Take Cyber Security “TO HEART”
SCARY STUFF Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) Armada Collective U.S. healthcare company based in Rhode Island threatening The DDoS attack did occur. A ransomware attack in March 2016 compromised a U.S.-based hospital using an outdated server vulnerability, according to a state government official with direct access to the information. located and encrypted more than 100,000 files. This attack denied hospital personnel access to sensitive files for two days… On February 5, 2016, malicious cyber actors encrypted access to patient medical records and other essential computer systems at a Los Angeles, California hospital. Hospital administrators paid the cyber actors a ransom of $17,000 to regain access to their computer systems.
IoT
Let’s Talk About Cyber Security Virus Protection – Practice good cyber hygiene – Flu shots? Mumps? Measles? Malware Ransomware – Los Angeles paid $28,000 – December 30, 2016 Phishing emails Zero day - Not a know vulnerability but seems to match one-”profiling” Weak Passwords Denial Of Service Attack Unencrypted traffic – Packet Sniffing End Of Life and Unpatched Systems – ie: Windows XP – Windows Server 2003
Virus Protection
Malware Protection
Let’s Talk About Phishing To: John Q. Public From: Macy’s Award Center Subject: YOU’VE WON A $50 Gift Card ! Click the logo below to claim your prize
Let’s Talk About Phishing
Spear Phishing
Catphishing Fraudster fabricates an online identity to trick someone-financial gain
Web Browsing BE VERY CAREFUL WHERE YOU GO BE CAREFULL WHERE YOUR FAMILY GOES BE CAREFULL OF SOFTWARE DOWNLOADS BUSINESS? LOSS OF PRODUCTIVITY, LIMIT SITES, HAVE A POLICY
REALLY ??? Strong Passwords !!! Most Common Passwords? 123456 123456789 Qwerty password REALLY ???
Password vs. Passphrase Password Don’t use dictionary words Make it complex Combination of upper AND lower case letters Include numeric Include special characters ()!@#$%^&,*
Password Examples Time it takes to crack a password joekoval - 1 minute JoeKoval - 5 Hours Capitalize certain letters J0eK0val - 21 Hours Add complexity by using numbers. In this example I substituted zeros for the letter O (as in Ocean) J0eK0val.. - 609 YEARS Just by adding the two periods at the end.
Passphrase Much stronger than passwords Easier to remember than a cryptic password Much more difficult to crack EXAMPLES Ilovearainyday – 730years IL0veaR@inyDay – 140449117 years .IL0veaR@inyDay. - 420805123888006 years
What Can You Do? Keep your devices up to date with patches/updates
What Can You Do? Windows / IOS Updates Anti-Virus – Get your inoculations Adobe Product Updates Malwarebytes – FREE download STRONG PASSWORDS/PASSPHRASES Change Default Passwords on all devices ! Especially wireless devices Good Email Hygiene Good Browsing Habits
BACKUP BACKUP BACKUP Cloud
BACKUP BACKUP BACKUP USB THUMB DRIVE Network Area Storage STORE YOUR BACKUPS OFF SITE FULL BACKUP INCREMENTAL BACKUP
LIVE HACKING DEMO
JOSEPH KOVAL 845-608-2505 JOE@SYBER3.COM WWW.SYBER3.COM