Supporting Users While Safeguarding Against Social Engineering

Supporting Users While Safeguarding Against Social Engineering

By Eric Egolf, CEO

Cyberattacks have evolved in many ways, and one major concern on the rise is the surge in social engineering threats targeting support teams. The MGM hacks made headlines recently for this when a straightforward call to the help desk resulted in a major security breach. It was a wake-up call to the IT industry at large. 

In that case, a hacker manipulated the help desk into changing a user’s phone number. The attacker then had control over not only the user’s credentials but also the power to approve MFA requests, granting them access to the company’s systems. This unfortunate event underscored the urgent need to verify users’ identities before implementing security and access-related changes. 

Focusing on User Authentication Solutions 

IT providers and support teams are increasingly focused on the importance of verifying user identities before making critical security changes. Think password changes, MFA settings, or access permissions. The goal is to ensure that these requests are coming from legitimate sources within the organization. 

CIO Solutions has utilized various techniques, like passphrases, for high-compliance businesses. While effective, these methods aren’t suitable for widespread use due to their potential clunkiness and incompatibility with our “First Call Resolution” support approach. 

So, what are the more effective strategies to bridge this security gap? 

  • User MFA Verification: Registering cell phones for currently approved users and requesting MFA during support interactions. 

When users contact support for significant security-related changes (such as password modifications, security access grants, or MFA number updates), the support agent would send an MFA verification code to that user’s registered number. The user would then need to confirm their identity by sharing the code with the support agent before the change could be made. 

  • Designated Approval Contacts: Establishing pre-designated company contacts to serve as Security Approvers. 

In situations where registering all users’ cell phone numbers isn’t possible, businesses would designate Security Approvers beforehand. When employees contact support for security-related changes, the support team would contact the pre-designated Security Approver for verification and approval, adding an extra layer of validation.  

These methods are some examples of how the issue may be addressed, and they are continually evolving. The goal is simple: ensure every security-impacting change is authorized as legitimate. Note: Regular support requests wouldn’t require this verification, only security-impacting ones. 

But here’s the thing—these methods require a team effort between your company and your IT team. Keeping databases updated with accurate employee information and increasing communication between your company and your IT provider is crucial. 

At CIO Solutions, we are actively evaluating and implementing the best solutions to balance increased security measures without disrupting the support experience —we understand the importance of both.

As business leaders, we need to acknowledge the value of these security measures, as well as the risk of not implementing them. Together, by remaining proactive and collaborative, we can continue to strengthen our defenses and stay ahead of evolving cyber threats.  


Not a client yet, but wondering how to improve your IT experience? Let’s talk!

Advanced Remote Desktop (RDP) Solutions for Central and Southern California Businesses

Modern business operations rely significantly on seamless remote team operations. It is more important than ever for businesses to have access to secure, seamless, and flexible solutions that support hybrid and remote workforces. For Central and Southern California businesses seeking optimal efficiency, enhanced security, and streamlined operations, a game-changing solution exists Advanced remote desktop (RDP) hosting by CIO Solutions, AKA: The CIO Private Cloud.

Powered by Citrix technology, this advanced RDP solution transcends traditional remote desktop functionalities, revolutionizing how businesses manage their operations.

Learn why businesses across Fresno, San Luis Obispo, Santa Barbara, and Ventura Counties opt for CIO Solutions’ Citrix Desktops for their RDP solution.

Video Conferencing App Compatibility

Choosing an RDP solution built on Citrix technology offers significant benefits including its compatibility with prevalent business apps. Today, businesses rely heavily on Zoom and Microsoft Teams for video conferences and communications within their hosted desktop environment. Citrix technology optimizes these platforms and provides the essential features to effectively replicate a typical desktop experience.

Unparalleled Security and Efficiency

Many small and midsized businesses operate in technical environments comprised of disparate systems with varying OS levels, posing security risks with multiple points of vulnerability.

Contrast this with the Citrix desktop RDP solution which offers a fortified security setup by centralizing data and management, ensuring a significantly higher level of security and control for your business.

Streamlined Updates and Enhanced Productivity

In addition to being more secure, RDP solutions are easy to update, unlike the labor-intensive and often error-prone process of updating individual machines.

The ability to update a gold image with new software across the entire organization is a key capability that sets Citrix Desktops apart. This reliably streamlines the process which is invaluable for reducing downtime and supporting productivity.

