                    <description><![CDATA[<div id="attachment_45093" style="width: 260px" class="wp-caption alignleft"><img decoding="async" aria-describedby="caption-attachment-45093" class="size-full wp-image-45093" src="https://adviservoice.com.au/wp-content/uploads/2016/09/plummer-julian-2016-250.jpg" alt="" width="250" height="180" /><p id="caption-attachment-45093" class="wp-caption-text">Julian Plummer</p></div>
<h3>The human resources software provider PageUp, which provides services to the likes of Zurich and the Reserve Bank of Australia, recently flagged that it had detected “unauthorized activity” on its system.</h3>
<p>Security breaches are happening at an increasing rate around the globe, some affecting billions of people, but the recent PageUp hack is a lot closer to Aussies, because many major Australian organisations use it as their HR platform.</p>
<p>Software-as-a-service (SaaS) products are great because they significantly reduce the cost of maintenance, including infrastructure, product updates and security.</p>
<p>Additionally, in the case of SaaS, the software service provider is responsible for the security of clients’ data. The benefit of software security providers is that they have access to greater security resources (often world-class), but the cost is that you don’t have much of a say in how those resources are deployed.</p>
<p>What then, are your responsibilities, as a financial planner, to ensure that your data in the cloud is safe? Well, as anyone in security will tell you, there is no 100 per cent safety.</p>
<p>But you can manage the risk and bring it down to an acceptable level. In other words, you will need to do your due diligence in order to protect your customers’ data.</p>
<p>As a buyer, when selecting a SaaS provider, you should ask the following questions –</p>
<ul>
<li>Does the SaaS provider comply with information security standards such as ISO27001?</li>
<li>Does the SaaS provider have an information security policy?</li>
<li>Does the SaaS provider carry out regular security assessments?</li>
<li>What security protection mechanism is installed, such as firewalls, anti-virus, intrusion detection system?</li>
<li>Where is the data stored?</li>
</ul>
<p>The cloud provider (and this includes financial planning applications) should be able to answer these queries without hesitation.</p>
<p>Some of the questions can get technical very quickly. If in doubt, it’s a great idea to engage a security expert to help make the decision. If possible, you should consider carrying out your own technical security assessment against the SaaS provider.</p>
<p>Many cloud providers are open to this, but some are still reluctant, in which case you should ask to see the full security assessment (a.k.a. penetration test) report from an independent service provider. Midwinter, as an example is very open to potential clients asking security-minded questions as part of their due diligence – it’s expected.</p>
<p>Now, what if you are a small business? A user of a cloud storage provider is a bit like being a bullet train passenger, while keeping all your data in-house is like driving your own car – you’re in the driver’s seat, you are in control, but you must now take full responsibility of your risks.</p>
<p>When you take a bullet train, you are saving cost (compared to driving the car all the way), you are gaining performance (getting there faster), but you are putting someone in control of your life.</p>
<p>In this case, you are not in the bullet train driver’s seat, and you don’t really have a say in how the bullet train company runs their trains, even if you know what questions to ask. This is the same when you sign up to something like Office 365 or Google Suite.</p>
<p>These are instances where you should look for contractual protection and what compensations are there for you in case their security is compromised.</p>
<p>You could also look out for past history of security incidents – albeit this is often moot because in information security, the past is not necessarily always a good indication of the future.</p>
<p>To give an example, you know a company takes security seriously when it has its own team of ethical hackers and is open to bug bounty programs (a bug bounty program is where everyone is invited to hack their products).</p>
<p>If you looked even closer, you will also see these companies typically respond to security vulnerability reports quickly and responsibly.</p>
<p>Last, but not least, prepare a communications plan with for your clients, should an incident like this happens.</p>
<p>Be prepared to be open and frank about what happened, what you are currently doing, and keeping the clients up to date.  Contact the SaaS provider and ask for details of the incident. Consult with your information security expert on how to handle the issue, and how your clients should be best informed to protect their data.</p>
<p>Individual financial planners may not in a position to be influential enough to get many SaaS providers to be responding to security questions – but their licensee should be. Licensees should be reviewing cloud-based software on behalf on their advisers.</p>
<p>Additionally, it is the licensee that is on the hook for much of this.</p>
<p>According to ASIC’s RG 109.30, the licensee must ensure they have “enough technological resources to enable you to: (a) comply with all of your obligations under the law; (b) maintain client records and data integrity; (c) protect confidential and other information; and (d) meet your current and anticipated future operational needs.”</p>
<p>So, any licensee whose advisers used PageUp should be re-reading that particular paragraph with interest. Luckily, I can’t see much client data being caught up in this breach, so it is a good early warning indicator of what is to come.</p>
<p>What I see happening in the future is that licensee and practices will end up having an approved list of applications that have passed security tests, much like products on APLs must pass research tests.</p>
<p>We are just starting to see this begin to take place – and this is even more important with the rise of the API and practices wanting to “build their own stack” of tech applications.</p>
<p>It’s also worth considering the damage done to all advisers in this royal commission.</p>
<p>Sure, you may have a completely compliant business, but the royal commission will have some sort of impact on you.</p>
<p>When I first saw the news of this breach, the attached graphic to the headline was a picture of the RBA building.</p>
<p>My first though was that the RBA had been hacked – and that assumption would have continued had I not read further. So now, in some minds, RBA’s brand has been tarnished.</p>
<p>That considered – the message is, you trade on trust. Make sure you treat your clients’ data with the care it deserves. Additionally, licensees must start doing due diligence on the applications that advisers under their AFSL use. If there is one thing worth protecting in our industry – it’s data.</p>
<p><em><strong>By Julian Plummer, Managing Director</strong></em></p>
]]></description>
                                            <content:encoded><![CDATA[<div id="attachment_45093" style="width: 260px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-45093" class="size-full wp-image-45093" src="https://adviservoice.com.au/wp-content/uploads/2016/09/plummer-julian-2016-250.jpg" alt="" width="250" height="180" /><p id="caption-attachment-45093" class="wp-caption-text">Julian Plummer</p></div>
<h3>The human resources software provider PageUp, which provides services to the likes of Zurich and the Reserve Bank of Australia, recently flagged that it had detected “unauthorized activity” on its system.</h3>
<p>Security breaches are happening at an increasing rate around the globe, some affecting billions of people, but the recent PageUp hack is a lot closer to Aussies, because many major Australian organisations use it as their HR platform.</p>
<p>Software-as-a-service (SaaS) products are great because they significantly reduce the cost of maintenance, including infrastructure, product updates and security.</p>
<p>Additionally, in the case of SaaS, the software service provider is responsible for the security of clients’ data. The benefit of software security providers is that they have access to greater security resources (often world-class), but the cost is that you don’t have much of a say in how those resources are deployed.</p>
<p>What then, are your responsibilities, as a financial planner, to ensure that your data in the cloud is safe? Well, as anyone in security will tell you, there is no 100 per cent safety.</p>
<p>But you can manage the risk and bring it down to an acceptable level. In other words, you will need to do your due diligence in order to protect your customers’ data.</p>
<p>As a buyer, when selecting a SaaS provider, you should ask the following questions –</p>
<ul>
<li>Does the SaaS provider comply with information security standards such as ISO27001?</li>
<li>Does the SaaS provider have an information security policy?</li>
<li>Does the SaaS provider carry out regular security assessments?</li>
<li>What security protection mechanism is installed, such as firewalls, anti-virus, intrusion detection system?</li>
<li>Where is the data stored?</li>
</ul>
<p>The cloud provider (and this includes financial planning applications) should be able to answer these queries without hesitation.</p>
