May 19, 2009

GFS Web-Ex Wednesday

gfs2008(small)

GraVoc is demonstrating the use of the GFS field service management system in a Web-Ex Wednesday morning.  Several businesses are already participating in the event, which begins promptly at 9:00 AM and will last for about an hour.

GFS is a powerful, easy-to-use business process management system built specifically for the service industry, as it manages the entire lifespan of a service call from entry and dispatch to billing and history.  Due to GFS’s ease of use and rapid accessibility of information, clients are wasting less time tracking hours and inventory, increasing customer service capacity, financial transparency, and profitability.

Jason Vlacich and Michael Roma from GraVoc Associates will demonstrate the use of the software, its features, and most importantly, what problems it can potentially solve for your business.  There is still availability for this free informational webinar.  You can register for this event online at the following link:  http://www.gravocsoftware.com/gfswebinar.html.  On the form, you have input on what questions you would like answered in Wednesday’s event.

GraVoc Associates, Inc, celebrating fifteen years of business, is a full-service consulting firm located in Peabody, Massachusetts. GraVoc prides itself on its ability to outfit clients in the Greater Boston area, New England, and beyond with quality software solutions that result in better business decisions, more productivity, and a prompt ROI. For more information about the GFS application, please visit gravocsoftware.com, and for more information about GraVoc, please visit GraVoc.com.

May 7, 2009

The “Year of the Insider Threat?”

What typically comes to mind when a person thinks of information security breaches is a sophisticated hacker maliciously using his or her technological manipulation skills to gain access to an organization’s information systems.  For the banking industry, this is similar to someone putting a mask on and robbing the bank.

However, perhaps partially due to the weakened economy and widespread concerns about job security, the threat of insiders—i.e. employees, vendors, or consultants—is a threat that is growing at an alarming rate.  This is similar to an employee pocketing money from a vault or from a cash register.

Statistics indicate that in 2008, the number of insider threats being realized skyrocketed.  Endpoint Security reports that out of all data breaches in 2008, insiders were responsible for 15.7% of them.  This is more than double the 2007 figure.  Logic would indicate that employees or consultants, fearing layoffs or due to other conditions of economic uncertainty, have more of a motive to compromise their own company’s systems and data.  BankInfoSecurity wonders if 2009 is the “Year of the Insider Threat” while offering advice on how to prevent insider threats from being realized.  In a whitepaper by Kevin Prince of Perimeter eSecurity, malicious insiders are identified as a “rising threat” and the biggest “network security threat of 2009.”

The threats are there and are largely unavoidable.  Every organization will have trusted insiders who have access to information and therefore have the capabilities to compromise that information.  However, there are many ways to control the risks associated with malicious insiders. 

Limiting access to information to those with a clear need-to-know is a generally-accepted best practice, and making sure insiders are following this “need-to-know” as well as information security policies is also a simple but crucial mitigating control.  It may be worth considering software that inhibits a user’s ability to use data storage devices such as PDAs, flash drives, or CD-ROMs.  But constant attention and diligence towards information systems, including upgrading technologies in a timely manner and monitoring access logs for suspicious activity is necessary.

Preventing insider threats must be an enterprise-wide effort.  Background checks should be considered before hiring a person with access to sensitive information, and procedures regarding issuing and removing access should be written and followed.  Policies should be drafted about responding to an insider threat.  With information more portable than ever, enterprise-wide decisions should consider the feasibility of a data breach caused by a malicious insider, and trying to minimize the likelihood and impact of such an event happening should be a consideration in these decisions.

GraVoc Associates, Inc., based outside of Boston in Peabody, MA, is celebrating fifteen years of providing consulting services in the practices of information security, information systems, and professional and technical services.  GraVoc is committed to informing clients about the latest information security threats, and their information security team is willing to help your business achieve your compliance with regulations and keep your information safe.  For more information about the company, please visit www.gravoc.com or call the GraVoc offices at 978-538-9055.

May 4, 2009

If It Blows Over…

The latest reports of the swine flu outbreak indicate that the virus is not as bad as first feared, and it is starting to wane in its epicenter of Mexico.  Of course, this is very good news, but it is important to note that the world is certainly not “out of the woods.”  The WHO has not downgraded the alert phase from 5, and it is unlikely they will do so anytime soon.

This is partially because historically, many flu pandemics do indeed start in the spring, then wane, but come back even stronger during the traditional flu season that starts around December.  The H1N1 virus may follow that trend.  Luckily, that gives scientists time to develop a vaccine for the virus so that the impact of it will more closely resemble the impact of the seasonal flu instead of a catastrophic event.  It also gives businesses that may have been panicking about swine flu more time to plan for a pandemic event.

If the crisis does indeed blow over, it serves as a very relevant wake-up call.  If you saw your business start to panic due to lack of preparedness for a pandemic, GraVoc continues to be here to help.

GraVoc Associates, based just outside of Boston in Peabody, Massachusetts, is celebrating fifteen years of business in information security, information systems, and technology and professional services.  With years of experience in business continuity and pandemic event planning, GraVoc is committed to minimizing the impact of any flu outbreak on its clients’ business operations.  For more information, please visit the new GraVoc.com or call the GraVoc offices at 978-538-9055.

May 1, 2009

CNN: Companies Preparing For Worst

There is a useful article available currently on CNN.com regarding some of the largest companies in the country preparing for the worst by starting to implement their pandemic contingency plans.  This is a good sign, as these businesses represent a significant portion of the economy.  A disruption in business operations for firms and institutions of all sizes significantly decreases the affected business’s income.  Therefore, it is important for businesses of all sizes to begin instituting pandemic plans similar to the ones being activated by these large companies.