Optimal Performance for Traditional Applications

For applications lacking equivalent browser versions, the Citrix Desktop guarantees optimal performance. This ensures that traditional client-server applications run seamlessly in your RDP solution so your business can still run these solutions in the Cloud Desktop solution despite the absence of web-based alternatives.

Robust Infrastructure and Support Options

CIO Solutions’ RDP solution, The CIO Private Cloud, provides unparalleled reliability and performance. It is implemented in highly redundant, secure data centers safeguarded from natural disasters. The cutting-edge hardware combined with layers of redundancy and security offers businesses access to an enterprise-level quality solution at a fraction of the cost of attempting remote desktops themselves.

Additionally, with The CIO Private Cloud, your business has the flexibility of choosing between full end-user support services with CIO Solutions, or the option to leverage existing internal IT teams. This offers businesses the freedom to optimize their IT functions based on their specific needs.

Adaptive Work Environments

A good RDP solution should empower employees to maintain consistent productivity, regardless of location. Today’s requirement for seamless, flexible solutions for remote and hybrid work setups is met by The CIO Private Cloud, the most robust RDP solution empowering employees to transition easily and maintain a seamless, secure experience.

Conclusion

CIO Solutions’ advanced Remote Desktop (RDP) hosting services built on Citrix technology support the paradigm shift of modern business operations. From bolstered security to enhanced productivity and versatility, this proven solution is a catalyst for seamless, efficient, and secure business operations in Central and Southern California.

Catering to businesses across Fresno, San Luis Obispo, Santa Barbara, and Ventura counties, CIO Solutions offers a cutting-edge approach to remote desktop hosting. Experience the power of advanced remote desktop solutions and transform the way your business works in today’s dynamic landscape.

Let’s talk! Contact us today to explore your options.

How To: Properly Power your Electronics

By Mike Shinn, Support Manager

IN THIS ARTICLE: 

For years California has hoped for more rain – we certainly could use the water. Unfortunately, with each storm comes additional problems in the form of power glitches. California is plagued by power outages, blips, surges, and everything in between. The cost to our businesses and homes is significant. 

The good news is, there are a number of things you can do to proactively prevent a power-related IT catastrophe which will save you money and sanity in the long run. 

Power Distribution Considerations

In addition to your computer, you can easily count half a dozen additional plugs required to get work done: a monitor, printer, speakers, maybe a phone charger or headset. These all require power to charge up or stay on.  

Wall outlets typically have two sockets and can therefore provide power for two items. But, with a simple power strip, you can easily turn one socket into 6 or 8. However, power strips aren’t one size fits all. Here are some dos and don’ts to keep in mind when choosing a power strip for your electronics:  

Don’t use cheap power strips for valuable electronics

Inexpensive power strips are common and can even be purchased in the local grocery store. But it’s important to remember that you get what you pay for.

These may power your items but using a bargain-rate power source poses risks to valuable technology (like in the case of a power surge). These types of cheap power strips should be avoided.

Don’t “daisy chain” multiple power strips

If you need more power outlets, it may seem like an easy solution to just plug one power strip into another. Power strips are not built to handle infinite power distribution, only distribution to the number of outlets they are designed for.  

This can cause problems to your equipment and be downright dangerous. I commonly see people doing this. In one case, I had to put out a fire caused by multiple strips plugged into one another. 

DO: Use power strips with “power conditioning” and the right number of sockets

You are always better off purchasing a proper power-conditioned strip that has enough outlets built in for your needs.  

Make sure your power strip says “power conditioning” on the box as well as on the strip itself. This means that it will take the “dirty power” coming out of the wall and turn it into the clean power needed to power electronics safely.  

What’s more – many power conditioners have surge-protection built in. This means they can absorb a power surge after an outage. By design, a surge may kill your power strip with surge protection. But it’s always better (and less costly) to have to replace that strip and not all of the equipment plugged into it!  

Power conditioners only cost slightly more than a run of the mill power strip and can easily be found at local electronics retailers or online (even twelve to sixteen-port strips!). 

What about Backup Batteries?

Sometimes equipment requires even more power protection than a power conditioner. This is where a backup battery (also known as a “UPS” or “uninterruptible power supply”) with built-in power conditioning and surge protection comes in. These are designed to keep your computer or other equipment running even during a brief outage.  