<p>Some of the questions can get technical very quickly. If in doubt, it’s a great idea to engage a security expert to help make the decision. If possible, you should consider carrying out your own technical security assessment against the SaaS provider.</p>
<p>Many cloud providers are open to this, but some are still reluctant, in which case you should ask to see the full security assessment (a.k.a. penetration test) report from an independent service provider. Midwinter, as an example is very open to potential clients asking security-minded questions as part of their due diligence – it’s expected.</p>
<p>Now, what if you are a small business? A user of a cloud storage provider is a bit like being a bullet train passenger, while keeping all your data in-house is like driving your own car – you’re in the driver’s seat, you are in control, but you must now take full responsibility of your risks.</p>
<p>When you take a bullet train, you are saving cost (compared to driving the car all the way), you are gaining performance (getting there faster), but you are putting someone in control of your life.</p>
<p>In this case, you are not in the bullet train driver’s seat, and you don’t really have a say in how the bullet train company runs their trains, even if you know what questions to ask. This is the same when you sign up to something like Office 365 or Google Suite.</p>
<p>These are instances where you should look for contractual protection and what compensations are there for you in case their security is compromised.</p>
<p>You could also look out for past history of security incidents – albeit this is often moot because in information security, the past is not necessarily always a good indication of the future.</p>
<p>To give an example, you know a company takes security seriously when it has its own team of ethical hackers and is open to bug bounty programs (a bug bounty program is where everyone is invited to hack their products).</p>
<p>If you looked even closer, you will also see these companies typically respond to security vulnerability reports quickly and responsibly.</p>
<p>Last, but not least, prepare a communications plan with for your clients, should an incident like this happens.</p>
<p>Be prepared to be open and frank about what happened, what you are currently doing, and keeping the clients up to date.  Contact the SaaS provider and ask for details of the incident. Consult with your information security expert on how to handle the issue, and how your clients should be best informed to protect their data.</p>
<p>Individual financial planners may not in a position to be influential enough to get many SaaS providers to be responding to security questions – but their licensee should be. Licensees should be reviewing cloud-based software on behalf on their advisers.</p>
<p>Additionally, it is the licensee that is on the hook for much of this.</p>
<p>According to ASIC’s RG 109.30, the licensee must ensure they have “enough technological resources to enable you to: (a) comply with all of your obligations under the law; (b) maintain client records and data integrity; (c) protect confidential and other information; and (d) meet your current and anticipated future operational needs.”</p>
<p>So, any licensee whose advisers used PageUp should be re-reading that particular paragraph with interest. Luckily, I can’t see much client data being caught up in this breach, so it is a good early warning indicator of what is to come.</p>
<p>What I see happening in the future is that licensee and practices will end up having an approved list of applications that have passed security tests, much like products on APLs must pass research tests.</p>
<p>We are just starting to see this begin to take place – and this is even more important with the rise of the API and practices wanting to “build their own stack” of tech applications.</p>
<p>It’s also worth considering the damage done to all advisers in this royal commission.</p>
<p>Sure, you may have a completely compliant business, but the royal commission will have some sort of impact on you.</p>
<p>When I first saw the news of this breach, the attached graphic to the headline was a picture of the RBA building.</p>
<p>My first though was that the RBA had been hacked – and that assumption would have continued had I not read further. So now, in some minds, RBA’s brand has been tarnished.</p>
<p>That considered – the message is, you trade on trust. Make sure you treat your clients’ data with the care it deserves. Additionally, licensees must start doing due diligence on the applications that advisers under their AFSL use. If there is one thing worth protecting in our industry – it’s data.</p>
<p><em><strong>By Julian Plummer, Managing Director</strong></em></p>
<p>The post <a href="https://www.adviservoice.com.au/2018/07/protecting-your-client-data-held-on-third-party-services-and-apps/">Protecting your client data held on third-party services and apps</a> appeared first on <a href="https://www.adviservoice.com.au">AdviserVoice</a>.</p>
]]></content:encoded>
                                    <wfw:commentRss>https://www.adviservoice.com.au/2018/07/protecting-your-client-data-held-on-third-party-services-and-apps/feed/</wfw:commentRss>
                <slash:comments>0</slash:comments>                            </item>
                    <item>
                <title>Financial services industry over confident and ill prepared when it comes to cyber security</title>
                <link>https://www.adviservoice.com.au/2018/03/financial-services-industry-confident-ill-prepared-comes-cyber-security/</link>
                <comments>https://www.adviservoice.com.au/2018/03/financial-services-industry-confident-ill-prepared-comes-cyber-security/#respond</comments>
                <pubDate>Tue, 13 Mar 2018 20:55:34 +0000</pubDate>
                <dc:creator>
                                    </dc:creator>
                		<category><![CDATA[FinTech]]></category>
                <guid isPermaLink="false">https://adviservoice.com.au/?p=54258</guid>
                                    <description><![CDATA[<div id="attachment_45093" style="width: 260px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-45093" class="size-full wp-image-45093" src="https://adviservoice.com.au/wp-content/uploads/2016/09/plummer-julian-2016-250.jpg" alt="" width="250" height="180" /><p id="caption-attachment-45093" class="wp-caption-text">Julian Plummer</p></div>
<h3>A survey of the financial services industry conducted by Kamino Cyber Security in October 2017 has revealed that most financial advisers, accountants and superannuation funds are not adequately prepared when it comes to cyber security – particularly in regard to the new Data Breach Notification Laws which came into effect in February 2018.</h3>
<p>The laws state that:</p>
<ul>
<li>Where a suspected unauthorised access occurs, the organisation must undertake an assessment of whether the incident is an “eligible data breach”.</li>
<li>As part of that assessment process, the organisation must decide whether the incident is “likely to result in serious harm” to any individuals.</li>
<li>If an “eligible data breach” has occurred then the organisation must provide notification of the incident to the Office of the Australian Information Commissioner (OAIC) and take steps to notify affected individuals.</li>
</ul>
<p>Only 32% of survey respondents were aware of the mandatory data breach notification laws with the remaining 68% either completely unaware or only somewhat aware.</p>
<p>Managing Director of Kamino, Julian Plummer said these results were highly concerning, particularly since the survey uncovered at 45% of the those surveyed within the industry had experienced at least one cyber security incident (both successful and unsuccessful).</p>
<p>Mr Plummer stated that “These laws will have a huge impact on the businesses affected. This lack of awareness of the laws most likely translates to an overall lack of preparedness for the changes now in effect, which is worrying considering the ramifications of a cyber breach incident on a financial planning or accounting practice.”</p>
<p>“Most respondents appeared to have a very good understanding of what is at stake in the face of a cyber incident. Customer information is of the utmost importance, and the survey revealed that business owners realise that their brand must be protected from being tarnished by cyber incidents, which could lead to direct revenue loss. However, this has not been reflected in the preparations and processes which should be set in place to protect advisers, accountants and superfunds from potential cyber-attacks”</p>
<p>Only 46% of survey respondents said they would be adequately prepared to deal with a cyber attack on their business, with 25% stating their business was not doing enough to adequately protect its systems from cyber threats and the remaining 29% were unsure.</p>
<p>Alarmingly, only 28% of survey respondents had full confidence in their staff’s cyber security hygiene, which Mr Plummer said is “particularly concerning considering that ‘human error’ is one of the biggest weaknesses in enterprise security defence.”</p>
<p>Overall key findings of the survey include:</p>
<ul>
<li>There appears to be over-confidence especially with business owners when it comes to dealing with cyber threats. Many believe that they are well protected against threats, relying only on their own expertise or general computer technicians.</li>
