Installing Patches Immediately Helps Protect Your Organization from Cyber Vulnerabilities
Posted on
Cyber criminals often exploit known or not yet known vulnerabilities of the Operating System and/or other critical systems, such as a web server or a database, in order to penetrate your network/systems. In the recent WannaCry attack, hackers exploited the Microsoft Windows Server Message Block protocol and encrypted data demanding ransomware. There was a patch that Microsoft had provided but thousands of systems around the world had not yet installed the security update.
In honor of October being Cyber-security awareness month, AAFCPAs would like to take this moment to remind our clients again of the critical importance of taking measures to protect against malicious cyber-attacks.
What can you do to minimize your vulnerabilities?
Have desktops/workstations on auto download / auto install mode so the latest patches are automatically installed on the system.
Schedule regular maintenance windows to apply patches, combined with “emergency” downtimes when critical patches need to be applied as soon as possible. Additionally, consider investing in a high availability system, i.e. two systems running parallel, which would allow you to apply patches easier with minimal down-time.
Regular maintenance should also include infrastructure systems, including: firewalls, routers, switches, printers, etc. These systems need patching as well because they are part of your network, and provide opportunities for exploitation.
Run regular, annual at a minimum, vulnerability tests which can help identify your risks.
Be aware of the latest vulnerabilities. You may subscribe to information services such as https://www.us-cert.gov/, an official website of the Department of Homeland Security, and managed by the US Computer Emergency Readiness Team.
AAFCPAs advises clients to take a disciplined approach to cyber-security in order to better guard against, and minimize your organization’s risk of becoming a victim. Patching is one tool making it harder for hackers to penetrate your environment and steal your data.
To schedule a cyber-security assessment, or for specific advice on how to best protect your organization against cyber-attacks, please contact James Jumes at 774.512.4062, jjumes@nullaafcpa.com, Vassilis Kontoglis at 774.512.4069, vkontoglis@nullaafcpa.com or your AAFCPAs partner.
James joined AAFCPAs in 2013 to lead the firm’s Business Process & IT Consulting practice. He leads a team of senior technologist in the delivery of solutions related to business intelligence & productivity, information risk management and cybersecurity, and special IT attestations, compliance, and certifications. His goal is to strengthen the links between people, process, and technology, which increases productivity and drives business growth.
James has more than 30 years of experience working with information technology …
Vassilis has 20+ years’ proven experience providing business intelligence, productivity, information risk management, and cybersecurity solutions. He is a critical resource in keeping clients and the firm on the forefront of transformative technologies while mitigating risks that come along with these advancements.
Vassilis leads the delivery of Robotic Process Automation solutions at AAFCPAs. He understands the unique requirements to achieve RPA success, including proper design, planning, implementation, and governance. He works collaboratively with clients and cross-functional …
0
We use cookies to ensure we give you the best experience on our website. By continuing your visit, you consent to the use of these cookies. See our:
Functional cookies
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.