User Awareness Program

Storm Worm Reappears

It’s baaack: The bot code used in the infamous, massive Storm botnet that was taken down nearly two years ago is being used to build another spamming botnet. Researchers have reverse-engineered the tweaked version of the original Storm code, which so far has spread som...

The Core Pa$S^^ord!

We’re supposed to use “unique passwords.”  This means that we can’t use the same password for everything.  We should use one for windows, a different one to log into the core, a different one for e-mail, a different one for the imaging program, etc. We’re also supposed to us...

Why is Cyber Security a Problem?

You’ve heard the news stories about credit card numbers being stolen and email viruses spreading. Maybe you’ve even been a victim yourself. One of the best defenses is understanding the risks, what some of the basic terms mean, and what you can do to protect your...

Let’s start a movement!

In spring 2009 I published an article in the Hoosier Banker magazine. The article, entitled “Sometimes Say Never,” was a slightly humorous “manifesto” about the illusion of password aging as a control. The issue seems to be rising again.  It came up i...

The User Level: Keep Your Desk Clean!

Office space is frequented by customers, consultants, vendors, cleaning crews, maintenance and other employees.  As it is crucial to protect sensitive information from disclosure, employees should be taught to not leave nonpublic personal information (also known as NPI) on t...

On-demand Dan!

NEWS RELEASE On-Demand Awareness Training Dan Hadaway CISA,CISM, in partnership with the Indiana Bankers Association has produced an On-demand Video entitled “Board Awareness Training.”  Intended for directors, this video can be watched in short segments in the director’s ow...

New Method of Automobile Break-In

I drove myself and two co-workers to lunch Monday. I chose a parking spot in the rear of the lot and backed into a space (there were no pull-throughs available at the location). This positioned my Chevy Avalanche with the passenger side doors facing away from the rest of the...

Scammers Capitalizing on Tax Season to Spread Zeus

SC Magazine has reported that cybercriminals have been capitalizing on tax season by sending messages that appear to come from the Internal Revenue Service but actually lead to the data-stealing trojan Zeus. According to the article, the messages ask users to follow a link a...

The User Level: Facsimiles!

In today’s technology oriented environment, many organizations send and receive important documents via facsimile. As such, we suggest that you require that your users follow a few guidelines. Management or supervisor authorization should be required prior to the transmiss...

Infotex Webinar – Data Flow Diagramming

If you’ve performed your Cybersecurity Assessment you’re probably wondering, “what is this data flow diagramming thing, why have my auditors never asked me for it, and how do I do one for my bank?” Join us as we run down the answers to those three imp...