<li>Most are not aware of their responsibilities with the incoming mandatory data breach notification laws. Ignorance of cyber security risks could be become a very costly for those who are affected (all accountants, and any business that stores TFN data or with a turnover over $3M).</li>
<li>The most common cyber incidents are caused by malware or phishing emails, indicating that there is a lack of basic security hygiene in the industry, and some very basic blind spots around user education.</li>
</ul>
]]></description>
                                            <content:encoded><![CDATA[<div id="attachment_45093" style="width: 260px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-45093" class="size-full wp-image-45093" src="https://adviservoice.com.au/wp-content/uploads/2016/09/plummer-julian-2016-250.jpg" alt="" width="250" height="180" /><p id="caption-attachment-45093" class="wp-caption-text">Julian Plummer</p></div>
<h3>A survey of the financial services industry conducted by Kamino Cyber Security in October 2017 has revealed that most financial advisers, accountants and superannuation funds are not adequately prepared when it comes to cyber security – particularly in regard to the new Data Breach Notification Laws which came into effect in February 2018.</h3>
<p>The laws state that:</p>
<ul>
<li>Where a suspected unauthorised access occurs, the organisation must undertake an assessment of whether the incident is an “eligible data breach”.</li>
<li>As part of that assessment process, the organisation must decide whether the incident is “likely to result in serious harm” to any individuals.</li>
<li>If an “eligible data breach” has occurred then the organisation must provide notification of the incident to the Office of the Australian Information Commissioner (OAIC) and take steps to notify affected individuals.</li>
</ul>
<p>Only 32% of survey respondents were aware of the mandatory data breach notification laws with the remaining 68% either completely unaware or only somewhat aware.</p>
<p>Managing Director of Kamino, Julian Plummer said these results were highly concerning, particularly since the survey uncovered at 45% of the those surveyed within the industry had experienced at least one cyber security incident (both successful and unsuccessful).</p>
<p>Mr Plummer stated that “These laws will have a huge impact on the businesses affected. This lack of awareness of the laws most likely translates to an overall lack of preparedness for the changes now in effect, which is worrying considering the ramifications of a cyber breach incident on a financial planning or accounting practice.”</p>
<p>“Most respondents appeared to have a very good understanding of what is at stake in the face of a cyber incident. Customer information is of the utmost importance, and the survey revealed that business owners realise that their brand must be protected from being tarnished by cyber incidents, which could lead to direct revenue loss. However, this has not been reflected in the preparations and processes which should be set in place to protect advisers, accountants and superfunds from potential cyber-attacks”</p>
<p>Only 46% of survey respondents said they would be adequately prepared to deal with a cyber attack on their business, with 25% stating their business was not doing enough to adequately protect its systems from cyber threats and the remaining 29% were unsure.</p>
<p>Alarmingly, only 28% of survey respondents had full confidence in their staff’s cyber security hygiene, which Mr Plummer said is “particularly concerning considering that ‘human error’ is one of the biggest weaknesses in enterprise security defence.”</p>
<p>Overall key findings of the survey include:</p>
<ul>
<li>There appears to be over-confidence especially with business owners when it comes to dealing with cyber threats. Many believe that they are well protected against threats, relying only on their own expertise or general computer technicians.</li>
<li>Most are not aware of their responsibilities with the incoming mandatory data breach notification laws. Ignorance of cyber security risks could be become a very costly for those who are affected (all accountants, and any business that stores TFN data or with a turnover over $3M).</li>
<li>The most common cyber incidents are caused by malware or phishing emails, indicating that there is a lack of basic security hygiene in the industry, and some very basic blind spots around user education.</li>
</ul>
<p>The post <a href="https://www.adviservoice.com.au/2018/03/financial-services-industry-confident-ill-prepared-comes-cyber-security/">Financial services industry over confident and ill prepared when it comes to cyber security</a> appeared first on <a href="https://www.adviservoice.com.au">AdviserVoice</a>.</p>
]]></content:encoded>
                                    <wfw:commentRss>https://www.adviservoice.com.au/2018/03/financial-services-industry-confident-ill-prepared-comes-cyber-security/feed/</wfw:commentRss>
                <slash:comments>0</slash:comments>                            </item>
                    <item>
                <title>“Detect, understand and respond!” Uh-oh! ASIC shifts its focus to Licensee’s cyber security</title>
                <link>https://www.adviservoice.com.au/2018/02/detect-understand-respond-uh-oh-asic-shifts-focus-licensees-cyber-security/</link>
                <comments>https://www.adviservoice.com.au/2018/02/detect-understand-respond-uh-oh-asic-shifts-focus-licensees-cyber-security/#respond</comments>
                <pubDate>Tue, 20 Feb 2018 21:00:34 +0000</pubDate>
                <dc:creator>
                                    </dc:creator>
                		<category><![CDATA[Regulation/Reform]]></category>
                <guid isPermaLink="false">https://adviservoice.com.au/?p=53420</guid>
                                    <description><![CDATA[<div id="attachment_53422" style="width: 260px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-53422" class="size-full wp-image-53422" src="https://adviservoice.com.au/wp-content/uploads/2018/02/disruption-2-250.jpg" alt="" width="250" height="180" /><p id="caption-attachment-53422" class="wp-caption-text">Increased reliance on information technology comes with an increased reliance on securing that information.</p></div>
<h3>For dedicated scholars of the Australian financial advice industry, “ASIC’s Corporate Plan 2017/18 to 2020/21” makes for some heavy but necessary reading, for within it lies ASIC’s regulatory intentions for the next three years.</h3>
<p>One of the less surprising key take outs is that ASIC considers digital disruption as a major challenge for financial services industries in the immediate years to come. Okay, that’s not exactly breaking news, but ASIC’s consideration of the risks of digital transformation certainly deserves thought.</p>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-53421" src="https://adviservoice.com.au/wp-content/uploads/2018/02/ASIC2.png" alt="" width="1020" height="380" srcset="https://www.adviservoice.com.au/wp-content/uploads/2018/02/ASIC2.png 1020w, https://www.adviservoice.com.au/wp-content/uploads/2018/02/ASIC2-300x112.png 300w, https://www.adviservoice.com.au/wp-content/uploads/2018/02/ASIC2-768x286.png 768w" sizes="auto, (max-width: 1020px) 100vw, 1020px" /></p>
<p>&nbsp;</p>
<p>Many advice providers have spent the 18 months or so undergoing major digital transformations of their CRMs, client engagement approach and advice provision systems. While the benefits of digital transformations are increasingly obvious, the self-evident conclusion is that digital transformations will also, only ever increase our industries reliance on information systems.</p>
<p>The problem with an increased reliance on information technology is that it comes with an increased reliance on securing that information. Easier said than done of course (and getting more difficult as each day goes by).</p>
<p>And so along with identifying digital disruption as a challenge, ASIC have correctly identified the key risk of cyber resilience in financial services and markets over the next four years.</p>
<p>So, how is ASIC intending to manage that cyber risk?</p>
<p>ASIC’s philosophy here is to use a ‘detect, understand and respond’ approach. ASIC intends to detect wrongdoing through surveillance, using continual market scanning to then respond to wrongdoing.</p>
<p>To that end, ASIC have set up an “Emerging Risk Committee” to analyse, monitor and respond to changes in cyber risks (in addition to other emerging risks). Underpinning this is increased emphasis on ASIC standardising their processes, further developing expertise in data management, and the application of new technology-based regulatory techniques to transform ASIC into a data-driven law enforcement agency.</p>
<h2>Licensee cyber risks</h2>
<p>It worth reminding ourselves of some of the licensee requirements when it comes to the cyber security of personally identifiable information.</p>
<p>ASIC’s RG 104.85 states that having “adequate technological and human resources is crucial to your ability to demonstrate that you have the capacity to carry on your financial services business in full compliance with the law and to supervise your representatives.” This means that ASIC has pointed out technology as a critical component of Licensees being able to supervise their representatives.</p>