These power supplies will often have two sides to them – one will say “surge protection-only” and the other will say “surge and battery.” In this case, it is wise to plug your computer and other essential equipment into the battery section. Leave your monitors, phone charger, printer, or other items in the surge-only section. If you have multiple monitors and absolutely need a monitor to be backed up by a battery, consider only plugging one into the battery section. The more items you have plugged into the battery backup, the less time it will live when there is an outage. 

Battery backups like this typically cost between $50 and $100 depending on the number of outlets or length of battery. Most power outages are under 5 minutes in length, but if you have ever lost a document that you were working on due to an outage, chances are you’d gladly go back to pay the $50 if you could. 

Be Choosy With Your Power

When it comes to powering your critical electronics, it’s important to be deliberate about the power supply equipment you’re using. And it’s good to be choosy about what else gets to share space with them! 

Having a backup battery (UPS) can be highly beneficial, but not all equipment should be plugged into it. Anything with a motor (refrigerators or pumps), hair dryers, air conditioners, air compressors or major electronics will trip and often break a battery backup unit. 

It’s important for the safety of your electronics (and yourself) that you consider how you’re powering them!  


NOTE: CIO Solutions offers additional paid tools to help flag emails based on a threshold of legitimacy. Please reach out to explore your options if this is of interest! 

Not a client yet? Let’s talk!

Email Safety | 5 Ways to Spot a “Phishy” Email

Quick Tips & Best Practices

We rely on email for many functions of business today. This makes it an excellent tool for bad actors to exploit. Email is one of the quickest and easiest opportunities threat actors have at their disposal.

Threat actors have gotten good at using our busy days and frequent use of email to trick users into providing information, making mistakes, or taking actions. That may look like tricking an Accounts Payable employee into wiring payments to a different account number or getting a user to enter login credentials by pretending to be a well-known company and sending a fake “response required”, “unusual activity”, or “update account details” email.

In the busy day-to-day, here are a couple of tips to keep in mind for practicing email safety both in your work and personal life so you don’t fall victim to these manipulation tactics.

5 Signs an Email Is Suspicious

Bad actors find success when their targets are busy, hurried, and accept things at face value. When you get a suspicious email, PAUSE and check to see if any of these signs are present:

P Passwords or sensitive info requested Pay attention to what the email is asking you to provide (passwords, social security numbers, account information, credit card info, etc.). This information shouldn’t be shared via email.
A Attachments you weren’t expecting Don’t trust attachments you didn’t ask for and avoid opening invoices, Word docs, and any other attachments that you didn’t request or weren’t expecting
U Urgency or intensity in the tone Notice the tone- is the sender requesting secrecy, stating something is past due or urgent, and generally trying to make you react quickly?
S Sender name & domain don’t match Check if the sender’s display name and email address don’t match, (name shows as John Smith, but the email is ra4azeu526@gmail.com) or if the email address domain is unfamiliar (usually from @company.com but this email is coming from @business.com)
E Errors in spelling & grammar Particularly from reputable, large companies, pay attention to spelling and grammar mistakes

Best practices if you think an email is suspicious:

  • HOVER, don’t click
    • Don’t blindly trust the display text, use your cursor to hover over links. This will display what the embedded link address is and give you more information. When in doubt, don’t click.
  • DELETE, don’t engage
    • Err on the side of caution and delete the email from your inbox rather than unsubscribing or engaging with it at all.
  • VERIFY, use a different method of communication to verify the source
    • Don’t respond to the email. Call, text, or chat with colleagues/vendors/executives to verify that email requests are from them.
  • LEAVE, go directly to vendor websites instead of through the email
    • Open your browser and go directly to the company’s website to log in to any accounts, change passwords, etc. Don’t go from any links in the email to reset passwords.

When it comes to email safety, be extremely skeptical.

This is an area in which it’s good to be hesitant, exercise extreme caution, and be wary. Email is quick and convenient, but now more than ever it’s important to slow down, stay vigilant, verify often, and change up communication methods.  

 


Are you a current client of CIO Solutions? Contact your vCIO or Customer Success Manager to continue the conversation around your IT security and anti-phishing education tools!   

Not a client yet, but curious about maturing your IT solutions? Let’s talk!