Laura Haight is the president of Portfolio, which works with small businesses to incorporate emerging media and technology into its business communications, operations and training.
[break]
Last week, the National Institute of Standards and Technology released its draft of a national framework for cybersecurity. Boring, right? And therein lies the problem at the core of our biggest vulnerability: ourselves.
In June 2010, Ret. Admiral Mike McConnell – former chief of national intelligence and Greenville native – warned that U.S. adversaries have the capability to bring down the US power grid and that the “United States is not prepared for such an attack.”
Perhaps those same adversaries sent a canary into the coalmine three years later when in June 2013, Department of Energy databases were hacked, compromising data on roughly 104,000 federal employees, contractors and dependents.
It’s a scenario that is starting to sound frighteningly familiar.
Across the board, these frameworks, guidelines and takeaways from hacking incidents great and small, reinforce one very basic fact that there is just no getting away from: No one can protect you from yourself.
The strongest code, the highest level of encryption, the most bullet-proof servers can be easily defeated anytime an authenticated user (1) clicks on something they should have deleted; (2) installs something they should have ignored, or (3) gives access authority to an application without understanding what it does.
That is the message from IT pros like Ashley Yellachich, of Yella-Soft, a Greenville software developer and web programming company, I spoke with recently about mobile security.
“You can’t become a digital recluse,” warns Yellachich. “Even if you cut yourself off, you are connected to others. Everything is connected. I know that is very conspiracy theory-ish.”
Yellachich sometimes makes her point with clients by hacking into their cell phones during meetings.
“You have to understand that you don’t have control over it (the technology) anymore,” she said, “and the best thing you can do is educate yourself and learn how to protect yourself.”
From corner bakeries to manufacturers, your business needs a cyber security plan. The FCC has a planning guide that does a great job of compiling key policies and resources for businesses to create their own programs. But the key to any set of policies working is that employees understand them and that they are enforced.
For businesses or individuals, here are some steps to better digital security.
Password security is important, but email addresses are even more so, Yellachich says.
While you may have dozens of passwords, most people have only one or two email addresses. Once a hacker has that, he is halfway to taking over your life and your finances. Get an email address that you don’t use for anything but your financial accounts. Make the password scary-long and complex so there’s no way you’ll remember it, then “write it down and lock it in your safe,” Yellachich says.
You only need to enter this password once, when you set up the account in your email program. Segment this email from other applications. And use it only to receive email from your financial institutions. Never send email from this account.
Hackers thrive on finding bits of personal information about you and then putting it together to enable them to crack into your accounts.
Web sites ask you security questions to help them authenticate you. Do not give them the right information, like your mother’s real maiden name or your first pet’s real name. Will they be harder to remember? Yes they will. That is the point. “The best protection,” says Yellachich, “is obscurity.”
Never use public Wi-Fi.
Although a big selling point for cities like Greenville and businesses like Panera Bread and Starbucks, there’s a balance between security and convenience. If your business has you on the go, invest in a Mi-Fi device that can create a secure VPN (virtual private network).
Have a throwaway email address and use this for online browsing and shopping.
Do not use password software like 1password, KeePass, RoboForm, or LastPass.
I admit that I have used these. But I’ve since stopped. When you think about it, all a hacker has to do is get into one application to find out everything about you. And, if you have mobile apps on your smartphone or tablet that synchronize with the desktop versions, you are even more exposed.
There are significant dangers in the digital world, but we can’t turn back and abandon all the advantages either. Somehow, we learned to lock our car doors, not to talk to strangers on the street, and to be cautious about flashing wads of money around. It’s time for us all to take responsibility for our own actions and be the best, last defense against hackers instead of the weakest link in the chain.