<p>ASIC’s RG 104.90 go on to further say that Licensees “need to have enough technological resources to enable you to:</p>
<p><em>(a) comply with all of your obligations under the law;</em></p>
<p><em>(b) maintain client records and data integrity;</em></p>
<p><em>(c) protect confidential and other information; and</em></p>
<p><em>(d) meet your current and anticipated future operational needs</em></p>
<p>It is evident that Licensees have an obligation to ensure that confidentiality and integrity of their clients’ information is adequately maintained in order.</p>
<p>So, it’s Licensees, not just financial planners that need to put cyber security at the top of this year’s priority list. Failures to meet these obligations will have consequences for Australian Financial Services Licensees (AFDL) – including the usual assortment of fines, penalties, enforceable undertakings, licensing conditions, or a license suspension or cancellation.</p>
]]></description>
                                            <content:encoded><![CDATA[<div id="attachment_53422" style="width: 260px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-53422" class="size-full wp-image-53422" src="https://adviservoice.com.au/wp-content/uploads/2018/02/disruption-2-250.jpg" alt="" width="250" height="180" /><p id="caption-attachment-53422" class="wp-caption-text">Increased reliance on information technology comes with an increased reliance on securing that information.</p></div>
<h3>For dedicated scholars of the Australian financial advice industry, “ASIC’s Corporate Plan 2017/18 to 2020/21” makes for some heavy but necessary reading, for within it lies ASIC’s regulatory intentions for the next three years.</h3>
<p>One of the less surprising key take outs is that ASIC considers digital disruption as a major challenge for financial services industries in the immediate years to come. Okay, that’s not exactly breaking news, but ASIC’s consideration of the risks of digital transformation certainly deserves thought.</p>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-53421" src="https://adviservoice.com.au/wp-content/uploads/2018/02/ASIC2.png" alt="" width="1020" height="380" srcset="https://www.adviservoice.com.au/wp-content/uploads/2018/02/ASIC2.png 1020w, https://www.adviservoice.com.au/wp-content/uploads/2018/02/ASIC2-300x112.png 300w, https://www.adviservoice.com.au/wp-content/uploads/2018/02/ASIC2-768x286.png 768w" sizes="auto, (max-width: 1020px) 100vw, 1020px" /></p>
<p>&nbsp;</p>
<p>Many advice providers have spent the 18 months or so undergoing major digital transformations of their CRMs, client engagement approach and advice provision systems. While the benefits of digital transformations are increasingly obvious, the self-evident conclusion is that digital transformations will also, only ever increase our industries reliance on information systems.</p>
<p>The problem with an increased reliance on information technology is that it comes with an increased reliance on securing that information. Easier said than done of course (and getting more difficult as each day goes by).</p>
<p>And so along with identifying digital disruption as a challenge, ASIC have correctly identified the key risk of cyber resilience in financial services and markets over the next four years.</p>
<p>So, how is ASIC intending to manage that cyber risk?</p>
<p>ASIC’s philosophy here is to use a ‘detect, understand and respond’ approach. ASIC intends to detect wrongdoing through surveillance, using continual market scanning to then respond to wrongdoing.</p>
<p>To that end, ASIC have set up an “Emerging Risk Committee” to analyse, monitor and respond to changes in cyber risks (in addition to other emerging risks). Underpinning this is increased emphasis on ASIC standardising their processes, further developing expertise in data management, and the application of new technology-based regulatory techniques to transform ASIC into a data-driven law enforcement agency.</p>
<h2>Licensee cyber risks</h2>
<p>It worth reminding ourselves of some of the licensee requirements when it comes to the cyber security of personally identifiable information.</p>
<p>ASIC’s RG 104.85 states that having “adequate technological and human resources is crucial to your ability to demonstrate that you have the capacity to carry on your financial services business in full compliance with the law and to supervise your representatives.” This means that ASIC has pointed out technology as a critical component of Licensees being able to supervise their representatives.</p>
<p>ASIC’s RG 104.90 go on to further say that Licensees “need to have enough technological resources to enable you to:</p>
<p><em>(a) comply with all of your obligations under the law;</em></p>
<p><em>(b) maintain client records and data integrity;</em></p>
<p><em>(c) protect confidential and other information; and</em></p>
<p><em>(d) meet your current and anticipated future operational needs</em></p>
<p>It is evident that Licensees have an obligation to ensure that confidentiality and integrity of their clients’ information is adequately maintained in order.</p>
<p>So, it’s Licensees, not just financial planners that need to put cyber security at the top of this year’s priority list. Failures to meet these obligations will have consequences for Australian Financial Services Licensees (AFDL) – including the usual assortment of fines, penalties, enforceable undertakings, licensing conditions, or a license suspension or cancellation.</p>
<p>The post <a href="https://www.adviservoice.com.au/2018/02/detect-understand-respond-uh-oh-asic-shifts-focus-licensees-cyber-security/">“Detect, understand and respond!” Uh-oh! ASIC shifts its focus to Licensee’s cyber security</a> appeared first on <a href="https://www.adviservoice.com.au">AdviserVoice</a>.</p>
]]></content:encoded>
                                    <wfw:commentRss>https://www.adviservoice.com.au/2018/02/detect-understand-respond-uh-oh-asic-shifts-focus-licensees-cyber-security/feed/</wfw:commentRss>
                <slash:comments>0</slash:comments>                            </item>
                    <item>
                <title>The top security threats to financial services in 2018</title>
                <link>https://www.adviservoice.com.au/2018/02/top-security-threats-financial-services-2018/</link>
                <comments>https://www.adviservoice.com.au/2018/02/top-security-threats-financial-services-2018/#respond</comments>
                <pubDate>Sun, 11 Feb 2018 20:55:27 +0000</pubDate>
                <dc:creator>
                                    </dc:creator>
                		<category><![CDATA[FinTech]]></category>
                <guid isPermaLink="false">https://adviservoice.com.au/?p=53415</guid>
                                    <description><![CDATA[<div id="attachment_53417" style="width: 260px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-53417" class="size-full wp-image-53417" src="https://adviservoice.com.au/wp-content/uploads/2018/02/data-protection-250.jpg" alt="" width="250" height="180" /><p id="caption-attachment-53417" class="wp-caption-text">What are the top security threats to financial services in 2018?</p></div>
<h3>If you are a small to medium business (SMB), how is cyber security relevant to you? Because only the big companies like Sony and Equifax get hacked, right? RIGHT?!</h3>
<p>WRONG.</p>
<p>The truth is, cyber criminals are turning their focus to small businesses, because they are soft and sweet – the low-hanging fruit, so to speak. There may be fewer targeted attacks against SMBs, but there are campaigns after campaigns that target the mass, reaping huge profits for cyber criminals through ransomware attacks, phishing attacks and others. SMBs often lack the awareness and protection that the big guys consider basic hygiene, and this is exactly what hackers are counting on.</p>
<p>Here we list and explain the top 5 security threats for small to medium businesses this year.</p>
<h2>Ransomware</h2>
<p><em>Pay us $1,000 to get your files back (maybe)</em></p>
<p>Ransomware is a type of malicious software (often dubbed malware) that infiltrates a victim’s computer, denies access to the victim’s data on the computer and then demands money to restore the access. Most Ransomware does so by encrypting the victim’s files, but some new breeds can upload files (such as photos) to the attacker’s server and demand money for the release.</p>
<p>Ransomware typically looks for files such as office documents, images and backups. It then encrypts the files and alerts the user, demanding money and a deadline for payment. There is no way to decrypt (restore) the file without the decryption key held by the attacker, meaning the data will be rendered useless. Unfortunately, the victim may not always receive the decryption key even if they made the payment in time. In some cases, the decryption simply doesn’t work and even the attacker does not know how to decrypt the files/</p>
<h3>How Ransomware is spread</h3>
<p>Ransomware is typically spread via email attachments, but sometimes it’s by website downloads or manually penetrating the network and the malware installed. Ransomware attacks require very little skill to execute, but are highly efficient and successful in the eyes of criminals. So much so that it has evolved into an underground industry where ransomware platforms are for hire.</p>
