• Skip to primary navigation
  • Skip to main content
  • Skip to footer
CACTUS IT

CACTUS IT

  • Services
    • Consulting
    • Hardware
    • Software
    • Managed IT services
    • Backup/Recovery
  • Contact
  • About
    • Case Studies
    • IT Support Services
  • What’s New
  • Quick Support
  • 01943 666711

News

GDPR IT compliance for Small Businesses

January 23, 2018 by bevanpy

The General Data Protection Regulation is coming this year (25th May 2018) and the time to act is now.

The focus of this blog is on Small Businesses in the UK with limited resources and stretched budgets. It’s a collection of practical steps to take in order to assess your compliance, specifically around your IT systems, IT procedures and IT policies.

There is a lot of guidance and documentation available online, but my information comes straight from ‘the horse’s mouth’, in this case, that’s the Information Commissioner’s Office (ICO). They will be policing the new regulations, so it makes sense to go to them for guidance.

There are many reasons to want to comply. Such as business best practice and striving for customer confidence with a secure and safe storage of personal information… then there are the hefty fines that the ICO can dole out. After the 25th of May, the ICO could levy penalties up to the new limit of €20 million or 4% or annual global turnover, whichever is higher!

Give us a call on 01943 666 711 if you would like to know how we could help.

Let’s look at some practical steps to take for your business:

1: Assess the threat and risk to your business
Review all of the data that you hold and consider the damage or stress it could cause if that data was subject to a security breach.

Follow your business processes and identify where and how your data is stored, collected and disposed of. With this information, you can decide on the appropriate measures for your needs.

2: Cyber Essentials- your Cyber Security Guide
Cyber Essentials is a government backed scheme to help protect businesses against the most common types of cyber threat.

The majority of cyber-attacks can be mitigated by applying good practice configurations and settings in the following 4 areas:

1- Firewalls- implement and configure gateway firewalls and computer firewalls to secure your internet connection.
2- Secure your devices and software- by changing default system passwords and by implementing secure passwords and multi-factor authentication where possible.
3- Control access to your data and systems- minimise damage by giving ‘just enough’ access to data and systems for staff to perform their jobs.
4- Protect yourself from Virus and Malware attacks- only use vendor approved software and always use Anti-Virus software… even better, use Endpoint Protection (Anti-virus, Malware, Firewall and Web control all in one). Always keep your software patched and up to date.

3: Secure your data…. Physically
Theft of filing cabinets and computers holding personal information are a real risk. If you know where your data is, you can better secure it.

There are several practical steps that can be taken to secure your data, like:

-Store sensitive data and computers in a separate, locked room.
-Prevent access to USB drives or CD-ROMs by implementing a device security policy.
-Where personal data is stored on laptops or mobile devices, secure and encrypt those devices.
-If you allow users to BYOD (bring their own device) from home into work, you may want to consider a ‘BYOD policy’ stipulating how that can be used and what (if any) business data can be stored on it.
-Secure your data in the cloud.
-If you decide to move some of your IT services to a Cloud Service Provider, you should assess their security measures to ensure that they are appropriate.

Be aware of what data you have stored in the cloud and implement 2FA (two factor authentication) where possible in case your credentials are compromised.

4: Backup your data
In the event of a disaster (fire, flood, theft, etc.) you need to be back up and running as quickly as possible. Malware and ransomware can also disrupt your data availability, loss of data is a breach of the Data Protection Act (DPA).

Implement a 3-2-1 data backup policy– 3 copies of your data on 2 different media with 1 copy off-site. Having a proper strategy will protect your data in the event of a disaster or ransomware attack (where your data is encrypted).

5: Train your staff
Accidental disclosure and human error are the leading causes of data breaches.

Train your staff on how to recognise threats like phishing emails and malware links. Small businesses often fall victim when publishing items in social media about the business (‘Look at our shiny new delivery of laptops and phones’ could result in a burglary!).

6: Monitor security logs
Regularly reviewing security logs can alert you to a potential vulnerability or attack.

You should be asking your IT provider to help you with this so that you have an automated alerting mechanism.

7: Have a policy so that you know how to react in case of a breach
A good policy will help you to address risks and an incident management document can reduce stress and risk in the event of a breach.