The article relies on analysis by the Gartner research firm, including vice president Ken McGee.  From the article:

For companies that already have contingency plans in place, he says that they need to halt all other activities and direct all their resources to activating their plans. He suggests testing home networks of critical employees to make sure they are working. He also suggests talking with vendors to see their level of preparedness.

"This is not a snow day," he said. "Companies need to review their plans and find their weaknesses and gaps readiness. And then they need to fill them immediately."

For companies that do not have a plan in place already, McGee says they need to be aware of hotspots where the virus is already infecting people, and they should be preparing to set up home networks and possibly shut down their offices in those regions.

The CNN article also refers to the blog of Gartner analyst Nick Jones, where Jones outlines how companies must consider exploiting technology to minimize business disruption while keeping employees safe from a pandemic.  Thanks to technology like telecommuting/remote access from employees’ homes, wireless broadband, and high-capacity mobile devices, it is certainly possible to keep people working while closing an office location.  It is, however, essential that your organization would not be technologically overwhelmed by a significant increase of telecommuting.

GraVoc Associates, based in Peabody, MA, is willing to help your business design contingency plans for pandemic events and other disasters that put business continuity in jeopardy.  As GraVoc celebrates fifteen years of business in greater Boston, the GraVoc information security team has many years’ experience in business continuity and pandemic planning.  Please don’t hesitate to browse past posts regarding the swine flu outbreak in the GraVoc news blog.  For more information about the company, please visit the website at www.gravoc.com.  Also feel free to call GraVoc at 978-538-9055 if you need assistance in planning and preparing for a pandemic.

April 29, 2009

Swine Flu Update – April 29

For the first time since the advent of the rating system, the World Health Organization (WHO) has raised the pandemic alert phase to Phase 5.

According to the WHO, Phase 5 is characterized by “widespread human infection” and is described as a “strong signal that a pandemic is imminent and that the time to finalize the organization, communication, and implementation of the planned mitigation measures is short.”

With worldwide travel significantly more common than it was in 1968, the date of the last worldwide influenza pandemic, this pandemic may spread across the globe more quickly than ever before.  However, as the WHO’s director-general pointed out, the world is more prepared for a flu pandemic than ever before due to medical technology and rapid electronic communication so that more information is readily available about the pandemic situation.

In the last two days, GraVoc has made an attempt to reach out to customers and the public to alert them about taking appropriate measures in accordance to pandemic event response policies.  With the alert level raised to Phase 5, the urgency of pandemic planning becomes more critical.

Organizations must plan very quickly how to cope with public fear, how to assist customers prevent the spread of influenza by offering services and products in locations, and means of communication without face-to-face contact.  Plans should be in place for communication with public officials, service providers, the media, employees, and customers so that business can continue interrupted despite a crisis that could result in a significant economic impact.

Furthermore, organizations should be in the process of finalizing their pandemic response plans, because the threats are no longer theoretical, but very real.  Avenues should be in place for immediate activation of a pandemic response procedure, and organizations should consider the costs and benefits of whether the procedures should indeed be activated.

GraVoc Associates, Inc, based in Peabody, MA, has substantial experience in helping organizations design business continuity and pandemic event response planning.  In this time of crisis, we are frequently updating the GraVoc News Blog (http://gravoc.blogspot.com) as we aim to help.  If you would like further assistance in preventing business disruption in the event of a disaster or a pandemic event, we strongly encourage you to contact GraVoc’s information security team at 978-538-9055.  We are committed to helping our customers’ bottom lines, and making sure businesses continue their processes as normally as possible is a crucial part of enhancing long-term profitability.

April 28, 2009

Swine Flu Blog

Regina Phelps of Emergency Management and Safety Solutions, has set up a blog specifically addressing the current swine flu crisis and how companies should plan accordingly to maintain business continuity.

The blog is available at http://emssolutionsinc.wordpress.com.

Swine Flu Update – April 28

In an emergency meeting Monday, the World Health Organization upgraded the influenza pandemic alert phase to a Phase 4.  Phase 4 is defined as a phase of sustained human-to-human transmission that can cause “community-level outbreaks,” so after the last few days, this came as no surprise.  Though a full-blown pandemic is not yet inevitable, the upgrade from Phase 3 to Phase 4 represents a significantly heightened likelihood of such an event.

As addressed in emails to be sent out to GraVoc business continuity and information security customers, it is recommended that organizations such as banks and credit unions start taking significant precautions immediately in response to the upgrade from Phase 3 to Phase 4.  As many cases of the pandemic event have already taken place in North America and specifically the United States, taking the following actions is a high priority:

  • Amid employees’ pandemic fears, your organization should take appropriate measures to cope with employee absenteeism, such as considering a skeleton crew roster and changes to telecommuting and sick leave policy.
  • Provide customers and employees with flu prevention/hygiene-related products in each location.
  • Consider the consequences of public panic, such as increased demand for products and services and potential interrupted service from vendors, and make plans accordingly.
  • Review plans and procedures for closing a location should the pandemic event strike the workplace.
  • Remain aware of the current developments of swine flu through news sources or other organizations.
  • Inform customers about ways they can conduct business with the organization electronically.

For more information or advice on how to maintain business continuity, please do not hesitate to contact the GraVoc Associates Information Security team at 978-538-9055.  GraVoc, based in Peabody, MA is celebrating fifteen years of business in the Boston area, and has many years’ experience helping clients design business continuity plans and pandemic event policies that have gained the strong approval of regulatory agencies such as the FDIC and NCUA.  For more information on the company, please visit www.gravoc.com, and for continued updates on the swine flu situation with specific attention to business continuity efforts, please consult the GraVoc News Blog at http://gravoc.blogspot.com.