<h3>How to protect your business</h3>
<ul>
<li>Ensure you have a data backup plan and stick to it. Test your backup regularly, at least once every 3 months to ensure you can restore the data. Don’t pretend to do it, don’t leave it for later – just do it.</li>
<li>Install up-to-date anti-virus software</li>
<li>Keep your software, operating systems, firewall, routers and other systems up to date.</li>
<li>Educate users about opening suspicious emails and attachments.</li>
</ul>
<h2>Malicious emails</h2>
<p><em>“Please click on the attachment for the latest market research report!”</em></p>
<p>Malicious emails continue to be a pain and trap for many users in 2017. These emails are easy to create as part of a campaign, and there is always someone who is in a hurry or just ‘didn’t think twice’ about clicking on that link. There are typically 2 types of malicious emails that affect small and medium businesses.</p>
<h3>Malicious attachments</h3>
<p>These are emails pretending to be a utility bill, a traffic infringement notice, or some funny pictures that entice a user to open the file attachment. The attachments are almost always malware that will then run on the computer. The malware can then steal and take control of your financial information, logins to bank websites, or anything you have on your computer. Often ransomware is delivered in this manner. This allows ransomware to control your computer to become part of a larger botnet – a group of “zombie” computers that participate in large scale attacks.</p>
<h3>Phishing email</h3>
<p>These emails pretend to be from your IT administrator or your bank websites – perhaps asking you to reset your password in the hopes that you will click on the link provided and enter your login credentials or personal details on the malicious website.</p>
<p>A more severe form of phishing email is called “spear phishing”, which targets single individuals or a group/sector. For example, financial advisers will be far more likely to open an email that claims to provide the latest market research report from what appears to be a reputable source then a random email with little relevance to their industry. These type of industry specific phishing emails have proven to be effective in attacking small and medium businesses and as such, has been one of the particular cyber attacks which are on the rise.</p>
<h3>How to protect your business</h3>
<ul>
<li>User education comes out on top here. There is no substitute for teaching yourself and your staff how to spot a suspicious email, because even defence like anti-virus software or email spam filters can’t catch all malicious emails.</li>
<li>There should be some mechanism of email filtering on your network. Depending on the functionality, these mechanisms can filter the most common spam and phishing emails, to keeping up to date with the latest phishing email campaigns.</li>
</ul>
<h2>Internet of things</h2>
<p><em>Attacker: Siri, can you unlock the door for me?</em></p>
<p>Our everyday lives have become more and more reliant and centred on digital technology and our appliances (PCs, phones) are increasingly getting “smarter”. Many small businesses have invested in technologies such as IP camera, smart TVs, smart locks, smart vacuum cleaners, mobile credit card readers, etc. These have brought convenience and in some cases – added security to the office, but if not managed properly, could be the one thing that gives the bad guys a point of entry.</p>
<p>Many such devices (collectively called Internet of Things (IoTs)), are in essence – computers in disguise. IoT devices function just like your Windows or iOS operating system, but with a caveat: they often don’t get the security attention from the vendors like their big brothers do. Tech giants like Microsoft and Apple are well versed in security and understand the security implications, so they regularly push out updates to the operating systems. Not so much for IoT devices. The vendors are not as well resourced, and not so much concerned about your security. Even if the device is initially supported and receives updates, chances are in two years the vendor would have moved on, leaving the device vulnerable to the latest security exploits.</p>
<p>To make matters worse, many of these devices have Internet connections, meaning that an attacker can reach and attack them from anywhere in the world. It’s not hard to find a security camera streaming live about someone’s home or office on the Internet, all because the vendor left a backdoor (that is now publicly known) or a default password left by the owner. Owners can also be a subject to ransomware or be coerced into participating in the next denial-of-service attack.</p>
<h3>How to protect your business</h3>
<ul>
<li>Consider the security implications when you decide to purchase a new “smart” device. Do you trust the vendor to continue update and support the device? What are risks if you installed it? Do you have plans to mitigate these risks?</li>
<li>Change default passwords on all IoT devices you have installed. They are too easy to guess and often publicly advertised (e.g. on the manual and a search on Internet will reveal them).</li>
<li>Update the device as soon as you have installed. This ensures your device is secure against the latest security vulnerabilities.</li>
<li>If possible, put the IoT devices on a separate network (e.g. guest wi-fi) so your most critical assets (such as file storage and servers) are not on the same network. This reduces the risk of everything getting compromised due to a mere vulnerability on the IoT device.</li>
</ul>
<h2>Password hygiene</h2>
<p><em>Human brains are not very good at creating and remembering unique, complex passwords that change regularly.</em></p>
<p>Passwords remain a popular choice for many applications and systems to verify who you say you are. However, they are notoriously easy to steal or guess. The core of the problem for most people is twofold – password reuse and difficulty to remember.</p>
<p>The nature of the password, and what makes them secure, is that they need to be unique and difficult to guess. This means for a very long time, the majority of websites and applications have been asking users to select a password that is complex and long (containing mixed case, numbers and symbols). In enterprises, it is also common for users to be forced to regularly change their password every month or so. Human brains are not very good at creating and remembering unique, complex passwords that change regularly. This means we create passwords with patterns that are easy to remember, and thus, easy for hackers to crack. Some great examples over the years are 12345678 and Welcome123!</p>
<p>We are also very likely to reuse those passwords across different websites and systems because there are a plethora of systems asking for them. The passwords are stored on the website, together with the usernames, often as email addresses. The bad guys know about all these, and they often break into websites and systems to steal the login credentials. There are now millions of passwords that have been stolen over the years.</p>
<p>To guess someone’s login, the bad guys can either try with the stolen login credentials, or common passwords that many people use.</p>
<h3>How to protect Your business</h3>
<ul>
<li>Develop and follow a proper password policy in your organisation.</li>
<li>Use a password manager for storing passwords (don’t know what this is? Try LastPass)</li>
<li>Use separate accounts and passwords for each system and website.</li>
</ul>
<h3>Software vulnerabilities</h3>
<p><em>Not implementing security updates is like having a broken lock on your door.</em></p>
<p>There was once a saying that for every line of code written, there is a bug. That may not be entirely true, but it shows how extensive software bugs are in just about everything digital.  Software vulnerabilities are just that, they are bugs. New vulnerabilities are being discovered at an alarming rate, and often just one of these is enough to let an attacker to take control of your entire network, and perhaps your digital life as well. What’s more is that you probably won’t know a thing while they are exploiting these vulnerabilities.</p>
<p>Most attackers rely heavily on known vulnerabilities, that is, vulnerabilities that have been publicised and well documented. Once a vulnerability is known, software vendors will (hopefully) rush to implement a fix. These fixes are the updates you get on a regular, and sometimes, ad-hoc basis. Thus it is extremely important that you install these updates as they become available, to block out the bad guys. Not implementing security updates is like having a broken lock on your door.</p>
<h3>How to protect Your business</h3>
<ul>
<li>Enable auto-update wherever possible on all IT assets</li>
<li>Install updates as soon as you install a new system</li>
</ul>
<h2>Things to keep your eye on in 2018</h2>
<ul>
<li>Ransomware is here to stay. There will be new variants, new techniques and ever larger campaigns developed by the cyber criminals.</li>
<li>Increased interest in crypto-currency hacking. The surge in value of cryptocurrencies in 2017 has made them a very attractive target for easy financial gains. Because they are not regulated by a bank or government, it also makes the job much easier for hackers to transfer and steal.</li>