8: Minimise your data
If you don’t need it any longer, delete or dispose of it properly.

Records should be kept up to date and cleared out if they are no longer required. Old computer equipment should be properly disposed of so that no confidential personal data is left on the hard drive.

9: Is your IT contractor doing what they should be?
If you (like many small businesses) outsource any of your IT services, make sure that your provider is treating your data with at least the same respect as you would.

You should have written contracts in place with your IT provider. Visit their premises if you feel it’s appropriate and insure that they are disposing of your equipment properly.

Our advice is to act now, before the 25th of May so that you have time to evaluate the risks and act on your findings.

Please find some links below for further reading, feel free to also contact us via our website, or call us on 01943 666 711 if you have any questions or would like help securing your business critical data and systems?

Cyber Essentials

Preparing for GDPR in 12 steps

Ref: IT security practical guide

Filed Under: News

HP laptop ‘keylogger’ bug discovered

December 11, 2017 by bevanpy

What is a ‘keylogger’  you ask?

‘Keylogging’ is a method of capturing and recording every keystroke you make on your computer from the moment it is turned on. All information from BIOS passwords to credit card and banking information can be collected and harvested by criminals.

How has this happened?

For the second time this year (a buggy audio driver in May 2017 caused a similar problem) HP software that was included with the laptop when it left the factory has been found to include a keylogger bug. The keylogger was a debug trace that the software developers forgot to remove while developing the software.

How do I get this fixed?

HP have fessed up and released an update to rectify the problem. Use the link below to check if your laptop in on the list and to also download the fix.

https://support.hp.com/us-en/document/c05827409

If you are not sure about how to do this, please contact us at Cactus IT and we will be more than happy to help.

Filed Under: News

WiFi security hack discovered

October 19, 2017 by bevanpy

A WiFi security loophole has been found

My WiFi is secure because it’s encrypted, or so I thought. Most modern WiFi networks are secured, we know this because we have to use a password to connect to them and we are told that the connection is encrypted.

Wrong!! A flaw was discovered this week by Mathy Vanhoef, and published here explaining the details of the vulnerability and how it could be exploited.

The weakness was discovered in the WPA2 standard itself and so can be exploited on the majority of modern WiFi networks where the client devices are running the popular Android or Linux operating systems. Microsoft released a patch on October the 10th to fix this issue in Windows operating systems (now is a good time to run your windows updates please everyone).

The attacker set’s up a cloned identical WiFi network including an SSL strip tool that de-crypts information transmitted in a secure web browser using HTTPS. With that, the ‘man-in-the-middle’ attack is ready to harvest your sensitive information.

What can you do to prevent this?

Now is the time to update the firmware on your WiFi access point or router. Don’t delay, check on the manufacturers website or cloud management portal to see if an update is available.

If you need assistance with the update or are not sure how to check the firmware, please contact us at Cactus IT and we will be happy to help.

Filed Under: News

Single Sign On (SSO) company OneLogin has a major security breach

June 1, 2017 by bevanpy

The global online identity management company OneLogin has reported that they have been the victims of a security breach. On the 31st of May 2017 OneLogin released a statement saying:

“Today we detected unauthorized access to OneLogin data in our US data region. We have since blocked this unauthorized access, reported the matter to law enforcement, and are working with an independent security firm to determine how the unauthorized access happened and verify the extent of the impact of this incident. We want our customers to know that the trust they have placed in us is paramount.“

ref: OneLogin press release

All impacted users should have received an email from OneLogin detailing the steps that they should take to secure their accounts and associated passwords.

This is the type of incident that will have to be reported by any and all UK businesses after GDPR regulations come into effect in May 2018. It also shows that EVERYONE is susceptible and that no company can claim to be immune from this type of incident.

The message here for me is to have a plan in place in case this happens to you…. and if you have a OneLogin account, you should have already reset your passwords including any that have been re-used.

Please contact Cactus IT if you have a business in the North of England and would like some help assessing your corporate data security needs. 

Filed Under: News

Microsoft responds to the recent WannaCrypt ransomware

May 14, 2017 by bevanpy

Microsoft has acted quickly in response to the recent WannaCrypt ransomware attack that has seen massive global infections and disruption to critical healthcare services.

If you have any concerns about your business systems or are unsure about how or if this might impact you, Cactus IT are offering a free backup audit* that you are welcome to contact us about.