<li>Identity theft. Given the recent major breaches in personal identifiable information, we expect that there will be an increase in identity theft. Australia is not affected as badly as the US and UK, but with the incoming breach notification laws, we may see more in the news about breaches that were not reported.</li>
<li>Speaking of which, the new breach notification law will become very relevant to Australian businesses, as every business that handles client’s TFN is applicable. This will be a good time to take a good look at your security posture.</li>
</ul>
]]></description>
                                            <content:encoded><![CDATA[<div id="attachment_53417" style="width: 260px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-53417" class="size-full wp-image-53417" src="https://adviservoice.com.au/wp-content/uploads/2018/02/data-protection-250.jpg" alt="" width="250" height="180" /><p id="caption-attachment-53417" class="wp-caption-text">What are the top security threats to financial services in 2018?</p></div>
<h3>If you are a small to medium business (SMB), how is cyber security relevant to you? Because only the big companies like Sony and Equifax get hacked, right? RIGHT?!</h3>
<p>WRONG.</p>
<p>The truth is, cyber criminals are turning their focus to small businesses, because they are soft and sweet – the low-hanging fruit, so to speak. There may be fewer targeted attacks against SMBs, but there are campaigns after campaigns that target the mass, reaping huge profits for cyber criminals through ransomware attacks, phishing attacks and others. SMBs often lack the awareness and protection that the big guys consider basic hygiene, and this is exactly what hackers are counting on.</p>
<p>Here we list and explain the top 5 security threats for small to medium businesses this year.</p>
<h2>Ransomware</h2>
<p><em>Pay us $1,000 to get your files back (maybe)</em></p>
<p>Ransomware is a type of malicious software (often dubbed malware) that infiltrates a victim’s computer, denies access to the victim’s data on the computer and then demands money to restore the access. Most Ransomware does so by encrypting the victim’s files, but some new breeds can upload files (such as photos) to the attacker’s server and demand money for the release.</p>
<p>Ransomware typically looks for files such as office documents, images and backups. It then encrypts the files and alerts the user, demanding money and a deadline for payment. There is no way to decrypt (restore) the file without the decryption key held by the attacker, meaning the data will be rendered useless. Unfortunately, the victim may not always receive the decryption key even if they made the payment in time. In some cases, the decryption simply doesn’t work and even the attacker does not know how to decrypt the files/</p>
<h3>How Ransomware is spread</h3>
<p>Ransomware is typically spread via email attachments, but sometimes it’s by website downloads or manually penetrating the network and the malware installed. Ransomware attacks require very little skill to execute, but are highly efficient and successful in the eyes of criminals. So much so that it has evolved into an underground industry where ransomware platforms are for hire.</p>
<h3>How to protect your business</h3>
<ul>
<li>Ensure you have a data backup plan and stick to it. Test your backup regularly, at least once every 3 months to ensure you can restore the data. Don’t pretend to do it, don’t leave it for later – just do it.</li>
<li>Install up-to-date anti-virus software</li>
<li>Keep your software, operating systems, firewall, routers and other systems up to date.</li>
<li>Educate users about opening suspicious emails and attachments.</li>
</ul>
<h2>Malicious emails</h2>
<p><em>“Please click on the attachment for the latest market research report!”</em></p>
<p>Malicious emails continue to be a pain and trap for many users in 2017. These emails are easy to create as part of a campaign, and there is always someone who is in a hurry or just ‘didn’t think twice’ about clicking on that link. There are typically 2 types of malicious emails that affect small and medium businesses.</p>
<h3>Malicious attachments</h3>
<p>These are emails pretending to be a utility bill, a traffic infringement notice, or some funny pictures that entice a user to open the file attachment. The attachments are almost always malware that will then run on the computer. The malware can then steal and take control of your financial information, logins to bank websites, or anything you have on your computer. Often ransomware is delivered in this manner. This allows ransomware to control your computer to become part of a larger botnet – a group of “zombie” computers that participate in large scale attacks.</p>
<h3>Phishing email</h3>
<p>These emails pretend to be from your IT administrator or your bank websites – perhaps asking you to reset your password in the hopes that you will click on the link provided and enter your login credentials or personal details on the malicious website.</p>
<p>A more severe form of phishing email is called “spear phishing”, which targets single individuals or a group/sector. For example, financial advisers will be far more likely to open an email that claims to provide the latest market research report from what appears to be a reputable source then a random email with little relevance to their industry. These type of industry specific phishing emails have proven to be effective in attacking small and medium businesses and as such, has been one of the particular cyber attacks which are on the rise.</p>
<h3>How to protect your business</h3>
<ul>
<li>User education comes out on top here. There is no substitute for teaching yourself and your staff how to spot a suspicious email, because even defence like anti-virus software or email spam filters can’t catch all malicious emails.</li>
<li>There should be some mechanism of email filtering on your network. Depending on the functionality, these mechanisms can filter the most common spam and phishing emails, to keeping up to date with the latest phishing email campaigns.</li>
</ul>
<h2>Internet of things</h2>
<p><em>Attacker: Siri, can you unlock the door for me?</em></p>
<p>Our everyday lives have become more and more reliant and centred on digital technology and our appliances (PCs, phones) are increasingly getting “smarter”. Many small businesses have invested in technologies such as IP camera, smart TVs, smart locks, smart vacuum cleaners, mobile credit card readers, etc. These have brought convenience and in some cases – added security to the office, but if not managed properly, could be the one thing that gives the bad guys a point of entry.</p>
<p>Many such devices (collectively called Internet of Things (IoTs)), are in essence – computers in disguise. IoT devices function just like your Windows or iOS operating system, but with a caveat: they often don’t get the security attention from the vendors like their big brothers do. Tech giants like Microsoft and Apple are well versed in security and understand the security implications, so they regularly push out updates to the operating systems. Not so much for IoT devices. The vendors are not as well resourced, and not so much concerned about your security. Even if the device is initially supported and receives updates, chances are in two years the vendor would have moved on, leaving the device vulnerable to the latest security exploits.</p>
<p>To make matters worse, many of these devices have Internet connections, meaning that an attacker can reach and attack them from anywhere in the world. It’s not hard to find a security camera streaming live about someone’s home or office on the Internet, all because the vendor left a backdoor (that is now publicly known) or a default password left by the owner. Owners can also be a subject to ransomware or be coerced into participating in the next denial-of-service attack.</p>
<h3>How to protect your business</h3>
<ul>
<li>Consider the security implications when you decide to purchase a new “smart” device. Do you trust the vendor to continue update and support the device? What are risks if you installed it? Do you have plans to mitigate these risks?</li>
<li>Change default passwords on all IoT devices you have installed. They are too easy to guess and often publicly advertised (e.g. on the manual and a search on Internet will reveal them).</li>
<li>Update the device as soon as you have installed. This ensures your device is secure against the latest security vulnerabilities.</li>
<li>If possible, put the IoT devices on a separate network (e.g. guest wi-fi) so your most critical assets (such as file storage and servers) are not on the same network. This reduces the risk of everything getting compromised due to a mere vulnerability on the IoT device.</li>
</ul>
<h2>Password hygiene</h2>
<p><em>Human brains are not very good at creating and remembering unique, complex passwords that change regularly.</em></p>
<p>Passwords remain a popular choice for many applications and systems to verify who you say you are. However, they are notoriously easy to steal or guess. The core of the problem for most people is twofold – password reuse and difficulty to remember.</p>
<p>The nature of the password, and what makes them secure, is that they need to be unique and difficult to guess. This means for a very long time, the majority of websites and applications have been asking users to select a password that is complex and long (containing mixed case, numbers and symbols). In enterprises, it is also common for users to be forced to regularly change their password every month or so. Human brains are not very good at creating and remembering unique, complex passwords that change regularly. This means we create passwords with patterns that are easy to remember, and thus, easy for hackers to crack. Some great examples over the years are 12345678 and Welcome123!</p>
<p>We are also very likely to reuse those passwords across different websites and systems because there are a plethora of systems asking for them. The passwords are stored on the website, together with the usernames, often as email addresses. The bad guys know about all these, and they often break into websites and systems to steal the login credentials. There are now millions of passwords that have been stolen over the years.</p>
<p>To guess someone’s login, the bad guys can either try with the stolen login credentials, or common passwords that many people use.</p>
<h3>How to protect Your business</h3>
<ul>
<li>Develop and follow a proper password policy in your organisation.</li>
<li>Use a password manager for storing passwords (don’t know what this is? Try LastPass)</li>
<li>Use separate accounts and passwords for each system and website.</li>
</ul>
<h3>Software vulnerabilities</h3>
<p><em>Not implementing security updates is like having a broken lock on your door.</em></p>
<p>There was once a saying that for every line of code written, there is a bug. That may not be entirely true, but it shows how extensive software bugs are in just about everything digital.  Software vulnerabilities are just that, they are bugs. New vulnerabilities are being discovered at an alarming rate, and often just one of these is enough to let an attacker to take control of your entire network, and perhaps your digital life as well. What’s more is that you probably won’t know a thing while they are exploiting these vulnerabilities.</p>
<p>Most attackers rely heavily on known vulnerabilities, that is, vulnerabilities that have been publicised and well documented. Once a vulnerability is known, software vendors will (hopefully) rush to implement a fix. These fixes are the updates you get on a regular, and sometimes, ad-hoc basis. Thus it is extremely important that you install these updates as they become available, to block out the bad guys. Not implementing security updates is like having a broken lock on your door.</p>
<h3>How to protect Your business</h3>
<ul>
<li>Enable auto-update wherever possible on all IT assets</li>
<li>Install updates as soon as you install a new system</li>
</ul>
<h2>Things to keep your eye on in 2018</h2>
<ul>
<li>Ransomware is here to stay. There will be new variants, new techniques and ever larger campaigns developed by the cyber criminals.</li>
<li>Increased interest in crypto-currency hacking. The surge in value of cryptocurrencies in 2017 has made them a very attractive target for easy financial gains. Because they are not regulated by a bank or government, it also makes the job much easier for hackers to transfer and steal.</li>
<li>Identity theft. Given the recent major breaches in personal identifiable information, we expect that there will be an increase in identity theft. Australia is not affected as badly as the US and UK, but with the incoming breach notification laws, we may see more in the news about breaches that were not reported.</li>
<li>Speaking of which, the new breach notification law will become very relevant to Australian businesses, as every business that handles client’s TFN is applicable. This will be a good time to take a good look at your security posture.</li>
</ul>
<p>The post <a href="https://www.adviservoice.com.au/2018/02/top-security-threats-financial-services-2018/">The top security threats to financial services in 2018</a> appeared first on <a href="https://www.adviservoice.com.au">AdviserVoice</a>.</p>
]]></content:encoded>
                                    <wfw:commentRss>https://www.adviservoice.com.au/2018/02/top-security-threats-financial-services-2018/feed/</wfw:commentRss>
                <slash:comments>0</slash:comments>                            </item>
                    <item>
                <title>What happens if you suffer a cyber breach? (If it hasn’t happened already)</title>
                <link>https://www.adviservoice.com.au/2018/01/happens-suffer-cyber-breach-hasnt-happened-already/</link>
                <comments>https://www.adviservoice.com.au/2018/01/happens-suffer-cyber-breach-hasnt-happened-already/#respond</comments>
                <pubDate>Tue, 30 Jan 2018 20:55:56 +0000</pubDate>
                <dc:creator>
                                    </dc:creator>
                		<category><![CDATA[Best Practice]]></category>
                <guid isPermaLink="false">https://adviservoice.com.au/?p=53314</guid>
                                    <description><![CDATA[<div id="attachment_30068" style="width: 260px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-30068" class="size-full wp-image-30068" src="https://adviservoice.com.au/wp-content/uploads/2014/05/cyber-crime-250.jpg" alt="" width="250" height="180" /><p id="caption-attachment-30068" class="wp-caption-text">Do you know what happens after a cyber breach in your business?</p></div>
<h3>First of all, there is quite a reasonable probability that your business has already been hacked and you just don’t know it yet. Cyber attacks are becoming more sophisticated and hackers are finding new ways to penetrate systems whilst going undetected. Cyber attacks are on the rise and are only expected to accelerate in the coming years.</h3>
<p>The bottom line (which in some ways should be enough on its own to propel you into action) is that the average price for a small business to clean up after being hacked stands at approximately $690,000. This includes direct and indirect costs but does not include the headache it will cause you.</p>
<p>Well over half (62%) of cyber-attacks are now targeting small and medium businesses because they are easier to penetrate according to IBM. This amounts to 4,000 attacks per day. These attacks range from stealing personal identity information, holding companies for ransom or draining bank accounts, to stealing information for fraudulent transactions. Keep in mind that not all attacks are external either. Sometimes it could be a disgruntled employee or a human error from a staff member.</p>
<p>Here’s what happens following a cyber incident (and why it costs so much).</p>
<h2>Business disruption</h2>
<p>In the immediate hours to days of an attack, you stand to lose access to the affected IT assets (i.e. computers, servers, internet) because either you may need to take them down to contain a virus outbreak, or they may be so badly damaged they need to be rebuilt or reconfigured. Very likely you will also lose access to some (or all) of your critical data such as accounting information or customer files that enable business operation.  As a result, employee productivity goes out the window.</p>
<p>According to a research (2017 Cost of Data Breach Study: Australia) a business takes 67 days on average to contain a cyber breach. It’s not uncommon to see businesses crippled for days, particularly if the business is dependent on IT in order to function (That’s pretty much everyone these days!). This can be worse if a business is disrupted during its busy season, which could mean losing a large chunk of revenue.</p>
<h2>Loss of data</h2>
<p>Business data is the crown jewel of many modern businesses. In an incident such as a ransomware attack, data could be permanently and completely lost. In other types of attacks, data could be stolen or wiped from the computer or system. If your data was deleted but you perform regular data backups, you might be in luck and only suffer from momentary down time as you restore the backup. However, if you do not have a backup or the data was stolen, then there is no way to recover that without sustaining prolonged down time and brand damage. There is no insurance that you can take to cover the cost of losing the data (assuming that your cyber insurance policies are worth the paper they are printing on)</p>
<p>The business cost associated with recovering the data could range from days at a minimum, to simply going out of business (in the case of not being able to afford to recover or rebuild the data). The U.S. National Cyber Security Alliance found that 60% of small companies that suffered a cyber attack are out of business within six months.</p>
<h2>Brand damage</h2>
<p>Although it’s hard to pin a direct monetary value on this, it is probably most damaging of them all. Losing client trust over a cyber security incident can translate directly into loss of business. Because your clients entrust you with their most sensitive financial and personal information, most will not return if your company has been breached. You will also lose value on the brand that you took years to build as media rush to cover the story of the latest company or business that got hacked.</p>
<h2>Direct financial loss</h2>
<p>If the attacker gains access to any of your banking details they may be able to wire money to accounts they control. You could be hit with ransomware where you will be demanded to pay ransoms in the thousands of dollars.</p>