Engineers at the company have been working through the weekend to better understand the virus and also to release a security patch for the retired Windows XP and Windows Server 2003 products.

The Windows XP and Server 2003 operating systems went end of life in 2014 but are still used in production in many organisations. No security updates have been made publicly available since 2014, but this large scale attack on a known vulnerability has seen a quick response. Microsoft released a security patch earlier this year that patched the vulnerability for Windows Vista, Windows 7, Windows 8 and Windows 8.1. Please run windows updates as soon as possible to make sure that the March update has been installed. The recent attack is reported to not be targeting the Windows 10 operating system.

If you are still using Windows XP or Windows Server 2003 and would like assistance in migrating over to new and fully supported operating system, please contact us at Cactus IT to discuss a migration strategy.

For additional information on this ransomware attack, and to download the Windows XP and Server 2003 patches, please refer to this article from Microsoft: Customer guidance article 

  • Our free backup audit is for an hour of our time and is available for businesses in Yorkshire and surrounding areas- please contact us for more information

Filed Under: News

12th May “Global ransomware offensive”

May 13, 2017 by bevanpy

To date, almost 100 countries have been impacted with the NHS in England and Scotland having to resort to pen and paper. Operations cancelled and Accident and Emergency units shut down by the crippling ransomware infection.

How did this happen?

Short answer: a convincing phishing email (SPAM email) was opened on a Windows PC that was not regularly updated.

A strain of ransomware names “WannaCry” has been delivered by a very well organised and synchronised mass email attack. The convincing email entices the recipient to open an attachment that infects Windows operating systems with the malware that exploits a vulnerability that has not been patched.

Cactus IT offer patch management solutions, please get in touch if your business Servers and PC’s are not regularly updated.

What does the malware do?

Once infected, the malware acts as the logged on user, gaining access to all of the files and folders that the user normally accesses. Systematically locking the files with an encryption key that leaves them completely locked for access and useless without the encryption key. The criminals are asking for a ransom to be paid in Bitcoins (a virtual currency) in exchange for the key to gain access to the locked files.

Only a backup can save you in this situation, Cactus IT offer a free backup audit to make sure that you have the right solution and that is “actually works”. Please contact us for more information.

Why didn’t my anti-virus prevent this ransomware?

The ransomware used in this attack was unique and had never been seen before. Known as a “Zero day attack”, without the signatures of this malware know to Anti-Virus vendors, it is invisible to the software.

A multi-pronged defence works best in this situation- Anti-virus, web filtering, firewall and user training. Please get in touch if you would like assistance with any of these defences.

What do you need to do?

  1. Backup, Backup, Backup!! Always keep a reliable backup of your critical files, with at least one copy “off site”. Follow the 3-2-1 backup rule
  2. Install business class anti-virus software and keep it up to date
  3. Regularly update and patch your Windows operating system and installed software (Windows XP and Server 2003 are no longer supported and no patch is available for this)
  4. Review your folder security access and restrict access rights to folders where possible
  5. Be vigilant and train your staff on how to identify suspicious email attachments and links

Cactus IT can help and assist you, if you are unsure about any of the points above, please contact us for advice.

If you are experiencing a live ransomware attack, then call Action Fraud immediately on 0300 123 20 40.

Filed Under: News

  • « Go to Previous Page
  • Page 1
  • Page 2
  • Page 3
  • Page 4
  • Page 5
  • Page 6
  • Go to Next Page »
  • Services
  • Contact
  • About
    • Case Studies
    • IT Support Services
  • What’s New
  • Quick Support
  • 01943 666 711

Footer

67b East Parade, Ilkley, West Yorkshire LS29 8JP
VAT: GB104229944 United Kingdom

INFO@CACTUS-IT.CO.UK

01943 666 711

  • Services
  • Contact
  • About
    • Case Studies
    • IT Support Services
  • What’s New
  • Quick Support
  • 01943 666 711
INFO@CACTUS-IT.CO.UK
01943 666 711
  • Privacy Policy
  • Terms and conditions
  • Cookie policy
  • IT support Ilkley
  • Technology partners

CACTUS BACKUP LIMITED - TRADING AS 'CACTUS IT' - © 2026
Design by Supafrank