<h2>Post-breach costs</h2>
<p>If you don’t have pre-arranged plans in place it could be very costly to have security specialists respond to the incident onsite when a cyber breach takes place. The costs also include investigation and remediation costs to patch the security holes. These costs can be upwards of $3,000 per day.</p>
<h2>Notifying customers</h2>
<p>It has become mandatory by law that a business must notify its victims and the regulators about a security breach. The post breach cost includes the cost to create contact database, postal expenditures, handling inbound communications, legal expenditures, and special consultant costs. This could be anywhere from hundreds to thousands of dollars.</p>
<h2>Fines</h2>
<p>Mandatory notification laws and regulatory laws are increasing being tightened. There is now a real prospect of monetary penalty for business that fail to comply with data protection legislations.</p>
<p>The new Data Breach Notification Laws in Australia will take effect in February 2018, and this applies to all businesses that:</p>
<ul>
<li>have a turnover of $3M or more</li>
<li>deal with client TFNs (this applies to virtually all accountants)</li>
<li>trade with client’s personal information (i.e. disclosing or receiving personal information to a third party for profit or as a service)</li>
</ul>
<p>Failure to comply with the notification scheme can result in fines of $360,000 for individuals, and $1.8M for businesses. You will also face increased scrutiny and auditing from the regulators.</p>
<h2>Lawsuit costs</h2>
<p>Customers can now sue companies for becoming victims in identity frauds because of the breach in class action suits, as shown in recent security breaches.</p>
<h2>Conclusion</h2>
<p>Whichever way you look at this, the cost of a cyber breach is staggering, even for a small business. The only way to prevent and contain it is to ensure that you invest in and implement a comprehensive security program that meets industry standards. Security is an aspect in business that many people ignore until it fails. But when it comes to cyber security, a stitch in time really does save nine (or in this case $690,000).</p>
]]></description>
                                            <content:encoded><![CDATA[<div id="attachment_30068" style="width: 260px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-30068" class="size-full wp-image-30068" src="https://adviservoice.com.au/wp-content/uploads/2014/05/cyber-crime-250.jpg" alt="" width="250" height="180" /><p id="caption-attachment-30068" class="wp-caption-text">Do you know what happens after a cyber breach in your business?</p></div>
<h3>First of all, there is quite a reasonable probability that your business has already been hacked and you just don’t know it yet. Cyber attacks are becoming more sophisticated and hackers are finding new ways to penetrate systems whilst going undetected. Cyber attacks are on the rise and are only expected to accelerate in the coming years.</h3>
<p>The bottom line (which in some ways should be enough on its own to propel you into action) is that the average price for a small business to clean up after being hacked stands at approximately $690,000. This includes direct and indirect costs but does not include the headache it will cause you.</p>
<p>Well over half (62%) of cyber-attacks are now targeting small and medium businesses because they are easier to penetrate according to IBM. This amounts to 4,000 attacks per day. These attacks range from stealing personal identity information, holding companies for ransom or draining bank accounts, to stealing information for fraudulent transactions. Keep in mind that not all attacks are external either. Sometimes it could be a disgruntled employee or a human error from a staff member.</p>
<p>Here’s what happens following a cyber incident (and why it costs so much).</p>
<h2>Business disruption</h2>
<p>In the immediate hours to days of an attack, you stand to lose access to the affected IT assets (i.e. computers, servers, internet) because either you may need to take them down to contain a virus outbreak, or they may be so badly damaged they need to be rebuilt or reconfigured. Very likely you will also lose access to some (or all) of your critical data such as accounting information or customer files that enable business operation.  As a result, employee productivity goes out the window.</p>
<p>According to a research (2017 Cost of Data Breach Study: Australia) a business takes 67 days on average to contain a cyber breach. It’s not uncommon to see businesses crippled for days, particularly if the business is dependent on IT in order to function (That’s pretty much everyone these days!). This can be worse if a business is disrupted during its busy season, which could mean losing a large chunk of revenue.</p>
<h2>Loss of data</h2>
<p>Business data is the crown jewel of many modern businesses. In an incident such as a ransomware attack, data could be permanently and completely lost. In other types of attacks, data could be stolen or wiped from the computer or system. If your data was deleted but you perform regular data backups, you might be in luck and only suffer from momentary down time as you restore the backup. However, if you do not have a backup or the data was stolen, then there is no way to recover that without sustaining prolonged down time and brand damage. There is no insurance that you can take to cover the cost of losing the data (assuming that your cyber insurance policies are worth the paper they are printing on)</p>
<p>The business cost associated with recovering the data could range from days at a minimum, to simply going out of business (in the case of not being able to afford to recover or rebuild the data). The U.S. National Cyber Security Alliance found that 60% of small companies that suffered a cyber attack are out of business within six months.</p>
<h2>Brand damage</h2>
<p>Although it’s hard to pin a direct monetary value on this, it is probably most damaging of them all. Losing client trust over a cyber security incident can translate directly into loss of business. Because your clients entrust you with their most sensitive financial and personal information, most will not return if your company has been breached. You will also lose value on the brand that you took years to build as media rush to cover the story of the latest company or business that got hacked.</p>
<h2>Direct financial loss</h2>
<p>If the attacker gains access to any of your banking details they may be able to wire money to accounts they control. You could be hit with ransomware where you will be demanded to pay ransoms in the thousands of dollars.</p>
<h2>Post-breach costs</h2>
<p>If you don’t have pre-arranged plans in place it could be very costly to have security specialists respond to the incident onsite when a cyber breach takes place. The costs also include investigation and remediation costs to patch the security holes. These costs can be upwards of $3,000 per day.</p>
<h2>Notifying customers</h2>
<p>It has become mandatory by law that a business must notify its victims and the regulators about a security breach. The post breach cost includes the cost to create contact database, postal expenditures, handling inbound communications, legal expenditures, and special consultant costs. This could be anywhere from hundreds to thousands of dollars.</p>
<h2>Fines</h2>
<p>Mandatory notification laws and regulatory laws are increasing being tightened. There is now a real prospect of monetary penalty for business that fail to comply with data protection legislations.</p>
<p>The new Data Breach Notification Laws in Australia will take effect in February 2018, and this applies to all businesses that:</p>
<ul>
<li>have a turnover of $3M or more</li>
<li>deal with client TFNs (this applies to virtually all accountants)</li>
<li>trade with client’s personal information (i.e. disclosing or receiving personal information to a third party for profit or as a service)</li>
</ul>
<p>Failure to comply with the notification scheme can result in fines of $360,000 for individuals, and $1.8M for businesses. You will also face increased scrutiny and auditing from the regulators.</p>
<h2>Lawsuit costs</h2>
<p>Customers can now sue companies for becoming victims in identity frauds because of the breach in class action suits, as shown in recent security breaches.</p>
<h2>Conclusion</h2>
<p>Whichever way you look at this, the cost of a cyber breach is staggering, even for a small business. The only way to prevent and contain it is to ensure that you invest in and implement a comprehensive security program that meets industry standards. Security is an aspect in business that many people ignore until it fails. But when it comes to cyber security, a stitch in time really does save nine (or in this case $690,000).</p>
<p>The post <a href="https://www.adviservoice.com.au/2018/01/happens-suffer-cyber-breach-hasnt-happened-already/">What happens if you suffer a cyber breach? (If it hasn’t happened already)</a> appeared first on <a href="https://www.adviservoice.com.au">AdviserVoice</a>.</p>
]]></content:encoded>
                                    <wfw:commentRss>https://www.adviservoice.com.au/2018/01/happens-suffer-cyber-breach-hasnt-happened-already/feed/</wfw:commentRss>
                <slash:comments>0</slash:comments>                            </item>
            </channel>
</rss>